Safety & responsible use
Practical boundaries for prompts, permissions, providers, and AI-generated work while Cloaky is in public beta.
Cloaky is a coding-agent workbench, not a safety guarantee. The app can help you inspect routes and approve consequential actions, but you are still the person responsible for the project, the provider you select, and the commands you allow to run.
Keep a human in the loop
Treat model output as a proposal, not a source of truth. Read diffs, review commands, run tests, check dependency licenses, and verify the result against the original requirement. Do not let Cloaky be the only reviewer for code that handles money, health, identity, safety, security, access control, or other high-impact decisions.
The default permission mode is Accept edits. Shell commands and other consequential actions pause for approval. If you choose a less restrictive mode, make that choice deliberately and understand that a model can make a mistake at machine speed.
Protect secrets and sensitive data
- Keep API keys, passwords, private keys, tokens, and recovery codes out of prompts, issues, screenshots, support messages, and committed files.
- Do not send personal, confidential, regulated, or third-party data to a provider unless you are authorized and the selected route is appropriate.
- Use a local model when inference must remain on your machine, and still inspect any network-capable tool you approve.
- Keep independent backups before allowing an agent to edit or delete files.
The provider badge tells you where inference went. It does not mean every network operation was local: web access, MCP servers, registries, update checks, and approved shell commands can create separate routes.
Verify providers and downloads
Venice, direct providers, local model services, and tools have their own terms, retention policies, pricing, and security properties. Read those terms before connecting an account. Cloaky does not guarantee a third party’s availability, output, retention, or security.
Download builds from cloaky.dev, verify the architecture, and follow macOS’s security prompts carefully. Beta builds can contain defects, break compatibility, lose data, or expose security weaknesses. Do not install a build on a machine or in a project where that risk is unacceptable.
Report a security issue
Do not publish credentials, exploit details, or private user data in a public issue. Send a concise report to legal@cloaky.dev with the affected version, reproduction steps, and a safe contact method. We cannot promise a response time or a particular remedy, but private reports give us a chance to protect users before details spread.
For the contract terms and full risk allocation, read the Terms of Use.
