Last updated 24 September 2026
Tilde collects nothing about you. There are no accounts, no analytics, no crash reporting, and no advertising. What happens in your terminal stays between your phone and your Mac.
Your phone and your Mac agree on keys when you pair them, by scanning a code shown on the Mac. Everything after that — keystrokes, output, the name of the window — is encrypted with those keys before it leaves either device.
When both are on the same network they talk directly and nothing of ours is involved. When they are not, the connection is carried by a rendezvous service at tilde.yescomet.com, which passes encrypted bytes between the two without holding the keys to read them.
| What the rendezvous sees | What it cannot see |
|---|---|
| An opaque room identifier, the amount of data passing through, and the network addresses of the two connections — the same thing any server sees of anyone who connects to it. | Terminal contents, commands, output, file names, your Mac's name, or which device is on the other end. |
None of this is logged or retained beyond what a connection needs while it is open.
Deleting the app removes both.
The agent stores its own key and the list of devices you approved, in a file readable only by your user account. It checks once a day whether a newer version has been published, which tells the download server the same thing any download does: that someone asked for a file.
Tilde is a developer tool and is not directed at children.
If this policy changes in a way that affects what leaves your devices, the change will be described here with a new date, and in the release notes of the version that introduces it.
Questions and reports: the issue tracker.