Privacy Policy
Updated
Early preview
Free Code is an early-preview coding agent. This short policy explains the main information flows today and will evolve with the product.
Accounts
GitHub or Google sign-in gives Free Code your basic profile, verified email, profile image, and provider account ID so we can create, secure, and link your account. We do not request Gmail, Google Drive, repository, or email-password access. We also process session and device details needed to keep you signed in and let you revoke a device.
Coding requests
Prompts, code, files, command output, and related context you choose to send are processed to complete your request. The needed content may be sent to model providers such as Google Vertex AI or Anthropic. Local coding sessions may remain on your device until you delete them.
Device and abuse prevention
To keep sponsor-funded model access available, the terminal app derives a device signal from identifiers and characteristics available without administrator access. Depending on your system, these can include the OS machine ID, hardware UUID or serial number, manufacturer and model, CPU and memory shape, operating-system and runtime details, hostname, shell, and non-loopback network-interface addresses.
Free Code receives the general platform, architecture, and app version directly. The app converts the machine-specific values into a versioned composite SHA-256 hash and separately hashed components before sending them; Free Code does not receive or store the raw machine-specific values. The API applies a second keyed hash and uses strong OS or hardware matches to associate accounts that use the same device and share abuse-prevention limits. Hostname, network address, and system shape are corroborating signals and do not independently link accounts or suspend access. Prompts, source code, files, commands, and command output are not used to create this device signal.
Ordinary device/account relationships are normally retained for the life of the account and up to 30 days after deletion. We may retain a minimal restriction record longer when needed to prevent immediate abuse re-enrollment, investigate confirmed commercial abuse, or meet legal obligations.
Recommendations and infrastructure
When contextual recommendations are enabled, best-effort-redacted prompt, conversation, and technical context may be sent to providers such as Gravity, Velocity, or Thrad. Providers may also receive delivery and fraud-prevention details such as your IP address and user agent. Free Code may record delivery, impression, action, and integration events, but does not give sponsors your GitHub or Google credentials. Redaction is not perfect, so do not put secrets in prompts.
Infrastructure providers including Vercel, Cloudflare, and PlanetScale process the data needed to operate Free Code. We do not sell personal information.
Operational telemetry
Free Code may collect content-free events such as app and session starts, task duration, selected mode, permission outcomes, and sponsored-card impressions. These events never include prompts, code, file paths, command output, or model responses. When you are signed in, these events are linked to your Free Code account using its internal account ID so we can investigate fraud, scams, and abuse; event batches do not copy your email or name. The events expire after 30 days, and you can stop future collection with freecode telemetry disable.
Your choices
You can sign out, review or revoke a device, disconnect a provider through that provider, control operational telemetry, or ask us to access, correct, or delete account information. We may retain limited records when needed for security, abuse prevention, or legal obligations.
Contact
Questions or privacy requests can be sent to andrew@freecode.sh.