Skip to content
OUT NOW

SofaCode is out on Google Play and the App Store. Fully released on both, no testing program to join — iPhone, iPad and Android at the same version.

Get the app ⟩
SOFACODE
Features Setup Pricing Contact
Download

§ Legal

Privacy Policy

Last updated 27 September 2026

SofaCode is an independent product of BOT-HOLDINGS, LLC ("we", "us"), operated under the CODEDATDA.CASA studio name. This policy covers the SofaCode phone, tablet, TV and watch apps, the desktop daemon, the editor extension, the SofaNode firmware, and this website. The short version: SofaCode is built so that your code, voice, and sessions never route through a server we control — most of this policy is about how little there is to tell, and about the few places where a third party you chose (your phone's speech service, Cloudflare for remote access, a model server you configured) does see something.

1. The architecture is the policy

The SofaCode app connects directly to a daemon running on your own computer, over your own local network or your own VPN / mesh network. Your prompts, dictated audio, code, files, terminal output, and chat transcripts travel only between your devices. We operate no relay, no sync service, and no backend that any of it is reported to. We do not receive, store, or see any of that content — ever. (The apps contain no analytics or crash-reporting SDK of any kind and no third-party code libraries that phone home. This website is a separate thing and is covered in section 9.)

Two things on your own computer are worth knowing. The daemon reads the local files your assistants keep — Claude Code's transcripts under ~/.claude, Codex's sessions under ~/.codex, Copilot Chat's session files in the editor's storage — so the app can show them to you; it never copies them anywhere but to your paired devices. And the app sends your paired computer a random install identifier it generates itself (so the daemon can tell your phone from your tablet); that identifier is not tied to your Google or Apple account and never reaches us.

Phone dictation is the one place the operating system may be involved. The wireless talk button streams your voice straight to your own computer and nowhere else. Dictating into the chat box on the phone instead uses your device's own speech recognition (Google's on Android, Apple's on iPhone and iPad), which, depending on the device and language, may send that audio to Google or Apple under their privacy policies. SofaCode records nothing and receives nothing from it.

2. Data we do receive

  • Website forms. If you submit the release-notice, contact, bug-report, feature-request or ambassador form, we receive the email address and details you enter, plus any screenshots and a debug log only if you choose to attach them. Used solely to reply to you and improve the product; never sold; no mailing list beyond what you asked for. Attachments are stored outside the web root and are never published. A feature request may describe something we later build — send only ideas you are free to share. Each form carries Cloudflare Turnstile, which checks that a person is sending it: the check runs in your browser, Cloudflare sees the signals it needs to tell people from bots and may set its own strictly necessary cookie, and our server only receives a pass-or-fail token from it. See Cloudflare's privacy policy.
  • Update checks. The daemon, the app and the SofaNode may check our download server (dl.codedatda.casa) for a newer version or firmware. That request reveals what any web download does — an IP address and the version you're on — and none of your session content. We keep no log of who checked.
  • Support chat. Every page of this site carries a chat button served from our sister site mr-tbot.com (also ours). Loading a page fetches the widget's settings from there, which shows that server your IP address like any script download does; nothing is stored in your browser and no chat exists until you open one. Section 9 has the details of what a chat sends.
  • SofaNode flasher login. Buying a SofaNode creates one login for the web flasher — the email address from your order and a password we email you — so only buyers can download firmware images from our site. It is kept in the same order database as your order (section 3) and deleted with it.

Things the software fetches that are not about you: the daemon downloads a speech voice model from Hugging Face (huggingface.co) the first time you use spoken replies, and the SofaNode sets its clock from public time servers (pool.ntp.org, time.google.com, time.nist.gov). Each sees an IP address and nothing else.

