Legal
Privacy policy for the vord apps
This is a courtesy translation. Only the German version is legally binding.
Last updated: 8 September 2026
This privacy policy applies to the apps vord (macOS), vord mobile (iOS), vord Cowork (macOS) and vord Cowork (iOS), as well as to the associated account, licensing and connection service at vord-app.dev (user area, API and relay). A separate privacy policy applies to visits to our website.
1. Controller
M&R Technologies UG (haftungsbeschränkt)
An der Strusbek 12
22926 Ahrensburg
Germany
Represented by: Rico Röder
Commercial register: HRB 26140 HL, Amtsgericht Lübeck
Email: moin@mandr-technologies.com
Please send privacy requests to moin@mandr-technologies.com.
2. The basic principle: your content stays with you
The vord apps are tools for running coding agent sessions that run entirely on your own Mac. We neither store nor read your source code, your terminal input and output, your chat messages or your image attachments:
- The Mac apps run all sessions locally on your device.
- The connection between your Mac and your iPhone runs through our intermediary server (relay), but it is end-to-end encrypted (ChaCha20-Poly1305 with keys negotiated anew for every connection). The relay server only forwards these encrypted data packets; it cannot decrypt them and does not store them.
A deliberate exception to this principle is push notifications (section 7): their title and text must be processed briefly in plain text on our server for delivery and transmitted to Apple.
For the apps to work, we process the account, device and connection data described in the following sections.
3. Account and sign-in
An account is required for purchases, the trial period and the Pro features (iPhone connection, session sharing). For this we process:
- Email address (also used as the sign-in name; verified by a confirmation email, double opt-in)
- Password: stored exclusively as a cryptographic hash (scrypt), never in plain text
- Account metadata: time of registration, verification status, start and duration of a trial period, chosen product
We do not collect a name or any other master data during registration.
Providing your email address and device data is necessary to conclude the contract: without this information we cannot provide the account, the licence or the Pro features. There is no statutory obligation to provide it.
If you invite team members (organisation feature), we store the email address of the invited person that you enter in order to deliver and assign the invitation.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
4. Licences, trial period and devices
To enforce the licence (number of devices activated at the same time, “seats”), we store for each activated device:
- a device identifier (on the Mac, the hardware UUID of the device; it is used exclusively for assigning the seat)
- the device name as set in your device’s system settings (e.g. “MacBook Pro of …”; you can change this name in the system settings at any time)
- platform and product (e.g. macOS/vord), as well as timestamps of the activation and of the last licence check (the apps check the licence about once a day)
For a free trial period, we store its start time in your account. Deactivated devices and ended activations are marked as revoked; they are deleted completely when your account is deleted (section 14).
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in preventing licence misuse).
5. Payment processing (Stripe)
We process purchases and subscriptions through the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland; where applicable, data transfer to Stripe, Inc., USA). You enter your payment details directly with Stripe in the hosted payment form; your card details never reach our servers. You also enter your billing address and optional VAT ID directly with Stripe; they only reach us as part of the invoice (see below).
We store:
- reference IDs (Stripe customer, subscription and invoice numbers) to link the purchase to the licence
- an invoice copy with name, billing address and, where applicable, VAT ID as transmitted by Stripe; these details are mandatory invoice content by law (§ 14 of the German VAT Act)
We retain invoice data for 10 years in accordance with commercial and tax retention obligations (§ 147 AO, § 257 HGB).
Stripe acts in part as an independent controller for payment processing; details can be found in Stripe’s privacy policy: https://stripe.com/de/privacy
Legal basis: Art. 6(1)(b) GDPR (processing of the purchase), Art. 6(1)(c) GDPR (statutory retention obligations).
6. Connection between Mac and iPhone (relay)
The iPhone apps connect to your Mac through our relay server, because Mac and iPhone can rarely reach each other directly. The following applies:
What the relay server processes for technical reasons:
- your account (sign-in of the devices to the service)
- per device: device name, platform, public key (which by design is not secret), times of pairing, connection and last activity
- when pairing: a short-lived pairing ticket (valid for 120 seconds, stored only as a checksum hash)
- connection metadata (which devices are connected when, volume and timing of the forwarded encrypted packets)
What the relay server cannot do: the content of your sessions (terminal input and output, chat messages, images, dictation audio) is end-to-end encrypted. The keys are negotiated exclusively between your Mac and your iPhone (with a key change on every connection, Perfect Forward Secrecy); the relay server never holds them and does not store the forwarded packets.
We use your IP address when establishing connections and for API requests only transiently in memory to prevent abuse (rate limiting); it is neither logged nor stored (section 11).
Legal basis: Art. 6(1)(b) GDPR; for abuse prevention, Art. 6(1)(f) GDPR.
7. Push notifications (iPhone)
If you enable notifications so that your iPhone informs you as soon as a session is waiting for you:
- we store the push token of your device assigned by Apple in order to deliver notifications;
- the title and text of the notification (by default including the session or project name) are generated by your Mac, processed briefly in plain text on our server for delivery and transmitted to the Apple Push Notification service (Apple Inc., USA). This is the exception to end-to-end encryption mentioned in section 2: delivery via Apple is technically impossible without readable content.
In the settings of the Mac app you can hide project names in notifications (a neutral text is then sent) and switch off notifications individually for each trigger. If you disable notifications, no content is transmitted to Apple.
Legal basis: Art. 6(1)(b) GDPR (a feature you have enabled); you additionally grant the permission on the iPhone via the iOS system dialog.
