Datenschutzerklärung | tau
Datenschutzerklärung für Tau
für die Desktop-App Tau und die Tau-App für Android und iOS (de.tbuck.tau)
Stand: 29. September 2026 · English version below
Kurz gesagt
Tau schickt nichts an mich als Entwickler. Es gibt keinen Tau-Server, kein Konto, keine Analyse, keine Werbung und keine Absturzberichte. Die App auf dem Handy spricht nur mit Tau auf deinem eigenen Rechner. Die einzigen fremden Dienste, die dabei vorkommen, sind die Push-Dienste von Google und Apple, und die auch nur, wenn du Benachrichtigungen erlaubst.
Verantwortlicher
Torben Buck (tbuck software)
Zu den Weiden 12
58339 Breckerfeld
Deutschland
E-Mail: info@tbuck.de
Was Tau ist
Tau ist eine Werkbank für Coding-Agents. Die Desktop-App läuft auf deinem Rechner (Mac, Windows, Linux). Die App für Android und iOS zeigt die Threads dieses Rechners auf dem Handy. Tau ist quelloffen; was hier steht, lässt sich im Quellcode nachprüfen: github.com/Rasalas/tau.
Handy und Rechner
Du koppelst das Handy einmal mit Tau auf deinem Rechner, über einen QR-Code und sechs Ziffern, die beide Seiten zeigen. Danach verbindet sich die App im Heimnetz oder über Tailscale direkt mit deinem Rechner. Die Verbindung ist mit TLS verschlüsselt und an den Schlüssel deines Rechners gebunden, sodass niemand dazwischen mitlesen kann.
Über diese Verbindung gehen Nachrichten, Code, Diffs, Terminal-Eingaben und Dateien, also alles, was du in der App siehst oder eingibst. Das alles liegt auf deinem Rechner und bleibt dort. Auf dem Handy speichert die App die gekoppelten Rechner und ihre Zugangsschlüssel im geschützten Speicher des Systems (Keychain bzw. Keystore) und eine Kopie der zuletzt gesehenen Threads, damit sie schnell startet.
Die Kamera liest nur den QR-Code zum Koppeln. Das Bild verlässt das Gerät nicht. Die Suche nach Rechnern im lokalen Netz (Bonjour) bleibt im lokalen Netz.
Push-Benachrichtigungen
Tau kann dich benachrichtigen, wenn ein Thread fertig ist, scheitert oder dich etwas fragt. Die Nachricht schickt dein eigener Rechner, nicht ein Server von mir.
- Android: Erst wenn du Benachrichtigungen erlaubst, fragt die App bei Firebase Cloud Messaging (Google) ein Geräte-Token an. Dafür legt Google eine Firebase-Installations-ID an. Das Token geht an deinen Rechner, und dein Rechner schickt Benachrichtigungen über Google an dieses Token. Datenschutzhinweise von Google: firebase.google.com/support/privacy.
- iOS: Erst wenn du Benachrichtigungen erlaubst, gibt iOS der App ein Geräte-Token des Apple Push Notification service (APNs). Das Token geht an deinen Rechner, und dein Rechner schickt Benachrichtigungen über Apple an dieses Token. Datenschutzhinweise von Apple: apple.com/legal/privacy.
Eine Benachrichtigung enthält den Titel des Threads und die erste Zeile der letzten Antwort, oder nur den Titel. Das stellst du auf dem Rechner unter Settings → Push ein. Der Inhalt läuft dabei über die Server von Google bzw. Apple. Die Übertragung ist verschlüsselt. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), die du jederzeit in den Systemeinstellungen widerrufen kannst.
Die Desktop-App
Tau auf dem Rechner schickt ebenfalls nichts an mich. Es spricht aber mit Diensten, die du ohnehin nutzt, in deinem Auftrag und mit deinen eigenen Konten. Für diese Dienste gelten deren Datenschutzerklärungen:
- Updates: Tau fragt bei GitHub nach neuen Versionen und lädt sie dort herunter (github.com/Rasalas/tau-releases). GitHub sieht dabei deine IP-Adresse (Datenschutzerklärung von GitHub).
- Versionen und Modelle: Tau liest die aktuellen Versionen der Agent-Programme aus der npm-Registry und die Liste der Modelle von models.dev. Dabei geht nichts außer der Anfrage selbst mit.
- Die Agents: Die Coding-Agents, die du in Tau benutzt (etwa Pi, Claude Code, Codex, OpenCode, Gemini), schicken deine Anfragen an ihre Anbieter, mit deinem eigenen Konto. Die Seite Usage fragt mit demselben Konto ab, wie viel von deinen Abos übrig ist. Tau leitet nichts um und liest nicht mit.
