Locality Privacy Policy


Effective Date: July 22, 2026


This Locality Privacy Policy (the “Policy”) explains how CodeFlash Inc.

(“CodeFlash,” “we,” “us,” or “our”) processes personal information in

connection with Locality.


Locality is a local-first application that makes content from services selected

by a user available as files on the user’s device. This Policy applies whether

the Locality desktop product is used by an individual or an organization, and

it applies only to:


- the Locality desktop application for macOS, Windows, and Linux;

- the `loc` command-line interface and `localityd` background daemon bundled

with the application;

- Locality’s local Model Context Protocol (“MCP”) integration;

- the CodeFlash-operated OAuth broker used to authenticate supported

connections;

- Locality’s software-update functionality; and

- support communications relating to those components.


This Policy does not apply to the CodeFlash.ai website or products, any Locality

marketing website, or any separate enterprise backend, hosted content service,

or other cloud-hosted Locality offering that CodeFlash may introduce in the

future. Each such offering will have its own privacy notice. If another

CodeFlash privacy notice conflicts with this Policy about the Locality

components listed above, this Policy controls for those components.


For purposes of applicable data-protection law, CodeFlash is the controller of

personal information for which it determines the purposes and means of

processing, including information CodeFlash itself processes in connection

with the OAuth broker, updates, and support. Roles may differ where required by

law or a separate written agreement. CodeFlash is not the controller of

connected source content that remains on the user’s device or with the

connected provider. A user’s organization and the connected provider may

separately determine the purposes and means of processing that content.


1. Local-First Design

Locality is designed so that content from a connected service travels directly

between the user’s device and that service. CodeFlash does not operate a content

relay for the Locality application and does not receive or store connected

documents, messages, email, calendar events, transcripts, issues, attachments,

or other source content through the OAuth broker.


Locality stores connected content and related sync data on the user’s device.

Depending on the connections and features a user chooses, this local data may

include:


- documents, messages, email, calendar events, meeting notes, transcripts,

issues, comments, attachments, media, and related metadata;

- local copies, cached content, canonical renderings, search indexes, sync

shadows, journals, conflict data, and recovery copies;

- provider account and workspace labels, identifiers, granted scopes, and

connection status;

- local paths, mount configuration, application preferences, and activity or

diagnostic logs; and

- local MCP credentials and configuration written to supported agent tools.

Except for the information and requests described in Section 2, including

authentication values sent to the OAuth broker, Locality does not automatically

transmit connected source content, local sync data, diagnostic logs, local

paths, or local MCP configuration to CodeFlash.


2. Information Processed by CodeFlash


2.1 OAuth broker information


For supported OAuth connections, Locality uses a CodeFlash-operated OAuth

broker hosted on Cloudflare Workers. The broker is required because the

provider’s confidential OAuth client secret cannot safely be distributed in a

desktop application. The broker handles authentication only; it does not proxy

or receive connected source content.


During authentication or token refresh, the broker may process:


- the selected provider and requested OAuth scopes;

- a loopback redirect address, short-lived session value, state value,

authorization code, and related authentication parameters;

- access-token and refresh-token responses returned by the connected provider;

- an encrypted, opaque refresh-token handle;

- identity tokens and provider-returned account or profile claims, which may

include name and email address, workspace, account, team, enterprise, bot, or

user identifiers, labels, icons, granted scopes, and connection status; and

- technical request information such as IP address, request date and time,

request path and method, response status, approximate network location,

user-agent or similar device information, and performance data.


The broker does not maintain an application database of OAuth codes, access

tokens, refresh tokens, or connected content. Authentication values are

processed in memory for the time needed to complete the request. In production,

the provider refresh token is encrypted into an opaque handle that is stored on

the user’s device and returned to the broker when a refresh is needed.


Cloudflare Workers logging currently records all broker invocations. Persistent

trace storage is disabled. The broker application is designed not to write

request bodies, OAuth codes, access tokens, refresh tokens, opaque refresh

handles, or connected content to those logs. Cloudflare may retain invocation

and network logs for up to seven days. CodeFlash has not configured regional

placement for the broker, so Cloudflare may process requests and logs on its

global network.


2.2 Update and application-media requests


Official direct-download versions of Locality contact GitHub Releases to check

for and download signed application updates. The onboarding experience may

also retrieve an instructional video from Microsoft Azure Blob Storage. When a

device makes these requests, GitHub or Microsoft may process technical

information such as the device’s IP address, request time, requested file,

user-agent, and download or error information under their own privacy terms.


