Privacy Policy
Last updated: August 22, 2026
This policy describes how Deyin handles information in connection with the desktop app, CLI, and website. Deyin is local-first: your code and secrets stay on your device unless you explicitly send them somewhere. Model traffic is handled by Openference under their privacy policy.
1. Information Stored Locally
The following never leaves your device except as described below:
- Your workspaces, files, and git history - Semantic index embeddings (stored under the app data directory) - Session transcripts (JSONL under ~/.deyin/sessions/) - OAuth tokens, provider keys, plugin secrets, and SSH credentials — encrypted with your operating system's keychain - Skills, commands, subagent definitions, and hooks
2. Information Sent to Openference
Model requests (prompts, attached context, tool results) are routed through the Openference gateway to generate responses. Openference processes this data under its own privacy policy, available at openference.com.
On sign-in and startup, your workstation registers basic identity data (profile identifier, device hostname, app version, workspace folder path) with the account API for plan and role enforcement.
3. Diagnostics
Diagnostics uploads happen only when you click "Send diagnostics". A scrubbed bundle — log tail, environment summary, redacted settings, and a truncated workspace fingerprint — is uploaded to our diagnostics endpoint. API keys, tokens, and OAuth codes are stripped before upload. The returned report id serves as your support reference.
4. Telemetry
Usage telemetry is opt-in and disabled by default. When enabled, anonymous feature-usage events flush to our telemetry endpoint under a random install id; anonymous usage counters may be included in diagnostics bundles. When disabled, no telemetry leaves your device.
5. Website
The Deyin website uses essential cookies for site function and optional analytics cookies only with your consent (see our Cookie Policy). We do not build advertising profiles from site visits.
6. Data Retention
Local data persists until you delete it or uninstall the app. Diagnostics reports are retained by Openference for support purposes per their retention schedule. There is nothing else to delete on our side because there is nothing else we collect.
7. Security
Secrets at rest use OS keychain encryption via safeStorage. MCP catalog OAuth tokens are stored encrypted per module. SSH host keys are pinned on first connection to detect tampering.
8. Children & Regions
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). If you use the Service from the EEA/UK, note that model processing occurs through Openference; contact them for regional rights requests concerning gateway data.
9. Changes & Contact
We will update this page with a new "last updated" date when the policy changes. Questions: support@openference.com, or by mail to Deyin, 195-197 Wood Street, Suite RA01.