The project stays local.
Your files, workspace, and editor settings live on your computer. Boongle does not upload the repo just because you opened a folder.
Trust
Trust is not a badge we print on the homepage. It is how the editor behaves when an agent wants to change your code, spend your plan, or send a prompt to a model. Here is what that actually means.
Your files, workspace, and editor settings live on your computer. Boongle does not upload the repo just because you opened a folder.
Changes show up as inline diffs. You accept what belongs and reject what does not. The agent does not get the last word.
You can require confirmation before sensitive file writes and before terminal commands run. Those switches are yours, in settings.
If a response goes the wrong way, stop generation. You are not locked into waiting out a runaway agent.
Auto, Boongle models, and frontier APIs are chosen in the picker. We do not silently swap you onto a different model mid-task.
AI requests can include the prompt, selected files, and context you attached. Those go to the provider for that model. We say so in the privacy policy, and we tell you not to paste secrets you would not share with them.
Things like Discord presence, speech input, and plugins are features you enable. The editor still works as a local IDE without them.
You can open a project and write code without a network. AI features need a connection. Your files do not.
Free, Pro, Pro+, Ultra, Max, and Teams are listed in public. First-party usage and API credit are explained, and usage resets each billing cycle.
The app shows how much of your included usage you have spent. You should not discover a limit only after a surprise invoice.
The changelog is public. When a model or build ships, you can read what changed instead of guessing from a silent update.
BoongleBench does not invent a number when an eval is missing. Missing axes are skipped. Compare inside a column, not across unrelated tests.
Windows and macOS installers are served from our release pipeline, not a random mirror. Beta builds still ask for an unlock code so random links do not hand out the app.
Accounts and usage sit on Supabase. The site is on Cloudflare. Installers go through GitHub. Inference goes through the model route you selected. That list is in the privacy policy.
Account and usage records exist so plans and sign-in work. You can request deletion of account-related data. We say how long we keep support and billing records, and why.
Boongle is not directed at children under 13, and we do not knowingly collect personal information from them.
Questions, beta, billing, and privacy requests go to Discord, where the team actually reads them. You are not dropped into a dead form.
Privacy and terms are on this site, dated, and written in plain language. If they change, the date changes with them.
We do not claim a SOC 2 report, a third-party security audit, or “we never see any data.” AI features send the context you include to a model provider. That is the product working, and hiding it would be the untrustworthy version.
If something on this page stops being true, it should be updated here and in the privacy policy and changelog — not buried in a tooltip.