Privacy policy
Effective 26 September 2026
claudezilla is an Android app and the server it connects to (claudezilla.nanobet.games). It lets invited members of a team use Claude Code on the team's git repositories and servers from their phone. This policy explains what information the service keeps, why, and who it goes to. "We" means the team that runs this server.
What we collect
- Your account. When you sign in with Claude, the server learns your Claude account's email address and name, to check that you were invited and to show who did what. Your Claude password never reaches us: you sign in on Claude's own page.
- Your Claude token. The token you paste (made with
claude setup-token) lets the AI work for you. It is stored encrypted on the server and never sent back to the phone. - Devices. Each signed-in phone has a session, with the device's name and when it was last used, so you can see and sign out your devices.
- Your work. The repositories you clone, the files you and the AI change, your chats with the AI and the tools it used, and your commits, branches and merge requests.
- Credentials you add. Git account tokens, SSH keys and server passwords are stored encrypted on the server with a key that only the server holds. The app and the AI never see their values.
- Activity and usage. An audit log of actions (pushes, merges, commands run on servers, who ran them) and the cost of each AI turn, to enforce spending limits.
- Technical logs. The server's logs record requests (including IP addresses) to keep the service running and to stop repeated failed sign-ins.
How we use it
Only to provide the service to you and your team: signing you in, running the AI in your workspaces, showing your history, keeping the service secure and within its limits. We do not sell your information, show ads, or use it to build profiles. The app has no advertising or analytics trackers.
Who it goes to
- Anthropic. When you use the AI, your prompts and the code and files the AI reads are sent to Anthropic's Claude API, with your Claude token, under Anthropic's terms and privacy policy.
- Your git host. Clones, pushes, merge requests and CI go to GitLab, GitHub or the git server a repository comes from, through the git account you chose.
- Your servers. Commands you (or the AI, with your approval) run go to the servers you added.
- Web pages. The AI may fetch public web pages you ask about; it cannot reach this server's private networks.
- Your team. Members of the same server share repositories' git accounts and servers, and can see who else has a repository open. Administrators can see the audit log and AI usage.
We share information with others only when the law requires it.
On your phone
The app keeps the server's address and your session, encrypted with Android's keystore, and a PIN (and optionally fingerprint or face unlock) for the app. It keeps what you viewed recently so you can read it offline; Settings → Clear saved data deletes it, and signing out deletes everything the app kept.
How long we keep it
Your work stays until you delete the workspace. Sessions expire after 90 days without use. Backups of the server are kept for 14 days. If you leave the team, an administrator removes your access; ask them, or us, to delete your account and what it holds.
Security
Traffic uses HTTPS. Tokens and credentials are encrypted at rest. The AI runs in an isolated container per workspace, with no access to the server's other files or networks. No system is perfectly secure, but we work to protect your information.
Children
claudezilla is a tool for software teams and is not meant for children under 16.
Changes
We may update this policy; the date at the top says when it last changed. Continuing to use the service after a change means you accept it.
Contact
Questions or requests about your information go to the administrator who invited you to this server.