Skip to content

Latest commit

 

History

History
80 lines (44 loc) · 6.93 KB

File metadata and controls

80 lines (44 loc) · 6.93 KB

RedEXCompile Privacy Statement

Effective date: July 12, 2026

This Statement explains how the RedEXCompile desktop application handles information. It should be reviewed and updated before each public release and reviewed by qualified privacy counsel where required.

1. Local-first operation

RedEXCompile is designed primarily as a local desktop application. Project files, editor settings, installed-plugin metadata, Toolchain Vault paths, terminal state, and lightweight project-link configuration are stored on your device. RedX Development does not operate a proprietary RedEXCompile cloud backend in this release and does not automatically receive those local files.

2. Information stored locally

The Software may store:

  • recently opened project locations and editor preferences;
  • paths, names, and detected versions of runtimes, SDKs, compilers, shells, CLIs, and package managers;
  • RedEXP plugin files and metadata;
  • .redexcompile/project.json files listing linked tool identifiers;
  • encrypted global and project secret vaults, including optional Help Write API keys;
  • Help Write provider, model, and endpoint preferences (but not a plaintext API key in the preferences file);
  • phone-pairing session information kept in memory while phone access is running;
  • GitHub Copilot runtime configuration and session information in the locations controlled by GitHub’s runtime.

Removing a Toolchain Vault entry removes RedEXCompile’s reference; it does not uninstall the underlying program.

3. GitHub Copilot and third parties

If you enable GitHub Copilot, prompts, selected project context, active-file content, tool results, and related information may be processed by GitHub and its model providers under GitHub’s terms, privacy statements, plan settings, and organizational policies. GitHub handles authentication; RedEXCompile does not request or store your GitHub password.

If you configure Help Write, your instruction, selected code, file context, language, and filename are sent directly from the desktop application to the provider you select. API keys are stored through the encrypted local Secrets Vault. RedEX does not operate an AI proxy for this feature and does not receive the request, but the selected provider does. Do not send secrets or code you are not permitted to share.

The Software may also communicate with services you intentionally invoke, including npm, PyPI, package repositories, Git hosts, Docker registries, plugin sources, language servers, websites opened from Help, and installers. Those parties’ policies govern their processing. Review sensitive code before sending it to any external service.

4. Phone workspace

Phone access is off by default. When enabled, RedEXCompile listens on the local network and serves the active project to a device that completes pairing. The service processes the connecting device’s network address for security and rate limiting and uses a temporary session cookie. Pairing sessions expire and are cleared when the service stops. RedX does not receive the transferred project content.

If you explicitly enable away-from-home access, the application starts the locally installed cloudflared tool and receives a temporary trycloudflare.com address. Cloudflare may process encrypted traffic, IP addresses, and operational metadata under its own policies. The tunnel ends when you stop it or close RedEXCompile. This feature is optional and is not a RedX-operated hosting service.

Live Collaboration transmits edits, QuickChat messages, temporary usernames, participant state, and WebRTC signaling through the host PC. Voice/video media normally travels through WebRTC peer connections and is not intentionally recorded by RedEXCompile. Peers, STUN infrastructure, browsers, operating systems, and networks may process IP addresses and connection metadata. Participants can independently copy or record anything they receive.

5. Automatic discovery

Toolchain Vault may inspect the system PATH and common installation directories and may execute known tools with version-reporting arguments. This information remains local unless you transmit it through a third-party feature. Manual fuzzy search may enumerate filenames and folders in common installation locations; it does not upload their contents to RedX.

Recommended Runtime and Package search sends search terms and standard network metadata to the selected official or community package registry, such as npm, PyPI, crates.io, NuGet, Maven Central, RubyGems, Packagist, pub.dev, Node.js, Go, or GitHub. Installing a result invokes that ecosystem’s package manager and is governed by its source and publisher.

6. Telemetry

RedEXCompile does not include proprietary RedX analytics or advertising telemetry in this release. Optional third-party components may process operational information according to their own settings and policies. The embedded Copilot session requests session telemetry to be disabled where the supported SDK option permits, but GitHub’s runtime and services may still process information necessary to provide, secure, bill, and administer Copilot.

Installed release builds periodically contact GitHub Releases to check for updates and may download a platform installer and release metadata. GitHub receives ordinary request metadata such as IP address and user agent under its own policy.

7. Sale and advertising

RedX does not sell personal information collected by this release and does not use local project content for targeted advertising. If future releases add accounts, hosted synchronization, analytics, advertising, or cloud processing, this Statement must be updated before those features launch.

8. Security

Safeguards include Electron context isolation, project-path containment, explicit phone activation, rotating pairing codes, rate limiting, temporary sessions, declarative plugin validation, and Copilot permission prompts. No safeguard is perfect. Keep your operating system and dependencies updated, use trusted networks, review permissions, maintain backups, and protect your device account.

9. Retention and deletion

Local information remains until you remove it, uninstall the Software, clear application data, or delete the relevant project/configuration. Third parties control their own retention. Uninstalling RedEXCompile may not remove projects, installed development tools, third-party accounts, package caches, or third-party records.

10. Children

The Software is a general development tool and is not directed to children under 13. RedX does not knowingly operate a service through this release that collects personal information from children. Users must follow applicable age requirements for GitHub and other third-party services.

11. Changes

This Statement may change when features or legal requirements change. Material changes should be presented with an updated effective date before the affected processing begins.

12. Contact

Questions or requests may be sent to:

RedX Development

redxdevelopment1998@gmail.com