PRIVACY

Deputy Shell Privacy Policy

Effective date: August 1, 2026

Policy version: 1.2

1. Who operates Deputy Shell

Deputy Shell is developed and operated by:

Gerasimos Simotas

Independent developer operating from Vienna, Austria

Privacy contact: privacy@deputyshell.com

Gerasimos Simotas is the data controller for personal data processed by Deputy Shell where the developer determines the purposes and means of processing.

Deputy Shell is offered globally. Depending on where you live, additional local privacy laws and rights may apply.

2. About Deputy Shell

Deputy Shell is an Android terminal and mobile development workspace. It allows users to create and manage local workspaces, run terminal sessions, import and export files, use development tools, and interact with supported third-party coding agents such as Codex.

Most Deputy Shell functionality operates locally on the user's device.

Deputy Shell does not currently provide its own:

  • User-account system;
  • Cloud storage;
  • Remote workspace hosting;
  • Advertising service;
  • Behavioural advertising system; or
  • Subscription account system.

3. Data stored locally on your device

Deputy Shell may create and store the following information in app-private Android storage:

  • Projects and workspace files;
  • Project, workspace and session names;
  • Session status and session metadata;
  • Current and previous working-directory information;
  • Retained terminal history and terminal display state;
  • Runtime files and installed development tools;
  • Application preferences and privacy choices;
  • Workspace import and export transaction files;
  • Diagnostic staging files;
  • Agent configuration and control files; and
  • Authentication and credential files used by supported agents, including Codex.

This information is processed locally to provide the functions requested by the user.

The Deputy Shell developer does not have remote access to this information merely because it is stored in the application. Local information reaches the developer only if the user deliberately sends or exports it.

Android cloud backup and device-transfer backup are disabled for Deputy Shell's app-private data.

Local data normally remains on the device until the user:

  • Deletes it through an available Deputy Shell function;
  • Clears Deputy Shell's app data through Android settings; or
  • Uninstalls Deputy Shell.

Some Deputy Shell actions remove an item from the application interface without deleting the underlying workspace files. The application provides a warning where this applies.

Files previously exported outside Deputy Shell's private storage are not removed when the application is uninstalled or its data is cleared.

Retained terminal context

Deputy Shell stores recent terminal output locally so that users can reopen and review retained sessions.

Retained terminal context may contain commands, terminal output, prompts, source-code excerpts, file paths, error messages, credentials or other information displayed during a terminal session.

Retained terminal context is limited to approximately 1 MB per session. It remains locally on the device until the corresponding retained session is deleted, application data is cleared, or Deputy Shell is uninstalled.

Retained terminal context is not included in default diagnostic exports.

Local operational and agent-control files

Deputy Shell may create local operational files inside a workspace's private .agent directory.

These files support functions such as:

  • Runtime operation;
  • Session lifecycle management;
  • Compatibility checks;
  • Agent approval handling;
  • Safety checks; and
  • Technical troubleshooting.

Depending on the operation, these local files may contain:

  • Timestamps;
  • Session identifiers or session names;
  • Runtime and session states;
  • Technical error information;
  • Redacted authentication-URL metadata;
  • Approval identifiers;
  • Approval requests and decisions;
  • Command, purpose, reason, risk or scope information supplied in an agent approval request; and
  • Compatibility-test results.

These files are stored locally in app-private storage. They are not automatically uploaded.

The .agent directory is excluded from standard workspace ZIP exports. Contents of operational logs and agent-control files are also excluded from default diagnostic exports.

These files remain on the device until the relevant workspace or application data is deleted, or Deputy Shell is uninstalled.

4. Terminal commands and user-directed network activity

Deputy Shell provides a general-purpose terminal. Commands, agents, project code and development tools used through the terminal may communicate with external services.

Examples include:

  • Git repositories and hosting providers;
  • Package registries such as npm or Python package indexes;
  • Websites and APIs;
  • Codex and other supported AI agents;
  • Commands such as Git, curl, SSH, SCP or SFTP;
  • User-installed project dependencies; and
  • Software or scripts created or executed by the user.

Deputy Shell does not automatically upload a user's entire workspace to the Deputy Shell developer.

