Privacy

Naoru Privacy Notice

Version: 1.1 Last Updated: August 14, 2026 Effective Date: August 14, 2026

1. Scope

This notice covers the Naoru local CLI research preview, Naoru documentation, and naoru.dev. It covers nothing else: Naoru is a standalone product, and no other Unpossible Creations product's policy applies to it.

2. Data Controller

Unpossible Creations, Inc. is the data controller for information it receives directly.

For privacy inquiries, contact: [email protected].

3. What We Collect

Data Collection Summary

Data typeWhat it includesHeld by Unpossible CreationsSent to LLM providersRetention
Naoru account dataNone. Naoru creates no account and operates no Naoru SaaS serviceNoNoNot applicable
Product telemetry and usage analyticsNone. Naoru does not intentionally send telemetry, source code, prompts, repository contents, provider configuration, or runtime logs to usNoNoNot applicable
License-acceptance receiptLicense version, license hash, accepted text, acceptance timestamp, Naoru version, and an explicit indicator that server logging is disabledNo — written to your machine onlyNoUntil you delete it
Your code, prompts, file paths, command output, logs, repository contextWhatever your run puts in front of the modelNoYes — to the provider you configure, under its own termsSet by that provider, not by us
Local run artifactsWorktrees, patches, logs, cache, configurationNo — local onlyNoUntil you delete them
naoru.dev request dataNetwork address, user agent, request metadataNo — processed by Cloudflare at its edge under its own termsNoSet by Cloudflare
Package download metadataWhatever the package index records for a downloadNoNoSet by that index

3.1 No account, no product telemetry

Naoru itself does not create a Naoru account, operate a Naoru SaaS service, or intentionally send product telemetry, usage analytics, source code, prompts, repository contents, provider configuration, or runtime logs to Unpossible Creations, Inc.

3.2 The local license-acceptance receipt

Naoru may store a local license-acceptance receipt on your machine. The receipt is used locally to avoid repeated acceptance prompts until the license changes. It may include the license version, license hash, accepted text, acceptance timestamp, Naoru version, and an explicit indicator that server logging is disabled. Naoru does not send this receipt to Unpossible Creations.

3.3 Data you direct to third-party LLM providers

When you configure a host or LLM provider, your code, prompts, file paths, command output, logs, repository context, and other local data may be sent from your machine to third-party LLM providers or provider CLIs under their own terms and privacy policies. Unpossible Creations does not control provider data handling, retention, training use, account actions, quotas, or charges.

3.4 Local automated processing

Naoru performs local automated processing to run checks, invoke configured providers, evaluate results, accept or reject candidates, store patches, and create local commits. These local automated decisions are not reviewed by Unpossible Creations.

3.5 No monitoring or filtering of content

Unpossible Creations does not monitor, review, scan, filter, or redact your local CLI prompts, repository contents, generated output, provider traffic, or local artifacts. You are responsible for excluding secrets, personal data, regulated data, and proprietary or employer/client content.

3.6 Regulated and sensitive data warning

Do not use Naoru with personal data, regulated data, secrets, credentials, employer or client code, proprietary organization code, production systems, or sensitive repositories.

3.7 Local artifacts

Naoru and its host may create local files such as worktrees, patches, logs, cache, configuration, and the local license-acceptance receipt under local runtime or state directories. You are responsible for reviewing and deleting local artifacts.

4. Third Parties

4.1 Service providers we engage

Any package index, mirror, or network infrastructure between you and those services may process routine technical data in the same way. This notice does not change third-party terms.

We run no analytics, advertising, or session-recording script on naoru.dev, and we keep no server-side record of your visit beyond what Cloudflare processes at its edge.

4.2 Recipients you direct us to

Third-party LLM providers are recipients you point Naoru at. They are not our service providers: the account, credentials, or subscription is yours, the agreement with the provider is yours, and your configuration determines which provider receives what. Their retention is independent of ours and outside our control, and data already sent to a provider must be addressed with that provider directly.

5. Retention

We hold no Naoru account record, so there is normally nothing of yours for us to retain. The local receipt and local artifacts live on your machine for as long as you keep them. Retention of request and download metadata is set by Cloudflare and the package index, not by us.

6. Your Rights

Because Naoru creates no account and sends us no product data, there is normally nothing for us to export, correct, or delete. If we hold correspondence from you, you may request a copy, a correction, or its deletion at the address in Section 8; we respond within 30 days, or such shorter period as applicable law requires.

Two limits worth stating plainly: the local receipt and local artifacts are on your machine and only you can delete them, and data you sent to an LLM provider must be addressed to that provider under its own policy.

7. Changes to This Notice

The version and dates at the top of this page track changes. Version 1.1 restructured the notice into numbered sections, named the site host and package index individually, and added retention and rights sections. What Naoru collects did not change; the substance of version 1.0 is carried forward intact.

8. Contact

Privacy questions: [email protected].