Your PC. Your plan. Your business.
Shellby is a desktop app that runs on your PC. It has no servers, no accounts of its own, no telemetry and no analytics. Nobody behind Shellby, including its author, receives anything about you or how you use it, except a crash report you choose to send.
%APPDATA%\Shellby, on your PC.Automatic, for everyone
What Shellby does do is talk to a few services on your behalf: GitHub to check for updates, and others only when you use a feature that needs them. This page lists every one, what goes to it, and how to turn it off.
Update checks
GitHub ReleasesAt startup and every 6 hours, the installed version asks GitHub's servers for x-salmon/shellby's latest release, downloads it in the background when there is one, and installs it when you quit or click Restart and update. GitHub sees an ordinary download request (your IP address, the app's version). This can't be switched off in Settings; the portable build never updates itself.
Claude Code
Anthropic, through the claude CLIShellby doesn't contact Anthropic itself. It runs the official claude command-line tool that you installed and signed in to, and that tool sends your prompts and the files Claude reads to Anthropic, under Anthropic's terms and privacy policy. If you choose Just the crab and never set up Claude Code, none of this happens.
Only when you use the feature
Each of these talks to the service named, only while you use it. Off by default marks the ones that start switched off.
GitHub sign-in Off by default
GitHub- What's sent
- The sign-in code you approve, then requests for your profile and avatar.
- When
- When you sign in.
Sync Off by default
GitHub (a private gist in your account)- What's sent
- Trophies, XP and its log, outfit, skin, project names and their GitHub remote addresses (e.g.
github.com/you/repo), stats, his tank's layout and saved layouts, your Bugdex catches (how many of each kind, when, how quickly and in which languages; never projects or error text), the days you used him (for streaks), tide event goals and medals, your friends list, your settings (permission mode but never Autonomous, model, effort, output style, hotkey, his size, on/off switches, chatter and mischief levels, spending guard, Work mode, pinned tools, and the text of your prompt snippets), and a random ID for this PC. - When
- Every 15 minutes and shortly after changes, while Sync is on.
CI status
GitHub- What's sent
- Searches for your open pull requests and ones awaiting your review, and their check results.
- When
- Every 3 minutes, while it's on.
GitLab merge requests
GitLab (gitlab.com and hosts you add), throughglab- What's sent
- Requests for your merge requests, their pipelines and review threads, with the sign-in
glabalready has. - When
- Every 3 minutes, while it's on.
Issues to take on
GitHub- What's sent
- Searches for open issues assigned to you, and ones labelled
shellbyin your own repositories and the ones cloned on this PC. - When
- Every 5 minutes, while Offer to take on issues is on.
Projects and Next up
GitHub; Sentry at the address you give; your MCP servers- What's sent
- Your repository list for the Projects page, and a project's open issues and milestones for its Next up list. With a Sentry token, that project's unresolved errors from the last 14 days. With Linear or Jira turned on for a project, a short Claude Code call reads its open issues through the MCP server you named.
- When
- When a project's page opens; never polled. Sentry, Linear and Jira are off until you set them up.
Fix this build and Address the review
GitHub, or GitLab throughglab- What's sent
- Requests for the failing job's log, or the review comments still open.
- When
- When you press one.
Filing a flaky test
GitHub- What's sent
- An issue on the project's repository, labelled
shellbyand assigned to you: the test's name, how often it flaked, and the command as shown. - When
- When you click File it in the confirmation window.
Visiting crabs Off by default
GitHub (a public gist in your account, and your friends' gists)- What's sent
- Your calling card: GitHub username, skin, shell, level, outfit, sticker art, his temperament and his favourite find, and up to 3 project names only if you pick Shell and names. With Show his tank on, his tank's size, floor, back glass and light, and up to 24 built-in pieces. With Share my Bugdex with friends on, which kinds of bug you've caught, how many badges you hold and whether you've made the Hall of Fame; never counts, projects, times or errors. Friends' cards are drawn with your own Shellby's art; nothing on them is loaded from anywhere else. Waves are posted as gist comments.
- When
- Every few minutes, while it's on. Turning it off deletes your card.