However, a command, script, dependency or third-party tool may read and transmit files, source code, terminal content, credentials or other information when instructed by the user or when required for the tool's operation.

Users are responsible for reviewing commands, agent actions, project dependencies and external destinations before allowing information to be transmitted.

Information sent to an external service is handled under that service's own terms, privacy policy, security practices and retention rules.

5. Codex and OpenAI

Codex integration is optional. Deputy Shell works without Codex.

Deputy Shell includes the Codex CLI, open-source software published by OpenAI under the Apache License 2.0. Deputy Shell distributes the client software; it does not provide OpenAI's hosted services.

To use Codex, users must sign in with their own eligible OpenAI account or use their own supported API key. Deputy Shell does not provide or resell OpenAI accounts, credits, subscriptions or hosted AI services.

When a user signs in to or uses Codex, information required to perform the requested task may be transmitted directly to OpenAI. Depending on the task and permissions given to Codex, this may include:

  • Prompts and instructions;
  • Terminal input and output;
  • Source code;
  • Workspace files or portions of files;
  • Project context;
  • Generated responses;
  • Technical error information;
  • OpenAI authentication and account information; and
  • Device, service and network metadata.

Deputy Shell stores supported Codex authentication files locally in app-private storage so that the user does not need to sign in separately for every workspace.

The Deputy Shell developer does not receive the user's OpenAI password and does not control the user's OpenAI account.

Before the first OpenAI authentication handoff, Deputy Shell presents a Codex privacy disclosure. Deputy Shell stores the version of that disclosure and the time the user chose to continue locally in application preferences.

The disclosure acknowledgement is not intentionally sent to Firebase Analytics or Crashlytics.

OpenAI determines how information submitted through Codex is processed, retained and used under the terms, privacy policy, account settings, data controls and service arrangements applicable to the user's OpenAI account or API use.

Data-use rules may differ between individual OpenAI services, business plans, enterprise services and API services. Users should review the current OpenAI terms, privacy information and data controls applicable to their account.

Deputy Shell does not intentionally include Codex prompts, generated responses or workspace contents in Deputy Shell's Firebase Analytics or Crashlytics telemetry.

Codex availability, usage limits and charges depend on the user's OpenAI account, plan and agreement and may change.

Deputy Shell is an independent product and is not affiliated with or endorsed by OpenAI.

Users should not submit credentials, secrets, confidential source code, personal data or other sensitive information to Codex unless they intend that information to be processed by OpenAI.

Requests concerning information held by OpenAI must generally be directed to OpenAI.

6. File imports and exports

Deputy Shell uses Android's system document picker when a user:

  • Selects a file to import;
  • Selects an export destination;
  • Exports a workspace ZIP; or
  • Exports a diagnostics file.

Deputy Shell does not currently provide or connect to its own cloud-storage service and does not automatically upload imported or exported files.

Android controls which locations and document-provider applications appear in the system picker.

If a user deliberately selects a location supplied by another application or storage provider, that provider may receive and process the selected file under its own privacy policy.

Exported files remain under the user's control at the selected destination. Deputy Shell cannot automatically delete copies stored outside its app-private storage.

Workspace export exclusions

Standard workspace ZIP exports are designed to exclude common sensitive, generated or unnecessary content, including:

  • .agent directories;
  • Agent authentication directories;
  • Codex configuration directories;
  • SSH directories;
  • Git metadata;
  • Session-state directories;
  • .env files;
  • Files or paths containing common authentication or token references;
  • Private-key files;
  • node_modules;
  • Build directories;
  • Distribution directories; and
  • Gradle cache directories.

These exclusions reduce accidental disclosure but cannot guarantee that every sensitive file will be detected.

Users should review exported archives before sharing them.

7. Diagnostics exports

Diagnostics exports are created only when the user requests them. Deputy Shell does not automatically upload diagnostic exports.

After a diagnostics export is created, Deputy Shell may open Android's sharing interface with support@deputyshell.com suggested as the recipient. The user remains in control of whether the file is sent and which application is used to send it.

