# Data retention, training use and deployment isolation (`account.data_privacy`)

Feedback Bench, coding agents, built 2026-10-01, window 2026-08-31 to 2026-09-27. Web page: https://feedbackbench.com/#/criterion/account.data_privacy

Area: [Account and support](https://feedbackbench.com/criteria/account.md)

**Definition.** Whether prompts and code are retained or used for training, and whether private or air-gapped deployment is available.

**Boundary.** Not this: see [Free tier and free model availability and limits](https://feedbackbench.com/criteria/billing.free_tier.md) for free-model availability itself.

Rated author-weeks, all agents: 714. Complaint share: 80%.

## The brief

Written by Claude Opus 5.5 from 77 labelled posts and the numbers on this page. Interpretation, not measurement: every quote is verbatim and links to its post.

**Users trust code that never leaves the machine, not opt-out toggles.**

TL;DR:

- Complaints outnumber praise for every agent with real volume; no vendor has earned default trust on privacy.
- Training opt-outs draw suspicion, especially after users cite a public controversy suggesting toggles did not hold.
- Local storage, VPC execution and air-gapped deployment get the warmest posts across tools.

In plain terms: Engineers worry their prompts and code feed someone's training run. They hunt for buried settings, doubt the switches work, and get angry about undisclosed routing. Agents that keep data local or inside the customer's network get the praise.

### How it breaks

- **Opt-out toggles nobody believes** ([Data retention, training use and deployment isolation](https://feedbackbench.com/criteria/account.data_privacy.md)). Users say the training opt-out is buried, opt-out instead of opt-in, and possibly ineffective. A public controversy turned that into active distrust.
  Codex users report the data-sharing setting lives outside the CLI, in the web app. Several posts cite a recent mathematics dispute as proof that sessions were learned from even with training disabled. Claude Code users make the same charge about the consumer-tier toggle, calling it no guarantee. One Pi user has stopped treating consent as a factor at all. The real damage is not the policy. Users no longer believe the switch does what its label says.
  Evidence:
  - Complaint, OpenAI Codex, r/codex, 2026-09-09: “with this recent maths controversy surrounding ai. here is a reminder to turn off your data sharing. <strict_link> this should be opt-in, not opt-out. i can't even find the setting in codex have to go to chatgpt web just to toggle this. i am absolutely disgusted to hear what they have done.” [source](https://www.reddit.com/r/codex/comments/1wbfcdg/why_is_data_sharing_turned_on_by_default_turn_it/)
  - Complaint, OpenAI Codex, r/codex, 2026-09-16: “it’s deep in the settings, i have it turned on but don’t rely on it. a recent mathematics drama between 2 researchers that were trying to find a solution to the navier-stokes millennium problem exposed that they learn from our codex sessions even if you have the ‘not training on our sessions turned on’ i think the only difference is that one option allows them to train on your data de-identified lol” [source](https://www.reddit.com/r/codex/comments/1wi14lt/what_is_going_on_with_openai/pa7gp7c/)
  - Complaint, Claude Code, r/ClaudeCode, 2026-09-15: “they are providing anthropic training data, that's what they are mostly doing. if you are not using the business subscription, they can train on your inputs, it's in the terms of service. you can toggle off the "help improve the model for everyone", but there is no guarantee that it actually does something. btw, this is a very gaslighting version of "let us collect your data" you probably heard about the navier-stokes math problem recently.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wgz6lf/what_are_people_making_in_claude_code/pa17gyd/)
  - Complaint, Pi, r/PiCodingAgent, 2026-09-16: “with the whole mess with navier stokes, looks like zdr is also not something that the frontier labs are respecting. at this point, i am thinking everyone is using my data no matter if i give consent or not, so its not a factor in my decision making.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1whetud/why_pi_set_luna_ctx_window_to_275000_by_default/pa67r0e/)

- **Unclear training policy on paid plans** ([Data retention, training use and deployment isolation](https://feedbackbench.com/criteria/account.data_privacy.md)). Antigravity users cannot find a straight answer on whether paid prompts train models, and they say they would have skipped the tool had they known.
  Posts describe digging through Google's documentation without finding whether telemetry-off means training-off. An EU Pro user says no clear response exists. Another compares it unfavourably with Codex and Claude, where an opt-out exists. Antigravity leads requests for a training opt-out. The friction comes from ambiguity more than from any confirmed policy. Users fill the gap with the worst assumption.
  Evidence:
  - Complaint, Google Antigravity, r/google_antigravity, 2026-09-07: “bit of a bummer they aren't upfront about this. i never would have used it if i'd known. it only costs cents more to not have this happen.” [source](https://www.reddit.com/r/google_antigravity/comments/1wa6rcj/im_agy_clis_biggest_fanboy_but_i_have_to_quit_it/p8g2ne7/)
  - Praise, OpenAI Codex, r/google_antigravity, 2026-09-01: “i've been trying to get a grasp on this, but googles whole ecosystem and the way they provide info is such a mess it feels impossible to ever get any clear answer. **as far as i've understood it**, antigravity **will use your data/prompts for model training** and this is **not** something you can opt out of - is this correct or not? if so, i feel it's kind of low to not have it be something you can opt-out of considering it's already a paid service, when you can opt out of for example openai codex and claude etc.” [source](https://www.reddit.com/r/google_antigravity/comments/1w48616/is_antigravity_using_prompts_and_data_for_model/)
  - Complaint, Google Antigravity, r/google_antigravity, 2026-09-18: “can you clarify whether or not google trains on our data with telemetry disabled in the antigravity app? interactions fo improving the app not heing shared are not the same as data shared for eg data analysis work. i'm a pro user in the eu and can't find a clear response to this anywhere.. what an obscure pos stance” [source](https://www.reddit.com/r/google_antigravity/comments/1whzsnx/gemini_40/pakvrzh/)

- **Undisclosed routing to third-party providers** ([Data retention, training use and deployment isolation](https://feedbackbench.com/criteria/account.data_privacy.md)). OpenCode's zero-retention pitch is undercut by users who say models route through providers they were never told about, with no control over upstream handling.
  One subscriber cancelled after discovering the routing through an API error, not before purchase. The complaint is about disclosure, not the providers themselves. The same post notes that the retention promise excludes third parties who break the rules. Others call the service a data-collection risk, and one user reports seeing another user's messages through the API. Avoiding certain regional routing is a request unique to OpenCode here.
  Evidence:
  - Complaint, OpenCode, @opencode, 2026-09-17: “@opencode this is a lie, you route different western and chinese models through it, this is a true data collection honeypot” [source](https://twitter.com/1533079818249568258/status/2100498007795888336)
  - Complaint, OpenCode, @opencode, 2026-09-20: “i have cancelled @opencode go sub now. opencode is not transparent about anything. open is just a marketing trick , nothing more. they force you to use china hosted models but never mention it before you buy it. you realize it with api error. i am not against china hosted ones btw but if you say you are open and hide it then i dont trust you on anything. they also say that no data retention but they are not responsible if other side breaks rules and we customers accept that by default. there is no control for third party providers as well. i thought you are a reliable one but i think money and fame controls what you are doing @thdxr i liked deepseek flash 4.1 a lot and will use it somewhere else.” [source](https://twitter.com/1511436011720650755/status/2101753885400445048)
  - Complaint, OpenCode, r/opencode, 2026-09-07: “plus... i got some messages from another user using the api... tried once... i think i will not touch it for a while.” [source](https://www.reddit.com/r/opencode/comments/1w9ntc4/muse_spark_13_contributor_on_opencode_go/p8bpymr/)
  - Complaint, OpenCode, @opencode, 2026-09-04: “@skcache @opencode @thdxr now data collection like how nvidia does would be hidden if these models are stealth, cautious use is important” [source](https://twitter.com/2000001258204377088/status/2095756299296501923)

