FiboCode
DocsBlogPricing
    • Codebase Understanding
    • Codebase Context
    • Spec-Driven Development
    • AI Code Completion & Repair
    • AI Code Review
  • Roadmap
  • Skills
  • Forum
  • Bug Report
  • Releases

Privacy Policy

Last updated: 2026-08-11

This Privacy Policy explains how the independently maintained FiboCode software and fibocode.ai website handle data. Local-first means workspace data is processed on your device and is not uploaded to FiboCode-controlled servers; remote-model requests and information you voluntarily submit through the website are the exceptions described below.

1. Local Workspace Processing

FiboCode processes source code and project files on your device. Generated analysis, summaries, and graphs are normally written inside your project, including under .fibo/analysis.

The FiboCode maintainer does not receive or store your workspace data through a FiboCode-controlled server. This statement does not mean all use is offline: sending a request to a remote model transmits the request data to the Provider you configured.

2. Code Analysis and Configuration Files

A remote code-analysis request may include the full contents and path of a selected supported file, plus derived summaries, generated analysis, and related project context. Only describing FiboCode as local-first does not remove this transfer when a remote model performs the analysis.

Configuration analysis supports formats including JSON, YAML, TOML, and INI. A .env file is not included by default, but you can explicitly add it or another file type to the analysis allowlist. If analyzed, configuration values may be included in the model request.

Remove API keys, passwords, tokens, private certificates, and other secrets before analysis. FiboCode does not currently promise automatic redaction of every sensitive value.

3. Remote Model Providers and Agent CLIs

When you invoke a remote AI model, relevant code, files, paths, configuration values, prompts, or context are sent directly to the Provider you selected. Provider credentials are used to authenticate with that Provider; they are not sent to the FiboCode maintainer through a FiboCode-controlled service.

The Provider's privacy policy and terms govern its processing, retention, model-training use, and deletion of request data. The FiboCode maintainer cannot make those guarantees for a third party. A separately installed Agent CLI may also transmit data under its own configuration and terms.

4. Sensitive and Private Repositories

Before analyzing a private or sensitive repository, review the file types and paths included in analysis, remove secrets, inspect generated analysis before reusing it as context, and review the Provider's current policy. You can configure an OpenAI-compatible endpoint that you operate or otherwise trust.

5. Website Submissions

When you submit a roadmap idea, the website stores the title, use case, current problem, expected result, optional email address, locale, creation time, and a salted hash of the submitting IP address. The hash is used for abuse limits; the raw IP address is not stored in the roadmap database. Cloudflare Turnstile receives the verification token and IP address under Cloudflare's terms.

Roadmap submissions currently remain stored until they are manually removed. Enterprise inquiries are composed in your local email client and are sent only when you choose to send the email to the FiboCode maintainer.

6. What the Maintainer Does Not Do

The FiboCode maintainer does not sell workspace data and does not use your code to train a FiboCode-operated model. No claim in this policy guarantees that a third-party Provider will follow the same practices; review that Provider's policy before use.

7. Contact and Security Reports

For privacy questions, deletion requests concerning website submissions, or suspected exposure of code, credentials, or local data, contact the FiboCode maintainer privately at qfy1390974313@gmail.com. Do not post real secrets or private source code in a public Issue; follow the SECURITY.md policy in the FiboCode release repository.

This document is provided in English and Simplified Chinese. In case of any discrepancy between the two versions, the English version prevails.

This text is provided for general information only and does not constitute legal advice. Please consult a qualified lawyer before relying on it.

FiboCode — from complexity to clarity.

License AgreementPrivacy PolicyContactGitHubX