For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security and privacy

Understand Sesori encryption, trust boundaries, and feature-specific data processing.

Sesori is local-first: your repositories and assistant processes remain on your computer rather than moving into a Sesori cloud workspace. The mobile app reaches them through the Sesori Bridge. Your selected assistant may still send prompts, source context, tool output, and other data to its configured model provider.

This page explains the technical boundary in plain language. The Sesori Privacy Policy is the authoritative source for personal-data processing, retention, rights, and sub-processors.

Ordinary session traffic

The phone and Bridge establish an encrypted application channel using X25519 key exchange and XChaCha20-Poly1305 authenticated encryption. Ordinary session payloads pass through the relay as opaque encrypted frames, so the relay does not ordinarily have plaintext access to prompts, responses, or file content in transit.

The relay still processes information needed to operate the service, including account identity, connection and routing metadata, session and project identifiers, timestamps, delivery status, and limited device or app metadata.

Features with a different data path

Some features cannot remain entirely inside the ordinary encrypted relay channel:

  • Push notifications: Sesori stores push tokens and sends notification payloads through Apple or Google. Depending on your settings, a notification can include limited session metadata or a partial snippet and may appear on the lock screen.

  • Voice input: Recorded audio is sent to Sesori and a transcription provider. The generated text is returned to the prompt field for review. The current policy says audio and transcripts are not retained after processing, except where limited retention is needed for operations, abuse prevention, security, incident response, or law.

  • Short text features: Invoked features such as session-title or branch naming can send limited readable text to Sesori and a configured processor.

  • Support and diagnostics: Logs, screenshots, attachments, crash data, or other details you submit or that supported diagnostics collect can be readable by Sesori and its service providers.

Review the Privacy Policy for the current provider list and retention details.

Your assistant and model provider

Sesori's phone-to-Bridge encryption covers the Sesori connection. It does not replace the security, permission, or privacy model of your selected AI coding assistant or model provider.

The assistant runs with whatever local access and approval configuration you give it. Prompts, source code, tool output, or other context may be sent by that assistant to its configured model provider. Review the provider's terms and configure the assistant's sandbox and permissions for your risk level.

Practical safeguards

  • Keep the Bridge and mobile app updated.

  • Use trusted projects and review project-local assistant configuration before opening them.

  • Prefer the assistant's sandbox and approval controls over unrestricted modes.

  • Prefer an assistant-owned credential store over provider secrets in the Bridge environment, which can be inherited by other assistant processes.

  • Hide sensitive notification previews at the operating-system level.

  • Review a session's local changes before committing or merging them.

  • Stop the Bridge with Ctrl+C when you no longer want remote access to that computer.

Privacy rights

Sesori does not currently provide self-serve account deletion in the app. To request deletion or exercise another privacy right, follow Delete your account. Requests are handled by email after identity verification.

Last updated

Was this helpful?