Storage and privacy
What Palisade stores, where it stores it, and which network connections it makes.
Palisade is local first. Where Palisade owns the computation, it stays on your Mac. Where you choose an external service, Palisade makes that boundary visible.
What lives where
| Location | What is in it |
|---|---|
~/.palisade-code | Session logs, completion telemetry, and settings. |
| Palisade-managed user storage | Database connection records. Kept outside your repositories. |
.palisade/project-settings.json | Project settings, in the repository. |
.palisade/chains/ | Saved playbooks, in the repository. |
.mcp.json | Project MCP server configuration, in the repository. |
Session history is append-only. Palisade never edits a past message.
Network connections
Palisade connects to the network for these reasons:
- Fetching the ACP registry.
- Checking for and downloading updates.
- Installing the local completion model.
- Talking to your git remotes.
- Searching the MCP registry.
- Running an agent or MCP server you selected.
What stays local
Fill-in-the-middle completion, thread-title suggestions, and commit-subject suggestions run on a bundled local model. Palisade does not upload your code or a repository index for these features.
Accounts and billing
Palisade uses your installed agents and your existing accounts or subscriptions. It does not bundle a hosted agent or bill you for provider usage.
Secrets
Database passwords use the macOS credential store when it is available. If Palisade falls back to a user-only local file, it tells you. Secrets do not enter logs.
File access
File operations are scoped to the selected project root.
Website analytics
This website uses Vercel Web Analytics to measure page views and clicks on downloads, installation guides, and Palisade’s GitHub links. Custom events contain the page path, link destination category, and placement on the page. They do not contain code, clipboard contents, provider credentials, or URL query parameters. A download click records intent to download; it does not confirm an installation in the app.