Summary: Flame Mobile is a local-first companion app. Camera access is used solely on-device to scan your desktop pairing QR code. The app contains no advertising SDKs, tracking libraries, or analytics. Remote connections are end-to-end encrypted through Flame Secure Relay.
1. Core privacy principles
Flame Mobile is engineered as a native companion control surface for the Flame IDE desktop application. Like the desktop IDE, Flame Mobile is built around local-first architecture and strict user privacy.
You do not need to create an account with Flame to use Flame Mobile. The application contains no advertising SDKs, no tracking pixels, no behavioral analytics libraries, and no third-party profiling services.
2. Device permissions and on-device use
Flame Mobile requests minimal device permissions strictly necessary to connect with your Flame IDE desktop workstation:
- Camera access: Used exclusively to scan the QR code displayed in your Flame IDE desktop settings during device pairing. QR code processing occurs entirely on-device in real time. Flame Mobile never takes photos, records video, stores imagery, or transmits camera frames to any server.
- Local network: Used to discover and establish a direct connection with your Flame IDE host machine when both devices are on the same Wi-Fi or local area network.
3. Connection security and Remote Access
Flame Mobile connects to your development environment through one of two modes:
- Same Wi-Fi (Direct connection): When your mobile device and desktop computer share a local network, communication travels directly between the two devices without leaving your local network.
- Anywhere (Flame Secure Relay): When connecting over the internet, traffic is relayed through Flame Secure Relay using end-to-end encryption. The relay server acts solely as a blind transport layer. It never holds encryption keys and is cryptographically incapable of decrypting or inspecting your source code, terminal commands, AI prompts, git data, or workspace files.
Live IP addresses used during active relay connections exist only in volatile memory for the duration of the active socket and are never written to disk.
4. Data storage and credential security
All pairing secrets, session tokens, and cryptographic keys are saved exclusively on your physical device using the operating system secure enclave / keychain (iOS Keychain Services). These credentials are sandboxed to Flame Mobile and are never synchronized to Flame cloud servers.
You can revoke device pairing at any time directly from the paired device settings within Flame IDE on your desktop computer, or by uninstalling Flame Mobile from your device.
5. AI requests and workspace context
When you trigger AI actions, inspect tasks, or review diffs from Flame Mobile, commands are dispatched to your paired Flame IDE desktop host. The desktop host communicates directly with the AI model provider you have configured (such as Anthropic, OpenAI, Google, or local models via Ollama). Flame Mobile does not operate an intermediate logging server or store your prompts and code context.
6. Crash reporting and diagnostics
Flame Mobile does not include automated third-party crash reporting SDKs. If an operating system level crash report is generated by iOS, it is governed by your Apple device analytics settings and Apple App Store privacy choices.
7. Your rights and data deletion
Because Flame Mobile does not collect user accounts, personal identities, or remote behavioral records, there is no centralized database holding your personal data.
Disconnecting your session or uninstalling the app immediately deletes all locally stored keys, session caches, and preferences from your device.
8. Contact us
If you have any questions about this Privacy Policy or how Flame Mobile handles device security, contact us at support@flame-ide.com.
Looking for other privacy policies? View the Flame IDE Desktop & Website Policy or Flame Browser Bridge Privacy Policy.