Privacy

Website Commander is built around one boundary: nothing leaves your machine unless you configure it to, and nothing is committed or deployed without your explicit approval.

Credentials

GitHub tokens, provider API keys, and deployment credentials are stored only in your macOS or iOS Keychain. They are never written to the repository, never included in logs, and never sent to any server other than the provider you configured.

AI requests

Website Commander connects directly to the AI provider you choose, using your own key, or runs compatible models on-device. Prompts, file contents, and diffs go straight to that provider — there is no intermediary service operated by the app.

Repository access

The app reads and writes only the repositories you connect. Changes are staged and shown to you as a diff first; a commit happens only after you approve it. Deployments run on your hosting provider of choice.

Analytics

The Website Commander app itself collects no analytics. This website may use privacy-friendly, cookie-free analytics for aggregate page views.

Contact

Questions about privacy: mesut.uk/apps/website-commander or the GitHub repository linked in the footer.