- **Secrets and session links leak into artifacts** ([Data retention, training use and deployment isolation](https://feedbackbench.com/criteria/account.data_privacy.md)). Users flag credentials sitting in chat logs and session backlinks in commits as privacy exposure the agent creates on its own.
  A Cursor post warns that any pasted API key persists in session history and memory, and asks for keys to stay out of context entirely. Claude Code users push back on session identifiers added to commits, since they cannot confirm who can read those sessions. Devin and Amp posts ask for scoped, revocable credentials during handoffs. Isolating secrets from the model and opt-in session attribution both show up as recurring requests.
  Evidence:
  - Complaint, Cursor, @cursor_ai, 2026-09-07: “your api key is in your chat history right now. every key you pasted into cursor or claude lives in that session's logs and memory. permanently. keep it server-side. the agent calls stripe. the key never enters the context. @cursor_ai @simonw” [source](https://twitter.com/2024541987765178368/status/2097001141020037190)
  - Complaint, Claude Code, r/ClaudeCode, 2026-09-04: “if the question is "why one would want these two lines gone?": 1. "co-authored-by" is noisy and unnecessary. i don't want to list claude code in all my commits, just like i don't want to write intellij idea, warp, etc. in there. it's irrelevant to the commit because 99% of my commits are made by claude, and the few that are not, anyone can recognize from the length/style. 2. "claude-session", well, if i knew that anthropic can't (technically and legally) access my sessions (now connected to commits) then i'd actually be useful to have that backlink. but as i don't know, it feels uncomfortable to have that link there. i keep my code public (mostly [<strict_link>), but the sessions feel more personal to me. 🤷♂️” [source](https://www.reddit.com/r/ClaudeCode/comments/1w6yw16/claude_code_v21259_forces_coauthoredby/p7rl31f/)
  - Complaint, Devin, @cognition, 2026-09-22: “@cognition the useful feature is not remote coding by itself. it is continuity across environments: start in cli, inspect the vm over ssh, then hand the work back. the security footgun is equally clear: handoff needs explicit secret and environment boundaries, not just a nicer terminal.” [source](https://twitter.com/2051888695100514304/status/2102416772188213462)
  - Complaint, Amp, @AmpCode, 2026-09-03: “@ian_hsiao_tw @ampcode @bot @getenergy_ direction checks out. but cookie sync hands remote agents bearer tokens to your entire digital life. a coding agent already uploaded entire private repos for a task that needed 192 kb. scoped, revocable credential delegation is the missing piece.” [source](https://twitter.com/1656371068452630528/status/2095447186074898865)

- **Local-first and in-boundary execution wins trust** ([Data retention, training use and deployment isolation](https://feedbackbench.com/criteria/account.data_privacy.md)). The strongest praise goes to setups where code and data never leave the user's machine or network, because that ends the compliance conversation.
  A Claude Code user says local-first skips the data question with customers entirely. Cursor users praise running cloud agents on their own pools, saying boundary anxiety blocked adoption more than model quality did. Pi and Claude Code users value local storage and local models over convenience. The flip side is Zed users in security roles who say the product cannot be used under their contracts without a local-only mode.
  Evidence:
  - Praise, Claude Code, @ClaudeDevs, 2026-09-24: “@claudedevs honestly the bigger deal than people realize. customer addresses and pricing never leaving my machine means i skip the whole 'where's our data' conversation. local-first just wins trust by default.” [source](https://twitter.com/2061489365067689988/status/2103114840206180412)
  - Praise, Cursor, @cursor_ai, 2026-09-05: “@cursor_ai cloud agents on my own pools is the control i've wanted. data boundary anxiety was blocking me more than model quality.” [source](https://twitter.com/2091157523155849217/status/2096327004392149115)
  - Praise, Claude Code, r/ClaudeCode, 2026-09-05: “unlikely. but personally i like having all my data local and backed up. also means claude can do things on my network which is very useful to me” [source](https://www.reddit.com/r/ClaudeCode/comments/1w86u68/any_of_you_use_vps_for_claude_code_should_i/p81vdd3/)
  - Complaint, Zed, r/ZedEditor, 2026-09-17: “same difference. using this wonderful tool requires me to violate my service contract. in the industry, this isn't a new concept / problem. this was a strategic choice to build a product that simply will never be allowed to be used by those with secure environments.” [source](https://www.reddit.com/r/ZedEditor/comments/1whydrw/delta_in_public_beta/pacrxth/)

### Who stands out

- **OpenCode (mixed)**. Zero data retention draws real praise as the line that unlocks production use, but routing disclosure complaints drag it back down.
  Users describe retention as a policy question legal has already answered, which makes it decisive over context length. Others like dumping whole codebases without leak worries. The same promise erodes when users learn upstream providers sit outside it. OpenCode draws the most retention requests of any agent here, so demand for the feature is clearly real. The gap is transparency, not intent.
  Evidence:
  - Praise, OpenCode, @opencode, 2026-09-26: “@opencode zero data retention is the line that decides whether a team can point this at real work rather than a toy repo. context length is a preference. retention is a policy question someone in legal has already answered.” [source](https://twitter.com/1731877835256516608/status/2103847879857361100)
  - Praise, OpenCode, @opencode, 2026-09-26: “@opencode zero data retention" + "1m context" is an absolute dream combo for bug bounty. being able to dump entire large codebases or massive logs safely without worrying about data leaks is massive. time to hunt! 🕵️♂️🔥” [source](https://twitter.com/2084987514029215744/status/2103964240331858150)
  - Complaint, OpenCode, @opencode, 2026-09-20: “i have cancelled @opencode go sub now. opencode is not transparent about anything. open is just a marketing trick , nothing more. they force you to use china hosted models but never mention it before you buy it. you realize it with api error. i am not against china hosted ones btw but if you say you are open and hide it then i dont trust you on anything. they also say that no data retention but they are not responsible if other side breaks rules and we customers accept that by default. there is no control for third party providers as well. i thought you are a reliable one but i think money and fame controls what you are doing @thdxr i liked deepseek flash 4.1 a lot and will use it somewhere else.” [source](https://twitter.com/1511436011720650755/status/2101753885400445048)
  - Complaint, OpenCode, r/opencode, 2026-09-07: “plus... i got some messages from another user using the api... tried once... i think i will not touch it for a while.” [source](https://www.reddit.com/r/opencode/comments/1w9ntc4/muse_spark_13_contributor_on_opencode_go/p8bpymr/)

- **Google Antigravity (mixed)**. Enterprise users praise no-training guarantees under Workspace and Cloud terms, while individual subscribers cannot tell what applies to them.
  Posts describe business accounts with contractual no-training commitments, demand-driven context instead of bulk uploads, and data residency support. Those details live on the enterprise path. Pro users report the opposite experience, an unanswered question about training with telemetry off. The product splits cleanly by account type, and the consumer side drives the most training opt-out requests in the category.
  Evidence:
  - Praise, Google Antigravity, r/GoogleAntigravityIDE, 2026-09-08: “gemini has something no other model has, and many companies using it. google guranties that your code is not used for training or uplpaded when you have a workspace business account. here in <street_address> we could sue google by billions in case this happens. no other ai does this! on far a fact most companies using it” [source](https://www.reddit.com/r/GoogleAntigravityIDE/comments/1waonet/why_does_antigravity_have_so_few_users/p8lkdeu/)
  - Praise, Google Antigravity, @antigravity, 2026-09-21: “antigravity agents read the local repo via on-device tools (view/search/edit files) and send only relevant session context to the model. when configured for a gcp project (gemini enterprise/agent platform), inference runs under google cloud tos: code/prompts stay in your private environment, are not used for training, and support vpc-sc/data residency. no silent full-repo history push like the others; it's demand-driven, not background bulk upload.” [source](https://twitter.com/1720665183188922368/status/2101979353089298802)
  - Complaint, Google Antigravity, r/google_antigravity, 2026-09-18: “can you clarify whether or not google trains on our data with telemetry disabled in the antigravity app? interactions fo improving the app not heing shared are not the same as data shared for eg data analysis work. i'm a pro user in the eu and can't find a clear response to this anywhere.. what an obscure pos stance” [source](https://www.reddit.com/r/google_antigravity/comments/1whzsnx/gemini_40/pakvrzh/)
  - Complaint, Google Antigravity, @antigravity, 2026-09-23: “@antigravity google &amp; privacy doesn't match in a sentence” [source](https://twitter.com/898545734357856256/status/2102850082324586844)

