Privacy Policy
Last updated: August 27, 2026
What Foreman collects and what it deliberately does not. Your code, prompts and transcripts stay on your machine; this policy lists exactly what leaves it.
This policy explains how FOP Yaroslav Rozumnyi (“Foreman”, “we”, “us”) collects, uses and protects your personal data when you use the Foreman desktop application and foremanapps.com. We act as the data controller for the data described below.
1. The short version
Foreman is a desktop application. Your source code, your prompts, your agent transcripts and your credentials live on your own machine and are not sent to us. There is no server-side copy of your work to leak, subpoena or sell. What does reach us is limited to the account and device records below, plus a fixed list of nine events about the application itself — which you can turn off. Your cost figures are off unless you turn them on.
2. What we never collect
We do not receive, and have no way to read, any of the following — not in aggregate, not in logs, not for debugging:
- your source code, or the contents of any file an agent reads or writes;
- your prompts, an agent's replies, or any part of a session transcript;
- your git remotes, branch names, commit messages or diffs;
- the commands agents run, or their output;
- your Anthropic, OpenAI or SSH credentials, or any API key. Those are held in your operating system's own secure credential store — the macOS Keychain, Windows Credential Manager, or your Linux keyring — and are read by the application on your machine only.
3. What we do collect
- Account data — your email address, and the plan attached to your account with its status and renewal or expiry date. Your password, sign-in methods and login sessions are held by Clerk, our authentication provider, and never reach our own database. The free plan runs on one machine without an account, in which case we hold nothing at all.
- Device records — for each machine you connect to your account: a display name you choose, the platform it runs, when it was last seen online, and a public key used to set up encrypted connections between your own devices. This is what makes a fleet a fleet; it contains nothing about what is on the machine.
- Cost and usage figures — opt-in, off by default. If you turn on cross-device cost tracking, we receive per-day and per-session spend: the amount in US dollars, the number of turns, which model was used, when the session was last active, an opaque session identifier, and a short label so you can tell your sessions apart. That label is derived from the name of the folder the session runs in — typically the last one or two path segments, such as projects/foreman. It is the only piece of this data that carries anything from your filesystem, we send no more of the path than that, and turning the setting off stops it entirely.
- Work-pattern counters — the same opt-in, off by default. Turning on cross-device cost tracking also sends a small set of daily counts that let the dashboard compare how you work on each machine: turns started and turns you stopped, permission requests answered and denied, checkpoint rewinds, fan-out lanes launched and kept, session launches and how long the first turn took, and lines of code added or removed. These are counts only. They contain no file paths, no prompts, no tool arguments and no code, and tool names are reduced to fixed categories (such as Bash or MCP) on your own machine before anything is written down — so the name of a tool you or a server added never leaves it. Turning the setting off deletes what was already sent.
- Shared sessions — if you share a session to your phone or browser, we store the opaque session id, the same short display label, and the time you shared it, so the session can be listed on your other device.
- Relay traffic — when you drive a session from your phone or a browser, the content is encrypted end-to-end on your own devices. Our relay routes ciphertext it cannot read and keeps no copy of it. We can see that a connection happened and how much data moved; we cannot see what was in it.
- Payment data — paid plans are charged by card through Creem, our merchant of record, who operate the checkout. Your card details go to them and never reach us — we do not see or store a card number. We keep only a subscription and order reference, the plan, its status as they report it, and the dates it was granted and renews.
- Website technical data — our host's logs record IP addresses and device/browser information as part of normal operation and to protect the site against abuse. We also run cookieless website analytics, which report aggregate visit counts only and store nothing on your device (see our Cookie Policy). We run no advertising trackers.
- Access tokens — devices authenticate with tokens we store only as a cryptographic hash, alongside when the token was created and last used.
- Product analytics — on by default, and you can turn it off. The application sends us a short, fixed list of events about the app itself: that it launched, that a session started or finished, that the canvas was opened, that the relay connected, that an error was shown, how far the first-run setup wizard got, and that you changed this setting. Each carries only the version of the app, true/false flags, and values chosen from fixed lists we publish in the application — there is no free-text field, so a file path, repository name, branch, prompt or command cannot travel in one even by accident. They are labelled with a random identifier belonging to the installation, not to you, and with your account id only while you are signed in. We use this to answer one question: whether people who install Foreman ever get as far as running an agent, and where they stop if they do not. The switch is in the application under Settings › Privacy, which also lists every event in full; turning it off deletes that random identifier and discards anything not yet sent. We rely on legitimate interests for this rather than your consent — see section 4 — because none of it can identify you or describe your work.
