Legal
Privacy policy
Courtesy translation. If the versions differ, the Portuguese text prevails.Summary
Cialai does not collect personal data. The desktop application runs entirely on your machine. The phone apps connect only to your own computer, through an end-to-end encrypted connection the computer sets up on its own, with no server of yours, Ordinum's or the project's in the path. Ordinum does not receive, store or access your terminals, your files or your traffic.
Who we are
Cialai is an open source project under the Apache 2.0 license, maintained by Ordinum Inovação e Tecnologia LTDA, based in Uberlândia, Minas Gerais, Brazil. Contact: contato@ordinum.com.br.
What the desktop application handles
Everything stays on your computer, in the application's own data directories:
- Raw history of each terminal, so it comes back after closing the application.
- Session metadata: name, subtitle, color, order, folder, open tabs and terminal size.
- Preferences: project folders, shell, appearance and font.
- The computer's identity, with its Ed25519 keys, and the list of paired phones, so each one can be revoked.
- Local reading of coding agent plan usage, from the files those agents write on your machine.
None of this data is sent to Ordinum. The little that leaves the computer for public networks is described under Network, below.
What the phone apps handle
- The public key of each paired computer, received through the pairing QR.
- One token per paired computer, kept in the device's secure storage and restricted to it.
- The device's own key, which identifies it to the computer and can be revoked on the computer.
The content shown on the phone is served by your computer, end-to-end encrypted on every path. The app uses no analytics, advertising or tracking services. The camera is used only to read the pairing QR code and nothing from it is stored. Biometrics, when enabled, are verified by the operating system; the app has no access to biometric data.
Network
Communication between computer and phone is end-to-end encrypted on every path: on the local network, on the direct connection over the internet and on the Tor fallback. There is no server of yours, Ordinum's or the project's in the path, and Ordinum does not receive or access terminals, files or traffic. For the devices to find each other, Cialai uses public networks, and each one sees only what is described below.
- Tor network. The computer publishes a built-in onion service, which works as the meeting point and the fallback connection. Tor relays carry only encrypted traffic. Because this onion service is single-hop to reduce latency, the introduction and rendezvous relays may see the computer's IP address, never the content.
- Public STUN servers from Cloudflare and Google. They are optional and help discover the computer's public address. When STUN is used, those servers see the computer's public IP address.
- DNS-SD on the local network. The announcement publishes an identifier derived from the computer's public key, without the person's name.
- Your router. When the router allows it, the computer requests a port mapping through UPnP, NAT-PMP or PCP.
The pairing QR carries the computer's public key and works only once: it rotates every 90 s and expires in 10 min. Each phone has its own key and its own token, revocable one by one, and revocation drops the device's sessions on both paths.
This website
The website is static and has no forms. We may use an aggregate audience measurement tool to understand how many people visit the pages. When that happens, the tool will be named in this policy. We do not sell or share visitor data.
App stores
Distribution through the App Store and Google Play follows Apple's and Google's privacy policies, which may collect installation and crash data according to your account settings. That information does not reach Cialai as identifiable personal data.
Your rights
Since Cialai collects no personal data, there is no data to access, correct or delete with Ordinum. To erase what the application keeps, remove the application or its data directories. For questions about this policy, write to contato@ordinum.com.br.
Changes
Changes to this policy will be published on this page, with the update date revised. Relevant changes will also be recorded in the project repository.