Legal

Privacy Policy

Last updated July 22, 2026

Overview

This Privacy Policy describes what information we collect, how we use it, and — just as importantly — what we deliberately do not collect, in connection with DF Code (the desktop application), this marketing and documentation site, and the Admin API that supports account authentication and subscription entitlements (collectively, the "Service"). It is intended to be read alongside our Terms of Service.

The short version: DF Code is designed to run entirely on infrastructure you control. We do not receive, store, or have any access to your workspace, thread, or conversation content, your source code, your credentials, or your connector configuration — that data never leaves your own installation. What we do retain, described in full below, is limited to (a) the account and entitlement records needed to authenticate you and enforce your subscription plan, and (b) aggregate, non-content product usage analytics for this marketing site.

Information we collect

Account and entitlement records. If you sign in via GitHub OAuth, our Admin API stores a record associated with your GitHub account identifier, including your subscription plan, account status, entitlement values, and server-side usage-metering counters (e.g. daily run counts) used solely to authenticate you and to enforce plan limits. We do not store your GitHub password, and we only request the OAuth scopes necessary for authentication and, where applicable, repository access you explicitly configure.

Product usage analytics. This marketing site uses Google Analytics (gtag.js) to collect aggregate, non-content usage data such as page views, referral source, approximate location (derived from IP address, not stored as a precise address), device/browser type, and specific interaction events we track deliberately — for example, which platform a download link was clicked for, and whether a Contact form submission succeeded or failed. These events do not include the contents of any message, form field, or file.

Contact form submissions. If you submit the Contact form, the name, email address, and message you provide are transmitted to us and relayed by email so we can respond to you. We do not write Contact form submissions to a database — they are processed transiently for delivery and are retained only in the resulting email correspondence (and, if applicable, its associated retention policy in the mailbox we use).

Information we do not collect

The DF Code application itself runs entirely locally. Your workspaces, threads, message and conversation history, Domain and Repository configuration, memories, Strategy and Agent definitions, connector configuration, credentials, tokens, and any code or file contents the application reads or writes live only in files and a local database on your own machine. None of that data is transmitted to, received by, or stored on any server we operate, and we have no visibility into it whatsoever. This remains true regardless of which subscription plan you are on.

We do not sell your personal information, and we do not use any data we collect to train AI models.

How we use information

We use account and entitlement records solely to authenticate you, enforce subscription plan limits, and prevent abuse of those limits. We use aggregate product analytics solely to understand how the marketing site and download funnel are used, so we can improve them — for example, which platform to prioritize, or whether the Contact form is functioning correctly. We use Contact form submissions solely to respond to your inquiry.

Cookies and similar technologies

Google Analytics may set cookies or use comparable identifiers in your browser to distinguish sessions and visits to this marketing site. You can control or block these through your browser settings, a browser extension, or Google's own opt-out tools; doing so will not affect your ability to use DF Code itself, which does not depend on these cookies. The DF Code desktop application does not use browser cookies for its own local functionality.

Data retention

We retain account and entitlement records for as long as your account exists, plus a reasonable period thereafter to satisfy legal, accounting, or fraud-prevention obligations. Aggregate analytics data is retained according to Google Analytics' standard retention settings. Contact form correspondence is retained only in the destination mailbox, at our discretion, for as long as is useful to respond to and follow up on your inquiry. We do not retain any local application data, because we never receive it in the first place.

Third parties and sub-processors

We rely on a small number of third-party providers to operate the Service: GitHub (OAuth authentication), Google Analytics (aggregate usage analytics on this marketing site), and our email provider (delivery of Contact form messages). Each of these providers processes data under its own privacy terms, which are outside of our control.

If you separately configure a CLI connector, MCP server, model provider, or other integration inside your own DF Code installation (for example, a Claude, Codex, Gemini, or Aider connector), any data you choose to send through that integration is governed entirely by that third party's own privacy practices and by your own configuration — not by us, and not by this policy, because that data never passes through anything we operate.

Security

We take reasonable measures to protect the account and entitlement records and Contact form correspondence described above, including signed, verifiable entitlement tokens rather than plain cached values. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because your workspace, thread, code, and credential data is never transmitted to us, its security is entirely your own responsibility, consistent with our Terms of Service.

Your choices and rights

You may decline to sign in via GitHub OAuth, in which case certain plan-gated features will be unavailable but the local, non-hosted functionality of DF Code remains unaffected. Depending on your location, you may have rights to access, correct, or delete personal information we hold about you (principally, your account and entitlement record); you can exercise these rights by contacting us via the Contact page.

Children's privacy

The Service is not directed to, and we do not knowingly collect personal information from, individuals under the age of 16. If you believe a child has provided us with personal information, please contact us so we can delete it.

Changes to this policy

We may update this Privacy Policy from time to time as the product evolves. We will update the "Last updated" date above when we do, and material changes will be reflected here. Continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.

Contact

Questions about this policy, or requests to access, correct, or delete your account information, can be sent via the Contact page.