Vyre / Privacy
Privacy.
What Vyre knows about you.
Almost nothing. Vyre runs on your own server, and the project behind it keeps no account of you, no copy of your work and no analytics. This page says what the few Vyre services do see, and what each app keeps on your device. Last updated 5 October 2026, for Vyre 0.2.9.
The short version
- Your work stays on your server. Sessions, memory, files, the vault and your conversations live on the server you run and on your own devices. Vyre does not receive them.
- No account, no analytics, no ads, no trackers. There is no Vyre sign-up. The apps, the server and this site contain no analytics or crash-reporting code, and none of them sends usage data anywhere. Two optional lookups are listed in section 07.
- Three small services run by the project: a relay that carries encrypted traffic, a name directory for
yourname.vyre.run, and this website. Below is what each one sees. Releases come from GitHub. - Your personal memory is encrypted with your own key. A server's owners and admins cannot read it, and each chat is encrypted to the people in it. Sections 03 and 04 say more.
- Your AI providers see your prompts, because that is how an AI works. You sign in to them yourself, with your own accounts and keys.
Your data stays on your server
Vyre keeps its data on the machine you installed it on: sessions, memory, project files you chose, the vault, logs and settings. On a Linux server that is a set of Docker volumes; on a Mac that runs Vyre directly it is the ~/.vyre folder. The vault is sealed on that machine. Nothing in it is sent to Vyre.
When an agent works, your server sends the prompt to the AI provider you picked (Claude, Codex, Grok or OpenRouter), under your own account, and that provider's terms and privacy policy apply to it. The sign-in for each AI account stays on your server. Anything else you connect, such as GitHub or Google, is likewise your own account under that service's terms. Your devices and your server reach each other through Vyre's own private network, which is built in; where a direct path is not possible, the relay carries the connection (section 05).
Voice is the same: when you talk to your assistant, your server sends the audio to the speech service you chose (Deepgram, OpenAI or ElevenLabs) with your own key. When a reply is spoken, your server sends the text of that reply, at most 2,000 characters, to the speech service you chose.
Where a space lives has a name. Your space on your devices is Personal: it keeps chats and projects on your devices, with an encrypted backup to a team's Cloud. Your space on your own server is My Cloud: it adds Records, flows and Planner, reachable from anywhere. Team spaces run on a server and are tagged Cloud.
Your personal memory and assistant
Your personal memory and your assistant are encrypted with your own key. They can be stored on a Cloud space's server, and the owners and admins of that server cannot read them.
While your assistant is unlocked, your memory is readable only inside the running program and is never written to disk unencrypted. While your assistant is working on a server you don't own, that server's operator could in principle see what it is working on. To avoid that, run your assistant on your own computer or your own server.
If you set up My Cloud on your own server, your personal memory can move there.
Your chats and their files
Each chat and its files are encrypted to the people in that chat. A Cloud space's owners and admins cannot read chats they are not in, even with access to the server's disk. File names are encrypted too.
While an agent works in a chat on a server, that server's operator could see that chat in use.
What the relay sees
The relay at relay.vyre.run lets a phone, a browser or a Windows PC reach your server without a direct path. Your server connects to it when the relay is on, which pairing a device turns on. It carries traffic and nothing else.
- Traffic is encrypted from your device to your server. Each side holds its own key and the relay holds none, so it cannot read a message and any change to one is rejected by the receiver. It can drop or delay a message.
- Pairing records are sealed and short-lived. A Wink pairing record is stored as ciphertext for at most 5 minutes, handed out once, and deleted when it is used or when it expires.
- Frames waiting for your server are held, still encrypted, until your server picks the connection up or the device disconnects, normally one round trip, at most 64 frames per connection. They are deleted on delivery or when the device leaves.
- What it can see: the address a connection comes from, when it connects, how large each message is, the route id (a hash of your server's public route key) and that public key. It never sees message contents.
- Rate limits count requests per address in a 60 second window, so one client cannot flood it: 30 a minute for device connections, 30 a minute for pairing lookups that find nothing, and 20 a minute for setup posts. The hosted relay's code does not write those addresses to its storage or to a log.
- No request logs. Cloudflare hosts the relay, and the relay's configuration has Cloudflare's Worker request logs turned off. The hosted relay's code writes no log of who connected; the self-hosted Node relay can log route ids when its operator turns logging on.
The relay is open source (relay/worker and relay/node in the repository). You can run your own and point your server at it with the relay address setting.
Your address on vyre.run
When you choose a name, the name directory at names.vyre.run creates yourname.vyre.run and points it at your server's public address, but only after an outside check shows the server answers; until then the name is not published and the server is reachable through the relay only. DNS is public, so anyone can look up that name and the address it points to. The certificate for the name is also recorded in public certificate logs, which is how the web works. Choose a name you are happy to have public.
