Privacy in the app

What may leave the machine, privacy modes, server-held keys, and redaction.

Necessary prompts and code context may be sent through api.eyeban.ir so the cloud agent can generate suggestions and tool plans. Local workbench files stay on your machine unless included as context for a run.

Privacy modes

Server-side privacy preferences include:

  • off
  • no_training
  • no_storage

Choose the mode that matches your risk profile, then confirm the binding language on the Legal pages (Privacy Policy and AI and data use). Product Settings expose the control; Legal pages define the obligation.

Keys and accounts

Default cloud turns use provider API keys held on Eyeban servers. Optional bring-your-own-key stores your provider key in the desktop secure store and sends it with each proxied Agent request; Eyeban does not persist that key after the request. See Bring your own key.

What typically leaves the machine

Depending on the task and tools:

  • Prompt text and selected code context
  • Tool results the agent needs for the next step (file excerpts, search hits, command output)
  • Account identifiers needed for auth and billing

What should stay local when possible: unrelated files, secrets, and huge generated trees excluded via .eyebanignore / .gitignore.

Redaction and hygiene

Leak redaction helps strip common secret patterns from outbound context, but it is not a guarantee. Still:

  • Keep .env and credential files out of prompts and indexes
  • Use .eyebanignore / .gitignore for sensitive trees
  • Review diffs and tool args before Allow all workflows

Where to read more

Legal pages on this site are authoritative for privacy, terms, and AI data use. Product docs describe controls; policies define obligations.