ClaudeRemote Privacy Policy
Effective date: 2026-10-10 · Operator: spark · Contact: spark.jgliu@gmail.com
ClaudeRemote lets you use a tab that is open in Chrome on your own computer from your own phone's browser. This policy explains what data the ClaudeRemote browser extension, the ClaudeRemote website (app.myclauderemote.com) and our relay servers handle, and why.
1. Page content and what you type: end-to-end encrypted
When your phone is connected, the extension sends the selected tab's content (its page structure or screenshots), the list of your open tabs (titles and URLs), and the fonts and images needed to display the page to your phone, and your phone sends back your taps, scrolling and typing. All of this is end-to-end encrypted between the extension and your paired phone (ECDH P-256 key agreement, AES-256-GCM). It passes through our relay servers, which only forward the encrypted data. We cannot read it, and we do not store it.
The relay servers can see only what they need to route the data: which account, computer and phone a connection belongs to, the type and size of each message, and timing. Because content is compressed before encryption, the size of a message can reveal a little about its content.
2. Data we store
| Data | Why | How long |
|---|---|---|
| Account: username, email address and password hash (scrypt). We never store your password itself | Sign-in, email verification, password reset | Until the account is deleted |
| If you sign in with Google: your Google account identifier (sub) and email address. We never store your Google password, tokens, name or photo | Sign in with Google, show the linked Google account on your account page | Until the account is deleted, or until you unlink it on your account page |
| Computers: a name such as "Chrome · Windows", the relay region, the public-key fingerprint of the extension's identity key, a hash of its sign-in token, when it was added and last seen | Show your computers, connect your phone to the right one, detect stolen tokens | Until the account is deleted. When you sign out or revoke a computer, its token is erased and the entry is kept, marked as revoked, so it can never connect again |
| Phones: a name taken from the browser (for example the phone model), the public-key fingerprint, when it was added and last seen | Show your phones, check a phone's identity before connecting | Until the account is deleted. A removed phone is kept, marked as revoked |
| Sign-in sessions on the website and phone page (a hash of the cookie) | Keep you signed in | A session expires after 30 days, or 7 days without use; expired sessions are kept, marked as revoked, until the account is deleted |
| One-time links for email verification and password reset (hashes only) | Verify your email, reset your password | Until the account is deleted (they expire after 24 hours or 1 hour) |
| Security log: sign-ins, failed sign-ins, devices added or revoked, password changes and similar events, with time and IP address. Never page content, titles or URLs | Detect and investigate abuse | 90 days |
| Server access logs: IP address, time and the requested path on our website | Operate and secure the service | 30 days |
The extension stores on your computer: your consent to the notice, its sign-in token (never your password), the chosen region, the identity keys (the private key cannot be exported) and the fingerprints of your paired phones. Your phone's browser stores its identity key and the fingerprints of your computers.
3. How we use data
Only to provide ClaudeRemote: signing you in, connecting your phone to your computer, sending verification and password-reset emails, keeping the service secure and preventing abuse. We do not sell data, do not use it for advertising, and do not use it to determine creditworthiness. The use of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
4. Sharing
We do not sell or share your data with third parties, except the service providers needed to run ClaudeRemote and when required by law:
- IBM Cloud (Tokyo, Japan), which runs our servers;
- Resend, which sends email-verification and password-reset emails and receives only the recipient address and the email content;
- Google, which verifies your identity when you choose to sign in with Google. We request only your Google account identifier and email address, and use them only to sign you in. Our use of information received from Google adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Public beta
ClaudeRemote is in public beta and free to use. We collect no payment information. If we start charging, we will update this policy and notify you in advance.
6. Your choices
- Revoke a computer, a phone or a sign-in session, or change your password, at any time on your account page or in the extension.
- Stop sharing a tab at any time: close Chrome's "being debugged" bar, close the phone page, or sign out of the extension.
- To delete your account and its data, contact spark.jgliu@gmail.com.
7. Security
All connections use HTTPS / WSS. Page content is end-to-end encrypted as described above. Phones must be paired by QR code or confirmed with a matching 6-digit code on both devices. The extension runs only code bundled in its package; our servers cannot make it run code.
8. Children
ClaudeRemote is not directed to children under 13 and we do not knowingly collect their data.
9. Changes
We will post changes to this policy on this page and update the effective date.