Legal

Privacy Policy

How the Muxr app, the muxr.app website, and the optional Muxr Push relay handle your data — operated by f0x.it LLC.

Effective date: August 13, 2026 · Last updated: August 13, 2026

The short version

Muxr is built so that we don't need your data

The app talks to your own server, not to ours.

  • No accounts. There is nothing to sign up for and no profile held by us.
  • No analytics, no ads, no crash reporting. The app ships with no analytics, advertising, or crash-reporting SDKs.
  • No sale of data. We do not sell your personal information, and we do not share it for advertising or cross-app tracking.
  • Your terminal traffic never reaches us. It flows directly between your device and the muxrd server you run.
  • Credentials stay on your device, in the operating system's Keychain (iOS) or Keystore (Android), behind your device biometrics.
  • The only data we ever receive is standard web-server access logs from muxr.app, and — if you deliberately turn on notifications and register a device with our hosted relay — a small registration record described in Muxr Push.

Who we are, and what this policy covers

Muxr is developed and operated by f0x.it LLC ("we", "us", "our"). You can reach us at [email protected].

This policy applies to:

  • The Muxr app — the mobile and tablet client for iOS and Android ("the App").
  • The muxr.app website — these pages, plus the Nerd Font catalog served at muxr.app/fonts/ that the App downloads fonts from ("the Site").
  • Muxr Push — the optional hosted notification relay we operate, used only if you enable notifications and register a device with it.

It does not cover the server software you run yourself. muxr-core (muxrd, muxrctl, muxr-notify) is open-source software that you install and operate on your own machine. Anything it stores — tokens, TLS certificates, device registrations — lives on your hardware, under your control. We never receive it.

Data stored on your device

The App keeps everything it needs locally. None of the following is transmitted to f0x.it LLC:

WhatWhere it livesSent to us?
Server credentials and bearer tokensiOS Keychain / Android Keystore, gated behind your device biometricsNever
Saved server profiles (address, port, label, TLS trust mode and certificate fingerprint)App storage on the deviceNever — used only to reach the server you chose
App preferences and settingsApp storage on the deviceNever
Diagnostic logs shown inside the AppApp storage on the deviceNever — they are not uploaded anywhere
QR pairing codesCamera frames decoded on-deviceNever — images are processed locally and are not stored or uploaded

The App has no account system, so there is no server-side copy of any of this. Removing a saved server or credential in the App deletes it from your device; uninstalling the App removes everything it stored.

Your terminal sessions

Everything you do in a session — keystrokes, command output, session, tab and pane names, anything rendered on screen — travels directly between your device and the muxrd server you host, over a TLS-encrypted gRPC connection authenticated with your own bearer token.

There is no intermediary, proxy, or cloud service in that path. f0x.it LLC never receives, sees, stores, or processes your terminal content. If your server is unreachable, the App simply cannot connect — there is no fallback route through us.

The website and the font catalog

When your browser loads a page on muxr.app, and when the App downloads a font from the catalog at muxr.app/fonts/, our web server writes a standard access-log entry. That entry contains the IP address the request came from, the user agent string, the time of the request, and the path requested.

We use those logs for two things only: keeping the Site and the font catalog running (diagnosing errors and sizing capacity), and preventing abuse (blocking floods, scraping, and attacks). We do not use them for advertising or profiling, we do not combine them with other data, and we do not sell or trade them. They are kept only as long as needed for those purposes.

The Site sets no cookies and loads no analytics or tracking scripts. The one external resource it loads is the Google Fonts stylesheet used for typography, which means your browser also contacts Google's font servers when you view a page; that request is handled under Google's own privacy policy.

Muxr Push (optional)

Muxr Push is an opt-in feature. It applies only if you turn on notifications and register a device with the relay we host. If you never enable it, nothing in this section happens and no data about you leaves your device for us.

You can self-host it instead

muxr-notify is part of the MIT-licensed muxr-core project and can run on your own machine. If you point the App at your own relay, f0x.it LLC receives nothing at all and this section does not apply to you.

What the hosted relay stores

The relay we host currently supports Android only — it rejects a registration from any other platform — so the push token it stores is a Firebase Cloud Messaging (FCM) registration token issued to your device by Google. Registering creates one small record:

DataWhy
An opaque device handleIdentifies the registration so your server can target it, and so you can remove it
FCM registration tokenThe address the notification is delivered to — without it, delivery is impossible
PlatformRecorded with the registration; today the relay accepts only android
Registration timestampRecords when the device was registered
Timestamp of the most recent notification sentRecords when the registration was last used
Per-day send counter, and the day it applies toCaps notification volume and prevents abuse of the relay
Inactive flagSet when Google reports the token is no longer valid, so the relay stops sending to it

That is the complete record — the relay's database table holds no other fields. We do not ask for — and the relay has no field for — your name, email address, phone number, contacts, or location, and no account is associated with a registration.