A default diagnostics export may include technical metadata such as:

  • Deputy Shell package, version and build information;
  • Android version and API level;
  • Device model;
  • Processor architecture and supported architectures;
  • Memory-page-size information;
  • Runtime state and runtime version;
  • Runtime and package integrity hashes;
  • Installed tool names and versions;
  • Project and session counts;
  • Session-state counts;
  • Terminal performance measurements and counters;
  • Update-check status;
  • Whether Codex credentials appear to be configured; and
  • The number of credential files detected, without including their contents.

Default diagnostics are designed not to include:

  • Terminal commands;
  • Terminal output;
  • Prompts or transcripts;
  • Retained terminal history or scrollback;
  • Raw PTY logs;
  • Runtime-debug log contents;
  • Agent operational-log contents;
  • Workspace or source-code contents;
  • File paths;
  • Project or session names;
  • Environment-variable values;
  • Authentication-file contents;
  • Passwords;
  • Access tokens;
  • API keys;
  • Private keys;
  • .env file contents; or
  • Previous diagnostic ZIP contents.

Although Deputy Shell applies safeguards and redaction rules, users should review diagnostic files before sending them to another person.

8. Optional Firebase Analytics and Crashlytics

Deputy Shell offers optional application monitoring through Google Firebase.

The relevant Firebase collection settings are disabled by default. The user is asked to choose whether to enable:

1. Crash and application-not-responding reports; and

2. Limited usage statistics.

The user may decline both options and continue using Deputy Shell.

These choices can later be changed independently in Deputy Shell settings.

Deputy Shell stores the user's telemetry choices locally together with the version of the disclosure presented and the time the choice was recorded.

A missing, older or stale disclosure-version record does not enable Firebase collection. If the disclosure changes materially, Firebase collection remains disabled until the user makes a new choice under the current disclosure.

The telemetry disclosure version, choice timestamp and local consent record are not intentionally sent to Firebase.

8.1 Crash and ANR reporting

When enabled, Firebase Crashlytics may process information such as:

  • Crash logs;
  • Stack traces;
  • Exception information;
  • Application-not-responding reports;
  • Relevant application state at the time of failure;
  • Application version and build information;
  • Android version;
  • Device model and processor architecture;
  • Available memory and storage information;
  • Device-state information generated by Crashlytics;
  • Crash timestamps;
  • Crashlytics installation identifiers;
  • Firebase installation identifiers; and
  • Other technical information required to diagnose application failures.

Deputy Shell's telemetry layer permits only a restricted set of coarse technical custom values.

If enabled in a release, these may include:

  • Application version;
  • Build type;
  • Runtime version and phase;
  • Coarse active-session-count categories;
  • Android API-level category;
  • Processor-architecture category;
  • Memory-page-size category; and
  • Whether crash reporting or usage statistics are enabled.

Deputy Shell does not intentionally attach the following to Crashlytics reports:

  • Terminal text;
  • Commands;
  • Prompts;
  • Terminal output;
  • Workspace contents;
  • Source code;
  • File paths;
  • Project names;
  • Session names;
  • Environment values;
  • Credentials;
  • Passwords;
  • Tokens;
  • API keys;
  • Private keys; or
  • Diagnostic exports.

Deputy Shell-authored non-fatal reports use sanitised failure categories rather than raw error messages where supported.

8.2 Limited usage statistics

When enabled, Firebase Analytics may process coarse operational events such as:

  • Application readiness;
  • Runtime provisioning starting or completing;
  • Runtime provisioning results;
  • Agent-launch results;
  • Session creation;
  • Session ending;
  • Workspace import results;
  • Workspace export results;
  • Diagnostics export results; and
  • Update-check results.

Custom parameters are restricted to predefined categories or numerical buckets. Deputy Shell does not intentionally place user-entered text into custom Analytics events.

Firebase Analytics may also process provider-generated information such as:

  • App-instance or installation identifiers;
  • Application version;
  • Android version;
  • Device brand, model and name;
  • Processor and device characteristics;
  • Operating-system and platform versions;
  • Screen resolution;
  • Application interaction information;
  • Session and engagement events;
  • Application-update events;
  • Technical diagnostic information; and
  • Country, region and city-level location derived from technical information such as an IP address.

Google states that Analytics uses IP addresses at collection time to derive location information and discards the IP address before the information is logged in an Analytics data centre.

Deputy Shell does not provide a Deputy Shell account identifier or custom User ID to Firebase. Firebase may nevertheless use pseudonymous app-instance or installation identifiers.