2a. Remote access

Remote access is off by default. When you turn it on from your computer and accept its risk on a device, that device can reach your computer over the internet. We still operate no relay and see none of the traffic — but a third party you chose does carry it:

  • Cloudflare tunnel (the usual route): your daemon runs a Cloudflare tunnel under your Cloudflare account, or a throwaway one Cloudflare hands out. Your devices connect to Cloudflare's edge over TLS and Cloudflare forwards the connection into the tunnel. As with any site behind Cloudflare, Cloudflare terminates the TLS connection at its edge and its systems can see the traffic passing through, subject to Cloudflare's privacy policy. Device authentication is a challenge-response, so your pairing token never crosses that path.
  • A forwarded port: traffic goes from your device to your router to your computer over TLS with a certificate your daemon generated; nobody but your internet providers is in between.
  • A gateway machine: one of your computers relays the others. The gateway carries the bytes; each device still authenticates end to end with the machine it is talking to.

Your daemon keeps a local log of connections (address, time, outcome) in its own log file on your computer, and your acceptance of the remote-access risk is recorded on the device and computer where you gave it — neither is sent to us. Remote access is described in full in the Terms of Use, section 4.

3. Purchases

Subscriptions are purchased through Google Play or the Apple App Store and are handled entirely by those stores. We never see your card number or billing details. The app stores your subscription state on your device to unlock features; the store's own privacy policy governs the transaction (Google, Apple). There are no SofaCode accounts for the apps — nothing to sign up for, nothing for us to hold. (The only login anywhere is the SofaNode buyers' flasher login in section 2.)

SofaNode hardware orders are different — shipping a physical thing needs an address. When you buy a SofaNode, PayPal handles the payment (we never see your card either way; PayPal's privacy statement governs it) and gives us your name, email address and shipping address, which we keep in an order record on our own server, off the public docroot. We use them to ship your order, answer questions about it, send the order and tracking emails, and deliver the subscription code that comes with the device — and for nothing else. They are never sold or shared beyond the carrier that delivers the parcel. Ask for deletion once the return window has passed and the record is removed.

4. Device permissions

  • Microphone — push-to-talk dictation. Audio streams directly to your own daemon and into your assistant; it is not recorded by us and never touches our servers. The Android app also declares the foreground-service microphone type so a hold-to-talk can outlive the screen.
  • Speech recognition (iOS) / the system recognizer (Android) — dictating into the chat box on the phone, handled by Apple or Google as described in section 1.
  • Camera — scanning the pairing QR code, and attaching a photo or screenshot to a chat, which is uploaded only to your own computer. Processed on-device otherwise.
  • Photos — picking a screenshot to attach to a chat. The picker is the system's; the app sees only the image you choose.
  • Local network, Wi-Fi state and multicast — discovering your daemon and SofaNode on your network and talking to them. That's the product.
  • Internet — the same connection when you are away from home (remote access, section 2a), the update check, and nothing else.
  • Notifications — approval prompts and session alerts, generated locally.
  • Display over other apps (Android, optional) — the floating bubble you can switch on in Settings. Off by default.
  • Foreground service, vibration, keep-awake (Android) — holding the connection to your computer open while the app is in the background and buzzing when a prompt needs you.

The SofaNode asks for nothing of you; it stores your Wi-Fi network name and password and its pairing tokens in its own flash memory and identifies itself to your daemon by its hardware address.

5. Data on your device

Settings, pairing tokens, saved prompts, your acceptance of the Terms and of the remote-access risk, and optional debug logs live on your device. Uninstalling the app deletes its data. Debug logs are recorded only when you switch them on, contain the app's own diagnostic output plus your device model and OS version, and leave the device only if you attach one to a bug report.

On your computer, the daemon keeps its configuration, the list of paired devices and their tokens, its own log, and any tunnel token you gave it, in your user profile (~/.config/sofacode and ~/.local/state/sofacode on Linux and macOS, the equivalent folders on Windows). Local LLM (beta, off by default) lets the extension send Copilot Chat conversations to a model server you configure — LM Studio or Ollama on your own machine, or any OpenAI-compatible endpoint you enter, which may be a cloud service; where you point it decides who sees those conversations, under that provider's policy.

