MobSession
legalprivacy policy

Privacy Policy

Last updated June 15, 2026.

The short version

MobSession runs a real Claude Code session on your own machine and mirrors it to a link so your team can watch and steer it. Your code stays on your machine. What leaves it is the session transcript you choose to share, plus the account details needed to run the service.

What runs locally vs. what we store

  • The agent runs on your machine using your own Claude subscription. We never receive your source code or your Claude credentials.
  • To share a session we store its transcript (the agent’s output, prompts, and chat the room sees), participant display names, and timing, on our servers so viewers can follow along live and reconnect.
  • Secrets in agent output are scrubbed before the transcript is mirrored. Control links and host keys are stored only as hashes.

Accounts

If you sign in, authentication is handled by a third-party identity provider, and we store your account identifier and organization membership to attribute sessions to your team. Anonymous link-joiners are identified only by the display name they type and a per-browser id.

Analytics & cookies

We use a cookie-based analytics service, with your consent, to understand aggregate usage and improve the product. It does not load until you accept the cookie banner; if you decline, no analytics cookies are set and no data is sent.

We also use a cookieless analytics service for basic page-view counts. It is cookieless: it sets no cookies and stores no persistent or cross-site identifier. Visitors are counted with a hash that rotates daily, so the same visitor cannot be followed from one day to the next or across other sites. Because it identifies no one, it runs on a legitimate-interest basis to measure traffic, including on shared session links where viewers never see the cookie banner (closing the banner without choosing still allows this basic counting).

We still honor your choice: if you decline cookies above, or your browser sends a Do-Not-Track or Global Privacy Control signal, we send no cookieless-analytics events either.

You can change or withdraw your choice any time; declining also stops the cookieless counting:

Retention

Sessions are transient. A session ends when the host stops it or its connection goes stale. An ended session and all of its data (transcript, prompts, chat, reactions, presence, and audit trail) are permanently deleted about 30 days after it ends.

Contact

Questions, data requests, or security reports: contact us.