Your phone loses signal.
The agent on your Mac never noticed. The thread catches up when you do. Nothing dies at ten minutes.
Claude Code and Codex run on your machine, the way they do now. Your repo, your env vars, your cookies, your MCP servers, your uncommitted state stay where they are. The phone reaches your own box. Nothing reaches in.
One command. Card is not charged until it proves it remembers. Reply "goldfish" for a full refund, any time in 60 days.

run the cleanup
Claude needs approval: DROP TABLE legacy_invoices
Destructive SQL waits for your tap. The diff:
- DROP TABLE legacy_invoices
+ ALTER TABLE billing_invoices RENAME TO billing_invoices_old
org.stripe_customer_id (unchanged, Thursday)
A small process on your Mac holds an outbound connection to the messaging app you already use. Your phone talks to that app. The process talks to Claude Code and Codex on the same machine. Nothing listens on a port. Nothing accepts inbound connections. This is the same architecture Anthropic chose when they made Remote Control outbound-only and OpenAI chose when they made the Mac the Codex worker. You noticed. So did we.
Everything the agents touch.
.env files.What crosses the wire: the text of the thread, the diffs and files you ask for, and memory entries (below). That is the whole list.
Decisions and the why behind them. "Keep Stripe customer IDs denormalized on the org row because the join was killing the dashboard." Rejected approaches. Conventions. Promises the agent made. Not your source.
Memory entries are encrypted at rest and keyed to you. One command exports all of it as markdown, so you can read exactly what is there. One command deletes all of it. Team plan can pin memory to your own storage.
Memory →--dangerously-skip-permissions.Every Telegram bridge you could build in a weekend runs with that flag. The flag turns every text into unrestricted code execution and secret exfiltration. One wrong message, one hijacked account, and your machine is somebody else's.
Tweety Bird does not use it. Permission prompts are relayed to your phone with the diff and three buttons.
| Runs unattended | Waits for your tap |
|---|---|
| Reading files and repos | Spending money |
| Running tests and lint | Pushing to prod, or to main |
| Opening PRs to a branch | Messaging any human |
| Searching, summarizing, drafting | Deleting anything |
| Browser reads (checking a dashboard, pulling an invoice) | Browser writes (posting, purchasing, changing settings) |
The defaults are the left column. You move things across per repo. The overnight refactor runs, and the DROP TABLE waits for you at 11:22 PM with the diff.
You. The thread is bound to your account and your paired devices. Nobody who finds your bot's handle can say "yes" to a shell command. Approvals require a paired device, not just a message. Pairing uses a one-time code shown in your terminal at install, and you can see and revoke paired devices from the thread.
The agent on your Mac never noticed. The thread catches up when you do. Nothing dies at ten minutes.
Work pauses. It resumes when the Mac wakes, with catch-up for anything scheduled. Nothing silently skips.
Nothing in Tweety Bird lives inside either agent. Your thread still answers. Your 7 AM audit still fires.
They can send messages. They cannot approve anything. Approvals need a paired device.
Revoke the device from any other paired device or from the terminal. Memory is keyed to you, not the phone.
Cancel from the thread with one message. Export your memory as markdown with one command. Delete it with another.
Tweety Bird is a process that runs on an engineer's own Mac beside Claude Code and Codex, the tools your team already approved. It does not add a cloud runtime, a code mirror, or a new place source lives. It relays the agents' permission prompts to a paired phone and stores decisions, not code, in an encrypted memory keyed to the user. Team plan adds per-repo permissions, an admin view of every unattended run and every approval, and the option to pin memory to your own storage.
Questions, or a copy of the security write-up: john@memoryrouter.ai
No. Claude Code and Codex run on your Mac, the way they do now. Your repo, your env vars, your cookies, your MCP servers, your uncommitted state stay where they are. The phone reaches your own box.
--dangerously-skip-permissions?No. That flag turns every text into unrestricted code execution and secret exfiltration. Tweety Bird relays permission prompts to your phone with the diff, and you set the policy per repo: what runs unattended and what waits for a tap.
You. The thread is bound to your account and your paired devices. Approvals require a paired device, not just a message.
The agent on your Mac never noticed. The thread catches up when you do. Nothing dies at ten minutes.
No. Nothing in Tweety Bird lives inside either agent. The memory, the schedules, and the thread sit beside them.
OpenClaw is free software and it can do a lot of this if you have an afternoon, a VPS, and an ops habit. It had a critical RCE in February. The guidance is to never expose the gateway and patch continuously. You have a full-time job. Tweety Bird is the packaged version with the sharp edges filed off, a memory that spans both agents by default, and someone whose job it is to keep it safe.
Found something? john@memoryrouter.ai. Founders' bugs ship first, and security bugs ship before those.
One command. Five minutes. Tell Claude one decision, ask Codex, and watch it answer. Your card is not touched until it does.
Install in one command$29 a month, locked for life for the first 500 machines. 417 left. Reply "goldfish" for a full refund, any time in 60 days.
Your laptop closes at 6. Your agents don't.