Privacy Policy
How the Muxr app, the muxr.app website, and the optional Muxr Push relay handle your data — operated by f0x.it LLC.
Effective date: August 13, 2026 · Last updated: August 13, 2026
The short version
The app talks to your own server, not to ours.
- No accounts. There is nothing to sign up for and no profile held by us.
- No analytics, no ads, no crash reporting. The app ships with no analytics, advertising, or crash-reporting SDKs.
- No sale of data. We do not sell your personal information, and we do not share it for advertising or cross-app tracking.
- Your terminal traffic never reaches us. It flows directly between your device and the
muxrdserver you run. - Credentials stay on your device, in the operating system's Keychain (iOS) or Keystore (Android), behind your device biometrics.
- The only data we ever receive is standard web-server access logs from muxr.app, and — if you deliberately turn on notifications and register a device with our hosted relay — a small registration record described in Muxr Push.
Who we are, and what this policy covers
Muxr is developed and operated by f0x.it LLC ("we", "us", "our"). You can reach us at [email protected].
This policy applies to:
- The Muxr app — the mobile and tablet client for iOS and Android ("the App").
- The muxr.app website — these pages, plus the Nerd Font catalog served at
muxr.app/fonts/that the App downloads fonts from ("the Site"). - Muxr Push — the optional hosted notification relay we operate, used only if you enable notifications and register a device with it.
It does not cover the server software you run yourself. muxr-core (muxrd, muxrctl, muxr-notify) is open-source software that you install and operate on your own machine. Anything it stores — tokens, TLS certificates, device registrations — lives on your hardware, under your control. We never receive it.
Data stored on your device
The App keeps everything it needs locally. None of the following is transmitted to f0x.it LLC:
| What | Where it lives | Sent to us? |
|---|---|---|
| Server credentials and bearer tokens | iOS Keychain / Android Keystore, gated behind your device biometrics | Never |
| Saved server profiles (address, port, label, TLS trust mode and certificate fingerprint) | App storage on the device | Never — used only to reach the server you chose |
| App preferences and settings | App storage on the device | Never |
| Diagnostic logs shown inside the App | App storage on the device | Never — they are not uploaded anywhere |
| QR pairing codes | Camera frames decoded on-device | Never — images are processed locally and are not stored or uploaded |
The App has no account system, so there is no server-side copy of any of this. Removing a saved server or credential in the App deletes it from your device; uninstalling the App removes everything it stored.
Your terminal sessions
Everything you do in a session — keystrokes, command output, session, tab and pane names, anything rendered on screen — travels directly between your device and the muxrd server you host, over a TLS-encrypted gRPC connection authenticated with your own bearer token.
There is no intermediary, proxy, or cloud service in that path. f0x.it LLC never receives, sees, stores, or processes your terminal content. If your server is unreachable, the App simply cannot connect — there is no fallback route through us.
The website and the font catalog
When your browser loads a page on muxr.app, and when the App downloads a font from the catalog at muxr.app/fonts/, our web server writes a standard access-log entry. That entry contains the IP address the request came from, the user agent string, the time of the request, and the path requested.
We use those logs for two things only: keeping the Site and the font catalog running (diagnosing errors and sizing capacity), and preventing abuse (blocking floods, scraping, and attacks). We do not use them for advertising or profiling, we do not combine them with other data, and we do not sell or trade them. They are kept only as long as needed for those purposes.
The Site sets no cookies and loads no analytics or tracking scripts. The one external resource it loads is the Google Fonts stylesheet used for typography, which means your browser also contacts Google's font servers when you view a page; that request is handled under Google's own privacy policy.
Muxr Push (optional)
Muxr Push is an opt-in feature. It applies only if you turn on notifications and register a device with the relay we host. If you never enable it, nothing in this section happens and no data about you leaves your device for us.
muxr-notify is part of the MIT-licensed muxr-core project and can run on your own machine. If you point the App at your own relay, f0x.it LLC receives nothing at all and this section does not apply to you.
What the hosted relay stores
The relay we host currently supports Android only — it rejects a registration from any other platform — so the push token it stores is a Firebase Cloud Messaging (FCM) registration token issued to your device by Google. Registering creates one small record:
| Data | Why |
|---|---|
| An opaque device handle | Identifies the registration so your server can target it, and so you can remove it |
| FCM registration token | The address the notification is delivered to — without it, delivery is impossible |
| Platform | Recorded with the registration; today the relay accepts only android |
| Registration timestamp | Records when the device was registered |
| Timestamp of the most recent notification sent | Records when the registration was last used |
| Per-day send counter, and the day it applies to | Caps notification volume and prevents abuse of the relay |
| Inactive flag | Set when Google reports the token is no longer valid, so the relay stops sending to it |
That is the complete record — the relay's database table holds no other fields. We do not ask for — and the relay has no field for — your name, email address, phone number, contacts, or location, and no account is associated with a registration.
