What we store, and why
Optimus runs inside your editor, in your process, against your environment. That is what makes it able to see tool calls, and it is also why almost nothing reaches us. This page is the list of what does.
What never leaves your machine
- Your source code, and every prompt in it.
- Your tool names. They are your business logic, and not ours to know.
- Your database, and every row in it. We never connect to it.
- Your provider keys, your environment variables, and your infrastructure.
- Any conversation Optimus did not itself ask you to drive — including every real conversation your agent has had. When your assistant reads some to make the probes sound real, it keeps a paraphrase of how customers open in
.optimus/, and that stays here unless you turn contributing on. - Everything in
.optimus/, the directory beside your repository, which holds the bindings, the decisions your team has made, and the run history.
.optimus/ is yours. Commit it and your team shares its decisions the way it shares its tests. A .gitignore is written into it excluding three files: session.json and last-report.json, which hold verbatim text from your agent’s conversations, and queries.json, which holds the read-only queries written against your own data. None of the three leaves your machine either way.What reaches us, and when
Some of Optimus’s own reasoning runs on our side rather than on your machine. That is the reason anything leaves at all, and it is a short list.
| Sent | Why it has to be |
|---|---|
| the findings | What was found, and the evidence behind it — anonymised on your machine first. |
| probe conversations | Only the ones Optimus itself asked you to drive, anonymised on your machine first. |
| counts | How many, of what kind, and how long a run took. Named in our own vocabulary, never yours. |
| your reason | When you reject a finding, the reason — but only where it survives being said without naming anything in your repository. That check runs on your machine, before anything is sent. |
| a run starting | One call when you ask Optimus to test, carrying only your key, so the run is counted against your plan. Nothing about the run itself. |
| how your customers open | Up to five paraphrased openers from a reading of your own conversations, and only those your machine has checked name nothing in your repository and carry no name, email, number or reference. It teaches our domain packs what real customers sound like. Listed on your data page, and deleted from there. |
| how far a session got | On each exchange: which of our own steps it has reached, what it is waiting on, and how long each piece of our work took. So we can see where people give up rather than only where they finish. Our step names, never yours — there is no field here a repository name could sit in. |
Anonymised means names, emails, phone and card numbers, order references, URLs, file paths and tool names are replaced with placeholders like [id-2] before anything is sent — the same value always getting the same one. The answer is put back on your machine before you read it, and the map never leaves. It works by pattern: thorough about anything with a shape, and unable to promise a business name written in plain prose.
Nothing is stored at either end of a reasoning call, and nothing here asks you for a second credential — your Optimus key is the whole of it.
None of this is a switch. There were three, and an opt-in for the fourth, and they are gone — not moved to a screen, removed. You agree to this list when you take a key, and the version you agreed to is recorded beside it; a key that exists is a key that sends what this page says it sends.
What replaces the switches is that the boundary is enforced rather than promised. Your machine filters before anything leaves, our server filters again on the way in, and the database rules are closed — three independent layers, none of which can be turned off by accident. Everything above is either a count, one of our own names, or something a check on your machine has certified could have come from anybody. Delete any of it from your data page.
What your account holds
| Held | What it is |
|---|---|
| identity | Your email address, display name and photo as your sign-in provider gave them, which providers you have used, when the account was created and when you last signed in. |
| keys | A SHA-256 digest of each key, a four-character hint, the label, when it was made and when it was last used. Never the key — it is shown once at creation and cannot be shown again, because a platform able to reprint a customer’s credential is a platform whose database breach reprints all of them. |
| usage | How many runs your account started this month and today — a count and a date, nothing about the run — so a plan limit can mean something. |
| subscription | Only if you pay: the plan, the number of seats, its status and renewal date, and Lemon Squeezy’s ids for you and the subscription. Never card details — Lemon Squeezy takes the payment. |
| run summaries | When sync is on: a run id, the repository label you chose, timestamps, which of our cause ids got which verdict, the coverage figure and the counts. No tool names, no evidence text, no transcript. |
| your reasons | The free text you wrote when rejecting a finding, where it passed the check above. Up to 300 characters each. |
Why we keep the counts at all
One number. The share of findings a customer marks by-design is our false-positive rate, measured by real people on their own agents rather than on a benchmark. Nothing else will tell us, and a check that fires when it should not is the one defect a testing product cannot afford.
Your written reason is what makes it actionable. A count says a check was rejected; only the reason says whether our gate was wrong or your agent was right, and those want opposite work.
Seeing it, and deleting it
Everything above is listed on your data page, with what it is and where it came from. Deleting removes the documents rather than hiding them, and revoking a key removes both the key and the index entry that resolves it.
Getting in touch
Write to hello@optimus-ai.dev for anything this page does not answer, including deleting an account outright.