Deputy Shell's Analytics property is configured with:

  • Google Signals disabled;
  • Ads personalisation disabled in all regions;
  • User ID collection not configured;
  • User-provided data collection not configured; and
  • Granular location and device data collection enabled.

Granular device and location collection is used to understand Deputy Shell's device, operating-system and hardware coverage, prioritise compatibility work, investigate device-specific problems and plan future support.

Deputy Shell does not intentionally send GPS coordinates, precise location, contact information, account names, project names, session names, file paths, terminal content, prompts, commands, command output, source code or workspace contents as custom Analytics event parameters.

Deputy Shell removes the Android Advertising ID permission, disables Advertising ID collection and does not use Firebase information for advertising or personalised advertising.

9. Google Play update checks

Deputy Shell may automatically ask Google Play whether an application update is available.

Automatic update checks are currently limited to approximately once every 24 hours. Users may also request an update check manually.

Google Play may process technical, device, account and application information necessary to provide update availability, download and installation services under Google's applicable terms and privacy policy.

Deputy Shell stores the following information locally on the device:

  • The time of the most recent automatic update check; and
  • The time an update prompt was most recently shown.

Deputy Shell may also store local update-state information for diagnostic purposes.

For users covered by the GDPR, automatic update checking is based on the legitimate interest in maintaining application security, compatibility and reliability under Article 6(1)(f).

A manually requested update check is performed to provide the service requested by the user under Article 6(1)(b).

10. Closed-alpha applications and tester communications

Users may apply to join the Deputy Shell closed alpha. The application form collects the Google Account email address the applicant uses with Google Play on their Android device, together with the applicant's explicit confirmation that it is that Google Account.

This information is used only to:

  • Verify the request through an emailed confirmation link;
  • Maintain the closed-alpha waiting list;
  • Manage Google Play tester access;
  • Send essential verification and access-ready emails; and
  • Provide support and administer the closed alpha.

Submitting a closed-alpha application does not enrol the applicant in a marketing newsletter or mailing list. The verification and access-ready emails are essential, transactional messages necessary to complete the applicant's own access request -- they are not promotional communications.

Anti-abuse verification

The public signup form uses Cloudflare Turnstile, an anti-abuse verification check, to help protect the signup system from automated or abusive submissions. This processing is limited to protecting the signup and administrative systems.

Service providers used for closed-alpha applications

Cloudflare hosts the Worker that operates the signup, verification and tester-administration system; the closed-alpha signup database; the Turnstile anti-abuse check; and Cloudflare Access, which restricts the tester-administration dashboard to the developer.

Resend sends the verification and access-ready emails on Deputy Shell's behalf as a transactional email provider.

Replies to these emails, and other support correspondence, are received through Google Workspace, the developer's ordinary business email service. Resend does not receive incoming mail for Deputy Shell.

As with any internet-connected service, Cloudflare and other infrastructure providers may transiently process ordinary technical request information -- such as IP addresses, request timestamps and security-relevant information -- to deliver and secure these systems. This transient infrastructure-level processing is separate from, and is not stored in, the Deputy Shell closed-alpha signup database.

Disclosure to Google Play

When the developer grants a confirmed applicant Google Play tester access, the developer manually adds that applicant's confirmed email address to the Google Play Console closed-test tester list. This is a manual, developer-performed step, not an automated integration with Google Play Console.

Discord

Applicants may optionally join the Deputy Shell Discord community while waiting for access. Joining Discord is optional and takes place outside Deputy Shell's signup system; Discord processes information about a user's participation under its own privacy terms.

Information not collected for closed-alpha applications

The closed-alpha signup database does not permanently store the applicant's IP address or user-agent string.

Retention

Closed-alpha application data is retained as follows:

  • Unconfirmed requests are deleted after 7 days;
  • Confirmed waiting-list requests are kept until withdrawn or the closed alpha ends;
  • After the closed alpha is explicitly marked as ended, remaining confirmed (not-yet-invited) requests are deleted within 30 days;
  • Invited testers' records are kept for the duration of the closed alpha and for 90 days afterward;
  • Withdrawn or removed applicants' personal data is deleted within 30 days; and
  • Security, administrative-audit and email-send records related to the closed alpha are retained no longer than 90 days.

