Local-first
Privacy
Aftermath is local-first.
- No telemetry in v0.x
- No source uploads
- No log uploads
- No analytics
- No required cloud service, account, or API key
What stays on disk
Verification evidence is written under .aftermath/ in your repository (runs,
receipts, summary.json, optional baseline, repair-attempt cache). Redaction of
secrets in logs is best-effort.
Cursor
Using Aftermath as a Cursor plugin or local MCP server does not send Aftermath telemetry. Cursor’s own model usage is separate from the verification engine.
If telemetry is ever introduced, it will be explicit opt-in only.
Full policy: docs/privacy.md