CC Blackbox Privacy Policy
Last updated: September 6, 2026
This policy covers both CC Blackbox apps: the Mac app, a personal IDE that records and visualizes your Claude Code sessions, and the iPhone app, a companion that lets you watch and steer the sessions running on your own Mac. Where a section applies to only one of them, it says so.
The short version.
There are no accounts, no analytics, no advertising, and no tracking in either app. We never see your code, your prompts, your sessions, or your conversations. The only data our own service handles is what the relay needs to deliver encrypted messages between your Mac and your phone, described below.
The Mac app: everything stays on your Mac.
Session recordings, transcripts, the events the app records, usage and cost figures, agent definitions and run history, and the app's own health samples are stored in a database in your user account's Application Support folder. Nothing in that database is uploaded anywhere by us.
The Mac app connects out for four things, each only when it applies. It checks GitHub for app updates and release notes. If you connect a client's Vercel account, the token you paste is stored encrypted on your Mac, is never written to the database, and is sent only to Vercel. If you turn on LAN Machine Sync, your session history moves directly between your own Macs over your local network, encrypted, with no server in between. If you pair an iPhone, the relay described below carries the traffic. Claude Code itself talks to Anthropic under your own account; the app does not sit in that path and does not add anything to it.
The iPhone app: what it stores.
The iPhone app stores your pairing keys in the device's Keychain, plus a cache of the sessions it has shown you, on the phone. It has no account of its own.
The relay: what it handles and for how long.
Your sessions travel from your Mac to your phone through a relay server we operate on Cloudflare. Everything that passes through it is end-to-end encrypted, so the relay cannot read your sessions, prompts, or any other content. To do its job it handles:
Routing identifiers: the random identifiers your Mac and phone create when they pair, so messages reach the right device. They are not tied to your name or any account.
Your device's Apple push token: stored so the relay can ask Apple to notify you when a session needs attention. Notification contents are encrypted; Apple delivers them but cannot read them. The token is deleted when you unpair.
Connection metadata: the IP addresses and timing of connections, as with any server on the internet. This is used only for abuse protection and appears in short-lived operational logs, which are not kept beyond that purpose and are never combined with anything that would identify you.
That is the complete list. The relay stores no message content, no session history, and nothing about your code.
Services we rely on.
The relay runs on Cloudflare. Push notifications are delivered by Apple. App updates and release notes are fetched from GitHub. None of them can read your content.
Children.
CC Blackbox is a developer tool and is not directed at children.
Changes.
If this policy changes, the update will be posted at this page with a new date.