Withdrawing an application

Applicants may withdraw a closed-alpha application, or request deletion of their closed-alpha application data, at any time by contacting support@deputyshell.com or privacy@deputyshell.com.

Legal basis

For users covered by the GDPR, processing a closed-alpha application is necessary to take steps at the applicant's request before entering into the closed-alpha service, under Article 6(1)(b). The anti-abuse verification check is based on the legitimate interest in protecting the signup and administrative systems from abuse, under Article 6(1)(f).

11. Why information is processed

Depending on the feature and the user's location, Deputy Shell relies on the following grounds.

Providing requested application functionality

Local workspaces, terminal sessions, retained terminal context, application settings, credentials, imports, exports and local operational files are processed to provide the features requested by the user.

For users covered by the GDPR, the legal basis is Article 6(1)(b): processing necessary to provide the requested service or take steps at the user's request.

User-directed external services

Information is transmitted to Codex, Git providers, package registries, websites, APIs or other destinations when required to perform an action requested or authorised by the user.

For users covered by the GDPR, the legal basis for Deputy Shell's role in carrying out that request is Article 6(1)(b).

External providers independently determine their own legal grounds for processing.

Optional Analytics and Crashlytics

Optional Firebase Analytics and Crashlytics information is processed to:

  • Detect and investigate application failures;
  • Improve compatibility and stability;
  • Understand whether important technical functions succeed or fail;
  • Diagnose performance problems; and
  • Prioritise development and testing work.

For users covered by the GDPR, the legal basis is the user's consent under Article 6(1)(a).

Consent may be withdrawn at any time through Deputy Shell settings. Withdrawing consent does not make processing that occurred before withdrawal unlawful.

Automatic Google Play update checks

Automatic update checks are performed to maintain application security, compatibility and reliability.

For users covered by the GDPR, the legal basis is the legitimate interest described in Article 6(1)(f).

Support, privacy and security correspondence

When a user contacts Deputy Shell, the information in the correspondence is processed to:

  • Answer the request;
  • Investigate a problem;
  • Protect users and the application;
  • Respond to a privacy request; and
  • Maintain records of the response.

For users covered by the GDPR, the legal basis may be:

  • Article 6(1)(b), where the request concerns the service;
  • Article 6(1)(f), based on the legitimate interest in providing support and protecting Deputy Shell and its users; or
  • Article 6(1)(c), where processing is required by law.

12. Firebase controls and withdrawal of consent

Users can separately disable crash reporting and usage statistics in Deputy Shell settings.

Disabling usage statistics:

  • Stops future Deputy Shell custom Analytics events;
  • Disables Firebase Analytics collection where supported; and
  • Clears Analytics data stored locally by the SDK and resets the local app-instance identifier where supported.

Resetting local Analytics information is not a claim that all previously transmitted or aggregated information is deleted from Google's systems.

Disabling crash reporting:

  • Stops future Deputy Shell-authored non-fatal reports and custom-key updates;
  • Disables automatic Crashlytics collection where supported; and
  • Requests deletion of pending unsent reports where supported.

A setting change may require restarting Deputy Shell before every Crashlytics component fully applies the new state.

13. Recipients and service providers

Information may be processed by the following recipients or categories of recipients, depending on the features the user enables or uses.

Google

Google provides:

  • Firebase Analytics;
  • Firebase Crashlytics;
  • Firebase installation services;
  • Google Play distribution; and
  • Google Play application-update functionality.

Google processes Firebase customer data and Firebase service data under the applicable Google and Firebase terms. Certain information may also be processed by Google under its own privacy terms.

OpenAI

OpenAI receives information when a user signs in to or uses Codex.

OpenAI processes this information according to the user's OpenAI account, service plan, settings and applicable OpenAI terms.

User-selected external services

Information may be sent to Git providers, package registries, websites, APIs, document providers or other external services selected or contacted by the user.

Cloudflare

Cloudflare hosts the Deputy Shell website and the Worker that operates the closed-alpha signup, verification and tester-administration system, including the signup database, the Turnstile anti-abuse check, and Cloudflare Access for the tester-administration dashboard.

