Legal & Trust Center
Ethen Code & Repository Data
Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.
This document explains how Ethen Code is designed to handle your source code and related data. That includes repository access, Git history, terminal commands and output, environment variables and secrets, local and cloud execution, AI model processing, and actions that change a repository. It is written for developers and Organizations evaluating Ethen Code. Ethen Code is not yet available. This document describes its designed behavior so you can understand it before release, and it will be updated to match the released product before anyone can use it. Read it with the Privacy Policy, the Terms of Service and the AI Use Policy.
On this page
- Current availability
- The parts of Ethen Code
- Local and cloud: where your code goes
- Repository access
- AI model processing
- Environment variables and secrets
- Cloud execution and sandboxes
- Actions that change code
- History, checkpoints and deletion
- Organizations and enterprise repositories
- Changes before release
- Related policies
- Contact
- Version history
Current availability
Ethen Code has not been released. There is no hosted Ethen Code service, and the Ethen desktop app is not yet distributed. Ethen does not currently access any code repository, run commands on any computer, or store any source code for Ethen Code users. When Ethen Code launches, this document will state the released surfaces, supported operating systems, permissions and data paths, and it will take effect then.
The parts of Ethen Code
Ethen Code is designed as four parts that handle data differently:
| Part | Where it runs | What it does |
|---|---|---|
| Ethen desktop app | Your computer | The application window you use for coding tasks. It also manages the local runtime. |
| Local runtime | Your computer, reachable only from that computer | Runs commands in terminals, reads and edits files in projects you open, keeps local history and checkpoints, and can run local models. |
| Web console | Ethen's cloud | A browser interface for tasks, reviews and history. |
| Cloud worker | Ethen's cloud | Runs longer tasks in isolated environments, works with repositories you authorize, and can check builds. |
Which parts handle your data depends on how you work. The rest of this document explains each path.
Local and cloud: where your code goes
| Activity | Stays on your computer | Leaves your computer |
|---|---|---|
| Reading and editing files in a local project | The files and edits | Only what is sent to a cloud AI model, if you use one |
| Running a command in a local terminal | The command and its output | Only what is sent to a cloud AI model, if you include it in a request |
| Local history and checkpoints | Stored in Ethen's data folder on your computer | — |
| Asking a local model (through a local runtime such as Ollama) | The Prompt, the code context and the response | — |
| Asking a cloud model | — | The Prompt and the code context Ethen includes go to the Model Provider, as for any Ethen request |
| Signing in, settings, task records in the web console | — | Your Account information and task records go to Ethen's cloud services |
| Cloud tasks and repository access through the cloud worker | — | Repository contents needed for the task are processed in Ethen's cloud environment |
Local is not the same as offline. Even when you use a local model and work only on local files, the desktop app still connects to Ethen's cloud to sign you in, sync settings and check for updates. Choosing a cloud model sends code context to that model's provider.
Data stored on your computer
On macOS, the desktop app and local runtime keep their data in an Ethen folder in your user Library (Application Support). That data includes:
- task history;
- checkpoints of file states, so changes can be undone;
- terminal session records;
- local settings.
This data stays on your computer unless you choose to sync or share it. You can delete it by removing that folder or uninstalling the app.
The local runtime accepts connections only from your own computer. It cannot be reached from other machines on your network or from the internet.
Repository access
Local repositories
When you open a project folder in the desktop app, Ethen Code can read and edit files in that folder, and run Git commands in it, using your existing Git setup. It does not need separate permission from your Git hosting provider for local work. It works with whatever access your computer already has.
Hosted repositories through GitHub
For cloud tasks, Ethen Code is designed to connect to GitHub through a GitHub App that you install on the repositories you choose. The installation determines which repositories Ethen can see, and what it can do with them. Ethen will request only the permissions its released features need. The exact permissions will be listed here and on GitHub's installation screen before release. You can change which repositories the app can access, or uninstall it, at any time from GitHub.
What Ethen Code may process
Depending on the task, Ethen Code may process:
- source code in files relevant to the task;
- repository metadata, such as repository and branch names, file structure and configuration files;
- Git history, such as commit messages, authors, timestamps and diffs, when a task needs it;
- branches, diffs and patches that Ethen proposes or that you ask it to review;
- issues and pull requests, such as titles, descriptions, comments and review status, when you ask Ethen to work with them;
- build, test and CI output, such as logs, test results and error messages;
- terminal commands and their output in sessions Ethen runs.
