Overview
Falkn lets you access coding-agent sessions running on Macs and Linux machines you control. The mobile app connects directly to those machines over SSH. Punk Labs does not operate the SSH connection, receive terminal transcripts, or receive the prompts, source code, file paths, and other content carried through it.
Falkn has no user account system, advertising, cross-app tracking, or analytics. Optional push notifications use a limited Punk Labs relay as described below.
Information stored by the mobile app
The app stores the information needed to reconnect to machines you add:
- host names or addresses, ports, usernames, display names, and app preferences;
- SSH passwords or private keys, stored in the iOS Keychain;
- SSH host-key settings and any host public key you provide; and
- notification credentials and encryption keys, stored in the iOS Keychain.
Punk Labs does not receive this information. Removing a machine from Falkn removes its saved credentials from the app. Uninstalling the app removes its local data in accordance with iOS behaviour.
Information stored on your Mac or Linux machine
falknd runs under your user account. It stores session
metadata, user-edited names, notification configuration, and bounded
terminal history in that account's local cache directory. It uses a
user-only Unix socket to communicate with Falkn clients. This
information remains on your machine and is not sent to Punk Labs.
SSH connections and coding-agent providers
The mobile app sends commands and receives session output through a direct SSH connection to the machine you configure. Your SSH server and network provider may process the normal technical information required to establish that connection.
Falkn starts an existing Codex or Claude Code installation on your machine. Those tools may send prompts, source code, terminal context, or other information to their respective service providers under the account and settings you use with them. Falkn does not control those services. Their privacy terms apply to that processing.
Optional push notifications
If you allow notifications, the app registers with Apple Push
Notification service (APNs) and with the Falkn notification relay at
relay.falkn.dev. The relay stores:
- the APNs device token issued for Falkn;
- a random Falkn device identifier;
- a one-way hash of a random write credential;
- whether the app uses Apple's sandbox or production notification service; and
- creation and update timestamps.
When an agent needs attention, falknd sends a random
event identifier, delivery credentials, and an encrypted event to the
relay. The event's host, session, title, agent, and attention state
are protected with AES-256-GCM using a key shared only between the
mobile app and your falknd. Punk Labs cannot decrypt that
information.
The relay sends APNs a generic notification and the encrypted event. APNs therefore receives the Falkn device token, delivery metadata, generic notification text, and ciphertext. Apple processes that information under its own privacy terms.
The relay keeps successful event identifiers for up to 24 hours to prevent duplicate delivery. Device-registration records are kept while their APNs tokens remain valid for delivery and are removed when APNs reports that a token is no longer active. Cloudflare, which hosts the relay, may process standard network and security logs as part of delivering and protecting the service.
Information not sent to the notification relay
Prompts, source code, terminal output, file paths, SSH credentials, and notification encryption keys are not sent to the Falkn notification relay.
Website
The Falkn website does not use analytics, advertising, tracking scripts, or tracking cookies. Cloudflare hosts the site and may process standard technical information such as IP addresses and request metadata to deliver the site and protect it from abuse.
How we use and share information
We use the limited notification-service data only to authenticate notification senders, deliver notifications, prevent duplicate delivery, operate security controls, and diagnose service failures. We do not sell it, use it for advertising, or use it to track you across apps or websites.
The relay relies on Cloudflare for hosting and Apple for notification delivery. We disclose information to those providers only as needed to provide those functions, or where required by law.
Your choices and rights
You can decline notification permission and use Falkn without the notification relay. You can manage notification permission in iOS Settings and remove saved machines in Falkn.
If you have a privacy question or want to exercise a data-protection right, contact us at privacy@falkn.dev. Because Falkn does not use accounts and relay identifiers are random, we may need information from your app to locate and securely verify a device-registration request.
Children's privacy
Falkn is a professional developer tool and is not directed at children. We do not knowingly collect personal information from children.
Changes
If this policy changes, we will post the updated version on this page and change the effective date above.
Who we are
Falkn is made and published by Punk Labs Ltd, a private limited company registered in England & Wales (company number 17307364), registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Punk Labs Ltd is the data controller for personal information processed by the Falkn notification relay.
Contact
Privacy questions: privacy@falkn.dev
General enquiries: hello@punklabs.ai