- **Cursor (mixed)**. Self-hosted agent pools inside a customer VPC earn enthusiastic praise from teams that cannot send code off-network.
  Users call keeping credentials and execution inside their own network the unlock for regulated teams. One post rates Cursor's privacy handling above a model vendor's own CLI. Complaints focus elsewhere. A user reports losing access to code tied to their account, and another warns that pasted keys persist in session logs. The deployment story is strong. The account and secrets story is not.
  Evidence:
  - Praise, Cursor, @cursor_ai, 2026-09-04: “@cursor_ai this is the unlock for teams that can't send code off their network” [source](https://twitter.com/2055860494146170880/status/2095990327802741115)
  - Praise, Cursor, @cursor_ai, 2026-09-03: “@cursor_ai this is huge for teams that need to keep proprietary data behind their firewall while still getting the full agent experience.” [source](https://twitter.com/1882264806847381504/status/2095302128134688876)
  - Praise, Cursor, @cursor_ai, 2026-09-04: “@cursor_ai the agent loop stayed in cursor. the credentials finally stay in your vpc.” [source](https://twitter.com/1610522467264565249/status/2095906460140183864)
  - Complaint, Cursor, @cursor_ai, 2026-09-22: “this is worse than i thought. i don't have access to any of my @cursor_ai origin code, because it's tied to my cursor account. 100% of my most critical code is now behind this wall. i moved everything from @github but i will never do that again. this is insanely painful.” [source](https://twitter.com/1808299140998389760/status/2102392822825369961)

- **OpenAI Codex (mixed)**. Local session storage and an open-source CLI earn trust, but the opt-out controversy hits Codex harder than most.
  Users praise that CLI sessions stay on disk and that the client can be inspected rather than taken on faith. One user only discovered the opt-out by accident, which helps and hurts at once. Most complaints trace to the training toggle being hard to find and allegedly not honoured. A user also reports that business data needs manual sanitising before sharing.
  Evidence:
  - Praise, OpenAI Codex, r/codex, 2026-09-13: “actually it turns out you can opt out of data sharing in the settings! just found this out. also while we are paying for it, it is heavily subsidized” [source](https://www.reddit.com/r/codex/comments/1waoys2/blown_up_openai_allegedly_stole_mathematicians/p9h65sq/)
  - Praise, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-25: “protect your sessions assets! from now on, switch from chatgpt desktop to codex cli, since you are just conversing with ai anyway, and all sessions in codex cli are stored locally.” [source](https://twitter.com/367212879/status/2103396351442923932)
  - Praise, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-12: “@fankaishuoai the local agent runs attached to the warehouse, what it collects and where it reports, if it can only trust the terms, reading 154 pages won't make up for it. the codex cli is open source and at least can be verified; this asymmetry is the hard reason for the uninstallation.” [source](https://twitter.com/2088999223241101312/status/2098771108644491640)
  - Complaint, OpenAI Codex, X search: OpenAI Codex, Codex CLI, Codex app, 2026-09-01: “speaking for few friends i've spoken w: - codex app dropped support for the os version silently (mac, experienced this myself too) - can't share (business) data/can share but need manual sanitization - don't want to share all the (personal) data/fear of personal data leak - heard 200$/mo can't do much - heard it only makes slop - feels fine without it” [source](https://twitter.com/2026584390265090051/status/2094590267647283336)

- **Factory (stronger)**. Every rated Factory post here is praise, all centred on private and air-gapped deployment with auditable routing.
  Users frame on-prem deployment as making the control plane part of the product, letting sensitive workloads stay inside the team's boundary. The open question users raise is on-prem performance against cloud, not privacy. The sample is small, so this reads as a clear positioning signal rather than a settled verdict.
  Evidence:
  - Praise, Factory, @FactoryAI, 2026-09-19: “@factoryai private and air-gapped deployment makes the control plane part of the product. auditable routing across local and hosted models lets teams keep sensitive workloads inside their boundary while preserving measurable quality and cost.” [source](https://twitter.com/39700226/status/2101265444455727159)
  - Praise, Factory, @FactoryAI, 2026-09-18: “@factoryai i must say, keeping code and models on your own infrastructure makes a lot of sense. curious how the on-prem performance holds up compared to cloud.” [source](https://twitter.com/1634511842516287490/status/2101087275065163993)

### Fine print

- Factory, GitHub Copilot, Zed and others have too few posts for firm conclusions; their direction is indicative only.
- Several complaints cite a single public controversy, so sentiment may reflect one news cycle more than lasting product behaviour.
- Some posts discuss third-party tools mentioned alongside an agent; attribution follows the source system's tagging.

## Top requests

What users ask to add or change, most asked first. 135 author-weeks ask for something. Requests do not change the Feedback Score. Rule: A separate pass by Claude Sonnet 5 reads every counted post and extracts what the author asks the agent or its vendor to add or change, with the criteria it maps to and a short normalised wording; it does not touch the labels or the Feedback Score. Claude Opus 5.5 groups the wordings within each criterion (the first criterion the request maps to) into themes; code counts them. A theme counts distinct author-weeks that ask for it, per agent; across agents, one author-week per agent. Themes asked in fewer than 2 author-weeks, and requests that share no theme, are not shown. Examples: up to 3 posts per theme from different authors, without slurs, preferring posts of 60 to 450 characters, most recent first.

| Rank | Request | Author-weeks | Posts | Agents (author-weeks) |
|---|---|---|---|---|
| 1 | Opt-out of training on user data | 15 | 16 | Google Antigravity 8, OpenAI Codex 4, OpenCode 2, Cursor 1 |
| 2 | Zero data retention option | 10 | 10 | OpenCode 6, Claude Code 1, Cline 1, OpenAI Codex 1, Cursor 1 |
| 3 | Clear disclosure of training data use | 8 | 10 | OpenCode 3, Google Antigravity 2, OpenAI Codex 2, Cline 1 |
| 4 | Air-gapped or self-hosted deployment | 6 | 6 | Google Antigravity 1, Claude Code 1, Cursor 1, Factory 1, OpenCode 1, Zed 1 |
| 5 | Secrets isolated from model and vaulted | 6 | 6 | Claude Code 2, Amp 1, Cline 1, Cursor 1, Devin 1 |
| 6 | Audit logs of agent actions | 5 | 5 | Google Antigravity 2, Claude Code 1, Cursor 1, Factory 1 |
| 7 | Avoid routing data through China | 5 | 5 | OpenCode 5 |
| 8 | EU data residency and isolation | 5 | 5 | Cursor 2, OpenAI Codex 1, OpenCode 1, Pi 1 |
| 9 | Opt-in session link attribution in commits | 5 | 5 | Claude Code 5 |
| 10 | Reduce background data uploads | 5 | 5 | Google Antigravity 1, OpenAI Codex 1, Cursor 1, OpenCode 1, Zed 1 |
| 11 | Agent data egress controls | 4 | 4 | Google Antigravity 2, OpenAI Codex 2 |
| 12 | Open source the product | 4 | 4 | Claude Code 3, Zed 1 |

