Aftermath

Local-first

Privacy

Aftermath is local-first.

What stays on disk

Verification evidence is written under .aftermath/ in your repository (runs, receipts, summary.json, optional baseline, repair-attempt cache). Redaction of secrets in logs is best-effort.

Cursor

Using Aftermath as a Cursor plugin or local MCP server does not send Aftermath telemetry. Cursor’s own model usage is separate from the verification engine.

If telemetry is ever introduced, it will be explicit opt-in only.

Full policy: docs/privacy.md