8. Dictation feature (Skald)
The apps optionally offer a dictation feature through our dictation service Skald (heyskald.com), which runs on the same server infrastructure operated by us (section 11). If you set up and use this feature:
- your voice recording is processed directly from the microphone and is never stored on a storage medium, neither on your devices nor on servers;
- the audio is transmitted from the iPhone, end-to-end encrypted, to your own Mac and sent from there to the Skald backend;
- the Skald backend transmits the audio for speech recognition to a specialised speech recognition service based in the USA, and the recognised text for linguistic clean-up to a provider of AI language models based in the USA. Under their contracts, these service providers do not use your audio and text data to train AI models.
The transfer to the USA is based on standard contractual clauses or on the respective provider’s certification under the EU-US Data Privacy Framework. Without setting up the dictation feature, no audio processing takes place at all; you grant the microphone permission via the system dialog.
Legal basis: Art. 6(1)(b) GDPR (a feature you actively use).
9. Sharing sessions with other users (Pro)
If you share a session with another person, we store the guest’s email address to assign and deliver the invitation, as well as cryptographic verification data for the share. The session content itself remains end-to-end encrypted between the devices involved here as well; our server cannot read it.
Legal basis: Art. 6(1)(b) GDPR.
10. Permissions and local data on your devices
Camera (iPhone): only for scanning the QR code when pairing with the Mac. No image is transmitted or stored; only the decoded pairing code is processed.
Photo selection (iPhone apps): if you choose images as an attachment for a session or a chat, the apps use the iOS photo picker (the app gets no access to your photo library, only to the selected images). The images are transmitted end-to-end encrypted to your own Mac and are not stored on our servers.
Microphone: only for the dictation feature (section 8).
Locally on your devices the apps store: the pairing and sign-in keys in the device’s protected keychain (without iCloud sync, not transferable to other devices), as well as settings and connection data (relay address, device identifiers, notification settings; for vord Cowork also the email address of the signed-in account) in the app storage. Terminal and chat content is not stored permanently on the iPhone but only kept in memory.
The apps contain no analytics, tracking or advertising SDKs and do not create usage profiles.
11. Servers, logs and security
Our servers (account service and relay) are operated by netcup GmbH, Karlsruhe, Germany. Connections are exclusively TLS-encrypted.
Our application logs contain no IP addresses and no session content; we log requests to API endpoints (method, path, status code, duration) with shortened identifier hints that do not directly identify anyone, for troubleshooting. IP addresses are used only transiently in memory to prevent abuse (rate limiting) and are discarded when the service restarts.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security and error diagnosis).
12. Diagnostic and feedback data (optional, only with consent)
The Mac apps can send us crash reports and, on your initiative, feedback. Crash reports are only sent if you have agreed (you are asked when starting beta versions); you send feedback actively yourself. The following is transmitted:
- the system’s technical crash report as well as the app version, macOS version and hardware model
- a pseudonymous device identifier (to group reports from the same device)
- a short excerpt of the app’s technical event log; it may contain project names, file paths and short technical messages (such as error and automation excerpts). User names in paths and recognisable credentials are removed automatically before sending; your complete terminal output, chat messages and source code are not included
- for feedback: your free text and, optionally, your email address (for follow-up questions) and a screenshot you have selected
The data goes exclusively to our own server (section 11) and is not passed on to third parties. Without your consent, no crash reports are transmitted; you can withdraw your consent at any time with effect for the future in the settings.
Legal basis: Art. 6(1)(a) GDPR (consent).
13. Email delivery, updates and app distribution
Transactional emails (verification, password reset, invitations) are sent via the service provider Resend (Resend, Inc., USA) on the basis of standard contractual clauses. The recipient address and the content of the respective email are transmitted.
Updates of the Mac apps are distributed via GitHub (GitHub, Inc., USA). During the update check, the app retrieves the update information there; in doing so, your IP address becomes visible to GitHub (as with any web page request). No system profile or usage data is transmitted to us or to GitHub.
The iOS apps are obtained via the Apple App Store or TestFlight. Apple processes data under its own responsibility. If you take part in a beta phase via TestFlight, we receive from Apple the feedback you send as well as crash reports, provided you have agreed to this in TestFlight.
14. Retention period and deletion
- Account data (email, password hash, licence and device data): we store it for as long as your account exists. An informal message to moin@mandr-technologies.com is sufficient to delete your account; we will then delete your data without undue delay, at the latest within one month.
- Invoice and purchase data is subject to the 10-year statutory retention obligation and is only deleted afterwards.
- Pairing tickets expire after 120 seconds; unconfirmed pairings are discarded after 10 minutes.
- Push tokens stop working when the device is unpaired and are removed at the latest when the account is deleted.
- Session content is never stored by us; there is therefore nothing to delete.
15. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). To exercise these rights, contact moin@mandr-technologies.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, https://www.datenschutzzentrum.de.
16. Recipients at a glance
- netcup GmbH: server hosting (account service, relay), Germany
- Stripe: payment processing, Ireland / USA
- Resend, Inc.: transactional emails, USA
- Apple Inc.: push delivery (APNs), app distribution, TestFlight, USA
- Specialised speech recognition service: speech-to-text conversion (dictation feature only), USA
- Provider of AI language models: text clean-up (dictation feature only), USA
- GitHub, Inc.: update distribution for the Mac apps, USA
Transfers to the USA are based on standard contractual clauses (Art. 46(2)(c) GDPR) or on the provider’s certification under the EU-US Data Privacy Framework.
17. Changes to this policy
We update this policy when the apps or the services used change. You can always find the current version at this address; the date at the top shows when it was last updated.