08 / 10

What does it send off my machine?

npx halfcycle

Less than you would guess. Your Claude login never touches us; the work runs in your own Claude Code. Your Claude works out the patterns in a change, such as which files and tables it touches, and sends us those patterns. We analyse patterns, not your full code files. The few checks that read a single line do so with the permission you give once, at signup.

Your Claude login never touches us.

Start with your Claude account, because it is what people worry about first. We never hold, pass through or see your Claude login. The work runs in your own Claude Code, on your own subscription or your team’s seats, and that is where your code is read and written.

When a change is made, your Claude works out its shape and sends us that rather than the change itself. Concretely: the file paths it touches, the database tables a write affects, the signatures of any routes it adds or alters, and the names of any outside hosts it calls. No file contents and no diff.

There is one exception, and it is better stated here than found in small print. A small number of checks have to read the single line of code that a claim points at, to see whether the claim is true. Permission for that is part of the terms you accept at signup, in plain words, and you will never be asked for it in the middle of a session. What is read is not kept: the finding and its evidence are recorded, and the line itself is not. And we do not train or benchmark on your documents, which is a decision already made rather than a policy we could quietly revise.

If you cancel, your own files stay where they are, every record included. What stops is the live checking. The part that runs on your machine is open source under the MIT licence, so you can read for yourself what it sends.