Skip to content

Latest commit

 

History

History
108 lines (85 loc) · 5.76 KB

File metadata and controls

108 lines (85 loc) · 5.76 KB

Weft privacy notice

Weft connects a phone to GitHub Copilot CLI sessions running on a laptop. It is designed so relay infrastructure does not receive plaintext session content.

Data stored on your devices

The phone or installed PWA stores data locally so it can restore your workspace:

  • paired devices and sessions;
  • transcript history and session metadata;
  • app and voice preferences;
  • pairing public keys and private keys.

Device Details can explicitly transfer bounded plain text through the paired laptop's clipboard. Clipboard contents are held only in runtime memory for the active operation: they are not continuously synchronized, stored in Weft device records, or written to Weft diagnostic event logs. Closing the Clipboard sheet clears its text from the app. The laptop and phone operating systems may retain copied text according to their own clipboard-history settings and policies.

The native app uses Capacitor Preferences. The PWA uses browser storage. Removing a session deletes its locally cached transcript; clearing the app's site data removes the PWA's local data.

The laptop stores installed code under ~/.copilot/extensions/weft/. Configuration, registered projects, logs, relay settings, and persistent Device Station pairing material are stored under ~/.weft/. The same user-private tree contains small runtime presence records, local endpoint capabilities, lifecycle operations, and recovery identity references. Completed operations and unclaimed recovery identities are removed after three days unless a live runtime or unresolved operation still references them. A /weft pairing inside one Copilot session uses an ephemeral identity that ends with that session.

A dormant extension publishes local presence and holds one idle local named pipe or Unix-domain socket, but performs no remote/network access, cryptography, QR generation, logging, diagnostics, polling, heartbeat, retry timer, or other timer. The filesystem supports discovery and recovery; the endpoint carries temporary local lifecycle commands. After pairing, phone session traffic bypasses Device Station and the local endpoint and travels directly over the encrypted relay.

Shared terminal

Shared terminal access is enabled by default on supported Windows laptops. Set terminal.enabled to false in ~/.weft/weft.config.json and restart Station to disable it. Terminal commands and output pass between the paired phone and laptop over the encrypted device channel. The local attach frontend communicates with Station through authenticated local IPC.

Weft keeps bounded terminal screen state and phone command recall in memory, not in diagnostic logs or persistent phone transcripts. The shell's own history, programs you run, and operating-system monitoring can independently record commands or output. Remote terminal access runs with the laptop account's permissions and is not restricted to the initial workspace.

Data handled by relay infrastructure

Session traffic is end-to-end encrypted between the paired phone and laptop. Relay infrastructure forwards ciphertext and stores no session content, transcripts, or key escrow. It cannot decrypt session traffic without an endpoint key.

The relay and its infrastructure providers may process ordinary service metadata such as IP addresses, connection times, request logs, channel identifiers, traffic volume, and error diagnostics. Self-hosted relay operators control their own logging and retention.

The hosted web app loads font files from Google Fonts. Google may receive ordinary web request metadata such as your IP address and browser headers when those assets load.

Optional Explore video provider

Explore's live Copilot dock only projects activity already present in the active end-to-end encrypted session. Its bundled shuffled Discover deck, reading progress, Play activities, Unwind activities, and scores remain local to the phone. If a deployment configures the optional Watch widget, Weft displays a disclosure and does not contact that provider until you explicitly choose to load the video feed.

The provider runs in a sandboxed frame and receives no Weft prompts, transcripts, repository names, filenames, tool arguments, agent activity, channel identifiers, or session identifiers from Weft. Like any external website, the provider can receive ordinary request metadata such as your IP address and browser headers and applies its own content and privacy policies. Weft does not copy the provider's viewing history into its local session data.

Accounts, analytics, and notifications

  • Weft pairing does not require a Weft account.
  • The Weft app does not include advertising or behavioral analytics.
  • Local approval notifications contain a tool name, not command arguments or transcript content. Browser and operating-system notification services remain subject to their own privacy terms.

Your choices

  • Use the hosted Supabase relay, self-host Supabase, or use a Microsoft Dev Tunnel.
  • Remove individual sessions to delete their cached phone transcripts.
  • Clear the app's browser/site data to delete PWA-local data.
  • Remove ~/.weft/ to delete laptop-side configuration and persistent pairing material.
  • Run weft rotate-pairing if a persistent QR or paired phone may be compromised.
  • Expect /clear to disconnect the current phone attachment; activate the replacement Copilot session again through Device Station or /weft.
  • Use Clipboard only when you intend the paired phone to read or replace the laptop's current plain-text clipboard value.
  • Stop an active Keep Awake lease from Device Details, or let its displayed duration expire automatically. Keep Awake does not alter the persistent Windows power plan.

See docs/security.md for the threat model and SUPPORT.md for cleanup and issue-reporting guidance.