What goes where.

A development data overview, with the final policy still to come.

Preview documentation for the upcoming Shard plugin. This describes the current build; setup and availability may change before release.

On your device.

Studio plugin settings hold saved chats, preferences, API keys and sign-in session data. This is local storage, not a promise of encrypted storage or local-only processing.

In a model request.

Shard sends relevant conversation and tool content through its services to the chosen AI provider. That can include script source, object details and Output logs. API-key connections send the provider key with the request.

Service records.

The current backend includes account authentication, usage records and diagnostic metadata. Redaction mechanisms reduce some sensitive error content; final retention and processor details still need confirmation.

Execution inside Studio.

RunCode is powerful edit-time code execution. It runs at plugin identity and its isolation is not a complete security boundary. Treat model-generated code and resulting changes as work to review.

Read the privacy policy draft. A finalized policy will be published before launch.