A clear data path.
What the connection stores
Open Machine Cloud stores your GitHub numeric identity and login, device public keys and names, pairing and authorization records, short-lived browser sessions, and connection routing state. Device private keys stay on the device. GitHub sign-in access tokens are used to verify identity and are not retained.
What passes through Cloud
Authorized tool requests and their results travel through Cloudflare to your device and back to your AI client. TLS ends at the gateway, so Cloud can process that content in transit. This is not end-to-end encryption. Your AI provider also receives results.
Content and diagnostics
The service does not persist workspace file contents or full tool payloads in its identity database, and application logs do not record those payloads. Operational providers may process connection metadata. The scheduled cleanup removes incomplete pairing attempts and unused or connection-purpose proofs after they have been expired for one additional day. Completed pairing receipts and proofs used for device revocation are retained with device and authorization records so the original device can recover a lost enrollment or revocation response. Revoking access preserves these records. This preview does not provide account or device-record deletion.
Your controls
You can revoke a device, remove an AI client connection, or sign out of this browser. These are separate actions. Local permissions and any already admitted Core work remain governed on your device.
This page describes the current preview implementation. Public distribution requires the operator’s final privacy and retention review.