Privacy
Local state. Explicit provider processing.
CodeCaddie has no hosted application tier or CodeCaddie account. Workspace state and signed event history are authenticated and encrypted in one data directory on the device. Device-local configuration and references are not all encrypted. CodeCaddie does not accept or store AI-provider credentials.
Repository analysis
The desktop app gives the selected, already-installed Claude, Codex, or Grok provider access to a disposable single-commit repository snapshot. The provider processes that snapshot under its own authorization, settings, privacy terms, and organizational policy. The original checkout is left untouched.
Repository source text is excluded from CodeCaddie storage, reports, IPC, logs, recovery exports, and provider diagnostics. Saved claims use the immutable commit, repository-relative paths, line ranges, and hashes instead of excerpts.
Product documents
Selecting a PDF, PowerPoint, Word, text, or Markdown file authorizes its bounded extracted text to be sent to the selected provider when goals are generated. CodeCaddie re-reads and hashes the file for that run, then keeps only its device-local path, display name, media type, size, page or slide count, and BLAKE3 hash. Extracted text is never persisted.
Missing or changed files must be reattached. Image-only, encrypted, corrupt, empty, unsupported, symlinked, or oversized documents are rejected with an actionable message. CodeCaddie does not perform OCR, silently truncate documents, or fetch the optional website field.
Website data
This public site provides documentation and download links. It does not set application cookies or operate product analytics at launch. The download pages use the browser’s low-entropy operating-system identity only to recommend the universal Mac app; the site does not request processor details, persist the result, or send it to a server.
Choosing a download leaves this site for the public CodeCaddie repository on GitHub. CodeCaddie sends no referrer with that request.