Omarchy Shell plugin

Know what your devices are doing.

Unified privacy indicators and controls for your microphone, camera, location, screen sharing, screenshots, recording, and audio output.

Stable v0.9.16 Release notes ↗
Privacy Devices activity panel showing live device state and controls
One glance. Direct control.

Your privacy state,
right in the bar.

Live activity

See which applications are using privacy-sensitive devices as it happens.

Inline controls

Mute audio, block supported devices, or apply a verified privacy lockdown with timed undo.

Configurable behavior

Customize monitored activity, hardware names and policies, ordering, colors, visibility, actions, and backends.

Current interface

Current state in the bar.
Full controls in settings.

Privacy Devices indicators occupying their exact center-bar footprint
Distinct markers keep active, disabled, verifying, and degraded states visible.
Privacy Devices notification showing a detected application icon
Activity alerts identify the application and affected privacy device.
Available for Omarchy

Install and enable the plugin.

Install Privacy Devices from the terminal or review its community marketplace listing.

Install and enable
omarchy plugin add https://github.com/bolens/omarchy-privacy-devices.git --enable
Update
omarchy plugin update io.github.bolens.privacy-devices
Disable without uninstalling
omarchy plugin disable io.github.bolens.privacy-devices
Uninstall
omarchy plugin remove io.github.bolens.privacy-devices
Compatibility

Requirements and optional controls.

Privacy Devices requires Omarchy Quattro with Omarchy Shell, Quickshell, Hyprland, and PipeWire. Optional controls detect their own dependencies and show Install only when needed.

Control or backendRequired package or command
Microphone and audio outputlibpulse (pactl) or wireplumber (wpctl)
Camera blockingpolkit and a UVC-compatible USB camera
Location blockinggeoclue and polkit
Screen-share blockingxdg-desktop-portal-hyprland
Omarchy screenshotsOmarchy capture command
Grim / Grim + Sattygrim, slurp; plus satty and wl-clipboard for Satty
Hyprshot / Flameshothyprshot; or flameshot, grim, and the Hyprland portal
Omarchy / GPU recordinggpu-screen-recorder
wf-recorderwf-recorder and slurp

Custom commands are user-managed. The plugin never installs their dependencies. Activity notifications use notify-send when available.

Using the widget

Open controls from the bar.

Add or move Privacy Devices through Setup → Bar. Its icons show current activity; the combined widget opens the full activity panel.

  1. Left-click Run the icon’s control, or open details for status-only items.
  2. Middle-click Open settings for a bar icon or popup row.
  3. Right-click Open the activity panel from an individual icon.

Keyboard: use ↑/↓ and Enter to select and open devices, H for history, S for settings, R to refresh observers, Esc to go back, and 1–4 to switch settings pages.

Toggle controllable rows directly in the popup. Blocking the Hyprland screen-sharing portal also suspends other features supplied by that portal until it is re-enabled.

Supported activity

Seven signals. One panel.

ActivityWhat you seeAvailable control
MicrophoneLive PipeWire applicationsMute the default input inline or manage each source from device settings
Audio outputApplications playing audioMute the default output inline or manage each sink from device settings
CameraDetected camera streamsAllow or block UVC USB camera interfaces
LocationGeoClue activityEnable or runtime-mask GeoClue
Screen sharingPortal and capture streamsEnable or runtime-mask the Hyprland portal
ScreenshotSelected capture backendLaunch a screenshot
Screen recordingActive recorder stateStart or stop the selected recorder
Configuration

Configure monitoring and presentation.

Open Setup → Plugins → Privacy Devices. Use General, Appearance, Alerts, and Monitoring; press 1–4 to switch pages.

General

Choose monitored activities, idle visibility, control availability, privacy modes, and alert deduplication.

Appearance

Tune bar layout, markers, counts, popup density, labels, colors, and disabled presentation.

Notifications

Choose activity and control alerts, with per-application or per-device suppression and the detected application icon when available.

Enhanced monitoring

Optionally inspect same-user open device handles to detect direct V4L2 camera and ALSA microphone access that bypasses ordinary PipeWire streams.

Recent activity

Opt in to private metadata-only history bounded to seven days or 100 completed sessions, then open it from the clock icon or with H. Review local today or seven-day counts, duration, and applications new within retained history, or search by application, device, activity, source, or confidence. Disabling or confirming clear deletes the stored file.

Device policies

Give detected hardware a friendly local name, hide a device from presentation, or suppress its alerts without changing monitoring.

Privacy lockdown

Confirm one action to mute or block every available service-owned privacy control. Each action is observed and verified; partial failures remain visible, and successful changes can be undone for 30 seconds.

Settings transfer

Export and import a versioned settings file in your private user data directory. Imports and global resets retain one undo point.

Monitoring health

Review observer state and heartbeat freshness in Monitoring. Run the non-mutating guided self-test, verify notification delivery on demand, or copy redacted results when reporting a detection problem. Optional health alerts fire only on degraded and recovered transitions and are rate limited.

Quick actions

Notification clicks and the optional searchable Omarchy menu rows share a fixed, allowlisted action helper for activity, filtered history, diagnostics, lockdown, undo, and rescanning. Install or remove the owned menu block with privacy-menu-entry. Lockdown always opens confirmation; observed metadata is never executed.

Audio

Prefer pactl, wpctl, or automatic backend selection.

Capture backends

Use Omarchy, Grim, Grim + Satty, Hyprshot, Flameshot, GPU Screen Recorder, wf-recorder, or custom commands.

Classification

Exclude noisy apps and extend camera or screen-share keywords for unusual drivers and capture clients.

Unrecognized active video-input streams are treated as screen shares by default. Add unusual camera drivers to cameraKeywords to classify them correctly.

Privacy and security

Local data and privileged controls.

No telemetry

The plugin reads local PipeWire metadata and selected local process state. It sends no activity data over the network.

Explicit authorization

UVC camera and GeoClue controls request Polkit authorization before changing system state.

Runtime blocking

Location and portal masks disappear after reboot. UVC cameras normally rebind after reboot as well.

Recorder process checks

wf-recorder PIDs stay in the owner-only runtime directory and are checked for ownership and executable identity before stopping.

Reported monitoring state

Idle, active, and degraded are distinct states. Session details identify the device, observation source, and whether attribution is confirmed or inferred.

Review custom commands before saving them. Custom screenshot and recording commands run unsandboxed as your user.

Troubleshooting and FAQ

Common questions.

Why is a control unavailable?

Open its settings and look for Install. Optional controls remain unavailable until their required package or command is present.

Why is my camera shown as screen sharing?

Add a distinctive driver or application term to cameraKeywords. Unknown video-input streams default to screen sharing.

Why did screen sharing elsewhere stop working?

The preventative screen-share control masks xdg-desktop-portal-hyprland. Re-enable it from the popup to restore all features supplied by that portal.

How do I restore blocked services?

Re-enable the camera, location, or screen-share control in the popup. Runtime masks clear after reboot, and UVC cameras normally rebind after reboot.

What does privacy lockdown change?

It serially mutes microphone and audio output and blocks available camera, location, and screen-share controls. Unsupported or unavailable controls are reported rather than treated as successful. Use Undo lockdown within 30 seconds to restore the observed prior state.

How do I change screenshot or recording tools?

Open plugin settings and choose a supported backend. Custom start, stop, or capture commands are available for user-managed tools.

Will restarting the shell repeat alerts?

No. Existing activity settles into a silent startup baseline, while completed activity remains available when optional history is enabled.

Where should I report a bug?

Choose the matching form on the GitHub issue page, or review the support guide.