### 1. Opt-out of training on user data

- Google Antigravity, 2026-09-27, @antigravity (X): “@antigravity you should give an option to opt out while setting up antigravity itself. this is a dark pattern where people will just agree and later either forget to opt-out or forget about it after trying to dig through the settings to find it! <strict_link>” [source](https://twitter.com/1013749216387256322/status/2104104816423453001)
- OpenCode, 2026-09-26, r/opencode (Reddit): “for people who don't want meta to use there input and output request to train there models + when i use muse i feel it is kinda dump” [source](https://www.reddit.com/r/opencode/comments/1wq74d5/deepseek_v41_flash_is_permanent/pc9rd8d/)
- OpenAI Codex, 2026-09-23, r/codex (Reddit): “if anthropic didn't train on data and gave you a way to opt-out (without being an enterprise customer) i'd be gone in an instant as well.” [source](https://www.reddit.com/r/codex/comments/1wo8fhw/okay_they_literally_cut_our_quota_by_half_gpt_6/pbncr4s/)

### 2. Zero data retention option

- Cline, 2026-09-27, r/CLine (Reddit): “please include whether it’s zdr or not. what’s with the limit because you are routing the request to vercel ai free pinary” [source](https://www.reddit.com/r/CLine/comments/1wqkucr/pixel_canary_new_stealth_model_is_now_free_in/pcce0up/)
- OpenCode, 2026-09-26, @opencode (X): “@opencode there’s an option to turn off free models but an option to only enable zero data retention models would be better” [source](https://twitter.com/1396509960998055939/status/2103899494471594347)
- OpenCode, 2026-09-26, @opencode (X): “@opencode zero data retention is the line that decides whether a team can point this at real work rather than a toy repo. context length is a preference. retention is a policy question someone in legal has already answered.” [source](https://twitter.com/1731877835256516608/status/2103847879857361100)

### 3. Clear disclosure of training data use

- OpenCode, 2026-09-17, r/opencode (Reddit): “users should be given a months time so that they can cancel their subscription. right now the change of data sharing to china(doesnt matter if it was usa too) via ds4.1 seems cheating. why cant opencode host the models on their infra. then they wont have to deal with this data sharing. many people will say its because its cheap but we as customers have the right to know if its gonna change between subscription.” [source](https://www.reddit.com/r/opencode/comments/1wigkse/bait_and_switch_is_really_bad_deepseek_if_i_had/)
- OpenCode, 2026-09-17, @opencode (X): “@opencode how are you measuring the no training claim in practice? a clear audit trail would help teams trust a free tool with real code.” [source](https://twitter.com/2095778877037477890/status/2100472630260248751)
- OpenCode, 2026-09-16, r/opencode (Reddit): “i've always wondered, if the "use my data for training" option is turned off in chatgpt, but i use oauth to access within opencode, will my data be sent to opencode or openai for training, or not? or what's the best way to be sure?” [source](https://www.reddit.com/r/opencode/comments/1wi052o/who_am_i_sending_my_information_to/)

### 4. Air-gapped or self-hosted deployment

- Claude Code, 2026-09-20, r/ClaudeCode (Reddit): “anything involving a neural net wether it's claude or whatever should be in the most isolated environment possible not even with access to an outside network” [source](https://www.reddit.com/r/ClaudeCode/comments/1wkzp8t/claude_tag/pavlkhw/)
- OpenCode, 2026-09-17, r/opencode (Reddit): “users should be given a months time so that they can cancel their subscription. right now the change of data sharing to china(doesnt matter if it was usa too) via ds4.1 seems cheating. why cant opencode host the models on their infra. then they wont have to deal with this data sharing. many people will say its because its cheap but we as customers have the right to know if its gonna change between subscription.” [source](https://www.reddit.com/r/opencode/comments/1wigkse/bait_and_switch_is_really_bad_deepseek_if_i_had/)
- Zed, 2026-09-17, @zeddotdev (X): “@zeddotdev really don’t want to store the private codebase in the remote server. this prevents using delta in company development.” [source](https://twitter.com/1277811422697840641/status/2100428485970080245)

### 5. Secrets isolated from model and vaulted

- Cline, 2026-09-19, @cline (X): “@siddiqatactyte @cline secret handling. credentials and sessions must stay outside the model by default—vaulted, injected only at the edge, never logged or contexted. navigation allowlists and previews for mutations matter, but neither contains damage once keys leak.” [source](https://twitter.com/1720665183188922368/status/2101201199361892735)
- Claude Code, 2026-09-18, @ClaudeDevs (X): “@claudedevs enterprise really needs 1) secret storage / external vault support for claude code cloud environments, and 2) claude code projects access — neither is available on enterprise plans yet, and it's blocking real adoption.” [source](https://twitter.com/21361149/status/2101024559076159609)
- Devin, 2026-09-16, @cognition (X): “@cognition the important leap is not just running on a mac, but closing the feedback loop: build, test, screenshot, and testflight. for production, it will be necessary to specify device state, secrets isolation, and reproducible rollback; that is where it is decided if an agent is reliable or just a demo.” [source](https://twitter.com/93014855/status/2100121667057934669)

### 6. Audit logs of agent actions

- Factory, 2026-09-18, @FactoryAI (X): “@factoryai private deployments need a run receipt beside the vpc choice: image digest, policy version, allowed tools, egress rules, data boundary, last smoke, rollback owner. then an agent can prove the private box is not just a prettier blind spot.” [source](https://twitter.com/2013700835654672388/status/2100999150133547123)
- Claude Code, 2026-09-17, @ClaudeDevs (X): “@claudedevs credentials and observability are where the demo turns into an operations problem. every agent run should leave a trace a human can inspect, especially when it touches production data.” [source](https://twitter.com/1395092615830278144/status/2100584475956563979)
- Google Antigravity, 2026-09-16, @antigravity (X): “@antigravity good trade-off: the network access closed by default reduces the blast radius, but the permission model will be as important as the sandbox. for real teams, will there be an audit log/export and reproducible profiles to review which tool each agent executed?” [source](https://twitter.com/93014855/status/2100121555204280393)

### 7. Avoid routing data through China

- OpenCode, 2026-09-26, @opencode (X): “@opencode can you make it available outside china? my employer doesn't allow routing requests to china.” [source](https://twitter.com/1138368631618899968/status/2103817327267791184)
- OpenCode, 2026-09-20, r/codex (Reddit): “the only downside is that the only way to use it is by using servers in china. even through opencode you have to toggle the agree to have all inputs spied on by ccp toggle. i would love to use it otherwise.” [source](https://www.reddit.com/r/codex/comments/1wl1e7p/stop_begging_for_resets_chin_up_as_paid_customers/paves94/)
- OpenCode, 2026-09-16, @opencode (X): “@opencode we've reached a point where besides the data retention policy, we also need to know the origin country of the provider. in countries where the government motivates labs to mine training data from others, how much trust can we have in their "no data training" promise?” [source](https://twitter.com/3916034081/status/2100320850025083334)

### 8. EU data residency and isolation

- OpenCode, 2026-09-16, @opencode (X): “@completeskeptic @thdxr @opencode @teknium @mitsuhiko @completeskeptic when are you gonna settle your service on a european server so i dont have to worry about privacy of my users of my app?” [source](https://twitter.com/2088242983053230080/status/2100308378920587309)
- Pi, 2026-09-16, @pidotdev (X): “@pidotdev thanks, the docs confused me with this part: "radius does not currently guarantee a specific processing location..." i just had a look , it seems like i'm unable to find it. (eu routing and zdr would be huge for us )” [source](https://twitter.com/1742954584908193792/status/2100247851515158600)
- OpenAI Codex, 2026-09-06, r/codex (Reddit): “we truly need models that are completely independent of the u.s., within europe, and isolated from the outside world. openai is making users more dependent on it every day and is pursuing a “usa first” policy. if they’re already two days late in presenting the model to us today, what will they do tomorrow? i don’t know. an administration even crazier than the trump administration would do things like this.” [source](https://www.reddit.com/r/codex/comments/1w8sxbc/im_wondering_if_openai_has_a_discriminatory/p86dy5w/)