Resend

Resend sends closed-alpha verification and access-ready emails on Deputy Shell's behalf as a transactional email provider. See section 10 for details.

Email and infrastructure providers

Deputy Shell's email, website-hosting and technical-service providers may process information necessary to:

  • Deliver the privacy-policy website;
  • Deliver and store support, privacy and security correspondence;
  • Maintain service availability; and
  • Protect systems from abuse or security threats.

Legal and professional recipients

Information may be disclosed to professional advisers, courts, regulators or public authorities where reasonably necessary to:

  • Comply with law;
  • Establish or defend legal claims; or
  • Protect users and the security of Deputy Shell.

Deputy Shell does not sell personal data and does not share personal data for behavioural advertising.

14. International data transfers

Deputy Shell is available globally.

Google, OpenAI and user-selected external services may process information in countries outside the user's country and outside the European Economic Area.

Where Deputy Shell is responsible for a transfer of personal data covered by the GDPR, an appropriate transfer mechanism will be relied upon where required. This may include:

  • An adequacy decision issued by the European Commission;
  • Standard Contractual Clauses approved by the European Commission; or
  • Another transfer mechanism permitted by applicable law.

Google and OpenAI maintain their own international-transfer arrangements under their applicable terms and privacy documentation.

Cloudflare operates global infrastructure. Resend sends closed-alpha emails from its Ireland (EU) sending region.

Transfers initiated through a user's own OpenAI account, terminal commands or selected third-party services are also subject to the chosen provider's terms and safeguards.

15. Retention and deletion

Local application data

Projects, workspaces, runtime data, settings, agent credentials, operational files and retained terminal history remain locally on the device until:

  • Deleted through an available application function;
  • Cleared through Android settings; or
  • Removed when Deputy Shell is uninstalled.

Retained terminal context is limited to approximately 1 MB per session.

Files exported outside app-private storage remain at the selected destination until deleted by the user or the relevant destination provider.

Firebase Crashlytics

Firebase Crashlytics crash information is retained according to Google's applicable Firebase retention practices.

Google currently states that Crashlytics crash stack traces and associated identifiers are generally retained for 90 days before the removal process begins.

Firebase Analytics

The Deputy Shell Analytics property is currently configured as follows:

  • Event-data retention: 2 months;
  • User-data retention: 14 months; and
  • Reset retention on new user activity: enabled.

Because reset on new activity is enabled, the expiration period associated with a pseudonymous user or installation identifier may restart when new activity is recorded.

Continued activity can therefore extend the time before that user-level information reaches its expiration point.

The reset-on-new-activity setting applies to user-level data. It does not extend the two-month event-level retention setting.

Google Analytics retention settings may not apply in the same way to standard aggregated reports.

Local update-check information

The times of automatic update checks and update prompts are stored locally until application data is cleared or Deputy Shell is uninstalled.

Support, privacy and security correspondence

Support, privacy and security correspondence is ordinarily retained for 12 months after the request or case is resolved.

Information may be retained longer where reasonably necessary to:

  • Comply with a legal obligation;
  • Investigate an ongoing security incident;
  • Prevent abuse;
  • Establish or defend a legal claim; or
  • Resolve an unresolved dispute.

Closed-alpha applications

Closed-alpha application retention periods are described in section 10.

OpenAI and other providers

OpenAI, Google Play, Git providers, package registries and other third-party services apply their own retention and deletion rules.

16. Security

Deputy Shell uses technical measures intended to reduce unauthorised access and accidental disclosure, including:

  • Android app-private storage;
  • Disabled Android cloud backup and device transfer for app-private data;
  • Restricted diagnostic exports;
  • Sanitised and allowlisted custom telemetry;
  • Disabled telemetry collection by default;
  • Removal of the Android advertising-ID permission;
  • A restricted Android FileProvider for diagnostics;
  • Android's system document picker for user-controlled file access;
  • Integrity checks for runtime and export files; and
  • Exclusion of common sensitive files from standard workspace exports.

No application, device, storage system or network transmission can be guaranteed to be completely secure.

Deputy Shell is a general-purpose terminal. Users can execute commands, install dependencies or contact services that use weak security, unencrypted protocols or malicious code.

