Privacy

Your terminal is
your business.

Here’s what stays private, what the relay needs to see, and how this website works.

Terminal content is end-to-end encrypted. Your screens, history, input, commands, and session titles are sealed between your paired computer and phone. The relay cannot decrypt them.

This website.

This site has no ads, analytics scripts, tracking pixels, contact forms, or advertising cookies. It does not connect to your Shellbell devices or collect terminal content. Fonts and images are served with the site.

Your theme preference is saved in this browser and isn’t sent to the server.

The site is hosted on Cloudflare. Its infrastructure processes normal request data, such as IP addresses and request metadata, to serve and protect the website. Visiting GitHub or bilal.sh follows a link to a separate website with its own practices.

Your terminal connection.

Your computer runs the terminal sessions. Shellbell sends encrypted screen updates and available history to your paired phone, and sends your input back. A WebRTC data channel carries that traffic directly between the devices when the network allows it. On the fallback path, the relay forwards ciphertext. Neither path gives the relay your keys or a terminal transcript.

The phone keeps terminal screens, history, and input in memory while in use, rather than archiving a persistent terminal transcript. Device pairing secrets and identities are stored locally. Pairing grants access to sessions exposed by the computer’s OS user, so approve only phones you trust.

What the relay can see.

A relay needs metadata to authenticate devices, route connections, manage pairing, and deliver notifications. This includes public device identities and names, pairing relationships, connection timing and source addresses, encrypted frame sizes, and native push tokens. Once terminal traffic switches to WebRTC, the relay no longer carries those terminal frames. Its coordination connections stay open.

It can also see notification routing and event metadata, such as an event kind, opaque session identifier, and supplied exit code or duration. It retains bounded pairing, rate-limit, connection, revocation, and notification-recovery records.

It does not receive plaintext terminal titles, commands, output, or typed input. Pending private notification ciphertext may be retained temporarily in a bounded job, for at most one hour, and cleared sooner on provider acceptance or other terminal outcomes. That is separate from terminal streaming.

Notifications.

Android background notifications travel through Google FCM; iOS notifications travel through Apple APNs. Those providers see the delivery token, generic notification fields, and routing metadata. Expo Push Service is not in the delivery path.

Private notification context is encrypted for the receiving phone. What an installed app can display depends on its build, enrollment, and push configuration. Shellbell’s private context does not include raw command, question, or output previews.

After the phone decrypts and displays a notification, lock-screen previews, OS notification history, and user-configured forwarding are outside the encrypted transport boundary. Provider acceptance does not guarantee that an alert appeared on the phone.

Your own relay.

Self-hosting gives you control over the relay’s hosting, stored metadata, access, backups, and retention. It does not eliminate Apple or Google from background push, or change the STUN configuration used by the clients for direct connections.

A self-hosted operator should protect backups and review host, proxy, and platform logging. Deleting live pairing records does not erase an older backup, and restoring a backup can restore older records. See the relay page for the deployment choices.

Unpairing and deletion.

You can unpair a phone or remove its pairing on the computer. Complete any remaining unpairing action if the relay was unreachable, and remove the phone on the computer when necessary. Revocation removes live pairing and notification state; already accepted provider pushes and OS history cannot be recalled.

The relay automatically removes records for a computer whose service has not connected for 90 days. Backup retention and platform logs remain the operator’s responsibility.

The full technical inventory.

This is a plain-language overview. The repository’s PRIVACY.md is the source of truth for stored data, encryption boundaries, notification jobs, deletion, and logging. The connection guide explains pairing and transport.

For privacy questions or a suspected vulnerability, contact Bilal directly at sudo@bilal.sh. Share sensitive details privately.