nextv1.4.0
Project

Data and privacy

What leaves your machine, where it goes, how to turn it off, and where Kraft keeps secrets and state.

Kraft has no telemetry. It sends no usage data, crash reports or analytics anywhere. The outbound calls it makes are listed below, and each one serves a feature you can see.

Model providers

Kraft never calls a model API itself. It runs the agent CLI you installed, such as Claude Code, and that CLI sends your code, prompts and tool output to its provider under your account and that provider's terms. What the provider keeps and for how long is set by your account with it, not by Kraft.

Under a sandbox with a network: policy, the agent's traffic leaves through Kraft's own egress proxy, and only to the hosts the policy and the harness allow.

Outbound calls

CallGoes toWhenTurn it off
Agent CLIIts provider, such as api.anthropic.comEvery agent taskNot applicable: this is the work.
Update checkapi.github.com, this project's releases listkraft admin start and kraft admin doctor, at most once a day (cached in run/update-check.json)KRAFT_NO_UPDATE_CHECK=1
kraft admin updateThe release's wheel on GitHub, then uv tool install (PyPI for dependencies) or brew upgradeOnly when you run itDon't run it.
Forge CLI (gh, glab)Your forgeMerge-request nodes: open, read checks and reviews, mark ready, mergeA chain without merge-request nodes makes none.
git fetch, git pushYour repo's originFetching the base branch, and pushing the item's branchNot applicable.
NotificationsThe webhook URL in notify.yamlThe events you chose, only while notifications are onOff by default.
Embedding modelHugging Face, Qdrant/bge-small-en-v1.5-onnx-Q, about 130 MBThe first vector index or search, only with the vector extra installedDon't install the vector extra.

The forge CLI and git calls use your own logins for those tools. The embedding model is cached in ~/.cache/kraft/fastembed, or in $KRAFT_EMBED_CACHE if you set it.

Secrets and state

Everything lives under $KRAFT_HOME (default ~/.kraft). Kraft writes its config files through a temporary file created with mode 0600, so a file Kraft has written is readable only by you. A file you created or edited by hand keeps its own mode.

WhatWhereMode
Settings password (scrypt hash) and bindtemplates/access.yaml0600 once Kraft writes it
Bearer token for the CLI and MCPrun/mcp-token0600; kraft admin doctor checks it
Bearer token for POST /api/triggers onlyrun/trigger-token0600; kraft admin doctor checks it
Notification webhook URLtemplates/notify.yaml0600 once Kraft writes it
Repo env: valuestemplates/repos.yaml0600 once Kraft writes it (kraft repo connect or a Settings save)
Everything belowrun/0700; Kraft sets it on every start
Login sessions (token hashes), work items, eventsrun/orchestrator.db0600 when Kraft creates it
Search index of specs, plans and other documentsrun/index.db0600 when Kraft creates it
Agent logsrun/logs/0600 for a session log; server.log has your default file mode
Agent resultsrun/results/Your default file mode
Attachment copies and worktreesrun/attachments/, run/worktrees/Your default file mode

Agent logs hold whole sessions: prompts, the code the agent read and wrote, and command output. Because run/ is 0700, other users on the machine cannot reach anything inside it, whatever mode a file has. A database created by an older Kraft keeps its mode. Treat run/ like the repositories it works on.

A repo's env: values go into each worker's process environment, not onto its command line. Your own user and root can read them there, for example with ps eww on macOS or from /proc/<pid>/environ on Linux. Every agent running for that repo can read them too.

Copyright © 2026