Deputy Shell cannot guarantee the security of commands, dependencies, scripts or external destinations selected by the user.

Users should protect their devices, OpenAI accounts, access tokens, private keys and exported files.

17. Notifications

Deputy Shell may use Android notifications to indicate that one or more terminal sessions continue running while the application is in the background.

Depending on the Deputy Shell version and the user's Android notification settings, a notification may include:

  • A session name; or
  • A workspace name.

Notification content may be visible on the device's lock screen.

Users can control lock-screen visibility and notification permissions through Android settings. Disabling notifications may reduce the visibility of background-session status.

18. Privacy-policy website

The Deputy Shell privacy-policy website is currently provided as a static webpage.

The privacy-policy page does not currently use:

  • Advertising cookies;
  • Analytics scripts;
  • Tracking pixels; or
  • Behavioural tracking technologies.

The website-hosting provider and external resource providers may process ordinary technical request information such as IP addresses, request timestamps, requested resources, browser or user-agent information, referrer information, and security or error information.

This information may be processed for website delivery, reliability, abuse prevention and security.

19. User rights

Privacy rights depend on the user's location.

Users covered by the GDPR or similar laws may have the right to:

  • Request access to personal data;
  • Request correction of inaccurate personal data;
  • Request deletion;
  • Request restriction of processing;
  • Receive certain data in a portable format;
  • Object to processing based on legitimate interests;
  • Withdraw consent at any time; and
  • Lodge a complaint with a competent data-protection authority.

Requests may be sent to:

privacy@deputyshell.com

Deputy Shell does not currently maintain a Deputy Shell user-account database that connects a person's identity to Firebase telemetry.

As a result, the developer may be unable to identify telemetry associated with a particular person without additional technical information, such as a relevant installation identifier.

It may also be impossible to associate an individual with information that has already been aggregated or de-identified.

The developer may request information reasonably necessary to confirm the identity of a person making a privacy request.

Requests concerning information stored by OpenAI, Google, a Git provider or another external service must generally be submitted directly to that provider.

Users in the European Economic Area may lodge a complaint with a data-protection authority in their country of habitual residence, place of work or the place where an alleged infringement occurred.

The controller's current supervisory authority is the Austrian Data Protection Authority.

Users outside the European Economic Area may have additional or different rights under the laws applicable where they live.

20. Age requirements

Deputy Shell is intended for users aged 16 and older.

Users under the age of 18 must have permission from a parent or legal guardian to use Deputy Shell.

Deputy Shell is not directed to children under 16, and the developer does not knowingly seek to collect personal data from children under 16 through Deputy Shell telemetry.

Third-party services accessed through Deputy Shell, including OpenAI and other AI-agent providers, may impose their own:

  • Minimum-age requirements;
  • Parental-permission requirements;
  • Account requirements; and
  • Identity-verification requirements.

Users must comply with the rules of each third-party service they access.

Google Play content ratings describe the content contained in an application and may differ from Deputy Shell's intended minimum user age.

21. Automated decisions and AI-generated output

Deputy Shell does not use Firebase telemetry to make automated decisions that produce legal or similarly significant effects concerning users.

Codex and other third-party AI agents may generate:

  • Code;
  • Commands;
  • Recommendations;
  • File changes; or
  • Other output.

Such output is provided by the relevant third-party service and may be incorrect, unsafe or incomplete.

Users should review AI-generated output before executing it or relying upon it.

22. Changes to this policy

This Privacy Policy may be updated when:

  • Deputy Shell features change;
  • New service providers or integrations are introduced;
  • Data practices or retention settings change;
  • Legal obligations change; or
  • Security and privacy controls are improved.

Material changes will be communicated through the application, the Google Play listing or the privacy-policy webpage where appropriate.

The effective date and version number at the beginning of this policy identify the current version.

23. Contact

For privacy questions, data-protection concerns or requests to exercise privacy rights:

Gerasimos Simotas

Independent developer operating Deputy Shell

Vienna, Austria

Email: privacy@deputyshell.com

For general support and application assistance:

Email: support@deputyshell.com

For responsible disclosure of security vulnerabilities or security incidents:

Email: security@deputyshell.com

For development, integration or general project inquiries:

Email: devteam@deputyshell.com