Privacy Policy
Last updated:
Wrapper is a remote terminal sharing service operated by Cupola Labs, LLC. Your terminal stays on your machine until you explicitly share it. This policy explains the metadata Wrapper stores, how terminal traffic moves between peers, which providers help us operate the service, and the controls available to you.
Information we collect
Account information
When you sign in with Apple, GitHub, or Google, we receive the name, email address, profile information, and provider identifier made available by that provider. Wrapper does not create or store a password for social-login accounts.
Apple may send cryptographically signed account-change notifications when an Apple user changes email forwarding, revokes consent, or deletes the Apple Account. Wrapper stores hashes of the notification id and Apple subject for up to 90 days to prevent replay. It does not store the raw Apple subject in that replay record.
Session metadata
Convex stores session metadata only after you share a session: identifier, account owner, shell name, working directory, process and port metadata, sharing and relay state, timestamps, and close reason. Unshared hosts send nothing to Convex. Share codes and relay tickets are stored only as cryptographic hashes. Session metadata may be sensitive, even though it is not terminal output.
Terminal content
Unshared terminal input and output stay on your device. When a direct WebRTC connection succeeds, its data channel is encrypted between peers with DTLS. Viewer input prefers that channel, while the host keeps a relay output copy available for fallback and mixed viewers. When direct connection is unavailable or disabled, all terminal traffic travels through the Wrapper relay over TLS. The relay processes that traffic in memory to route it and is technically able to access the plaintext after TLS termination. Wrapper does not intentionally persist terminal input or output on the relay.
Local application data
The CLI stores an authentication session, local session registry, protected local attach tokens, telemetry preference, and diagnostic logs on your device. These files are created with user-only filesystem permissions where supported.
Billing and optional analytics
Autumn and Stripe process subscription and payment information. Wrapper does not store payment-card details. Resend sends transactional account emails such as welcome, plan change, and deletion notices. The website uses Vercel Web Analytics for anonymized page views. Anonymous CLI telemetry is disabled by default and is sent to PostHog only after you run wrapper telemetry enable. Neither website analytics nor CLI telemetry is designed to include terminal input, output, share codes, relay tickets, or authentication tokens.
How sharing works
- You must explicitly share a session before a remote viewer can join.
- Your own authenticated devices may join your sessions without a share code.
- Another user needs the session id and the share code supplied by you.
- People you invite can read output. They cannot type unless you allow it. You always can.
- Unsharing closes the host relay bridge and revokes unused viewer tickets.
- Direct P2P connections disclose each peer's IP address to the other peer.
Attention alerts
If you allow notifications, Wrapper can ping your phone when a shared session needs you. The alert names the session. It does not include terminal output, commands, paths, or credentials.
How we use information
- Authenticate accounts and authorize session access.
- Route explicitly shared terminal sessions between authorized peers.
- Maintain session liveness, prevent abuse, and investigate service failures.
- Process subscriptions and provide account support.
- Improve Wrapper using anonymized website analytics and optional CLI telemetry.
- Comply with applicable legal obligations.
Service providers
- Convex for backend functions, authentication data, and session metadata.
- Fly.io for the authenticated WebSocket relay.
- Vercel for the Wrapper website and anonymized Web Analytics.
- Apple, GitHub, and Google for optional social authentication.
- Autumn and Stripe for subscriptions and payment processing.
- Resend for transactional account and billing emails.
- PostHog for optional anonymous CLI telemetry.
- Google and Twilio STUN servers for WebRTC network discovery.
We do not sell personal information or terminal content for advertising.
Security
Wrapper uses TLS for network transport, DTLS for direct WebRTC data channels, short-lived single-use relay tickets, hashed share codes, server-side ownership checks, rate limits, session-scoped relay routing, and protected local attach tokens. No security control eliminates all risk. Treat share codes as secrets and unshare immediately if a code or device may be compromised.
Report suspected vulnerabilities privately through the instructions on our support page.
Retention and deletion
Account and session metadata is retained while needed to provide, secure, and operate the service. Relay tickets expire quickly and are deleted after use or expiry. The application does not intentionally retain relayed terminal payloads. Billing providers retain billing records under their own policies and applicable law.
You can remove local CLI credentials with wrapper auth logout. Signed-in users can permanently delete their account from the Dashboard. Wrapper deletes local account data and queues removal of the associated billing customer. Temporary billing-provider failures do not keep the local account active; bounded background retries continue and operators can investigate exhausted cleanup attempts. To request access, correction, export, or assistance with deletion, contact [email protected].
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information and to object to certain processing. We do not sell personal information. Contact [email protected] to make a request. You may also complain to your local data-protection authority.
International transfers
Our providers may process information in the United States and other countries. Where required, we rely on provider contractual safeguards and applicable transfer mechanisms.
Children
Wrapper is not intended for anyone under 18. Contact us if you believe a minor has provided personal information so we can investigate and delete it where required.
Changes and contact
We may update this policy as Wrapper changes. Material changes will be reflected by the date above and may be communicated through the service or account email.
Privacy questions: [email protected]. See also our Terms of Service.