What a notification contains

A notification payload carries only the event kind, a short title, and the workspace or session label you named. It never contains terminal content — no command output, no keystrokes, no file contents, no environment variables.

Notification text is visible in transit

Push notifications are delivered through Google's infrastructure, so the title and label you choose pass through its systems and may appear on your lock screen. Keep sensitive strings out of workspace and session names if that matters to you.

Who else receives it

Delivering a notification means handing the payload and your registration token to Google's Firebase Cloud Messaging, which carries it to your device. Google is the only third party that receives any data in this flow, it receives it solely to deliver the notification to your device, and its handling is governed by Google's own privacy policy.

If and when we ship iOS support, delivery will also be routed through Firebase Cloud Messaging — with Apple's push service performing the final hop to Apple devices — and we will update this policy to describe it.

IP addresses

While the relay handles a registration or a send request it necessarily sees the client's IP address, and uses it in memory to enforce rate limits. The relay itself never writes it to its database — the registration record has no IP field — and the in-memory rate-limit entry is dropped once it falls idle, and on every restart.

Like most web services, the hosted relay sits behind a TLS-terminating reverse proxy, and that front-end infrastructure keeps standard, short-lived access logs of the same kind described under the website and the font catalog — used only for keeping the service running and preventing abuse, and kept only as long as needed for those purposes.

How long registrations are kept

A registration record is kept until it is deleted. It is deleted when:

  • The App deletes its registration with the relay — a capability arriving together with app-side push support — at which point the relay removes the record, token included, from its database immediately.
  • You ask us to delete it by emailing [email protected].

One distinction worth knowing: removing a device on your own server (for example in the muxrctl Devices screen) deletes it from your server's registry and stops your server sending notifications to that device — but it does not delete the relay-side registration record. Email us if you want that record removed as well.

If Google reports the token as invalid or expired (for example, the App was uninstalled), the relay marks the registration inactive and stops sending to it — every later notification request for that handle is refused, and the stored token is undeliverable. That flag does not by itself erase the record: the row, token included, stays in the database until one of the two deletions above happens. If you want it gone, email us.

There is no other schedule: while a device stays registered, its record stays. With no registered devices, the relay sends no outbound traffic at all.

What we don't do

  • No analytics or telemetry SDK is bundled in the App, and it reports no usage statistics to us.
  • No crash-reporting service. Crashes are not transmitted anywhere.
  • No advertising and no advertising identifiers. The App shows no ads.
  • No tracking of you across apps, sites, or devices, and no behavioural profiles.
  • No sale or rental of personal information to anyone, for any purpose.
  • No account creation, so no credentials or personal details are held on our side to lose.

How data is protected

  • Credentials are held in the operating system's secure storage — iOS Keychain or Android Keystore — released only after a biometric prompt.
  • Connections to your server use TLS. When you pair by QR against a self-signed server, the App pins the certificate's SHA-256 fingerprint, so a CA-valid impostor cannot take its place.
  • The hosted relay stores only the minimal registration record described above, on infrastructure we control, and talks to Firebase Cloud Messaging over encrypted connections.

No system is perfectly secure. Because the server is yours, its hardening — network exposure, token hygiene, OS updates — is in your hands; see the setup documentation for the recommended configuration.

Your choices and rights

  • Notifications: turn them off in the App at any time and unregister the device. That deletes the relay's registration record for it.
  • Locally saved data: remove an individual saved server or stored credential in the App, or uninstall the App to remove everything it stored on the device.
  • Self-hosting: run your own muxr-notify relay, and no notification data reaches us at all.
  • Deletion requests and questions: email [email protected]. Because we hold no account, tell us enough to locate the record — we will work with you to identify and delete any registration associated with your device.

Depending on where you live, you may have rights to access, correct, delete, or object to the processing of your personal data, and to complain to your local data-protection authority. Write to [email protected] and we will honour those rights. We will not discriminate against you for exercising them.

Children

Muxr is a developer tool. It is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.

Changes to this policy

If our practices change, we will post the revised policy on this page and update the "last updated" date at the top. This page is the canonical, publicly accessible version of the policy; the App and the app stores link to it. Continued use of the App, the Site, or Muxr Push after a change takes effect means you accept the revised policy.

Contact

Questions, deletion requests, or privacy complaints about the Muxr app:

See also the Terms of Use and the support page.