Privacy & Terms

Privacy policy & terms of use

This page explains what personal data AI Commander processes when you use the relay at aicommander.dev, who else is involved, how long it is kept and how to exercise your rights — and the terms for using Free or buying Pro.

1. Who is responsible

The operator responsible for the AI Commander service, and the controller for the processing described here, is:

The same company operates Coder AI and other services. 2Dynamic Games is the operator and seller of Pro; Stripe processes payments but is not the seller or merchant of record.

2. What data we process

AI Commander is built to hold as little as possible. By default you can drive a machine without any account — you simply quote its session code — so for anonymous use we hold no identity data at all. The data we do process is:

We never log or store your commands or their output. Command text and stdout/stderr are processed only transiently in the relay's memory while they stream through, then discarded — they are never written to logs or any database. Cloudflare observability/logpush is deliberately left off so the platform does not retain them either.

3. How we use it

We do not sell personal data, and we do not use your data to build advertising profiles.

4. Recipients and subprocessors

AI Commander relies on the following infrastructure and external services, each for a narrow, defined purpose:

We do not add a subprocessor that receives command payloads, because no command payload is ever stored or forwarded to anyone but the agent that runs it. Files you explicitly transfer are the one exception to “nothing is stored”: they are held temporarily in Cloudflare R2, become inaccessible after 24 hours, and are then deleted by an hourly, retrying cleanup sweep.

5. Retention

6. Access model & anonymous use

A session code is the credential for its machine: anyone who knows a current code can act on it until the owner resets the code or blocks their account. Linking an account is optional: signing in lets you save machines under friendly aliases and reach them with a personal API key. Free includes up to 10 usable saved devices and no new file transfer. Pro enables every saved device up to the technical 100-record ceiling and upload/download. If Pro ends while more than 10 records exist, nothing is deleted: the 10 oldest remain usable and the rest stay saved but plan-restricted. Anonymous command/status onboarding remains available during a code's first hour, but anonymous file transfer is not. Full detail is in Security.

7. Pro subscription, cancellation, payments & consumer rights

8. Your rights

Subject to the conditions in the GDPR, you have the right to access your personal data, rectify inaccurate data, erase it, restrict or object to processing, and data portability. To exercise any of these — or to delete your account — contact support@coderai.dev. Because most processing is keyed by hashes and accounts are minimal, you may need to provide enough information to identify the account concerned. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa.

9. The service is provided “as is”

AI Commander is a relay plus an agent that, once installed by the user, can execute shell commands — by default as root — on the user's machine. It is remote shell access, not a sandbox. Because of that, the following terms apply to everyone who uses the service:

You are solely responsible for your machines and every command run on them. The person who installs the agent is solely and fully responsible for that machine, for every command executed on it (by themselves, by another person they share a code with, or by an AI acting on their behalf), for any data exposed, and for all consequences.

Nothing in this section limits liability that cannot be limited or excluded under applicable mandatory law.

10. Report a bug or feature, and contact

Found a bug or have a feature request? On public pages, the feedback button loads the CoderAI widget from coderai.dev. The authenticated dashboard does not load the widget; its feedback links return you to the public site to open it. You can also reach the team directly for any matter — including privacy requests and security reports — at support@coderai.dev.

11. Licensing

Three different regimes apply, so it is worth stating which is which. The desktop application (AI Commander for macOS and Windows) and the relay service are proprietary: this notice grants no licence to their source, and no right to copy, modify or redistribute them. @aicommander/agent, the on-machine agent published on npm, is licensed under the Elastic License 2.0 from version 1.1.0 onward — version 1.0.56 and every release before it were published under the MIT licence, and that grant is irrevocable for those versions. @aicommander/mcp, the MCP server you install beside your AI client, is MIT.

The agent’s source is public at github.com/AICommander-dev/aicommander-agent. Third-party components carry their own terms: each npm package ships its licence file in its own tarball, and the desktop application installs a THIRD-PARTY-NOTICES.txt naming the components compiled into it and where the remaining texts live.

12. Changes to this notice

We may update this notice as the service evolves. The current version is always published at this URL; the date below reflects the last revision.

Last updated: 2026-08-19