Last updated: March 26, 2026
We store the minimum necessary to operate the service:
That's it. We do not store agent data, prompts, telemetry, logs, or any user activity. Shoofly runs locally on your machine — nothing phones home.
Our backend runs on Railway. Data is encrypted in transit (TLS) and at rest on Railway's infrastructure.
If you discover a security vulnerability, please report it responsibly:
Our commitment:
Note: security@shoofly.dev needs to be set up. Flag for Evan.
We consider good-faith security research to be authorized conduct. If you act in good faith and in accordance with this policy, we will not pursue legal action against you. We ask that you:
In scope:
Out of scope:
For vulnerabilities that warrant a CVE, we will use GitHub Security Advisories to coordinate disclosure and publish advisories.
The following content is also available at /.well-known/security.txt: