Skip to main content

Safety & privacy

Phonton runs on your machine. Your repo, config, memory, and task history stay local unless you explicitly enable cloud features (Desktop Pro sync).

What stays local

  • ~/.phonton/config.toml and API keys
  • SQLite store (tasks, memory, receipts)
  • Code index (default: local HNSW)
  • Generated diffs until you commit them

Approvals

  • Workspace trust — Phonton asks before acting in a new repo
  • Permissions — modes from read-only to full-access; default ask
  • MCP tools — declared in local manifests; calls need approval
  • Budget — optional token and USD caps stop runaway spend

Verification before merge

Phonton runs checks (tests, linters, project scripts) and shows pass/fail in the Receipt. Treat failed verification as a blocker unless you understand the gaps.

Benchmark claims

Public efficiency comparisons require pinned fixtures and token_claim_eligible artifacts — see Benchmarks. Phonton does not headline global “X% cheaper than tool Y” without that evidence.

Report issues safely

When filing a bug, include phonton doctor output and a redacted receipt — never paste API keys or full .phonton/config.toml.