Prthole

Privacy

Short, because the architecture makes it short: Porthole has no servers. There is no account, no sign-in, no backend, and no analytics. Nothing you do in the app reaches ShrimpScript, because there is nowhere for it to go.

What the app talks to

Your own computer, inside your own tailnet, and GitHub for Porthole's own updates:

DestinationWhat forWhen
ws://<your computer>:8737the daemon: sessions, feed, approvals, terminal, builds of your projectswhile the app is connected
SSH to <your computer>the failsafe shellonly when you open it
api.github.comasks whether a newer Porthole release existsat most once a day, and when you tap Check now
github.com, *.githubusercontent.comdownloads the new Porthole APKonly when you tap Update

There is no other destination. Links in the app (Tailscale's store page, links in Claude's replies, a dev server you choose to open) are things you tap, not requests the app makes on its own. Scanning a pairing QR code uses Google's code scanner, part of Google Play services on the phone; Porthole receives only the scanned text and needs no camera permission. Play services runs the scanner under Google's own terms, which let it send Google usage metrics; typing the 6-digit code instead avoids it.

The update check

What it sends

One unauthenticated HTTPS request:

GET /repos/ShrimpScript/porthole/releases/latest
Host: api.github.com
Accept: application/vnd.github+json
User-Agent: Porthole/0.26.0

The app sets Accept and User-Agent, and the version in User-Agent is the Porthole you have installed. Host and the rest are the ones any HTTP client adds to reach a server. There is no account, token, cookie or device identifier, and nothing about your computer or your sessions. As with any web request, GitHub sees your IP address, and GitHub's privacy statement covers what it does with it.

How often

At most once every 24 hours, when the app is opened or comes back to the screen. Also when you tap Check now in Settings > Updates, and when you turn the switch back on.

What the app keeps

The time of the last check and, when a newer release was found, its version, download address, size and release page, so the banner survives a restart without a connection.

The download

Only when you tap Update. The APK comes from github.com over HTTPS, and GitHub serves the file from *.githubusercontent.com. The app refuses a download address, or a redirect, that leads anywhere other than GitHub over HTTPS. Android then installs the file only if it is signed with the same key as the Porthole you have.

Turning it off

Settings > Updates > Check GitHub for new versions. While it is off the app sends nothing to GitHub and shows no release banner. You can still download a release yourself from the releases page.

Store builds

A build of the app made for an app store has the check compiled out: no Updates section in Settings and no request to GitHub. There is no store build yet.

What leaves your computer

Your session transcripts, file contents, command output and terminal bytes travel from your computer to your phone across your tailnet, which is a direct WireGuard connection between two devices you own. Traffic does not pass through ShrimpScript, and it does not pass through Tailscale's servers either except as encrypted relay traffic when a direct path cannot be established - the standard DERP behaviour, documented by Tailscale.

Builds of your own projects, offered with portholed publish, download from your computer over the same connection.

What the app stores on the phone

Nothing beyond those recent copies, and no credentials of the app's own. All of it is in the app's private storage, which other apps cannot read. Forgetting a computer (or unpairing) deletes the copies of its sessions and their drafts. There is nothing to delete on a server, because there is no server. Uninstalling the app removes all of it. Revoking the device with portholed revoke on the computer cuts it off immediately, whether or not the phone cooperates.

Permissions the app asks for

PermissionWhy
INTERNETto reach your computer over the tailnet, and GitHub for updates
ACCESS_NETWORK_STATEto reconnect when your phone gets a network back
FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USEto hold the connection open while you are away from the app
POST_NOTIFICATIONS, POST_PROMOTED_NOTIFICATIONSthe connection, finished turns, questions and approvals
REQUEST_INSTALL_PACKAGESto hand a downloaded APK (a Porthole update or a build of your project) to Android's installer, which asks you first

The app requests no location, no contacts, no camera, no microphone, and no storage access. Photos you attach come through Android's photo picker, which shares only the photos you pick.

What it can do on your computer

Everything the consent screen lists, because that is the point of the product: run commands as your user, read and write files your user can reach, approve tool calls, and read your Claude Code session transcripts. It is worth being plain about this: a device paired with Porthole is a device that can act as you on that computer. Pair only your own phone, and revoke it if you lose the device.

Third-party code

The app bundles no analytics or advertising SDKs. Its dependencies are AndroidX and Jetpack Compose (UI), OkHttp (the connection and downloads), sshj with BouncyCastle and eddsa (the SSH failsafe), Glance (the widget) and Google's code scanner (pairing QR codes). Porthole uses none of them to send data anywhere else; the code scanner's own reporting to Google is described above.

This website

This site sets no cookies and runs no analytics. It is hosted on Vercel. Its fonts are served from this site. The front page draws the phone with three.js, loaded from cdn.jsdelivr.net, and animates it with GSAP, loaded from cdnjs.cloudflare.com; like any server a page loads files from, those see your IP address. Your browser keeps two things for this site, and they never leave it: whether you have seen the opening, so it does not play every time, and whether you picked Mac or Linux in the install steps.

Contact

Questions about this policy: open an issue on the repository.

This policy covers Porthole 0.26.0 and later. The repository has it as PRIVACY.md.