phone-use is operated by Saurav Kumar Tomar (GitHub: sauravtom). The local CLI sends no telemetry. When you use this hosted MCP service, commands, screen text, screenshots, device identifiers and action results pass through Cloudflare to your MCP client and its AI provider. Only connect devices you own or have permission to control.
We do not intentionally persist screen contents, screenshots or input text. They are forwarded while processing requests. Cloudflare processes network metadata to operate and protect the service; your MCP client and AI provider may retain tool results under their own policies.
Pairing codes expire in 10 minutes and can be used once. Session credential hashes and phone-session metadata expire after 8 hours or are deleted when the bridge disconnects cleanly. OAuth access tokens last 1 hour and refresh grants at most 8 hours; dynamic OAuth client metadata expires after 30 days. Short-lived abuse counters store a hash of the connecting IP for about one minute. Cloudflare may retain platform security records and storage backups according to its policies. We do not sell this data or use it for advertising.
Stop the bridge to prevent further phone actions. Revoke the plugin in your MCP client to remove its connection. For privacy questions, use the support tracker; do not post screenshots, pairing codes, credentials or personal data there. Password-labelled UI text is redacted by the backend; screenshots are not redacted.
Updated September 28, 2026.