6. Children

SofaCode is a developer tool, is not directed at children under 13, and we do not knowingly collect personal information from children.

7. Retention & deletion

The personal data we hold is email you've sent us and, if you bought a SofaNode, the order record described in section 3. Ask for deletion any time at [email protected] and it will be removed (order records once the return window has passed).

8. Changes

If this policy changes, the new version is posted at this URL with an updated date. Material changes will be noted in the app's release notes, and the Terms of Use, which incorporate this policy, are shown again in the apps for agreement when they change materially.

9. Cookies & local storage

By default this site sets no cookies — none for advertising, none for sessions, and nothing that follows you anywhere. Three optional features do use your browser's storage or load someone else's script, and each is a separate choice you make yourself. (The support chat button, described at the end of this section, is our own and stores nothing until you open it.)

On your first visit a notice offers the three below, all switched off. You can allow any of them, all, or none, and change your mind any time from the Cookie settings link in every footer — turning one off also deletes what it stored. Refusing changes nothing else about how the site works.

  • Referral code memory (off by default) — if you reach the SofaNode page through a creator's link, their code is kept in your browser's local storage (sofanode_code) for 30 days, so an order you place later still credits them. Without this permission the code is neither saved nor read back, and anything you type in the code box yourself always wins.
  • PayPal checkout (off by default) — the SofaNode buy box loads PayPal's checkout script, and PayPal sets its own cookies when it does (see PayPal's privacy statement). Until you allow it, the buy box shows a button that loads PayPal only when you press it; pressing it allows PayPal and nothing else.
  • Audience measurement (off by default) — Google Analytics 4, so we can see which pages people actually read and which ones they leave. It sets Google's own _ga cookies and reports the visit to Google (see Google's privacy policy). Until you allow it, nothing about Google is loaded and no request reaches them at all — we do not use the "load it anyway and ask permission afterwards" pattern. Advertising signals and ad personalization are switched off, so this is audience measurement and not ad targeting. Turning it off again deletes the _ga cookies.

Your answer is kept in local storage (cdc_consent: which of the two you allowed, a timestamp and a version — nothing about you) for up to a year, after which you are asked again. It is never sent anywhere. It is the one thing stored without asking, because it is how a "no" is remembered.

Page counts at the CDN. This site is served through Cloudflare, and Cloudflare counts page views for us at its edge. This is cookieless: it stores nothing on your device and reads nothing from it, which is why it is not one of the switches above — there would be nothing for the switch to turn off. It produces aggregate counts (pages, rough country, browser family), not a profile of you, and it is not shared or used for advertising. See Cloudflare's note on it. Cloudflare may also set a strictly necessary security cookie (__cf_bm) to tell bots from people; it carries no identity and is exempt from consent.

Ambassador link counting. When you open the SofaNode page through a creator's link (/sofanode/?code=THEIRCODE), our own server counts that visit for them so they can see their link is working. We store a salted one-way hash of your IP address and browser string together with the day, only to avoid counting the same visitor twice in one day — it cannot be reversed to identify you, is not shared, is not used for advertising, and cannot follow you to other sites. Nothing is written to your device by this, and it does not happen unless you arrived through such a link.

Support chat. The chat button in the corner of every page is our own support widget, served from our sister site mr-tbot.com. Loading the page fetches its settings from there; nothing is stored until you open a chat. When you do, it keeps a random chat id, your name and email as you entered them, and the conversation so far in your browser's session storage (keys beginning cbot:sofacode:), which the browser clears when the tab closes. Your messages, with the page you were on, are sent to that server, where an AI assistant answers them and a member of our team may join; a transcript is emailed to our team and to the address you give. Cloudflare Turnstile checks that a chat is started by a person and may set Cloudflare's own cookie when it does. The chat's own consent line says all of this before you type; if you never open it, none of it happens.

Nothing else about you is stored in your browser by this site.

10. Contact

Privacy questions: [email protected]. See also our Terms of Use.