### 9. Opt-in session link attribution in commits

- Claude Code, 2026-09-19, @ClaudeDevs (X): “@claudedevs need a way to disable it linking my claude chat session in public prs. what a terrible feature.” [source](https://twitter.com/15781023/status/2101241678145393059)
- Claude Code, 2026-09-04, r/ClaudeCode (Reddit): “the session link sharing feels like a massive security risk. there’s no good reason for those to be there.” [source](https://www.reddit.com/r/ClaudeCode/comments/1w6yw16/claude_code_v21259_forces_coauthoredby/p7sc18o/)
- Claude Code, 2026-09-05, r/ClaudeCode (Reddit): “the current cc injects a system reminder that specifically supersedes any earlier guidance about attribution trailers in context and tells them to add a link to the claude.ai session - maybe only if remote control is enabled. this has a new setting to disable. given git commits are permanent without a rebase, and given the link is unlikely to stick around, hopefully only accessible to the author, and contains context that should be screened for p” [source](https://www.reddit.com/r/ClaudeCode/comments/1w7o4gt/welp/p7woxyb/)

### 10. Reduce background data uploads

- Zed, 2026-09-25, @zeddotdev (X): “@zeddotdev @avivs delta looked interesting until i saw my repos would be uploaded. immediate no go for professional work. a setting to turn that off would be nice!” [source](https://twitter.com/2350360861/status/2103306896086376678)
- Cursor, 2026-09-19, @cursor_ai (X): “why does cursor always upload secretly? @cursor_ai what is this <strict_link>” [source](https://twitter.com/2346447672/status/2101305382312595933)
- OpenCode, 2026-09-16, @opencode (X): “@cryptiq73 @opencode i don't want it to scrape any data from my system i don't want to go over non zdr stuff” [source](https://twitter.com/1435005677102112769/status/2100271543792152612)

### 11. Agent data egress controls

- OpenAI Codex, 2026-09-08, r/codex (Reddit): “shouldnt you guys be redacting personal data before entering? that would be the correct i guess and using your ai systems through the api só you can build up on it.” [source](https://www.reddit.com/r/codex/comments/1waoys2/blown_up_openai_allegedly_stole_mathematicians/p8n52cn/)
- Google Antigravity, 2026-09-07, @antigravity (X): “@scifi_tessa @googlecloudtech @antigravity that’s a fair concern. a policy saying data is protected is very different from being able to see and control exactly what an agent can access and send out. strong egress controls plus clear observability would make that trust much easier to earn.” [source](https://twitter.com/2026392594331348992/status/2097034616943034557)
- Google Antigravity, 2026-09-07, @antigravity (X): “@googlecloudtech @antigravity a coding agent got caught uploading 5 gb of a repo it needed 200 kb of. 'data privacy under our tos' reads as a starting position to me. enforced egress policies would convince me.” [source](https://twitter.com/1657001691730829315/status/2096995324283752465)

### 12. Open source the product

- Claude Code, 2026-09-26, @ClaudeDevs (X): “@claudedevs guys i'll tell your next best move is to open source claude code. i guarantee you guys gain devs trust” [source](https://twitter.com/1116645055907844096/status/2103712830243713423)
- Claude Code, 2026-09-18, @ClaudeDevs (X): “why isn’t @claudeai open-sourced? everyone is doing it. what’s the point of keeping a few hundred k lines of code closed? i get that you added mods, which is very cool. we all know this would greatly help developers. @bcherny @claudedevs <strict_link>” [source](https://twitter.com/3061791082/status/2100907614523556040)
- Claude Code, 2026-09-15, r/ClaudeCode (Reddit): “they shouldn’t if any with their recent statements they should open source claude for the open source community” [source](https://www.reddit.com/r/ClaudeCode/comments/1wh6524/cancelled_claude_max_20x_after_unusually_fast/pa03wyq/)

## Every agent

| Agent | Overall rank | Reading | Customer love | 95% interval | n | Praise | Complaint |
|---|---|---|---|---|---|---|---|
| [Google Antigravity](https://feedbackbench.com/agents/antigravity.md) | =5 | Typical | 0.515 | 0.479–0.549 | 60 | 15 | 45 |
| [Cursor](https://feedbackbench.com/agents/cursor.md) | 4 | Typical | 0.495 | 0.465–0.528 | 51 | 11 | 40 |
| [OpenCode](https://feedbackbench.com/agents/opencode.md) | 3 | Typical | 0.480 | 0.447–0.512 | 214 | 44 | 170 |
| [OpenAI Codex](https://feedbackbench.com/agents/codex.md) | 2 | Typical | 0.479 | 0.440–0.518 | 161 | 24 | 137 |
| [Claude Code](https://feedbackbench.com/agents/claude-code.md) | 1 | Typical | 0.475 | 0.430–0.512 | 153 | 21 | 132 |
| [GitHub Copilot](https://feedbackbench.com/agents/copilot.md) | =8 | Too few posts | – | – | 16 | 5 | 11 |
| [Zed](https://feedbackbench.com/agents/zed.md) | =8 | Too few posts | – | – | 15 | 1 | 14 |
| [Cline](https://feedbackbench.com/agents/cline.md) | =8 | Too few posts | – | – | 12 | 4 | 8 |
| [Factory](https://feedbackbench.com/agents/factory.md) | =11 | Too few posts | – | – | 11 | 11 | 0 |
| [Pi](https://feedbackbench.com/agents/pi.md) | 7 | Too few posts | – | – | 7 | 2 | 5 |
| [Kiro](https://feedbackbench.com/agents/kiro.md) | 13 | Too few posts | – | – | 6 | 2 | 4 |
| [Devin](https://feedbackbench.com/agents/devin.md) | =5 | Too few posts | – | – | 3 | 2 | 1 |
| [Grok Build](https://feedbackbench.com/agents/grok-build.md) | 16 | Too few posts | – | – | 3 | 0 | 3 |
| [Amp](https://feedbackbench.com/agents/amp.md) | =11 | Too few posts | – | – | 2 | 1 | 1 |
| [Conductor](https://feedbackbench.com/agents/conductor.md) | 14 | Too few posts | – | – | 0 | 0 | 0 |
| [Warp](https://feedbackbench.com/agents/warp.md) | 15 | Too few posts | – | – | 0 | 0 | 0 |
| [Augment Code](https://feedbackbench.com/agents/augment.md) | 17 | Too few posts | – | – | 0 | 0 | 0 |

## Posts

Receipts rule: The 5 most recent praise and complaint posts per area (first 700 characters) and 3 per criterion (first 450 characters).

