SECURITY

Zero telemetry.Your code never leaves the machine.

CodeOtter's two engines run entirely on infrastructure you control. The product does not ship a telemetry endpoint. This page explains exactly what runs, what doesn't, and where to verify it yourself.

Zero telemetry by construction

CodeOtter's two engines never phone home. System 1 calls a local rubric file on the same machine and returns typed answers (`choice`, `score`, or `noul`). System 2 streams to whatever BYOK endpoint you configure — Claude, OpenAI, OpenRouter, MiniMax, a local `llama.cpp` + GGUF sidecar, or any OpenAI-compatible chat endpoint you point it at. There is no CodeOtter SaaS endpoint for your code to reach, and the product does not include a `/v1/telemetry` route. The only outbound requests the platform makes are the calls you explicitly configured: provider calls against your BYOK endpoint and the GitHub API calls your `GH_TOKEN` authorizes. Audit it yourself — `grep -r "telemetry" server.mjs` returns nothing, because there is nothing to find.

No third-party tracking on your code

The review pipeline does not embed Segment, Mixpanel, Sentry SDK, FullStory, Hotjar, Facebook Pixel, or Google Analytics. Nothing inside CodeOtter observes your code other than the rubric engine (System 1) and the language-model endpoint you configured (System 2). We are not the data processor — you are. The system runs on your machine, on your network, against endpoints you picked.

Architecture: engines talk to rubrics + BYOK only

System 1 is exposed at `POST /v1/systemone`. It takes a PR diff and answers a strict typed rubric (`choice` / `score` / `noul`) against a local rubric file shipped with the product. Scores are clamped to 0–100 and gates are yes/no; the JSON schema is enforced server-side, which is what stops scores from drifting between 75 and 85 on every review. System 2 streams against `/v1/chat/completions` to your BYOK endpoint with the same diff and any `AGENTS.md` / `CLAUDE.md` context auto-detected at the repo root. Both engines can run on the same machine with no network egress other than the endpoint you configured. The single-file `server.mjs` backend uses Node stdlib + `fetch` only — no npm dependencies in the backend you have to audit alongside the product, and a server-side `judge()` validates every LLM output before it reaches storage, the dashboard, or the GitHub PR comment.

Self-host deployment options

A Mac mini or any 16 GB unified-memory laptop (Apple Silicon or modern x86) runs the dual engine comfortably for a single team. A $20/month VPS (4 GB RAM, no discrete GPU) handles small teams with System 1 and a small quantized GGUF for System 2. For larger teams, a Kubernetes deployment with a GPU node is fully documented in the repository. The Docker image packages the full platform with persistent storage under `/app/pb_data`; mount it as a volume and your reviews, settings, and downloaded local models survive upgrades. Access is gated by GitHub OAuth on the PocketBase `users` collection with Owner / Admin / Developer RBAC; the first account to sign in is promoted to instance Owner automatically, and organisation scoping in the header dropdown keeps teams isolated from each other.

About this marketing site

The marketing site at `codeotter.io` uses Cloudflare Web Analytics and Cloudflare Turnstile, both of which are cookie-free. Comments on blog posts use Giscus (no cookies on our domain; GitHub OAuth for sign-in). We do not set advertising cookies, sell personal data, or load third-party advertising or social-pixel scripts. Standard HTTP request logs (IP, User-Agent, URL, status) are retained by Cloudflare for roughly seven days for security and abuse investigation; after that window they are deleted or fully anonymized. Full details are in our Privacy Policy.

License — Elastic License 2.0 (ELv2)

CodeOtter is released under the Elastic License 2.0 (ELv2). Free to use, copy, distribute, and modify, including for commercial use inside your own organisation. The one restriction: you may not provide CodeOtter as a hosted or managed service to third parties. The full LICENSE is published in the public product repository.

Verify it yourself.

The source is public. grep -r "telemetry" over the repository turns up nothing.

Read the source on GitHub →