opeco CLI and MCP server.opeco.link temporarily connects a program performing a task with your devices to exchange status updates, notifications, questions, answers, messages, and photos. There are no user accounts, and you do not need to register your name or email address to use the service. On first use, the app automatically registers your device and uses generated identifiers and cryptographic keys to establish connections.
The source code is publicly available. Third parties that operate services using this code or distribute modified software determine their own data handling practices. When third-party software connects to the opeco.link relay service, this policy still applies to data handled by that relay service.
We handle the following information to authenticate communications, deliver content, and support sharing across devices. The relay server can observe connection relationships, communication times, and the size of encrypted data.
| Information | Purpose |
|---|---|
| Device, group, session, event, and attachment identifiers; delivery destinations | Identifying connections and the information to deliver |
| Public keys, hashes of authentication credentials, signatures, and encrypted shared keys | Authenticating communications and sharing keys among approved devices |
| Group membership and change history, device addition requests and their results, and session participation records | Supporting sharing across devices and tracking participation |
| Creation, update, and expiration times; encrypted data sizes; outstanding items; status update notification preferences | Managing expiration, delivery, and notifications |
| Apple push notification device tokens and notification environment | Delivering notifications to iPhone, iPad, and Mac |
There is no registration system that links these identifiers to names or email addresses. However, the identifiers allow the service to recognize continued use by the same device or group.
The apps do not include advertising or cross-service tracking for advertising purposes. We do not use additional analytics services.
The apps do not provide us with readable copies of locally stored private keys or decrypted communication content, such as messages and photos. Section 2 describes the encrypted content and connection and delivery information, such as device identifiers and public keys, that the server receives during communication.
| Provider | Purpose and information handled |
|---|---|
| Cloudflare | Web hosting, communication relay, data storage, and operational logs. In addition to the server-side information described in Section 2, Cloudflare handles connection information such as source IP addresses. Session content is handled in encrypted form. |
| Apple | Notification delivery through Apple Push Notification service. We send device tokens, generic text indicating that updates or questions are available, outstanding item counts, and related delivery information. Notifications do not include session titles, message content, or photos. |
| Receiving and storing inquiry emails through Google Groups, including the sender's email address and display name, message text, and attachments. |
You can turn off push notifications for iPhone, iPad, and Mac in the operating system's notification settings.
Membership of the Google group used for inquiries is restricted to the maintainers. Inquiry messages are not made public.
A session expires 24 hours after it is created or last renewed by an event sent by the program that created it. Viewing, syncing, or sending answers from a device does not, by itself, extend this period. The program that created a session can also close the entire session before it expires.
| Information | Storage location | Retention and deletion |
|---|---|---|
| Encrypted communication content and connection and delivery information within a session | Active server storage | Deleted as part of session closure or expiration. |
| Encrypted photo attachments | Active server storage | Deleted after the program that created the session acknowledges receipt. Remaining attachments are deleted as part of session closure or expiration. |
| Earlier versions of database records | Cloudflare database recovery history | Encrypted session content and connection and delivery records may remain recoverable for up to 30 days after deletion from active storage. Photo files are not included. |
| Device registrations, push notification device tokens, groups and their change history, and device addition request records | Server | No fixed automatic deletion period. Closing a session or allowing a device addition request to expire does not, by itself, delete these records. |
| Session participation records held by groups | Server | Deleted during explicit session closure or when group synchronization confirms that participation has ended. Deletion may not coincide exactly with session expiration. |
| Operational logs | Cloudflare Workers Logs | Retained for up to 7 days after each log entry is recorded. |
| Session information in the apps | Device or browser | Deleted when the app detects closure or expiration, such as during startup or synchronization. Information may remain while the app is not running. |
| Cryptographic keys and device and group connection information | Device or browser | Retained for continued use. Session expiration alone does not delete this information. |
| Decrypted photos received by the CLI or MCP server, and session information (including cryptographic keys) saved in shell mode | Temporary storage on the computer running the CLI or MCP server | Deleted when the session is explicitly closed. In shell mode, files are also deleted when the CLI detects that the session has expired or no longer exists. If the program stops without cleanup, files may remain with no fixed automatic deletion deadline. |
| Sender email addresses and display names, message text, and attachments in inquiry emails | Google Groups and the operator's email inbox | Retained to investigate and respond to inquiries and related questions, then deleted from both locations within one year after the inquiry is resolved. |
We do not keep separate backups of relay data.