Legal
Privacy Policy
Effective . Covers the Handback app for macOS and iOS and the Handback Engine.
The short version
- No accounts. You never sign up or sign in to Handback.
- No Handback servers. There is no relay, sync service or backend that your links pass through.
- No analytics, tracking or crash-reporting SDKs, in the app or in the Engine.
- Nothing leaves your own devices and machines, except the links you choose to open, which go to the sites they point at.
What Handback is
- The Handback app runs on your Mac, iPhone and iPad (App Store).
- The Engine is the free handback daemon on your own machines (macOS or Linux). It catches browser links there and hands them to your devices.
How links travel
- Links and OAuth callbacks go directly between your machine (the Engine) and your devices, over a WebSocket on a network you control: your Tailscale tailnet, your LAN, or your own TLS reverse proxy.
- Encryption in transit depends on that choice. Tailscale and wss:// through your proxy encrypt the connection. Plain ws:// on a LAN does not.
- The app connects only to the machines you pair with it. Opening a link visits that site in your browser, as any link would.
What's stored on your devices
- Link history is stored on the device only, in the app's local database (SwiftData). It is not synced to iCloud or anywhere else.
- For each paired machine the app stores its name, address and pairing token, plus a random device ID it sends to your machines so they know what it has already received.
- You can delete a single link, all links from a machine, or a whole machine with its history. Deleting the app deletes everything it stored.
- This data is protected by the operating system's own storage protections. Handback adds no encryption at rest of its own.
What's stored on your machine
- The Engine keeps an outbox of recent links (outbox.json, owner-only) so a device that connects later still gets them. Entries are kept for up to 24 hours, and at most 500 at a time.
- The pairing token and the local control secret live in the Engine's config file (config.toml, owner-only) on that machine.
- When no device confirms it stored a link, the Engine prints it to its terminal or log on that machine, so you can open it yourself. Where that log goes, and for how long, is up to you.
Notifications
- Notifications are local: the app posts them on the device itself. There is no push service, and no notification passes through Apple's or our servers.
Apple
- If you install through the App Store or TestFlight, Apple collects what it collects for those services. That is covered by Apple's privacy policy, not this one.
- If you turned on sharing with app developers in your device's analytics settings, or send TestFlight feedback, Apple passes us the crash reports and feedback it gathered. Handback itself sends nothing.
App Store privacy label
- Handback's App Store label is "Data Not Collected": nothing the app handles is sent to us or to any third party.
Changes
- If this policy changes, the new version is posted here with a new date.