# OneAgent for VS Code privacy policy

Effective date: 2026-08-11

OneAgent for VS Code runs an agent on the user's computer through a local
OneAgent Host and a tenant-bound OneAgent Gateway.

## Data processed to provide a turn

When a user submits a request, the prompt and any explicitly attached context
may be sent through the tenant-bound OneAgent Gateway to the tenant's configured
model provider. Files and command output are read locally by the agent when
needed for the requested work. OneAgent does not add prompt text, file contents,
image contents, or command output to its audit or reliability telemetry.

The configured model provider processes request content to generate the agent
response. Provider terms and retention controls associated with the tenant's
provider credential also apply.

## Data stored locally

Threads, the Agent Home, caches, tenant profile artifacts, and change snapshots
remain on the user's device. OAuth refresh credentials and device secrets are
stored with VS Code SecretStorage. Passwords and provider API keys are not
stored by the extension.

Uninstalling the extension preserves local Agent Home data by default so an
accidental uninstall does not destroy work. The user can run the OneAgent purge
command to remove the selected tenant's local profile after reviewing the
confirmation prompt.

## Service metadata

OneAgent retains content-free audit metadata for up to 90 days. This may include
tenant, user, device, model, request identifier, timestamps, status, latency,
and usage counters. It does not include prompts, file contents, command output,
or response text.

Reliability telemetry is off by default during the pre-release. If enabled in
a later release, it will be consented, content-free, documented here, and
separable from tenant business data.

## Tenant isolation

Tenant membership, provider policy, quota, and audit metadata are isolated by
the authenticated tenant identity. Local Agent Homes use opaque tenant/user
profile keys and are not shared between memberships.

## Contact

Privacy questions may be sent to `charles@one-agent.ai`.