- It stores: the name, the route id of your server (a hash of its public key), when the name was claimed and pointed, the public address in the DNS record, a hash of your recovery code (it sees the code itself only when it creates it for you and when you use it to recover), the last 50 recovery attempts with their time, whether the code was right and the first 8 characters of the route id, up to 20 notices, a pending recovery (the new route and code hash), and signature nonces for a couple of minutes.
- It asks for no email and no personal details. Every request that changes or reads your name is signed by your server's key, and recovery also needs the recovery code. The availability check is unsigned.
- Per-address counters hold the requesting address and limit claims (5 a day) and recovery attempts (20 a day). An hourly sweep drops them once they are about two days old.
- Giving a name up deletes it if it was never pointed. A name that was ever live stays reserved: the directory keeps the name, the recovery-code hash, the claim and point times, the notices and the recovery log, with no route and no address, so nobody else can take it over; only the recovery code can move it.
- No request logs. Cloudflare hosts the directory, with Worker request logs turned off, as for the relay.
This website, updates and downloads
- vyre.run has no analytics and no cookies.
- The marketing pages load their fonts from Google Fonts, so Google sees a font request with your IP address when you open them. The server behind
app.vyre.runsets no cookies and keeps nothing about you or your server; the page keeps your device key, server address and pairing in your browser, as section 08 lists. - Two optional lookups: Vyre Lumen on a Mac fetches exchange rates from
open.er-api.comwhen you type something that reads as money, at most every 12 hours, with none of your words sent. The weather action sends a city name (by default one derived from your time zone) toopen-meteo.com. The device sign-in page that your own server serves loads its fonts from Google Fonts. - The pages are served by Cloudflare, which keeps ordinary server logs under its own policy.
- Updates: your server checks GitHub's releases API for new versions and pulls signed images from
ghcr.io; the Windows app checks GitHub's releases feed once a day and downloads its installer from GitHub; the install line fetches fromvyre.run. Those services see the address your server or PC connects from, under their own policies. Vyre itself receives no report of which version you run.
What each app keeps on your device
- The Vyre app in a browser or on a Home Screen keeps in the browser's own storage: a device key the browser cannot export, the key that opens your private chats and notes, the pairing with your server, a cache of recent views (needs rows, the chat list and snippets), your pins, unsent drafts, recent searches, your appearance settings, where setup stopped, an outbox of writes not yet delivered, and cached app files. The browser's push service holds your push subscription, and the app sends it to your server. The web app keeps no unlock session: the browser asks for your passkey on each protected call. On a phone, keys and the pairing sit in the phone's secure store, and an unlock session lasts 30 minutes after you confirm. When the owner removes a device, it forgets all of this the next time it reaches Vyre and asks to be paired again; a device that is offline keeps it until then. Two more limits: an old browser that cannot list its databases has only the app's four named databases deleted, and a sign-in cookie that your server sets (when the app is opened at your server's own address) belongs to the server, which refuses a removed device anyway.
- The hosted web app at app.vyre.run keeps two keys the browser cannot export, the pairing record in localStorage, the relay key in IndexedDB and cached app files. It has no wipe: sign out and clear the site's data in your browser.
- The phone app (iPhone and Android) makes two keys in secure hardware where the phone has it, the Secure Enclave on iPhone and the Android Keystore on Android (some phones fall back to software). One signs its requests, and the other signs only after your face or fingerprint. They cannot be exported. Your sign-in tokens and the pairing with your server are kept in the system Keychain or Keystore. On iPhone those items are marked this-device-only; on Android, backup follows Android's own backup rules. The view of recent threads and lists is held in memory and is gone when you close the app. Signing in on your own address opens the system sign-in browser. Pairing links open the app. The app declares no camera, microphone, location, contacts or photos permission, and this version has no notifications.
- Vyre Lumen on a Mac keeps its approval key in the Secure Enclave where the Mac has one, with only an opaque handle in the login keychain; a Mac without one keeps a software key in the login keychain. It talks to your server.
- Vyre Lumen on Windows (the app is named Vyre in Windows) keeps your server's address in a pairing file and its device key in its app data folder, with the key protected by Windows DPAPI. The installer for a newer version is saved there before it runs. Starting at sign-in uses a Windows scheduled task named Vyre, which the app creates and deletes when you change that setting.
- Password AutoFill (in the Android phone app, and on iPhone and Mac in builds that include the extension) asks your server for one login at a time, after you confirm with your face or fingerprint. On iPhone and Mac it keeps the server address and a device token in the Keychain and the unlocked session in memory only, and gives the system the sites, usernames, passkey names and one-time-code labels from your vault, never passwords, passkey private keys or code seeds. On Android the address and token sit in Keystore-protected storage, and it uses its own biometric key.