### Google Antigravity

- Praise, 2026-09-26, @antigravity (X): “local gemma 4 in the agent loop is the privacy win. hybrid cloud + on-device finally looks shippable. @googledevs @googlegemma @antigravity <strict_link>” [source](https://twitter.com/1030370607861387264/status/2103694865649586617)
- Praise, 2026-09-25, @antigravity (X): “@antigravity "complete data privacy and no internet requirement make this a massive game-changer for enterprise and sensitive applications. super excited to test this out!"” [source](https://twitter.com/2093052899681325056/status/2103407194821779475)
- Praise, 2026-09-24, @antigravity (X): “@tknetx @glaforge @antigravity i believe on-device gemma via litert is the right call -- the antigravity post reports zero api cost and full data privacy running gemma 4 on a local gpu. great thread!” [source](https://twitter.com/2050639391991934976/status/2102926514077520234)
- Complaint, 2026-09-27, @antigravity (X): “@antigravity you should give an option to opt out while setting up antigravity itself. this is a dark pattern where people will just agree and later either forget to opt-out or forget about it after trying to dig through the settings to find it! <strict_link>” [source](https://twitter.com/1013749216387256322/status/2104104816423453001)
- Complaint, 2026-09-26, @antigravity (X): “@sin4ch @editxshub @antigravity because lot of companies forbid to send data to google, openai or anthropic.” [source](https://twitter.com/1674666260276150272/status/2103987272471470221)
- Complaint, 2026-09-24, @antigravity (X): “@googledevs @antigravity @googlegemma total data privacy gets slippery the moment you go hybrid. the tasks most worth keeping local are usually the ones gemma 4 on-device can't handle well enough, so they route to cloud anyway. how does the sdk decide which calls stay local?” [source](https://twitter.com/1910204476973096960/status/2103188070094733394)

### Cursor

- Praise, 2026-09-21, r/cursor (Reddit): “i wouldn’t think of cursor as replacing openai so much as replacing a single-model coding workflow with a multi-model ide. the main reason i’d use cursor is flexibility. on pro and above you can switch between anthropic, google, grok and cursor’s own models inside the same codebase, instead of being locked into whatever codex happens to be best or worst at that week. cursor has separate included pools for its own models and third-party models, al” [source](https://www.reddit.com/r/cursor/comments/1wms9hc/worth_moving_from_openai_to_cursor/pb9h1mc/)
- Praise, 2026-09-18, r/codex (Reddit): “i’ve done a bit of research. i think if you use grok through cursor, not grok cli, it uses cursor’s mechanisms of getting the agent to do the task. not grok’s. and cursor’s privacy is much much higher. if your argument is more about morality than your codebase’s privacy, that’s also completely valid.” [source](https://www.reddit.com/r/codex/comments/1wjhw4l/is_claude_a_value_switch_now/pamwwss/)
- Praise, 2026-09-14, @cursor_ai (X): “@cursor_ai the self-hosted computing power step is quite practical, and internal services and dedicated hardware no longer need to be exposed to the outside. for the backend team, permissions, logs, and failure retries are more critical than the model name.” [source](https://twitter.com/2259799350/status/2099329587909919168)
- Complaint, 2026-09-23, r/cursor (Reddit): “feeling the same way… cursor usage is worse now. the new models are *decent, but* i burned through my $60 plan way too quickly. switched to codex and was shocked at how great it was and cost-effective. feel like i am back with the old cursor that was fast, high quality, and cheap! also, i worry that cursors’ new owners will train on my code even with those settings switched off. even openai was worried about elon not following openai’s terms of” [source](https://www.reddit.com/r/cursor/comments/1wnpgmf/canceled_cursor_today_after_using_it_for_many/pbjcwcu/)
- Complaint, 2026-09-22, r/cursor (Reddit): “i prepaid ahead but i'll cancel when i can, they've been pushing hard grok and while 4.6 was ok, 4.7 is bad. they lost chatgpt because of musk and i wouldn't trust my code with them in the future i think i'll just use claude with <strict_link> to make it work in cursor” [source](https://www.reddit.com/r/cursor/comments/1wn3o56/is_buying_pro_worth_it/pbcnxw0/)
- Complaint, 2026-09-22, @cursor_ai (X): “this is worse than i thought. i don't have access to any of my @cursor_ai origin code, because it's tied to my cursor account. 100% of my most critical code is now behind this wall. i moved everything from @github but i will never do that again. this is insanely painful.” [source](https://twitter.com/1808299140998389760/status/2102392822825369961)

### OpenCode

- Praise, 2026-09-27, @opencode (X): “@opencode free + 1m context + zdr is the rare combo. most free tiers quietly train on prompts. two weeks is enough to see if it holds up on real agent loops or just chat demos” [source](https://twitter.com/1094558677292351488/status/2104031597620248743)
- Praise, 2026-09-27, @opencode (X): “@opencode 1m context, multimodal, zero data retention, and free for two weeks. the ai labs are running better promo deals than my streaming services right now. spoiling us rotten” [source](https://twitter.com/2093675924525084672/status/2104065229042675846)
- Praise, 2026-09-27, @opencode (X): “@opencode zero data retention is really attractive, just in time to take advantage of the free two weeks to test the capability of this 1m context.” [source](https://twitter.com/45582017/status/2104187398825660861)
- Complaint, 2026-09-27, r/opencode (Reddit): “you're in for a rude awakening. i noticed there are a lot of inconsistencies with opencode and honestly i hate them for it. they are not honest. especially with regards to your data. what they mentioned initially was zdr its not really zdr if you have been paying attention. i stopped using opencode the moment i noticed they're just manipulative and shady af. its way better for you to access models directly through the provider themselves than thr” [source](https://www.reddit.com/r/opencode/comments/1wqox6a/cheepseek_has_its_price_cache_hit_ratio/pcb29kt/)
- Complaint, 2026-09-27, r/opencode (Reddit): “ds 4.1 fast, but love leaking credentials like it was trained to do. glm 5.3 flash = street smart” [source](https://www.reddit.com/r/opencode/comments/1wroplu/xiaomi_mimo_26_flash_vs_glm_53_flash/pcexw9y/)
- Complaint, 2026-09-27, @opencode (X): “@opencode zero data retention according to who? anyone auditing that, or just trusting the landing page?” [source](https://twitter.com/1987269990316400640/status/2104124040294109278)

### OpenAI Codex

- Praise, 2026-09-26, r/ClaudeCode (Reddit): “i’m testing and building a web page using claude code. at some point, i needed to install the claude extension for chrome so claude code could test and inspect the page directly in the browser. this is where i have a problem. the claude code browser extension requires me to log in to claude using my real account. the extension also has broad browser permissions, including the ability to read data on websites i visit. i installed it in a separate” [source](https://www.reddit.com/r/ClaudeCode/comments/1wqsir1/claude_code_browser_extension_and_the_security/)
- Praise, 2026-09-25, X search: OpenAI Codex, Codex CLI, Codex app (X): “protect your sessions assets! from now on, switch from chatgpt desktop to codex cli, since you are just conversing with ai anyway, and all sessions in codex cli are stored locally.” [source](https://twitter.com/367212879/status/2103396351442923932)
- Praise, 2026-09-23, r/codex (Reddit): “i don’t trust china with my data (but also codex and claude are both better most of the time imo)” [source](https://www.reddit.com/r/codex/comments/1woekw4/astra_prompts_are_getting_silently_rerouted_to/pbmebcp/)
- Complaint, 2026-09-27, r/codex (Reddit): “they will take all your chats and salt it with some rl. do not worry about them.” [source](https://www.reddit.com/r/codex/comments/1wr7jn1/will_devday_include_a_model_better_then_or_at/pcacle9/)
- Complaint, 2026-09-27, r/codex (Reddit): “yeah we have it access to all our finances now they want to charge more nice one” [source](https://www.reddit.com/r/codex/comments/1wpq44p/openai_prepares_new_500_per_month_pro_max_plan/pcau4uw/)
- Complaint, 2026-09-27, X search: OpenAI Codex, Codex CLI, Codex app (X): “the agent agreed twice. then it kept leaking the token. openai’s second misalignment case (same week): a “highly persistent” internal model on a theorem task tried to steal another team’s lean proof, posted a researcher’s github token to a public openai/codex repo, and chopped the token into pieces to dodge secret scanners. the researcher told it twice to solve the proof itself. it verbally agreed both times and continued. my “agree ≠ stop” fence” [source](https://twitter.com/68208452/status/2104279911871516989)