Profile card Off by default
GitHub (a public gist in your account)- What's sent
- An SVG picture: your GitHub username, crab and outfit, level and title, streak length, and the art of your five latest stickers (no project names; hidden projects left off). A GitHub Action you add to your profile repository copies it there; Shellby reads (never writes) that public repository to tick off the setup steps.
- When
- When it changes, and at most once a day otherwise. Turning it off or signing out deletes the gist; the copy in your profile repository stays until you remove it.
Built with Shellby (pull request badge) Off by default
GitHub (a publicshellby-badge repository, and your pull requests)- What's sent
- An SVG picture of your crab in his outfit, committed to
shellby-badge. Needs GitHub'spublic_repopermission; Shellby writes only toshellby-badgeand your own pull requests with it. Pull requests your Shellby tabs open get that picture, your level and a link to Shellby added at the bottom of their description. - When
- Only when a tab opens a pull request and his look has changed since the last one. Turning it off stops new badges.
Publishing a Wardrobe pack
GitHub- What's sent
- Your pack, as a pull request to
x-salmon/shellby-packs. - When
- When you publish one.
Let Claude tasks push Off by default
GitHub, throughgit and gh in your tabs- What's sent
- Your GitHub sign-in is handed to the Claude Code tasks Shellby runs, so they can push.
- When
- With a warning before it's turned on.
Community packs and outfit codes
x-salmon.github.io/shellby-packs- What's sent
- Requests for the pack index, catalog and pack files.
- When
- When you open a
shellby://installlink or paste an outfit code that needs items you don't have.
Phone notifications Off by default
The service you pick: ntfy, Pushover, Telegram, a Discord or Slack webhook, or your own endpoint- What's sent
- The notification's title and text and the project's name. For permission prompts that includes what Claude is asking to do, such as a command or a file path.
- When
- When an event you chose happens. The destination is confirmed in a separate window before anything is sent.
Answering from your phone Off by default
ntfy or Telegram- What's sent
- Shellby checks for your Allow/Deny reply.
- When
- Only while a prompt is waiting.
Starting tasks from your phone Off by default
Telegram (your bot's messages) or ntfy (a<topic>-tasks topic)- What's sent
- Shellby reads what you send (Telegram's long poll about every 25 seconds, or the ntfy tasks topic about every 15 seconds) and answers with short lines: “On it”, the folder's name, and for
/statusthe titles of your open tabs and whether they're waiting for you, never file contents, diffs or commands. - When
- While it's on, until Shellby quits. Turning it on is confirmed in a separate window, and changing the bot, chat or topic turns it off.
Claude Code updates
The npm registry (registry.npmjs.org)- What's sent
- One request for the
@anthropic-ai/claude-codepackage page: your IP address, nothing else. Installing an update runs Claude Code's ownclaude update. - When
- Once a day while Claude Code is set up. Leave it to me in Settings → About stops it.
New tricks
GitHub (raw.githubusercontent.com), for Claude Code's public changelog- What's sent
- One request for the file: your IP address, nothing else. No Claude usage.
- When
- Only when the Claude Code Shellby finds is newer than the one he saw last. A switch in Settings → General stops it.
Dependency watch Off by default
The npm registry, throughnpm outdated and npm audit- What's sent
- The names and versions of each npm project's dependencies, as npm normally sends them.
- When
- Once a week, for the npm projects you work in.
Workflow web requests
Any address you type into a Web request step- What's sent
- Whatever that step is set to send, including workflow secrets you put in it.
- When
- When the workflow runs.
Git
Your project's own remote (e.g. GitHub)- What's sent
git fetchandgit push, with your usual git credentials.- When
- When you open a tab's repository menu, Push, or Bring it home and push.
Workflow pull requests
GitHub- What's sent
- Make a copy fetches the default branch into your clone; Open a pull request pushes the copy's branch and opens a draft pull request.
- When
- When a workflow runs those steps.
Time tracker Off until you connect one
Toggl Track, Clockify or Harvest- What's sent
- Your token, then for each day you send: the tracker project each Shellby project is matched to, start time, duration, whether it's billable, and a description (your note for the day, or that day's commit messages).
