Skip to content
iPhone + iPad$19.99 one-time · no subscriptioniOS 26+ · iPadOS 26+
Privacy · Matador · Effective 2026-09-23

Privacy policy.

There are no Matador servers — so there is nothing to collect.

The short version

Matador has no servers and collects no data.

No analytics. No telemetry. No account. No usage metrics. No crash reporting SDK. No advertising IDs. No fingerprinting. Matador pairs your iPhone or iPad with the free Matador Host app on your own Mac and drives terminals and coding agents over an end-to-end encrypted connection between your devices. Silo Systems operates nothing in that path. Unless you turn relays off on the Mac, a relay helps the two devices find each other and forwards the encrypted traffic until a direct path opens, or for the whole session when none can. By default that is n0's public relay, and the Mac also publishes its address to n0's discovery service; you can pin a relay you run instead, which removes n0 entirely. A relay sees each device's endpoint id and IP address, never the decrypted session.

How your devices connect

A Matadoor session is one QUIC connection, encrypted with TLS 1.3, between your iPhone or iPad and your Mac. It is built on the open-source iroh networking library, and each side is authenticated by its iroh endpoint id. After pairing, Matadoor seals every message again with its own session key. Silo Systems operates nothing in this path.

  • Direct. When the two devices can reach each other, on the same network or across the internet after NAT traversal, the encrypted bytes go device to device. On the same network this uses the optional local network permission.
  • Relay. Unless you choose Direct only (below), both devices also connect to a relay, n0's by default, to set up each session. It carries the connection whenever no direct path is working, including while one is still being found. A relay passes along packets that are already encrypted. It can see the endpoint ids and IP addresses of your devices, but it cannot read your terminal input, output, or files.

What pairing exchanges

Pairing is a QR scan plus an explicit approval on your Mac. The phone and Mac perform an X25519 key exchange to derive a session key, and the Mac operator must approve each device before any command runs. The camera is used only to read the pairing QR code shown by Matador Host; images are never stored or uploaded.

You choose the relay

The relay is a setting in Matadoor Host on your Mac, and the pairing QR code carries that choice to your iPhone or iPad. Your iPhone or iPad keeps using the relay from the code it last scanned, so after you change the setting, scan the new code.

  • n0 relays (the default). Your devices use public relays operated by n0, the team that maintains iroh. Your Mac also publishes a signed record with its endpoint id and how to reach it to n0's public discovery service. The relays and the discovery service see endpoint ids and IP addresses, never decrypted data. Your iPhone or iPad does not use the discovery service; it finds your Mac from the pairing QR code and uses only the relay named in it.
  • Self-hosted. Pin a relay you run. Neither device then uses an n0 relay or n0 discovery, so the only server that can appear in the path is yours.
  • Direct only. No relay and no discovery service, so your Mac contacts no n0 service. Your devices connect to each other directly or not at all, so sessions across different or restrictive networks may fail to connect.

The iPhone and iPad app uses no iCloud storage and no push notification service. Its banners and Lock Screen status are created on your device.

Agents and terminals run on your Mac

The terminals and coding agents (Claude Code, Codex, OpenCode, Cursor) run on your Mac, as your user, exactly as they would if you were sitting at the keyboard. Matador makes no LLM API calls of its own and ships no cloud component. What an agent you launch does is governed by that tool's own behavior and policies — Matador simply relays your input and its output over the encrypted session.

What we never see

Because there is no Matador server, none of the following exists in any infrastructure we operate (our infrastructure being: none):

  • Your name, email, phone, IP address, or device identifiers.
  • Your terminal input or output, the commands you run, the files on your Mac, or anything an agent reads or writes.
  • Session timing, feature usage, taps, or any behavioural data.
  • Crash reports. Matador implements no crash-reporting SDK.

Purchase

Matadoor is a paid download on the App Store, with no in-app purchases. Apple handles the transaction under Apple's privacy policy, and Matadoor never sees your payment details. Matadoor Host for the Mac is free.

Children's privacy

Matador is rated 4+. Because no personal data is collected from any user, the same policy applies regardless of age: nothing collected.

Changes

If we ever materially change how Matador handles data, we will publish an updated version of this page and announce it in the release notes. The effective date at the top reflects the current policy. The current policy is: nothing is collected.

Contact

Questions about this policy: admin@ohmslaw.net

Contact
Last updated 2026-09-23 · v1.1