AJ Cortez

Independent software by AJ Cortez

Compass Code Privacy Policy

How Compass Code handles information, with confirmed source behavior and open release questions.

Developer and scope

AJ Cortez (Armando J. Cortez) develops Compass Code as an independent software project. This app-specific draft does not cover Veyra Sky, which maintains its own infrastructure at veyrasky.com.

Pairing and authentication

Compass Code connects an iPhone or iPad to Compass Hosts you choose. It uses one-time pairing and device authorization rather than an in-app developer account signup in the inspected client.

The app processes host names/endpoints, environment and session identifiers, device identity, public-key proofs, and authorization credentials to connect and authenticate. Private signing keys use the Secure Enclave; pairing grants and short-lived session tokens use device-only, non-synchronizing Keychain storage. Public keys, device identifiers, proofs, and tokens are sent to the paired host for authorization.

Camera permission is used to scan a pairing code. The inspected pairing flow does not save or upload camera images.

Content sent to a host and AI services

Prompts, coding instructions, session configuration, approvals, questions, terminal input, and other requested operations go to the paired host over authenticated HTTPS or a ticketed WebSocket. Transcripts, repository/session metadata, file previews, artifacts, terminal output, and operation status return from that host. Coding content does leave the device.

Agents and repositories run on the host. The inspected Compass server stores session and event records in Postgres and maintains workspaces and agent-session files on the host. The host operator can control access to and retention of that data. These are host-side stores, not a direct iOS connection to Supabase.

Host-side agents can send prompts, code, tool results, or other context to the AI/model provider configured by the host operator. The exact providers, gateways, data sent, provider retention/training settings, and external tools are not established for the submitted service configuration. No claim of on-device-only AI or zero provider retention is made.

For a host you operate or select, review the host operator’s and configured providers’ policies. Any host operated by AJ for customers or App Review needs its own confirmed data-handling disclosure before this draft is finalized.

Local storage and diagnostics

The app keeps an environment catalog, cached session summaries, transcript checkpoints, pending safe operations, saved drafts, and reusable prompt Tiles in local application storage. The inspected storage implementations use iOS file protection and exclude those files from device backup. Non-sensitive preferences use app-scoped UserDefaults.

Prompt Tiles stay in the local library until you edit or remove them. Inserting a Tile into a draft does not itself send it; submitting the resulting prompt sends that wording to the chosen host. The inspected client has no automatic retention period for its local saved data.

App-owned connection diagnostics use Apple unified logging. No developer log-upload endpoint, advertising, cross-app tracking, analytics, or third-party crash-reporting service was found in the inspected client. Host logs, diagnostics, backups, and any AJ-operated service remain a separate review item.

SwiftTerm supplies the native terminal renderer. The inspected app has no StoreKit purchase/subscription integration or app-managed iCloud content sync. System photo/file pickers are present, but attachment-byte transfer is not implemented in the inspected revision. The final archive and dependencies must be checked for changes.

Deletion and host retention

Clear offline data removes cached session/transcript state, pending safe operations, and saved drafts while keeping pairing credentials. It does not clear the separate prompt Tile library; remove unwanted Tiles from that library.

Removing an environment clears its local metadata, credentials, signing key, cached state, and environment-scoped drafts. It does not revoke the device grant on the host or delete host-owned content. A new-chat draft is not environment-scoped and is cleared by Clear offline data.

Ask the trusted host operator to revoke the device grant and handle deletion of host records. Local removal cannot promise deletion of prompts, transcripts, repositories, artifacts, terminal state, logs, or backups retained by a host or AI provider. Retention and deletion periods for any AJ-operated host remain unconfirmed.

Support correspondence

If you email support, your email provider and the support inbox process your address, message, and anything you choose to attach so AJ can respond. Opening the app’s support link does not automatically attach writing or coding content. Inbox access, retention, and deletion rules still need confirmation.

Before this policy is finalized

  • Identify whether AJ will operate any customer, demo, relay, or App Review host; list its operators and who can access prompts, code, transcripts, identifiers, logs, and backups.
  • Confirm the actual AI providers, gateways, external APIs/tools, data sent to them, and applicable provider retention, training, and deletion settings.
  • Specify retention periods and deletion/revocation procedures for each AJ-operated host, including session content, device grants, access/error logs, and backups.
  • Confirm final-release authentication, purchases/subscriptions, SDKs, analytics, crash reporting, telemetry, and attachment transfer against the submitted archive.
  • Confirm the professional support inbox is monitored, its access and retention/deletion rules, and any region-specific developer contact details.

Policy updates

This page will be updated when release behavior is confirmed or changes. The finalized policy and App Store privacy answers must describe the same submitted build and operated services.

Privacy questions

For questions about this draft or a data request, contact AJ Cortez.

contact@ajcortez.com

Send only the details needed to explain the problem. Omit passwords, pairing codes, access tokens, private writing, repository contents, and sensitive screenshots.