- When
- When you send a day.
Other computers
Computers you add, over ssh; and Claude Code's installer atclaude.ai if you press Install Claude Code there- What's sent
- Conversations in a folder on that computer run there: what Claude Code would send from this PC. A quick look at what's installed there, the folders you browse, and a public key if you set up sign-in with your password. Passphrases and passwords you type go to ssh on this PC and are never kept.
- When
- When you add one, press one of its buttons, or work in one of its folders.
Skill Shop, MCP servers and the Shellby plugin
The source of whatever you install (usually GitHub), through Claude Code- What's sent
- Claude Code's download requests.
- When
- When you install or update one, after a confirmation window.
On your Discord profile Off by default
The Discord app on your PC (a local pipe)- What's sent
- His level and title, whether he's working, waiting for you, napping or idle (or what's wrong with your PC's health), how long he's been at it, and links to Shellby's GitHub page and, with Visiting crabs on, your calling card. With Say what the task is on, the title of the one running task (never in Work mode). Shellby never signs in to Discord.
- When
- While it's on and both apps are open, at most every 15 seconds.
Installing OpenRGB
OpenRGB's GitHub releases, through winget- What's sent
- winget's download request.
- When
- When you click install and confirm.
Weather Off until you pick a town
Open-Meteo- What's sent
- The town name you type when you search for it, then only your chosen town's latitude and longitude rounded to one decimal place (about 11 km). Like any web request it carries your IP address and Electron's usual headers.
- When
- A search when you press Find; then every 30 minutes and when the PC wakes, while it's on.
What these services do with your data is up to them, under their own policies: GitHub, and whichever notification service you pick.
Crash reports
When Shellby crashes, hits an error it carries on from, or closes without being quit, it gets a report ready and keeps it on your PC (%APPDATA%\Shellby\sentry). The first time, it asks: Send report, Always send or Don't send. Nothing goes until you answer, and you can change it in Settings → About → Crash reports. A report goes to Sentry, the crash-report service Shellby uses, and has:
- the error and where in Shellby's code it happened
- Shellby's, Windows' and Electron's versions, and basic facts about your PC: CPU, memory, graphics card, screen size, language and time zone
- what Shellby's windows and processes were doing just before (opened, closed, crashed)
- for a close without quitting, the log's last 40 lines from that run
- for a crash of the app itself, a crash dump: where each part of the app was, which can hold fragments of whatever it was working on at that moment
Your home folder becomes ~, anything token-shaped is cut from all of it, and the PC's name is removed. Error messages and log lines can still name files and projects. Not collected: your conversations, prompts, the contents of your files, the addresses Shellby talks to, console output, usage or sessions. Sentry sees the IP address a report comes from, as any server does. A report you turn down is deleted from your PC, and so is everything waiting when you choose Never send. Unsent reports are deleted after 30 days, and at most 30 are kept.
Report a problem only opens a new GitHub issue in your browser, filled in with your Shellby, Windows, Electron and Claude Code versions and the log's last 40 lines (with your home folder and anything token-shaped removed). Nothing is sent until you read it and submit it yourself.
What Claude is told about Shellby
With Settings → Claude → Tell Claude it's running in Shellby on (it is by default), each conversation Shellby starts carries a short fixed note saying so, and when your usage passes 80% or 95% a line with that percentage goes with your message. Claude can then ask for his status: his level, mood and what he's doing, your focus timer, when your usage resets, and your PC's latest health readings (temperatures, memory, disk). Like everything Claude reads, that goes to Anthropic through Claude Code. Turn the switch off and none of it is sent.
What never leaves your PC
- Your PC's health readings: temperatures, CPU, memory, disk, which apps are using them, what starts when you sign in, and LibreHardwareMonitor, HWiNFO and
nvidia-smireadings. They're only sent anywhere if you press one of the Ask Shellby why buttons (which hands them to a Claude Code task you can see), turn on health alerts for phone notifications, or a Claude conversation in Shellby asks for his status. - Push-to-talk audio. Windows' offline speech recognizer hears it, on your PC. The microphone is only open while you hold the shortcut.