What a notification contains
A notification payload carries only the event kind, a short title, and the workspace or session label you named. It never contains terminal content — no command output, no keystrokes, no file contents, no environment variables.
Push notifications are delivered through Google's infrastructure, so the title and label you choose pass through its systems and may appear on your lock screen. Keep sensitive strings out of workspace and session names if that matters to you.
Who else receives it
Delivering a notification means handing the payload and your registration token to Google's Firebase Cloud Messaging, which carries it to your device. Google is the only third party that receives any data in this flow, it receives it solely to deliver the notification to your device, and its handling is governed by Google's own privacy policy.
If and when we ship iOS support, delivery will also be routed through Firebase Cloud Messaging — with Apple's push service performing the final hop to Apple devices — and we will update this policy to describe it.
IP addresses
While the relay handles a registration or a send request it necessarily sees the client's IP address, and uses it in memory to enforce rate limits. The relay itself never writes it to its database — the registration record has no IP field — and the in-memory rate-limit entry is dropped once it falls idle, and on every restart.
Like most web services, the hosted relay sits behind a TLS-terminating reverse proxy, and that front-end infrastructure keeps standard, short-lived access logs of the same kind described under the website and the font catalog — used only for keeping the service running and preventing abuse, and kept only as long as needed for those purposes.
How long registrations are kept
A registration record is kept until it is deleted. It is deleted when:
- The App deletes its registration with the relay — a capability arriving together with app-side push support — at which point the relay removes the record, token included, from its database immediately.
- You ask us to delete it by emailing [email protected].
One distinction worth knowing: removing a device on your own server (for example in the muxrctl Devices screen) deletes it from your server's registry and stops your server sending notifications to that device — but it does not delete the relay-side registration record. Email us if you want that record removed as well.
If Google reports the token as invalid or expired (for example, the App was uninstalled), the relay marks the registration inactive and stops sending to it — every later notification request for that handle is refused, and the stored token is undeliverable. That flag does not by itself erase the record: the row, token included, stays in the database until one of the two deletions above happens. If you want it gone, email us.
There is no other schedule: while a device stays registered, its record stays. With no registered devices, the relay sends no outbound traffic at all.
What we don't do
- No analytics or telemetry SDK is bundled in the App, and it reports no usage statistics to us.
- No crash-reporting service. Crashes are not transmitted anywhere.
- No advertising and no advertising identifiers. The App shows no ads.
- No tracking of you across apps, sites, or devices, and no behavioural profiles.
- No sale or rental of personal information to anyone, for any purpose.
- No account creation, so no credentials or personal details are held on our side to lose.
How data is protected
- Credentials are held in the operating system's secure storage — iOS Keychain or Android Keystore — released only after a biometric prompt.
- Connections to your server use TLS. When you pair by QR against a self-signed server, the App pins the certificate's SHA-256 fingerprint, so a CA-valid impostor cannot take its place.
- The hosted relay stores only the minimal registration record described above, on infrastructure we control, and talks to Firebase Cloud Messaging over encrypted connections.
No system is perfectly secure. Because the server is yours, its hardening — network exposure, token hygiene, OS updates — is in your hands; see the setup documentation for the recommended configuration.
Your choices and rights
- Notifications: turn them off in the App at any time and unregister the device. That deletes the relay's registration record for it.
- Locally saved data: remove an individual saved server or stored credential in the App, or uninstall the App to remove everything it stored on the device.
- Self-hosting: run your own
muxr-notifyrelay, and no notification data reaches us at all. - Deletion requests and questions: email [email protected]. Because we hold no account, tell us enough to locate the record — we will work with you to identify and delete any registration associated with your device.
Depending on where you live, you may have rights to access, correct, delete, or object to the processing of your personal data, and to complain to your local data-protection authority. Write to [email protected] and we will honour those rights. We will not discriminate against you for exercising them.
Children
Muxr is a developer tool. It is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.
Changes to this policy
If our practices change, we will post the revised policy on this page and update the "last updated" date at the top. This page is the canonical, publicly accessible version of the policy; the App and the app stores link to it. Continued use of the App, the Site, or Muxr Push after a change takes effect means you accept the revised policy.
Contact
Questions, deletion requests, or privacy complaints about the Muxr app:
- f0x.it LLC
- Email: [email protected]
See also the Terms of Use and the support page.