Privacy Policy
Last updated: 15 September 2026
Iron Rain is a tool for driving coding-agent sessions that run on your own Mac. It is designed to be private by construction. This policy explains what it does and does not do with your data.
What Iron Rain does not collect
Iron Rain has no ads and no third-party trackers. We do not operate servers that receive your source code, prompts, agent output, API keys, or credentials. We cannot see any of it.
Anonymous diagnostics
The Mac daemon sends anonymous diagnostics, and this is on by default. You can turn it off at any time: on the Mac, Settings → Send anonymous diagnostics. Turning it off stops all reporting immediately.
Each report contains only:
- the name of a lifecycle event (for example, that a session started or a turn finished);
- which agent provider was used (opencode, claude-code, pi, or a CLI agent);
- whether it succeeded, and how long it took;
- an error class when something failed, with absolute paths and your home directory stripped out;
- the app version and your operating system and CPU architecture;
- a random identifier the daemon generates for itself on first run.
That identifier is not derived from your hardware, your account, or anything about you — it
exists so that ten reports from one machine are not mistaken for ten machines, and it can be
reset by deleting ~/.oculus/telemetry.json. Diagnostics never include your source
code, prompts, agent output, file paths, repository names, branch names, API keys, or
credentials. We use them only to find out which failures are actually happening to people.
How your data flows
Iron Rain connects the iOS app directly to a daemon you run on your Mac. That connection is end-to-end encrypted: the app and the daemon establish keys during pairing, and all session traffic is encrypted between the two devices. Your code and prompts stay between your phone and your Mac (and, where you configure one, a relay you control). The coding agents run on your Mac using your own subscription or API keys.
Data stored on your devices
The app stores pairing information (a daemon's public key, connection URL, and pairing secret) and your session history locally on your device so it can reconnect. This never leaves your device except to reach your own Mac. You can remove a paired desktop at any time from within the app.
Push notifications
If you enable notifications for tool approvals, Iron Rain registers a device token with Apple Push Notification service so your Mac's daemon can alert you when an agent needs approval. The notification payload contains only identifiers needed to route the approval (for example a session identifier) — not your code or prompts.
Camera
The app uses the camera solely to scan a pairing QR code. No images are stored or transmitted.
TestFlight & the App Store
While Iron Rain is distributed via TestFlight or the App Store, Apple collects crash and usage data per Apple's privacy policy. That data goes to Apple, not to us, and is governed by Apple's terms.
Children
Iron Rain is a developer tool and is not directed at children under 13.
Changes
If this policy changes, the updated version will be posted on this page with a new date.
Contact
Questions? Email support@howlerops.com.