- Git-Hosts: Pull Requests und ihre Checks liest Tau über deine eigenen Werkzeuge bzw. Zugänge bei GitHub, GitLab und anderen.
Löschen
Ich habe keine Daten von dir, die ich löschen könnte. Deine Daten löschst du selbst:
- Kopplung aufheben: Auf dem Rechner unter Settings → Connections das Gerät widerrufen, oder in der App den Rechner entfernen. Damit endet auch der Versand von Benachrichtigungen an dieses Handy.
- App entfernen: Beim Deinstallieren löscht das System alles, was die App auf dem Handy gespeichert hat. Das Push-Token wird damit ungültig.
- Auf dem Rechner: Threads löschst du in Tau. Die Push-Schlüssel entfernst du unter Settings → Push.
Deine Rechte
Du hast nach der DSGVO das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch sowie das Recht, dich bei einer Aufsichtsbehörde zu beschweren. Da ich keine Daten von dir verarbeite, gibt es bei mir nichts auszukünften. Frag trotzdem gerne: info@tbuck.de.
Änderungen
Ändert sich etwas daran, was Tau sendet, ändere ich diese Seite und das Datum oben.
Privacy policy for Tau
for the Tau desktop app and the Tau app for Android and iOS (de.tbuck.tau)
As of 29 September 2026
In short
Tau sends nothing to me, the developer. There is no Tau server, no account, no analytics, no ads and no crash reporting. The phone app talks only to Tau on your own computer. The only outside services involved are Google’s and Apple’s push services, and only if you allow notifications.
Controller
Torben Buck (tbuck software), Zu den Weiden 12, 58339 Breckerfeld, Germany. Email: info@tbuck.de
Phone and computer
You pair the phone once with Tau on your computer, through a QR code and six digits both sides show. After that the app connects directly to your computer on your home network or through Tailscale. The connection is encrypted with TLS and pinned to your computer’s key, so nobody in between can read it.
Messages, code, diffs, terminal input and files travel over this connection: everything you see or type in the app. It all lives on your computer and stays there. On the phone, the app keeps the paired computers and their access keys in the system’s protected storage (Keychain or Keystore), and a copy of the threads it saw last, so it starts quickly.
The camera only reads the pairing QR code; the picture never leaves the device. Looking for computers on the local network (Bonjour) stays on the local network.
Push notifications
Tau can tell you when a thread finishes, fails or asks you something. Your own computer sends the notification, not a server of mine.
- Android: Only once you allow notifications does the app ask Firebase Cloud Messaging (Google) for a device token; Google creates a Firebase installation ID for it. The token goes to your computer, which sends notifications to it through Google. Google’s privacy information: firebase.google.com/support/privacy.
- iOS: Only once you allow notifications does iOS give the app an Apple Push Notification service (APNs) device token. The token goes to your computer, which sends notifications to it through Apple. Apple’s privacy policy: apple.com/legal/privacy.
A notification holds the thread’s title and the first line of the latest reply, or the title only; you choose on the computer under Settings → Push. Its content passes through Google’s or Apple’s servers, encrypted in transit. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in the system settings.
The desktop app
Tau on your computer sends nothing to me either. It does talk to services you use anyway, on your behalf and with your own accounts; their privacy policies apply:
- Updates: Tau asks GitHub for new versions and downloads them there (github.com/Rasalas/tau-releases). GitHub sees your IP address (GitHub’s privacy statement).
- Versions and models: Tau reads the current versions of the agent programs from the npm registry and the list of models from models.dev. Nothing goes along but the request itself.
- The agents: The coding agents you use in Tau (such as Pi, Claude Code, Codex, OpenCode, Gemini) send your requests to their providers, with your own account. The Usage page asks, with the same account, how much of your plans is left. Tau does not reroute or read along.
- Git hosts: Tau reads pull requests and their checks through your own tools or access to GitHub, GitLab and others.
Deleting your data
I hold no data of yours that I could delete. You delete your data yourself:
- Unpair: revoke the device on the computer under Settings → Connections, or remove the computer in the app. That also stops notifications to this phone.
- Uninstall the app: the system deletes everything the app stored on the phone, and the push token stops working.
- On the computer: delete threads in Tau; remove the push keys under Settings → Push.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to complain to a supervisory authority. As I process no data of yours, there is nothing to disclose, but do ask: info@tbuck.de.
Changes
If what Tau sends changes, I change this page and the date above.