| 1 | import type { DocsTrustDict } from "../types"; |
| 2 | |
| 3 | /** |
| 4 | * English reference dictionary for `app/[locale]/docs/trust/page.tsx` |
| 5 | * ("See what leaves your machine"). Every claim traces to |
| 6 | * docs/public-surface-facts.json (`trust`), docs/TELEMETRY.md, and |
| 7 | * docs/SANDBOX.md. The security contact is code-owned in the page. |
| 8 | */ |
| 9 | export const docsTrust: DocsTrustDict = { |
| 10 | metaTitle: "See what leaves your machine · Codewhale Docs", |
| 11 | metaDescription: |
| 12 | "What stays local, what a model provider receives, what usage counting sends and how to turn it off, where the audit log lives, and how to report a vulnerability.", |
| 13 | bodyClassName: "text-ink-soft leading-relaxed", |
| 14 | title: "See what leaves your machine", |
| 15 | lede: |
| 16 | "Codewhale runs on your computer and talks to the model provider you choose. This page lists what goes where, what the anonymous usage count contains, and how to switch it off — as built today.", |
| 17 | sections: [ |
| 18 | { |
| 19 | id: "boundaries", |
| 20 | title: "Where your work goes", |
| 21 | blocks: [ |
| 22 | { |
| 23 | rows: [ |
| 24 | ["Stays on your machine", "The runtime, your workspace, session history, snapshots, and the audit log."], |
| 25 | ["Goes to your provider", "The context each turn needs — your messages, the files and tool results Codewhale reads for that turn — goes directly to the provider you selected. There is no Codewhale relay in between."], |
| 26 | ["Stays local entirely", "With a local model (Ollama, vLLM, SGLang), inference never leaves your machine."], |
| 27 | ["Needs no account", "Installing and running Codewhale locally needs no Codewhale account."], |
| 28 | ["Plan mode", "Cannot edit files or run shell commands. Research it is allowed to do may still contact outside services."], |
| 29 | ], |
| 30 | }, |
| 31 | { |
| 32 | p: "Tools you add can send data elsewhere: an MCP server, a web search, or a hook runs with your permissions and reaches whatever it reaches. Add only ones you trust.", |
| 33 | }, |
| 34 | ], |
| 35 | }, |
| 36 | { |
| 37 | id: "telemetry", |
| 38 | title: "Know what usage counting sends", |
| 39 | blocks: [ |
| 40 | { |
| 41 | p: "Codewhale counts anonymous usage by default and says so the first time you launch it, naming Codewhale and PostHog. Here is exactly what it covers:", |
| 42 | }, |
| 43 | { |
| 44 | rows: [ |
| 45 | ["Never sent", "Prompts, responses, code, diffs, file contents, file or repository or branch names, paths, model ids, MCP server names, API keys or tokens, error message text, keystrokes, or any per-turn or per-tool timeline."], |
| 46 | ["Sent while on", "Version and platform classes, session length and outcome, feature and error counts as fixed categories, and a random install id that changes every 90 days."], |
| 47 | ["Where it goes", "`https://telemetry.codewhale.net/v1/telemetry`, a first-party service whose source is in the repository. It stores no IP address, country, or location, keeps no request logs, and holds data for three months."], |
| 48 | ["PostHog", "Forwarding to PostHog happens only if the service operator configures it separately; it carries the same fields and nothing more."], |
| 49 | ], |
| 50 | }, |
| 51 | ], |
| 52 | }, |
| 53 | { |
| 54 | id: "turn-off", |
| 55 | title: "Turn usage counting off", |
| 56 | blocks: [ |
| 57 | { |
| 58 | code: `codewhale config set telemetry false # stop, and erase the local id and buffer |
| 59 | CODEWHALE_TELEMETRY=0 codewhale # stop for this process, erase nothing`, |
| 60 | lang: "Terminal", |
| 61 | }, |
| 62 | { |
| 63 | p: "The config setting is the lasting choice: later versions keep it, and a command-line flag or environment variable cannot turn it back on. You can also switch it in `/settings`. Turning it off deletes what was kept on your machine; rows already sent are keyed only to the random id you just erased, and expire with the three-month window.", |
| 64 | }, |
| 65 | { |
| 66 | p: "To see exactly what would be sent without sending anything, set `telemetry_endpoint = \"\"` in `~/.codewhale/config.toml`. Each batch is then written to `$CODEWHALE_HOME/telemetry/dryrun.jsonl` on your machine, byte for byte, and no network connection is made.", |
| 67 | }, |
| 68 | ], |
| 69 | }, |
| 70 | { |
| 71 | id: "audit", |
| 72 | title: "Check the local audit log", |
| 73 | blocks: [ |
| 74 | { |
| 75 | p: "Credential, approval, and elevation events are appended to `$CODEWHALE_HOME/audit.log` (by default `~/.codewhale/audit.log`). Writing is best-effort: if a write fails, the failure is logged rather than hidden. The log never leaves your machine.", |
| 76 | }, |
| 77 | ], |
| 78 | }, |
| 79 | { |
| 80 | id: "report", |
| 81 | title: "Report a vulnerability", |
| 82 | blocks: [ |
| 83 | { |
| 84 | p: "Email security reports to the address below instead of opening a public issue. Include your Codewhale version (`codewhale --version`) and steps to reproduce if you have them.", |
| 85 | }, |
| 86 | ], |
| 87 | }, |
| 88 | ], |
| 89 | next: [ |
| 90 | { |
| 91 | href: "/docs/sandbox", |
| 92 | label: "Limit what commands can touch", |
| 93 | note: "What the operating-system sandbox enforces on each platform.", |
| 94 | }, |
| 95 | { |
| 96 | href: "/docs/modes", |
| 97 | label: "Set modes and approvals", |
| 98 | note: "Decide what Codewhale may do without asking.", |
| 99 | }, |
| 100 | { |
| 101 | href: "/docs/auth", |
| 102 | label: "Connect a provider", |
| 103 | note: "Choose who receives your turns — or keep them local with a local model.", |
| 104 | }, |
| 105 | ], |
| 106 | sourceNote: |
| 107 | "Source documents: docs/public-surface-facts.json (trust), docs/TELEMETRY.md, docs/SANDBOX.md · Update docs-map.ts when changing.", |
| 108 | }; |
| 109 |