2.3 Support communications


If a user contacts us, we process the information the user chooses to provide,

such as name, email address, organization, support messages, screenshots, and

attachments. Local diagnostic logs and trace files remain on the device. If a

user manually assembles diagnostic materials or uses a support-bundle export

feature when available, CodeFlash receives them only if the user separately

chooses to send them. Diagnostic materials may contain device,

operating-system, application-version, connection, local-path,

remote-identifier, and error information.


Never send passwords, API keys, OAuth tokens, refresh handles, MCP tokens, or

other credentials. Send connected source content only when it is necessary to

resolve the issue and CodeFlash specifically requests it through an appropriate

secure channel.


2.4 Analytics and crash telemetry


Locality does not currently send automatic product analytics or crash telemetry

to CodeFlash. Routine application diagnostics and optional trace captures stay

on the user’s device by default.


If CodeFlash introduces automatic analytics, performance monitoring, or crash

telemetry, we will update this Policy and provide an appropriate in-product

choice before that collection begins. This will include an opt-out control for

default-on analytics and an opt-in where required by the feature or applicable

law. Such telemetry will be designed not to include connected source content,

document or message bodies, attachments, credentials, or OAuth tokens.


2.5 Information we do not use


CodeFlash does not:


- sell personal information collected through Locality;

- share personal information for cross-context behavioral advertising or use

Locality for targeted advertising;

- use connected source content to train artificial-intelligence or

machine-learning models; or

- access connected source content unless a user deliberately supplies it in a

support request or otherwise directs CodeFlash to receive it.


3. How We Use Information


We use personal information processed by CodeFlash to:


- provide, secure, maintain, and troubleshoot the OAuth broker;

- authenticate provider connections and refresh provider credentials at the

user’s request;

- deliver and secure Locality updates;

- respond to support requests and other communications;

- derive and use aggregated or deidentified diagnostic information to improve

Locality, without using connected source content for that purpose;

- detect, prevent, and investigate fraud, abuse, security incidents, and

technical failures;

- comply with law and protect the rights, safety, and property of users,

CodeFlash, and others; and

- establish, exercise, or defend legal claims.


For users in the European Economic Area (“EEA”), United Kingdom, or

Switzerland, providing OAuth authentication information is necessary to connect

a supported provider. We process authentication and session information to

perform the requested service; broker security and network information for our

legitimate interests in securing the service and preventing abuse; support

information to respond to requests and maintain the service; and legal records

to comply with law and establish or defend claims. We rely on consent where

required. CodeFlash does not make decisions based solely on automated

processing that produce legal or similarly significant effects.


4. How We Disclose Information


We may disclose personal information in the following circumstances:

- **Service providers and independent parties.** Cloudflare and support vendors

may process information on CodeFlash’s behalf. GitHub distributes

direct-download updates, and Microsoft hosts onboarding media. GitHub,

Microsoft, application marketplaces, and connected providers may process

request information as independent parties under their own privacy notices,

depending on the service and relationship.

- **Connected services.** At the user’s direction, Locality communicates

directly with selected providers such as Notion, Google, Slack, Linear, and

Granola. Those providers process information under their own terms and

privacy policies.

- **Legal and safety reasons.** We may disclose information if reasonably

necessary to comply with law or legal process, protect rights or safety,

investigate abuse or security incidents, or enforce applicable agreements.

- **Corporate transactions.** Information may be disclosed in connection with

an actual or proposed financing, merger, acquisition, reorganization, sale of

assets, or similar transaction, subject to appropriate safeguards.

- **With direction or consent.** We may disclose information as a user directs

or otherwise consents.


Because CodeFlash ordinarily does not receive connected source content, it

ordinarily has no such content to disclose. If a user deliberately provides

source content in a support request, CodeFlash may process and disclose it only

as described in this Policy and as reasonably necessary to handle the request,

protect security, or comply with law.


5. Retention


We retain information only for as long as reasonably necessary for the purposes

described in this Policy:


- OAuth codes and token responses are processed transiently and are not stored

in an application database by the broker.

- A broker session is designed to expire after approximately ten minutes.

- Cloudflare may retain broker invocation and network logs for up to seven

days.

- Support communications and materials are retained for the time reasonably

necessary to resolve the request, maintain appropriate business records,

comply with law, and resolve disputes.

- Legal and security records may be retained as necessary to comply with law,

prevent abuse, or establish or defend legal claims.