- The vault browser extension keeps the address of your server, this browser's device id and token, and its two on and off choices in the extension's storage, and the unlocked session in session storage. It talks only to the server address you set and sends no page content. With the API-key offer on, it reads the page text on your device looking for one key-shaped value, and a matched value leaves the page only after you tap Save.
Camera and microphone
The camera is used for one thing: scanning a Wink, the code that pairs or introduces a device, in the Vyre app in a browser or on a phone. It asks for video only, never audio. The picture is read on your device. It is not saved and not sent anywhere. You can also scan a pairing QR code with the phone's own camera and it opens the app.
The microphone is used by push-to-talk in Vyre Lumen on a Mac, only while you hold the key or button. The audio goes to your server and from there to the speech service you chose; your server does not log or keep it. The phone app declares no microphone permission (the browser app never asks for audio), and the Windows app has no microphone code.
Passkeys and keys
You make your passkey for your own server's address, with your device's own passkey system. The private key stays in your device's secure hardware or your password manager. Your server keeps only the public half, and Vyre never receives either. The approval key in the phone app is made in secure hardware where the phone has it (the Secure Enclave or the Android Keystore; some phones fall back to software), cannot be exported, and needs your face or fingerprint to use. Your identity has its own recovery code. It is shown to you once; keep it somewhere safe. It restores your identity on a new device.
Notifications
A notification carries a fixed sentence, such as "A session is waiting for your answer", "A milestone is done" or "A teammate finished", and a link to an item by its id. That is all. It carries no thread text, no goal or milestone text, no message text, no teammate name and no project name. The phone opens the item and asks your own server for the details, over your own connection. The fixed sentence does say what kind of thing happened: a question, an approval or a finished goal.
One setting is an exception, and it is off by default: Show a reminder's own words on the lock screen. When you turn it on, the label you typed on a reminder rides in that notification and passes through Apple's, Google's or Mozilla's push service. The setting says so.
Notifications work today through Web Push in a browser or on a Home Screen web app. Web Push encrypts the payload end to end and delivers it through your browser's push service (Google, Mozilla, Apple or Microsoft), which still sees that a notification was sent to a device, and when. The phone app has no notifications in this version.
Crash logs and diagnostics
Vyre sends no crash reports and no diagnostics anywhere. Your server writes a log file for each day on your own machine, and vyre doctor prints its checks to your own screen. If something breaks, you decide whether to share a log, for example in a GitHub issue. Your phone's operating system may send its own crash reports to Apple or Google if you turned that on in system settings; that is theirs, not Vyre's.
Delete everything
- On your server: if you claimed a name, run
vyre name releasefirst. If you want a copy of your data, runvyre backupand copy the file off the server, because it is saved inside the volume the uninstall deletes. Then runvyre uninstall --delete-data, which stops Vyre, removes its images and deletes its data volumes for good. Finally remove the install folder (/srv/vyre, or yourVYRE_DIR; the uninstall prints it) and/var/lib/vyre-update, where automatic updates keep their backups. - On a Mac that runs Vyre as a server, run the installer's
--uninstall --purge(scripts/install-mac-server.sh), which removes the service,~/.vyre-server,~/.vyreand the system data. Delete~/Vyre/projectsif you used it, and remove thevyre-vaultandsh.vyre.capsule.presenceitems in Keychain Access. - On a phone: remove it in Devices on your server first, so its keys stop working. Signing out in the phone app ends your session when the phone can reach your server and forgets the sign-in on the phone, but the phone stays paired. Deleting the app removes its keys on Android; on iPhone the system may keep them.
- On a Mac with Vyre Lumen: Lumen lives in
~/.vyre/capsule/Vyre.app, so it goes with~/.vyre, but its Keychain item stays: removesh.vyre.capsule.presencein Keychain Access. On Windows: uninstall Vyre in Windows Settings, delete therun.vyre.appfolder in%APPDATA%(the pairing file and key), and delete the scheduled task named Vyre in Task Scheduler, or turn off start at sign-in before you uninstall. - What stays with the project: nothing of your work, because it never arrived. Relay records expire within an hour, held frames go when delivered or when the device leaves, and address counters go within about two days. A name that was ever live stays reserved, as described above. To have even that looked at, write to the contact below.
Contact
Questions about this page, or a request about a name: email [email protected], or open an issue at github.com/vyre-ai/vyre/issues. A security problem goes to a private advisory at github.com/vyre-ai/vyre/security, not a public issue.
Vyre is open source (Apache 2.0). Every claim on this page can be checked in the code, and changes to this page are in its history on GitHub.