At a glance
- Project files and command output are not archived in the cloud by default.
- Requested results can leave your computer to reach your AI client.
- Basic account, permission and usage records are stored to run the service and deleted on fixed schedules.
Who operates the service
Local Commander is operated by Peter Mamrukov, a private individual based in Israel. For privacy, support or security questions, contact peter.mamrukov@localcmd.app.
Information we use
You choose whether to provide information and connect a computer. Providing it is voluntary; without a sign-in email and the necessary account and device details, we cannot provide the connected service.
| Information | Why it is used |
|---|---|
| Account and sign-in records | Your email, account status, sign-in challenges and sessions let you sign in and help protect your account. Accounts we issue a password to (such as app-review accounts) also have that password stored, only as a salted hash. |
| Device and permission records | Device public keys, connection status and authorization records control which computer and actions can be used. |
| Activity and usage records | Operation references, timestamps, outcomes, usage counters and limited security records support execution, quotas and troubleshooting. Security records note sign-ins, device pairing and revocation, permission changes and refused actions. |
| Setup progress events | To see where setup fails and improve the service, we record when your account reaches a setup step: email confirmed, computer paired, AI client connected, first successful task and usage allowance reached. Each event holds only the step, your account’s internal ID and a time. It never includes commands, file paths, file contents, output, your email address or IP address. |
Your files and tool results
Operations run on your enrolled computer. Files, command arguments and results needed for your request may pass through the Local Commander relay to your chosen AI client. That provider handles what it receives under its own privacy terms.
Ordinary cloud execution records store metadata, not a default archive of your project files or command output. Results can be present temporarily in relay memory. The native application also keeps an encrypted local recovery journal that can contain operation results. Optional local audit logging is separate and is off by default.
Cookies and service providers
We use cookies for sign-in and request security. Browser storage keeps pending connection or pairing references so setup can resume after email sign-in; normal completion removes them. Clearing this storage may sign you out or interrupt setup.
The website, sign-in and relay run on a Netcup server in Austria. Service records are kept in a hosted SQL Server database (databaseasp.net) on servers in Germany. Sign-in email is sent through Resend, an email provider in the United States. Your chosen AI provider receives the results you request. Information is therefore processed in the European Union, in the United States for email delivery, and wherever your AI provider operates.
The reviewed website code contains no advertising or third-party analytics scripts, and setup progress events are stored only in our own database. Google, Yandex and GitHub sign-in applications are registered, but those sign-in methods are not yet available on the website.
Retention and your choices
Records are deleted automatically on the schedules below. Each period is a maximum.
| Record | Kept for |
|---|---|
| Sign-in links and connection requests | Up to 30 days after they expire |
| Website sign-in sessions | Up to 30 days after they expire or are signed out |
| Operation and usage detail | 12 months. Monthly usage totals stay with the account. |
| Security records | 90 days |
| Setup progress events | 90 days |
| Encrypted copies of sign-in emails | 7 days after sending |
| Account, device and permission records | While your account is open, then closed as described below |
To close your account, or to request access to or correction of your information, email peter.mamrukov@localcmd.app from the address on the account. We may need to verify your identity. We complete a verified closure within 30 days. Closing revokes your sessions, connected AI clients, devices and workspace permissions, deletes any password and pending sign-in links, and removes your email address and your account, device and workspace names from our records. Remaining operation detail is then no longer linked to you and is deleted on the 12-month schedule.
Our database hosting provider makes its own backups. Deleted records can remain in those backups until the provider's backup rotation overwrites them. We use backups only to recover the service, and we reapply closures after any restore.
You can revoke available account, client, device or workspace access. Revocation does not undo completed actions or remove results already delivered to your AI client. Contact us if you need help with these controls.
Security and contact
The service uses encrypted cloud connections and protects stored authentication values. Device private keys stay on your computer. These protections do not eliminate every risk, and a permitted local program is not contained by a complete operating-system sandbox.
For a concern, email Peter at peter.mamrukov@localcmd.app with a brief description. Do not send passwords, sign-in links, tokens, private keys or recovery keys. Ask for a secure reporting route before sharing sensitive vulnerability details.