Local data is retained on the user’s device until the user deletes it. Locality

provides controls to disconnect sources, reset Locality state, and prepare the

application for uninstall. Reset or uninstall may not delete visible mounted

files, manually assembled diagnostic materials, exported support bundles,

source backups, recovery copies, or copies made by another application. Users

should separately review and delete those files when appropriate. Revoking a

connection in Locality also may not delete data held by the connected provider;

users must use the provider’s controls for that purpose.


6. Local Storage and Security


Locality uses reasonable technical measures intended to protect locally stored

credentials and state. By default:


- on macOS, provider credentials are stored in Apple Keychain;

- on Windows, provider credentials are stored in Windows Credential Manager;

and

- on Linux, provider credentials are stored in files restricted to the current

operating-system user.


If a file-based credential store is explicitly configured on macOS or Windows,

credentials are instead stored in current-user-restricted files. File-based

credential protection also depends on the security and disk encryption of the

user’s device.


OAuth credentials are not stored in Locality’s SQLite database; that database

stores a reference and non-secret connection metadata. Locality also applies

redaction rules intended to keep credentials and connected content out of

routine local diagnostic logs.


No method of storage or transmission is completely secure. Users are

responsible for securing their devices, operating-system accounts, backups,

provider accounts, and local agent configurations. A person or agent with

access to the user’s operating-system account or mounted files may be able to

access connected content.


7. User Choices and Controls


Users can:


- choose which providers and scopes to connect;

- disconnect a source and revoke its access through the provider;

- disable or reconfigure Live Mode and local MCP integrations;

- reset Locality’s local state or uninstall the application;

- delete remaining mounted files, backups, recovery copies, logs, manually

assembled diagnostic materials, and exported support bundles from the

device;

- choose whether to export and send diagnostics to CodeFlash; and

- use the in-product choice that will accompany any future automatic telemetry.


Because CodeFlash does not receive connected source content, requests relating

to content held by a connected provider generally must be directed to that

provider or to the organization controlling the provider account.


8. International Processing


CodeFlash is based in the United States. Cloudflare Workers normally executes

the OAuth broker on Cloudflare’s global network at or near the location from

which a request is received, and Cloudflare and our other providers may process

information in the United States and other countries where they operate. Those

countries may have data-protection laws different from those in the user’s

country.


Where required, CodeFlash uses contractual or other legally recognized transfer

mechanisms and safeguards made available by its service providers. Users may

contact us for additional information about relevant transfer safeguards.


9. Privacy Rights


Depending on location and applicable law, a user may have the right to request:


- access to or a copy of personal information processed by CodeFlash;

- correction of inaccurate personal information;

- deletion of personal information;

- restriction of or objection to certain processing;

- portability of information the user provided;

- withdrawal of consent, without affecting prior lawful processing; and

- review or appeal of a decision concerning a privacy request.


Users may exercise applicable rights by emailing privacy@codeflash.ai. We may

need to verify the requester’s identity and authority. Authorized agents may

submit requests where permitted by law. Users also may complain to their local

data-protection authority.

California residents may have rights to know, correct, or delete personal

information and to receive information about its collection and disclosure.

CodeFlash does not sell personal information or share it for cross-context

behavioral advertising. Authentication information may qualify as sensitive

personal information under some laws; CodeFlash uses it only to provide and

secure the requested authentication functionality and not to infer

characteristics about a person. CodeFlash will not discriminate against a user

for exercising an applicable privacy right.


10. Children


Locality is intended only for users who are at least 18 years old. CodeFlash

does not knowingly collect personal information through Locality from anyone

under 18. If we learn that we have done so, we will take reasonable steps to

delete the information. A parent or guardian who believes a minor has provided

personal information may contact privacy@codeflash.ai.


11. Third-Party Services and Agents


Connected providers, operating-system vendors, application marketplaces, local

AI agents, editors, and other software used with Locality are independent third

parties. Their processing is governed by their own terms and privacy policies.

Locality may detect supported agent tools and, with the workflow presented in

the application, install local instructions or MCP configuration into their

documented configuration files. This detection and configuration occurs on the

user’s device and is not automatically reported to CodeFlash.


12. Changes to This Policy


We may update this Policy to reflect changes to Locality, our practices, or

applicable law. We will post the revised Policy with a new effective date and,

when required, provide additional notice in the application or request renewed

consent. We will update this Policy before enabling automatic analytics or crash

telemetry.


13. Contact Us

Questions and privacy requests may be directed to:

CodeFlash Inc.

465 California St., Floor 7

San Francisco, CA 94105, USA

Email: privacy@codeflash.ai

Support: support@codeflash.ai