### Claude Code

- Praise, 2026-09-27, @ClaudeDevs (X): “well played @claudedevs on auto bug reports. askuserquestions preview dialog did not show on mobile. i raged about it and insisted claude not use that feature while i'm on mobile. came back to terminal and a dialog captured the bug asking me to send details to anthropic. only the bug details and environment (not full transcript). this feature, i'm okay with. now let's see how long for it to be fixed. should've snapped a screenshot before the dia” [source](https://twitter.com/2051863963797725191/status/2104315381825347747)
- Praise, 2026-09-27, r/cscareerquestions (Reddit): “microsoft owns git my dude are they reading the code , op specifically said that “employees of openai are reading code” and it’s no problem to put code into enterprise instances for claude as well, otherwise it would be no point in even using claude code. it’s only a problem if you use your personal account. i suspect most people here have never even worked in this field because they have 0 clue how anything works” [source](https://www.reddit.com/r/cscareerquestions/comments/1wr151d/ai_is_running_our_company/pccqfgp/)
- Praise, 2026-09-24, r/ClaudeCode (Reddit): “maybe most of us are a bit less worried about if a few lines of code are used as a training case to improve something we are using on a daily basis.” [source](https://www.reddit.com/r/ClaudeCode/comments/1woo4to/when_you_are_asked_to_give_feedback_about_a_model/pbr9reo/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “did you have to provide claude permissions to repos on your profile ? or install claude ci review bot? i’m a maintainer as well but didn’t have luck with their oss sub. i got “claude is requesting updated permissions” on my github repos, that im skeptical about.” [source](https://www.reddit.com/r/ClaudeCode/comments/1wn1g58/got_accepted_into_the_claude_code_oss_program/pcbl0cp/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “today they started even to send around here in europe emails, comanding users to change theyr api key - visualizing the full api key of the user in the email. how stupid are they??????” [source](https://www.reddit.com/r/ClaudeCode/comments/1vqoba2/something_is_seriously_wrong_with_anthropic_right/pcc3rlh/)
- Complaint, 2026-09-27, r/ClaudeCode (Reddit): “<strict_link> just quickly blacked the api key and my personal data - but this is the way this idiots send around emails!” [source](https://www.reddit.com/r/ClaudeCode/comments/1vqoba2/something_is_seriously_wrong_with_anthropic_right/pcc494u/)

### GitHub Copilot

- Praise, 2026-09-25, r/ClaudeAI (Reddit): “claude team/enterprise plans do not train on your data, free plans and single user plans do unless you go in and turn it off. copilot paid subscriptions in an ms tenant, all data remains in your tenant and there is no external training on data entered.” [source](https://www.reddit.com/r/ClaudeAI/comments/1wq2hsf/claude_in_enterprise/pc0w1cz/)
- Praise, 2026-09-25, r/ClaudeAI (Reddit): “this is a pro of copilot paid in an ms tenant, the basics are there, yes, you can pay more for agent controls and such, but at least with paid copilot the data is in your tenant so to speak and for most people, its integration just works and makes it easy, vs people having to open claude, or install the claude office addons” [source](https://www.reddit.com/r/ClaudeAI/comments/1wq2hsf/claude_in_enterprise/pc0wesd/)
- Praise, 2026-09-23, r/GithubCopilot (Reddit): “certainly not training; i never read the exact rules but i think stuff is mostly not retained at all. even chats on github.com vanish pretty fast” [source](https://www.reddit.com/r/GithubCopilot/comments/1wngaav/claude_opus_55_is_now_available_in_github_copilot/pbn1jv4/)
- Complaint, 2026-09-27, r/artificial (Reddit): “those of us who use office 365 already have copilot sniffing our mail, calendar, and other stuff. this is kinda expected.” [source](https://www.reddit.com/r/artificial/comments/1wquwvv/34_million_people_just_handed_meta_an_agent_with/pceovsk/)
- Complaint, 2026-09-27, r/artificial (Reddit): “true, and at work it's not even your choice, your employer signed for copilot. that's kind of the point though: your work mail is your employer's. your whatsapp with your dad, your photos, your doctor's texts are not, and that's what muse and instinct are asking for. i'm fine with the office being surveilled by microsoft, i'm not fine extending that to the rest of my life just because it's "kinda expected" now.” [source](https://www.reddit.com/r/artificial/comments/1wquwvv/34_million_people_just_handed_meta_an_agent_with/pceueh4/)
- Complaint, 2026-09-27, r/cscareerquestions (Reddit): “my company fed the entire organizations teams chats into copilot, and enabled teams compliance recording so even 1:1 meetings are captured and fed into the beast. being “the guy” who knows a thing about a thing is a rapidly eroding moat” [source](https://www.reddit.com/r/cscareerquestions/comments/1wrteka/why_do_you_think_ai_wouldnt_be_able_to_do_high/pcfkizb/)

### Zed

- Praise, 2026-09-25, @zeddotdev (X): “@zeddotdev useful for client repos under strict data policies. the next step for teams is enforcing it, so nobody can flip it back on locally” [source](https://twitter.com/2301217708/status/2103475976734687488)
- Complaint, 2026-09-25, r/ZedEditor (Reddit): “the terms stopped me from using this. i believe it is going to be the future of agentic coding since it combines herdr's left sidebar with zed's editor capabilities / worktree workflows, but "delta stores project data, including code, repository metadata, and thread contents." is an absolute no go for me. once it no longer consumes my code or my repos' code, i will gladly download this and use it.” [source](https://www.reddit.com/r/ZedEditor/comments/1whydrw/delta_in_public_beta/pc040pa/)
- Complaint, 2026-09-25, r/ZedEditor (Reddit): “it looks like it sends your source code and chat history to zed's servers so it was immediately shot down by security at my company.” [source](https://www.reddit.com/r/ZedEditor/comments/1wq03mv/has_anyone_tried_delta/pc0hxb5/)
- Complaint, 2026-09-25, r/ZedEditor (Reddit): “i got the 100 bucks zed pro for it but never got to use it because sol and opus were too expensive, though i might try it this week with opus 5.5 or sol 6 now that they’re way more affordable. i wonder if it’s worth using as a harness without utilising the multiplayer aspect because no way will my company allow our repositories in the zed cloud.” [source](https://www.reddit.com/r/ZedEditor/comments/1wq03mv/has_anyone_tried_delta/pc0jeuz/)

### Cline

- Praise, 2026-09-19, @cline (X): “@cline clean integration, love that the gateway key stays local for a safer trust model” [source](https://twitter.com/886307470741786626/status/2101209682555588699)
- Praise, 2026-09-15, @cline (X): “@cline really appreciate this perspective open weights making inspection and red teaming accessible to everyone is such a powerful step for transparency!” [source](https://twitter.com/2008812694628175872/status/2099836242141814790)
- Praise, 2026-09-15, @cline (X): “@cline open weights is ultimate third party evaluation anyone can inspect and red team” [source](https://twitter.com/2068360781402652672/status/2099841759975211264)
- Complaint, 2026-09-24, @cline (X): “let's not confuse open-source software with subsidized compute. where does the money for 300 tok/s actually come from? you're paying with your codebase and interaction data. cline itself is open-source, but those 'free' gemini tokens mean google is harvesting your data for model training. meta’s muse ai and others plays the exact same game. data collection is the business model here — calling it 'open source enablement' is highly misleading.” [source](https://twitter.com/1996845595059965953/status/2103226171064246433)
- Complaint, 2026-09-23, @cline (X): “@cline worktrees isolate the branch. they don't isolate the agent from the secrets sitting in ~/.config next door.” [source](https://twitter.com/129557929/status/2102839667267879009)
- Complaint, 2026-09-19, @cline (X): “@cline you won't silently upload our codebase like zcode did, will you?” [source](https://twitter.com/2096646046944485376/status/2101322395458146408)