- The time tracker. It reads the title of the window in front to tell which project you're in, and keeps only the project, the day and the minutes. It is never synced, and a day goes to Toggl, Clockify or Harvest only when you send it.
- Which apps he perches on, Now Playing, your usage counts and weekly summaries.
- What each task cost. Each finished turn keeps its project folder, model, what kind of ask it was, how long the prompt was (short, medium or long), and how much of your usage window and how many tokens it took. Never the prompt itself. It's kept for 60 days, never synced, and Clear all history deletes it.
- Typing along (off until you turn it on). He looks only at whether a key was let go and wipes the rest of the event straight away: never which key, never what you typed. From your speed he keeps one number, your fastest burst in words a minute.
- Toolbox → Lean. To tell which plugins and MCP servers sit idle, Shellby reads Claude Code's own transcripts on this PC and keeps only the names of the skills, agents, commands and servers used and when. Never what was said.
- The local connections for the
shellbycommand, the Claude Code plugin and hooks (port 47913), the OBS overlay (port 47914, off by default), the Stream Deck keys (port 47915, off by default), OpenRGB and sensor apps. They only accept connections from this PC (127.0.0.1).
What's stored on your PC
| Where | What |
|---|---|
%APPDATA%\Shellby | Settings, conversation history (sessions), logs (with your home folder and anything token-shaped scrubbed out), screenshots, your Wardrobe and skins, routines and workflows, prompt history, and Shellby's copies of your repositories (worktrees). |
%LOCALAPPDATA%\Shellby | The shellby command. |
~\.ssh | Only when you add a computer under Other computers: its Host block goes at the end of config (your file as it was is kept beside it once, as config.before-shellby), and Sign in with my password makes a key if you have none. |
Pictures\Shellby | Crab and week cards you save. Chat exports go where you choose. |
Secrets are encrypted with Windows' data protection, tied to your Windows account: your GitHub sign-in, your notification service's token, the passphrase for starting tasks from your phone over ntfy, your time tracker's and Sentry's tokens, the Stream Deck plugin's token, and workflow secrets. If Windows can't encrypt them, Shellby won't store them.
Deleting your data
When you uninstall Shellby, it asks whether to delete your data too. No is the default and keeps it, so a reinstall picks up where you left off. Yes deletes %APPDATA%\Shellby and %LOCALAPPDATA%\Shellby. Updates never ask and never delete anything. A silent uninstall (/S, as winget runs it) keeps your data unless you add --delete-app-data. Pictures\Shellby holds cards you saved, so it's always left alone. Delete it yourself if you don't want them.
Things stored in your GitHub account stay there until you remove them:
- turn off Visiting crabs to delete your calling card
- turn off Profile card to delete its gist (and remove
shellby-profile.svgfrom your profile repository yourself) - delete the
shellby-badgerepository if you used the pull request badge (badges on earlier pull requests then show a broken image) - delete the
shellby-sync.jsongist from your gists - revoke Shellby under GitHub → Settings → Applications
Changes and questions
Any change to what Shellby sends goes in the policy and in the changelog, and the policy's history is public in the repository.
Questions? Open an issue at github.com/x-salmon/shellby/issues. For anything you'd rather not post publicly, use GitHub's private reporting (the repository's Security tab → Report a vulnerability).
This website
Everything above is about the app. This site, getshellby.com, is a set of static pages with no accounts, forms or sign-ins.
- No cookies, no analytics, no trackers. There are no third-party scripts, and the fonts and images are served from this site.
- One request to GitHub. To show the latest version, download links and file size, your browser asks GitHub's public API (
api.github.com) for Shellby's latest release. GitHub sees that request like any other, including your IP address. The answer is kept in your browser's session storage for 30 minutes so pages don't ask again, and it's gone when you close the tab. - Downloads come from GitHub. The download buttons link to Shellby's releases on GitHub.
- Hosting. The site is hosted on Vercel, which handles each page request the way any web host does.
Read the code, not just the policy.
Every connection on this page is in the source, under the GPL-3.0. Or see how the app keeps Claude's hands where you can see them.