> For the complete documentation index, see [llms.txt](https://docs.codna.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.codna.ai/concepts/privacy.md).

# Privacy and data

What leaves your machine when Codna runs, what never does, where keys live, and the privacy controls in codna.yaml.

Runs on your machine or your cloud. Your code never leaves without your key. This page says exactly what that means, command by command.

## What leaves your machine

| Command                                                        | What is sent                                                                                                                                                                                                                               | To                                                                         |
| -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------- |
| `codna triage`, `codna impact`, `codna memory`, `codna_recall` | Nothing.                                                                                                                                                                                                                                   | —                                                                          |
| `codna fix`                                                    | The evidence bundle for this issue: the code and structure the agent needs, not the repository. With `--open-pr`, the branch and pull request.                                                                                             | Your model provider, with your key. GitHub, with your token.               |
| `codna review`                                                 | The pull-request diff, the changed-file list, and your project guidance (`AGENTS.md`, `.codna/review.md`, `.cursor/BUGBOT.md`). Up to 24 bounded lookups of package names and versions for dependency findings. With `--post`, the review. | Your model provider. The npm and PyPI registries. GitHub, with your token. |
| `codna secure` (classify)                                      | Nothing with the default `--engine local`. With `--engine remote`, the findings to classify.                                                                                                                                               | The Codna engine over HTTP, when configured.                               |
| `codna secure --fix`                                           | A patch request for each eligible finding.                                                                                                                                                                                                 | Your model provider.                                                       |
| `codna report`, `codna_report_bug`                             | The title and body you typed, and, only when you ask, the redacted `codna doctor` output.                                                                                                                                                  | GitHub, [thyn-ai/feedback](https://github.com/thyn-ai/feedback).           |

Codna reports the bundle size on every `triage` and `fix` run, as the `context` line.

## Secrets are always redacted

Secrets are redacted from what Codna sends to a model. `privacy.redact_secrets: false` in `codna.yaml` is ignored with a warning. Redaction cannot be disabled.

## Where keys live

Provider keys and your Codna key are stored in the OS keychain by `codna key set` and `codna login`. They are read through a hidden prompt or from the environment, never passed on the command line, and never printed. `codna key list` shows which providers are stored, never the values. Set `CODNA_DISABLE_KEYCHAIN=1` for headless runs that must not touch the keychain.

## Egress control

```yaml
# codna.yaml
privacy:
  egress: fail-closed
```

`privacy.egress: fail-closed` is opt-in. When set, Codna refuses to run a repository's tests unless it can deny them network access at the kernel level, and `codna review` makes no registry lookups. Kernel-level denial is available on Linux (a fresh network namespace via `bwrap` or `unshare`); elsewhere the sandbox records the policy without enforcing it, and fail-closed refuses to run the tests open.

Sandboxed test runs (`codna fix --tests`, `codna secure --fix`, and the hosted App's fixes) run with credentials scrubbed from the environment. Write tokens never enter an environment that runs repository code.

## The GitHub App

* Every job runs with a short-lived token scoped to the one repository the event came from, with only the permissions that job needs. A review holds no write token beyond the one that posts the review.
* The App is keyless. It never inherits provider keys from its host; a model key is used only when your organization added one on the account page.
* Fix commits are authored as `codna-ai[bot]`, a real GitHub identity.
* Codna opens pull requests. It never merges.

## Code memory

Code memory is built and queried on your device. Per-repository indexes live in the repository's `.codna-memory/`; MCP recall indexes live under `~/.codna/telys-memory/`. Recall runs offline and calls no model.

## Reporting a security issue

Email <security@codna.ai> or use GitHub's private vulnerability reporting on the repository. Reports are acknowledged within two business days.

## Next steps

* [Configuration](/reference/configuration.md) — the `privacy:` block and every variable.
* [Models & BYOK](/concepts/models-and-byok.md) — keys and the keychain.
* [GitHub App](/guides/github-app.md) — the permissions each job requests.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.codna.ai/concepts/privacy.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