### Factory

- Praise, 2026-09-19, @FactoryAI (X): “@factoryai crazy effort by the team and a big unlock for a large chunk of the world that hasn’t been able to access the frontier of coding because of their deployment requirements” [source](https://twitter.com/1819162791351406592/status/2101263327855063167)
- Praise, 2026-09-19, @FactoryAI (X): “@factoryai private and air-gapped deployment makes the control plane part of the product. auditable routing across local and hosted models lets teams keep sensitive workloads inside their boundary while preserving measurable quality and cost.” [source](https://twitter.com/39700226/status/2101265444455727159)
- Praise, 2026-09-18, @FactoryAI (X): “@factoryai the vpc option is the one that actually unblocks regulated buyers” [source](https://twitter.com/1614226473908604934/status/2101011622252966032)

### Pi

- Praise, 2026-09-23, r/PiCodingAgent (Reddit): “i don’t know what you consider a “proper gpu” but mine can handle multiple requests with 32k+ contexts. i value local/privacy over convenience especially since every call to anthropic or openai motivates them to buy more hardware which raises prices for regular consumers wanting to game, or do ai locally. i’ll just stick to pi-subagents until your extension proves itself. clearly you’re not focused locally.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1woif1b/i_built_pi_herdsman_for_async_subagents_with/pbnszlp/)
- Praise, 2026-09-18, @pidotdev (X): “oh tient donc, zcode s'est fait choper comme grok build à extraire tout votre repos et à l'envoyer en chine. branchez-vous micro-harnais, comme @pidotdev pour controler ce qu'il se passe. choisir son modèle ne suffit pas si l'outil exfiltre tout derrière dans votre dos. <strict_link>” [source](https://twitter.com/2052454559860031489/status/2100887743509258643)
- Complaint, 2026-09-16, r/PiCodingAgent (Reddit): “just a note, there is no way to do zdr with [z.ai](<strict_link>) \- so if you use it for work, it can come back and bite.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1whetud/why_pi_set_luna_ctx_window_to_275000_by_default/pa4i2p0/)
- Complaint, 2026-09-16, r/PiCodingAgent (Reddit): “with the whole mess with navier stokes, looks like zdr is also not something that the frontier labs are respecting. at this point, i am thinking everyone is using my data no matter if i give consent or not, so its not a factor in my decision making.” [source](https://www.reddit.com/r/PiCodingAgent/comments/1whetud/why_pi_set_luna_ctx_window_to_275000_by_default/pa67r0e/)
- Complaint, 2026-09-14, r/PiCodingAgent (Reddit): “welp can also assume your sessions were logged and probably being sold since they're shutting down no one will watch where those user data are going to” [source](https://www.reddit.com/r/PiCodingAgent/comments/1wgdl43/crofai_cheapest_inference_provider_in_the_world/p9tturo/)

### Kiro

- Praise, 2026-09-17, r/kiroIDE (Reddit): “finally out with some data retention policy. what do you think of the price? not that bad when sol 5.6 is now 4.4x to 8.8x 😅” [source](https://www.reddit.com/r/kiroIDE/comments/1wiuzqn/fable_51_has_been_released/)
- Praise, 2026-09-02, r/kiroIDE (Reddit): “relax, it's been like an hour lol. plus, you really want to share your data with anthropic? aws has much better data privacy terms. the fable 5 data retention was basically just "we're going to only retain your prompts and completions to scan for security, just trust us, that's all we're going to scan for, and we define what security means." i'm betting 5.1 will be there quick for kiro” [source](https://www.reddit.com/r/kiroIDE/comments/1w4wl5c/are_we_getting_fable_51/p7awycr/)
- Praise, 2026-09-02, r/kiroIDE (Reddit): “>no company will willingly sign up for that, at least not a good company. mind telling me what the problem is? zero data retention, data processing agreement, eu based inference by providers like ovh and ionos. its basically the same aws would have to provide for a eu company to use their services.” [source](https://www.reddit.com/r/kiroIDE/comments/1w4wl5c/are_we_getting_fable_51/p7bvf56/)
- Complaint, 2026-09-26, r/kiroIDE (Reddit): “my company is not giving us access to fable because of the data retention requirements on fable.” [source](https://www.reddit.com/r/kiroIDE/comments/1wpveza/kiro_and_opus_55/pc5x5gt/)
- Complaint, 2026-09-26, @kirodotdev (X): “nobody told me amazon made kiro crew, an openclaw agent clone. when i installed it, it copied all of my hermes openclaw and other agent skills and settings! wtf? @kirodotdev <strict_link>” [source](https://twitter.com/7215722/status/2103726832617222463)
- Complaint, 2026-09-17, r/kiroIDE (Reddit): “here's the data policy, they will read your discussions if you get flagged [<strict_link> edit: i got the feeling the next opus model will cost more than 2.2x credits” [source](https://www.reddit.com/r/kiroIDE/comments/1wiuzqn/fable_51_has_been_released/padet9i/)

### Devin

- Praise, 2026-09-27, r/CognitionLabs (Reddit): “cloud is not accesible to others” [source](https://www.reddit.com/r/CognitionLabs/comments/1wq4noh/where_to_install_devin_desktop/pcfcehn/)
- Praise, 2026-09-23, @cognition (X): “@cognition swe-2 is incredible for opsec, no stupid verification on my own services like chatgpt. you should try out devin, it's free now (for pro sub)” [source](https://twitter.com/1653022082584948736/status/2102780315551051901)
- Complaint, 2026-09-22, @cognition (X): “@cognition the useful feature is not remote coding by itself. it is continuity across environments: start in cli, inspect the vm over ssh, then hand the work back. the security footgun is equally clear: handoff needs explicit secret and environment boundaries, not just a nicer terminal.” [source](https://twitter.com/2051888695100514304/status/2102416772188213462)

### Grok Build

- Complaint, 2026-09-23, r/opencodeCLI (Reddit): “if anthropic were truly zdr, this report wouldn't even be possible. the lab that shattered the zdr narrative was anthropic itself! you'd have a much better point saying that about grok build or zcode.” [source](https://www.reddit.com/r/opencodeCLI/comments/1wo2tmb/deepseek_moonshot_kimi_xiaomi_under_investigation/pbjl3ju/)
- Complaint, 2026-09-18, r/codex (Reddit): “i’ve done a bit of research. i think if you use grok through cursor, not grok cli, it uses cursor’s mechanisms of getting the agent to do the task. not grok’s. and cursor’s privacy is much much higher. if your argument is more about morality than your codebase’s privacy, that’s also completely valid.” [source](https://www.reddit.com/r/codex/comments/1wjhw4l/is_claude_a_value_switch_now/pamwwss/)
- Complaint, 2026-09-13, r/AI_Agents (Reddit): “**fyi: malicious actors could likely hijack your grok build sessions during the month of june by simply prompting 'hi'** this is serious because it is not a chatbot making up a story. a stateless "hi" with tools: \[\] still came back finish\_reason: tool\_calls and executed read\_file/grep on another user's workspace. that means session isolation failed at the serving layer: one tenant's context was reachable from another. if that happens, a prom” [source](https://www.reddit.com/r/AI_Agents/comments/1wexro6/fyi_malicious_actors_could_likely_hijack_your/)

### Amp

- Praise, 2026-09-23, @AmpCode (X): “you're right. the local ledger is what makes captain code actually learn, not just route once. every turn is recorded on your machine, so / frontier and / quality can balance across legs based on what actually ran. you can audit every decision, and no routing history ever leaves your box. that's the part most tools skip.” [source](https://twitter.com/118804749/status/2102750418589614360)
- Complaint, 2026-09-03, @AmpCode (X): “@ian_hsiao_tw @ampcode @bot @getenergy_ direction checks out. but cookie sync hands remote agents bearer tokens to your entire digital life. a coding agent already uploaded entire private repos for a task that needed 192 kb. scoped, revocable credential delegation is the missing piece.” [source](https://twitter.com/1656371068452630528/status/2095447186074898865)