4. How and why we use it (legal bases)
- To provide the service, link your devices and secure your account — performance of a contract.
- To process subscriptions, apply your plan and prevent fraud — contract and legitimate interests.
- To show you your own cost figures across machines — consent, given by turning the setting on and withdrawable by turning it off.
- To understand whether the application works for the people who install it — legitimate interests. We cannot improve a tool we cannot tell is being used, and the format of these events is what keeps the balance in your favour: eight fixed names, no free-text field, a random per-installation identifier rather than one tied to you, and nothing stored on your device. You can object at any time by turning analytics off in Settings › Privacy, which takes effect immediately and requires no explanation.
- To send service email you cannot opt out of while you hold an account — email verification and password resets, which Clerk sends on our behalf, and notices about your subscription — performance of a contract.
- To send product email, where you asked for it — consent, withdrawable at any time.
- To keep the service available and resist abuse — legitimate interests.
- To meet legal, accounting and tax obligations — legal obligation.
5. Who we share it with (processors)
We share data only with service providers that process it on our behalf under a data processing agreement:
- Clerk — accounts, sign-in, passwords, email verification and session management.
- Creem — merchant of record: card processing, checkout, subscription billing, tax and receipts.
- DigitalOcean — hosting for the website, the account service and the relay.
- Plausible Analytics — cookieless website analytics. It receives no account data: only the page viewed, the referring site and coarse device and country information, none of it tied to you.
- Sentry — error reporting for our own account and relay service, so a fault affecting you is noticed and fixed. It receives the technical detail of a server-side error: the stack trace, the request method and path, and your account id. Credentials and email addresses are stripped before a report leaves our servers, and it receives nothing from the desktop application.
- GitHub — hosts the application downloads. Requesting a download is a request to them, subject to their privacy policy.
We do not sell your personal data, and we do not share it with advertising networks or data brokers. The agent tools Foreman runs — Claude Code, Codex and similar — talk to their own providers directly from your machine under your own account with them; that traffic does not pass through us, and what those providers do with it is governed by your agreement with them.
6. International transfers
Some processors may store or process data outside your country, including outside the EEA and UK. Where they do, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. How long we keep it
We keep your account, its devices and its usage records for as long as your account exists. When you delete your account, all of it is erased from our database, permanently and without a shadow copy — and because the credentials live with Clerk, deleting the account deletes them there too.
Three things sit outside that erasure. Creem keeps its own record of the transactions it handled, under its own legal and accounting obligations — that copy is theirs, not ours. Server logs containing IP addresses age out on their own retention cycle rather than being deleted per account. And the product-analytics events described in section 3 are stripped of your account id rather than deleted: what remains counts an anonymous installation and can no longer be connected to you, which is what lets us keep an accurate historical count without keeping anything about you.
Anything held only on your own machine — projects, sessions, transcripts, checkpoints, stored credentials — is deleted by you, there. We cannot reach it and cannot delete it for you.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent at any time. You can download a copy of everything we hold from the Account tab of your dashboard, withdraw consent for cost telemetry in the application at any moment, object to product analytics by turning them off under Settings › Privacy, and delete your account to remove everything else. For anything else, email privacy@foremanapps.com — we respond within the 30 days the GDPR requires. You also have the right to lodge a complaint with your local data protection authority.
9. Security
We protect data in transit with TLS, delegate credential storage to Clerk — which means we never hold your password in any form, readable or hashed — store access tokens only as hashes, and seal phone and browser sessions end-to-end so the relay carries ciphertext it cannot decrypt. On your machine, agent credentials are handed to the operating system's own secure store rather than kept in our files — the macOS Keychain, Windows Credential Manager, or your Linux keyring. On a Linux system with no keyring available, the platform falls back to obfuscating them instead of encrypting them to your login; the application tells you when it is in that state, because it is genuinely weaker. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and the relevant authority of any breach as required by law.
10. Children
Foreman is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes
We may update this policy. Material changes will be notified in the application or by email, and the “Last updated” date above revised.
12. Contact
For privacy questions or to exercise your rights, email privacy@foremanapps.com. For anything else, including billing, contact@foremanapps.com.