What we store
Sign-in email, hashed install-key metadata, content pull counts, Audit summaries, and optional usage signals you send (for example cache hits). We do not ask you to upload your repository for Audit.
What stays on your machine
Project notes and cached module text stay on your machine, outside the chat thread. Diffs and local command output stay in your IDE unless you choose to send short labels (paths, command names, exit codes) with an Audit result.
Cookies
Signed-in sessions use HTTP-only cookies. Theme preference uses a cookie on public pages. Content API calls use a Bearer install key or session token. No ad trackers. Deployment analytics, when enabled, use Vercel Analytics without advertising cookies.