AI model processing
When a coding task uses a cloud AI model, Ethen sends the model the Prompt and the code context the task needs: relevant files or excerpts, diffs, error messages, and command output. That content goes to the provider of the model you select, as described in the Privacy Policy. Ethen Code is designed to select the context a task needs rather than send an entire repository to a model.
When a task uses a local model, the Prompt and code context are processed on your computer and are not sent to a Model Provider.
Generated code can contain bugs, vulnerabilities or code resembling existing licensed code. Review it before you run, commit or deploy it, as the AI Use Policy explains.
Environment variables and secrets
Source code often sits near secrets: API keys, tokens, passwords and private keys in configuration files, environment variables or command output. How Ethen Code detects and handles secrets will be documented here before release. Until then, assume that anything Ethen Code reads or a command prints may be included in a model request or a task record. To protect your secrets:
- keep secrets in environment variables or a secrets manager, not in source files;
- exclude secret files from projects you open in Ethen Code;
- be careful when asking Ethen to read configuration files or run commands that print environment variables;
- rotate any secret you believe was exposed in a Prompt, a log or a repository.
Ethen Code will not ask you to paste production credentials into a Prompt. Integrations that need credentials, such as the GitHub App, use the authorization flows of the service they connect to.
Cloud execution and sandboxes
The cloud worker runs tasks inside isolated, temporary environments (sandboxes) created for each task. A sandbox receives the repository contents and tools the task needs, runs commands such as builds and tests, and is discarded when the task finishes. Records of what happened, such as commands, output, diffs and results, are kept as task history.
Sandboxes are designed to be isolated from other customers' tasks. Their isolation and network access will be documented at release.
Actions that change code
Ethen Code distinguishes actions by how far they reach:
| Action | What it changes | Authorization |
|---|---|---|
| Read only | Nothing. Ethen reads code and history to answer or plan. | Opening the project or authorizing the repository |
| Local write | Files on your computer | Ethen proposes changes; local runtime actions follow the approval settings you choose. Checkpoints let you undo. |
| Run a command | Your computer or a sandbox | Commands the local runtime runs are subject to your approval settings; sandbox commands are confined to the sandbox |
| Remote write (push a branch or commit) | A repository on GitHub | Requires your explicit approval for that action |
| Open or update a pull request | A repository on GitHub | Requires your explicit approval |
| Merge | A repository's protected branch | Not performed by Ethen Code without your explicit approval, and subject to your repository's own branch protections |
| CI or deployment | Your CI system or production | Ethen Code may read CI results and propose fixes; it does not deploy to production on its own |
Writing to a hosted repository is switched off by default. Ethen Code will push, open pull requests or merge only after you approve that specific action, showing the repository, branch and changes involved. Your repository's own protections, such as branch protection rules and required reviews, continue to apply.
History, checkpoints and deletion
| Data | Where | How to delete it |
|---|---|---|
| Local task history, checkpoints, terminal records | Your computer | Delete them in the app, or delete Ethen's data folder |
| Cloud task records (tasks, approvals, diffs, command output) | Ethen's cloud | Delete tasks in the web console; deleting your Account will follow the rules in the Privacy Policy |
| Code processed in a sandbox | A temporary cloud environment | Discarded when the task ends; the task record keeps the results |
| Content sent to a cloud Model Provider | The provider | Retained under the provider's terms, as for any Ethen request |
| Changes pushed to GitHub | Your repository | Managed in GitHub |
Retention periods for cloud task records will be set out in the Data Retention Policy before release.
Organizations and enterprise repositories
Organizations evaluating Ethen Code for company repositories should consider:
- which repositories the GitHub App may access;
- whether cloud execution is permitted under company policy, or whether teams should use local execution only;
- which Model Providers may receive code;
- how generated code is reviewed before merge.
Organization administrator controls for these choices will be described when Organization features are available. Until then, apply your organization's own source-code policies. Do not connect repositories you are not authorized to share with third-party AI services.
Changes before release
Ethen Code's design may change before launch. This document will be updated to match the released product, and it takes effect only when Ethen Code is available to you.
Contact
Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.
Version history
| Version | Date | Status | Summary of changes |
|---|---|---|---|
| 1.0 | October 5, 2026 | Not yet in effect | First version, written ahead of Ethen Code's release from its designed data paths. |