Trust

Privacy & security

Where your prompt goes

SurfaceWhere the engine runsPrompt leaves your machine?
Workspace (/app)Your browser tabNo
CLIYour machineNo
MCP serverYour machine (stdio)No, but your MCP client may forward tool results to its model
VS Code extensionInside VS CodeNo, unless you choose Send to AI Chat
HTTP APICloudflare WorkersYes, over TLS. It is processed in memory and never stored or logged

What is stored

  • No accounts and no server-side storage.
  • The workspace keeps your draft, settings, and saved prompts in this browser's localStorage. Clearing site data removes them.
  • If Cloudflare Web Analytics is enabled, it records cookieless page views. It never sees prompt text.

What is logged

For each API request: a request id, route, method, status, duration, an input-size bucket (such as 1k-10k), and whether it was rate limited. Prompt text and results are never logged.

Security model

  • Strict Content Security Policy (hash-based scripts, frame-ancestors 'none'), HSTS, and nosniff.
  • No third-party scripts except the optional Cloudflare analytics beacon. Fonts are self-hosted.
  • The API validates every field, caps input size, rate-limits per IP, and returns typed errors without internal details.
  • Sensitive-data detection returns categories and offsets, never the matched value.
  • Prompt-injection detection is signature-based. It reports risk, not proof, and can miss novel attacks.

Report a vulnerability through a private GitHub security advisory on the repository.