burdgen ai
Trust

Privacy

Hosted Burdgen stores project and run records. A paired runner can upload output and artifacts that may include source code. This page describes where that data already lives.

Last updated 2026-09-09 · Document version 2026-09-09. This is a trust account of shipped behavior, not a legal compliance conclusion.

Data location summary

Where data already lives

Reuse the same locations named in authentication and data-location (F06). Unknown location is better than a guessed cloud story.

On your device

Local workspace entry, local databases, and runner credentials in the machine’s credential store. The runner opens outbound HTTPS; it does not require an inbound public port.

In hosted Burdgen

Account projection and browser session, connected repository records, execution requests, uploaded inputs, runner events, output, results, and artifacts. Those records can include source code and other project content.

Provider and runtime processing

The browser does not authenticate to Claude Code, Codex, or another local runtime. The runner invokes an already-installed runtime on the execution machine. Runtime credentials stay on that machine.

Optional telemetry

Opt-in and off by default. Local queue only until a collector URL is configured. Preview the exact payload under Settings → Privacy & Telemetry after you sign in.

Who we are

Burdgen is a hosted workspace for reading projects, recording decisions, and dispatching coding work to an authorized runner. It is not a local-only app named “landing,” and it is not a product that claims to keep all project data on your Mac with no server or account.

Account and session

On the hosted control plane, account authority comes from Zahir. Burdgen keeps a local user projection and browser session. Signing in does not by itself authorize repositories or a runner. GitHub repository authorization and runner pairing are separate doors.

Hosted storage

Hosted Burdgen stores project and repository records you connect, execution requests and their uploaded inputs, run events, output, results, and artifacts. Attachment bytes use the configured execution-attachment disk. Downloads stay authenticated; object URLs are not account identity.

Runner uploads

A paired Mac or Linux runner polls outbound and uploads events, output, artifacts, and results. Local execution does not mean that all project data stays on the machine. Uploaded material can include source code and other project content from the authorized workspace.

Provider processing

Model and tool use depend on the runtime and providers you configure for a feature or run. Runtime credentials remain on the execution machine. App AI features such as summaries use their own configured providers. This page does not invent additional retention promises for third-party providers beyond what those owners already document.

Retention and deletion

Suspended or signed-out sessions do not delete projects. Disconnecting or revoking a runner blocks new work without erasing run history or deleting files on the computer. Artifact sync can tombstone vanished copies after deletion. Stronger retention, export, or cryptographic erasure work is tracked under existing retention tickets and is not claimed here until those owners ship it.

Optional telemetry

Telemetry is opt-in and off by default. When enabled, the app may queue anonymous usage events locally and flush them only when a collector URL is configured. Scrubbed properties exclude free-form content, credentials, and identifying paths. The install UUID is not an account id. Signed-in users can preview the exact payload on Settings → Privacy & Telemetry.

Contact

Questions about this privacy account can be sent through the interest list before you have an account, or through the support channel published for your deployment after you are admitted. Do not send secrets, tokens, or private repository contents in that mail.

Version history

  • 2026-09-09 — Replaced obsolete local-only “landing” copy with hosted Burdgen storage, runner upload, provider, retention, and contact wording. Documents made publicly reachable without a session.