Agent Deck LogoAgent Deck
LEGAL SPECIFICATION // TRANSPARENCY PROTOCOL
SPEC_ID: PRIV-RFC-0089-V2.14 · SHA-256: 9f8e4c...08a1

Privacy Policy

Effective Date: [Pending Final Confirmation] · Last Updated: October 2025

gavel
DRAFT NOTICE — Business & Legal Terms Pending Confirmation Pre-Commercial

This draft privacy document outlines our local-first engineering architecture and data handling practices. Formal entity registration, official jurisdictions, corporate incorporation numbers, and binding statutory clauses will be finalized prior to general commercial availability. We disclose our telemetry constraints openly below.

Storage Vector 127.0.0.1 LOCAL
Zero Cloud Ingestion

Code AST, contextual diffs, and prompt streams terminate strictly at your local Unix loopback socket.

Hardware Protocol USB HID / NO RADIO
Air-Gapped Console

The Deck peripheral holds zero onboard Wi-Fi, Bluetooth, or radio transmitters. Hardware frames render via physical bus.

Telemetry Guarantee STRICT "UNKNOWN"
Zero Extrapolation

Unreported LLM metrics register visibly as "Unknown". We reject behavioral synthesis, fingerprinting, and trend farming.

01

Core Engineering Principle: Local-First

Agent Deck is engineered from the ground up as strictly local-first developer infrastructure. We believe autonomous code generation tools require uncompromising confidentiality. Your intellectual property, proprietary abstractions, uncommitted Git diffs, token payloads, and filesystem trees must remain bounded to the physical machine executing the work.

Architectural Boundary Specification

The Agent Deck local daemon process (agentdeckd) communicates over a protected local loopback Unix domain socket (/var/run/agentdeck.sock on POSIX environments or named pipes on Windows). Under no architectural circumstance does the Agent Deck client software mirror, stream, or siphon your code repository to central Agent Deck cloud servers.

// Runtime Data Boundary Flow
[LOCAL IDE / FS] ---(IPC/Socket)---> [AGENT DECK DAEMON] ---(USB HID)---> [PHYSICAL DECK CONSOLE]
block AGENT DECK SERVERS: NO REPOSITORY ACCESS CHANNEL
02

Data Collected by the Desktop App

The Agent Deck Desktop client operates as an orchestration visualizer and runtime controller. The metrics processed are maintained strictly in localized, non-persistent memory buffers during active sessions.

memory Strictly Local Execution

We locally compute agent step counters, token depletion rates, context-window saturation percentages, and OS Process Identifiers (PIDs). None of these instrumentation telemetry points leave your localhost loopback adapter.

bug_report Optional Opt-In Crash Dumps

If the desktop binary encounters a unhandled panic, an error report is prompted. It is strictly opt-in, off by default, and sanitizes all system paths, environment variables, credentials, and code snippets prior to packaging.

Default Telemetry Status: ALL_CLOUD_METRICS_DISABLED
03

Telemetry & The "Unknown" Standard

Our strict anti-hallucination engineering commitment guides our instrumentation. Many proprietary developer utilities synthesize or extrapolate vague performance averages when real-time operational telemetry is hidden by underlying LLM inference providers. Agent Deck repudiates this practice.

help

The Truth-in-Telemetry Rule

If an autonomous agent runtime or external API does not deliver deterministic, factual byte-level operational telemetry (such as exact prompt token counts, tool execution latency, or cache hits), our interface visibly outputs "Unknown".

Console Telemetry Render Behavior
Token Saturation 84.2% [FACTUAL]
Model Temperature UNKNOWN
Global User Baseline NOT_COLLECTED

We do not harvest cross-user behavioral benchmarks or construct predictive models from your work patterns.

04

Data Collected via Hardware (The Deck)

The physical console—The Deck—is built on deterministic microcontroller firmware. It acts strictly as an input/output peripheral terminal, not an intelligent edge computer.

Inbound Display Bus

Receives raw pixel frames and numerical gauge vectors directly from the local agentdeckd engine over USB.

Outbound Tactile Events

Transmits momentary mechanical key switches (Accept Diff, Reject Execution, Step Over) and dual rotary optical encoder ticks.

verified_user
Zero Network Interface Hardware: The Deck PCB contains no Wi-Fi chipsets (ESP32 / 802.11), no Bluetooth Low Energy radios, and no persistent flash storage partitions capable of caching codebase contents. Unplugging the USB cable immediately severs all operational memory.
05

Website & Commerce Information

When interacting with this website or participating in hardware pre-order reservations, limited operational business data is required to process commercial commitments.

  • › Order Processing: Full name, verified shipping delivery address, and electronic mail coordinates for fulfillment alerts and firmware update notices.
  • › Financial Transactions: Credit card numbers and bank credentials are tokenized directly through Level-1 PCI-DSS compliant payment gateways (e.g., Stripe). Agent Deck systems never store raw card numbers.
  • › Corporate Entity Notice: Formal legal entity registration details, physical corporate headquarters addresses, and foreign entity subsidiaries are presently undergoing regulatory processing and will be displayed once commercial hardware shipping commences.
06

Analytics, Cookies & Web Tracking

Our web presence adheres to minimal footprint standards. We do not maintain marketing tracking pixels, retargeting ad beacons, or cross-site fingerprinting matrices.

Essential State Tokens

Strictly functional HTTP cookies to preserve shopping cart contents during checkout and track session state for authentication portals.

No Ad Networks

We do not sell user data to advertising syndicates, nor do we permit third-party trackers to profile visitors across our documentation.

07

Third-Party Agent APIs (Claude, OpenAI, Copilot)

Agent Deck does not act as an intermediate proxy for your LLM prompts. The software acts as an instrumentation dashboard over autonomous agent runtimes you execute directly.

Credential Containment Model

When linking providers such as Anthropic (Claude Code), OpenAI (Codex / GPT-4o), GitHub Copilot CLI, or Cursor daemon bridges:

# File location on your local machine:
~/.agentdeck/config.json
{
  "auth_storage": "OS_KEYCHAIN_SECURE_ENCLAVE",
  "remote_proxy": false,
  "egress_allowed": "DIRECT_TO_PROVIDER_ONLY"
}

All API keys, OAuth tokens, and model configurations remain locked inside your operating system's native keychain (macOS Keychain, Linux Secret Service API, Windows Credential Manager). They are presented directly by your machine to the provider's HTTPS endpoint. Agent Deck cloud infrastructure never touches your inference credentials.

08

Data Retention & Local Deletion

Because Agent Deck adheres to local-first principles, you maintain sovereign control over your developer history, agent execution logs, and cache indexes at all times.

Manual & Automated Purge Routines

You can permanently erase all historical agent telemetry, session journals, and cache files with a single terminal instruction or via Desktop App preferences:

$ agentdeck purge --all --hard CLI Action

For online pre-orders, transaction records are retained only as required by statutory tax obligations. You may request immediate removal of pre-order reservation inquiries prior to manufacturing batch lock.

09

Developer Inquiries & Audits

We welcome direct security inspections, socket verification scripts, and architectural queries from systems developers and enterprise compliance officers.

Privacy & Security Protocol Team privacy@agentdeck.example
mail Initiate Inquiry
key PGP Key: 0x9B14E87401C9
terminal Security RFC Channel: #sec-audits