privacy policy
Effective 2026-08-17. Mossbear is in private beta.
The entity that operates Mossbear is being formed and is not yet named here. The practices below describe what the software actually does today, which does not depend on that filing — but if you need a named data controller before entrusting anything to it, ask before signing up.
what Mossbear syncs
Section titled “what Mossbear syncs”Enumerated rather than summarised, because a summary of this list was wrong once: the CLI’s npm page said it synced “only action metadata” until 2026-08-22, and classes 4 and 5 below are why that was false.
- Account information — who you are and which workspace you belong to.
- Action metadata — the type of each tool call, a one-line summary, and the file paths touched. Not the file contents, and not the diffs.
- Rule-file manifests — which guide files a repo has on disk, as paths and content hashes. Never their contents.
- Content you push on purpose — guides and guide files you choose to manage, and context you capture.
- Guide suggestions, and redacted excerpts of the turns they were drawn from. When the CLI notices you correcting an agent mid-session, the proposed rule and its reasoning are derived from your transcript on your machine, and those — plus a prose-redacted, length-capped excerpt of the user and assistant turns behind them — are what reach the server. This is the most sensitive class on the list, which is why it is named rather than folded into “metadata”.
- Evaluation verdicts and run metadata — the grading results and the runs they belong to.
- Token counts and run usage, read from your transcripts locally.
- CLI connection state — your CLI version and which agent sessions have finished.
what stays local
Section titled “what stays local”Mossbear’s CLI keeps raw hook logs, your code file contents, your diffs, and your full conversation transcripts on your device. The CLI holds no model credentials and produces no verdict of its own — grading runs on the server, from the list above.
What leaves your machine from a transcript is the redacted excerpts in class 5, and nothing else. See the live sync inventory.
service providers
Section titled “service providers”- Fly.io hosts the application and database infrastructure.
- OpenRouter and OpenAI may process guide and evaluation context.
- Resend sends transactional email.
- PostHog provides product analytics and error tracking.
- GitHub provides OAuth login if you choose to sign in with it.
analytics
Section titled “analytics”Product analytics are cookieless and anonymous by default. Persistent, identified analytics run only after you opt in. Server-side error reporting runs regardless, to keep the service working — it records what failed, not what you were writing.
retention and your rights
Section titled “retention and your rights”We keep account and product data while your account is active or as needed for security, operations, and legal obligations. You can export your data as a JSON download from Settings → Export my data, or permanently delete your account and all its data from Settings → Delete account. Both are self-serve and take effect immediately — you do not have to ask us.
If you are in the EU, UK, or California, you have further rights — access, correction, portability, objection, and complaint to your local regulator. The export and delete controls above already satisfy access, portability, and erasure. For anything else, contact us.
contact
Section titled “contact”Beta testers were invited directly — reply on the channel you were invited through and it reaches a person, usually the same day. A published privacy address goes here when the operating entity is named.