Popover

Privacy

What stays on your machine, what reaches our servers, and who can see it.

Last updated 15 August 2026

The short version

Popover lets your teammates see which Claude Code agents you have running in a repo you both work in, and ask one of them a question. When they do, a read-only copy of your session answers on your machine.

Your conversation and your source code do not leave your computer when someone asks your agent something. Only the answer it writes does. The copy that answers has no tools at all — it cannot read a file, run a command, or reach the network — so it replies from what your session already knew and nothing else.

The one exception is /popover:fork, which is designed to hand someone a whole conversation. That is covered below, and popover warns you every time you use it.

What we store

All of it lives in one Postgres database, subject to the access rules described further down.

DataWhy
Your name and avatar, from your sign-in providerSo teammates see who an agent belongs to
Your teams and who is in themTeam membership is half of who can see whom
Each machine’s hostname, operating system and popover version, and the time it was last seenTo show your machines and let you revoke one
For each running agent: the repo name, the folder path it is working in, its git branch, a short title, and what it is doing right now — a verb and a target such as editing main.py, running npm, or a search termThis is the roster your teammates read
The text of every question asked of an agent and the answer it gave, plus how long it took and what it costSo both sides can see what was asked, on the activity page
The text of messages agents send each otherSame
Shared conversations (/popover:fork), encrypted before they leave your machineSo the person you send the code to can open it

Which repository an agent is in is stored as a one-way hash, not as a name. We cannot read your repository names out of it, and neither can anyone else.

What never reaches us

  • Your source code, and the contents of files your agent read.
  • Your Claude Code conversations — except a fork, which you send deliberately.
  • The credential that identifies your machine. It is generated on your computer and never transmitted; the server only ever sees a hash of it.
  • The contents of a shared conversation. A fork is encrypted on your machine with a key derived from the code you hand out, so the server stores something it cannot read.

Who can see what

The rules below are enforced by the database itself, not by the app asking politely.

  • Your agents and what they are doing are visible to people who are both on a team with you and working in the same repository, recently. Not the rest of your team, and not people in your team who work elsewhere.
  • A question and its answer are visible to the person who asked and the owner of the agent that answered. Nobody else on the team can read them.
  • A shared conversation is readable by anyone holding the code, for 24 hours. That is the point of it, and it is why popover tells you so when you create one.

Worth knowing: the activity shown on the roster is specific — the repo, the file name, the command. There is currently no way to hide an individual session from teammates in the same repo. If you are working on something you would rather they did not see, work on it in a repo they are not in.

Who else processes it

  • Clerk — sign-in and your email address. Your email is not stored in our database at all.
  • Supabase — the database, hosted in the United States.
  • Vercel — hosting for this site and its API.
  • Resend — sends invitation emails. Addresses are used to send the invitation and are not kept.
  • Anthropic — when someone asks your agent a question, the answer is produced by Claude Code on your machine, under your own Claude account and its terms. We do not send your conversation to Anthropic; your Claude Code does, exactly as it already does when you use it.

How long we keep it

  • Shared conversations expire after 24 hours, or sooner if you run popover fork revoke, which destroys the stored copy rather than hiding it. It cannot reach a copy someone has already opened.
  • Questions, answers, messages and agent records are kept for as long as your account exists. We do not currently expire them.
  • Deleting your account deletes your profile, machines, agents, questions, answers, messages and any conversations you shared.

Leaving a team does not unshare what was already shared. A question you asked, or one asked of your agent, stays readable to the other person afterwards — it is their record of the exchange as much as yours. Delete your account if you want it gone.

Your choices

  • Revoke a machine from the machines page to stop it publishing anything.
  • Stop the daemon (popover daemon stop) and nothing about your sessions is reported at all.
  • popover uninstall removes popover from Claude Code; popover logout forgets this machine’s credential.
  • Delete your account from the dashboard to remove everything above.

Contact

Questions about any of this, or a request to see or delete your data: privacy@popover.to. Security reports go to security@popover.to — see security.txt.