Privacy and control
Understand local reading, remote model requests, editing permissions, and the terminal.
Different parts of Yenpo have different boundaries. Knowing which part is acting helps you decide what to open, what to send, and what to authorize.
Local reading and AI requests
File browsing, reading, and navigation are local workspace activities. AI conversations send selected context to the configured model service. That context can include your messages and relevant code gathered during the run.
Review the model configuration and your provider’s data handling terms before using restricted code. The fact that the workspace is on your Mac does not mean an AI request stays on your Mac.
Reading is the default
The built-in agent reads by default. In a normal run, you can explicitly enable controlled text editing for that run. The permission is not automatically inherited by later runs or child conversations.
Authorized edits can replace text, create text files, or delete eligible text files within the supported workspace boundary. They do not provide general shell execution or Git mutation tools.
Fixed Git comparisons remain read-only regardless of the normal editing setting.
Stopping does not undo edits
Stopping a run cancels ongoing work where cancellation can be applied. It does not roll back a change that has already been committed to disk.
Inspect your working tree after an interrupted editing run. Use your normal version-control and backup practices, particularly before authorizing deletion.
The terminal is a separate tool
Yenpo’s terminal runs as your macOS user. The workspace folder is its initial working directory, not a sandbox boundary.
The built-in agent cannot execute terminal commands through that terminal. Terminal input, output, history, and working directory are not supplied to the agent’s model conversation.
Commands you run yourself still have their usual effects and permissions. Read them before executing them.
Share deliberately
Keep credentials out of messages, repository content, and shared screenshots. Images are disabled by default for each provider; enabling image input is a separate configuration choice.
If you are unsure whether particular data may be sent to a model, confirm the applicable policy and provider configuration before starting the conversation.