Skip to content
Privacy

Privacy Policy

Frontal Codes is local-first. This policy explains exactly what we collect, where it lives, and who sees it — for both self-hosted and Frontal Cloud modes.

Last updated: June 2026

Privacy policy details

1. Overview

Frontal Codes is local-first. This policy distinguishes between self-hosted (your data stays on your machine) and Frontal Cloud (we process on your behalf). In both cases, the core principle is the same: you describe what to build, agents do the work, and an append-only event log records what happened. What differs is who holds the log.

2. Data We Collect

Depending on mode, Frontal processes the following categories of data:

  • Goals & submissions — what you type when describing what to build.
  • Git artifacts — commit messages, file diffs, branch names (stored in the HMAC event log).
  • Usage metrics — gateway token counts, agent-minutes, task durations (for billing & limits).
  • System logs — Docker container stdout/stderr, error traces (for debugging).
  • Account info (Cloud only) — email, team membership, role.

3. Local-First Architecture

Self-hosted: All data lives on your host under .frontal/. Secrets vault is Fernet/AES encrypted. No telemetry. No data leaves your machine unless you explicitly push to GitHub.

Cloud: We process your data on your behalf as a data processor. The event log remains the source of truth; we don’t mine it.

4. Model Provider Disclosure

Be honest here. When agents execute, prompts (which may include your code snippets) are sent to your configured model providers via the gateway. Supported providers: GLM (Zhipu AI), MiniMax, OpenCode Go.

Provider keys are NEVER sent to the engine subprocess — they live only in the gateway. But the prompts themselves (including code) DO reach providers.

Use self-hosted mode with your own provider keys if this is a concern.

5. Data Retention

Data type Retention
Event logUntil project deletion
Gateway meteringRolling 90 days
Cloud session dataDeleted on project deletion (30-day grace period)
Audit logForever (append-only)
Secrets vaultUntil manually deleted

6. Subprocessors

Provider Purpose Privacy
GLM (Zhipu AI) Model inference open.bigmodel.cn
MiniMax Model inference minimaxi.com
OpenCode Go Model inference privacy link
Docker (local) Container runtime —
ArangoDB (local/self-hosted) Memory graph —

7. Your Rights

  • Access — request a copy of your data.
  • Export — event log export at any time.
  • Deletion — delete project = delete data.
  • Objection — contact us with concerns.

Contact: [email protected] (mock)

8. Cookies

Self-hosted: none. Cloud: essential session cookies only. No analytics cookies. No third-party tracking.

9. Children’s Privacy

Not directed at children under 16. If you believe a child has submitted data, contact us for deletion.

10. Changes

Material changes announced via the changelog 30 days before effective date. Continued use after effective date constitutes acceptance.