Privacy Policy
Last Updated: September 11, 2026
Your code and context stay on your machine.
FAF tools run locally and send nothing to FAF. A few features go online — only when you use them, and only to the service you pick.
- No telemetry from the CLI, the extensions, or the MCP servers
- No tracking cookies on faf.one
- No training — FAF has no training pipeline
- Never sold
Tools on Your Machine
faf-cli, FAF Context for VS Code, the Stack Grabber Chrome extension, and the MCP servers claude-faf-mcp, faf-mcp, grok-faf-mcp, gemini-faf-mcp, rust-faf-mcp, and faf-memory-mcp.
- They read your
project.fafand project files locally - The WASM scoring kernel runs in-process — nothing leaves the process
- Your
project.fafholds only what you and the tools write into it — never source code - Stack Grabber reads the page you're on when you use it, and keeps its results and usage logs (including page URLs) in your browser's local storage
Only When You Ask
These features go online when you use them, and only to the service named:
- GitHub:
faf git, thefaf_gitMCP tool, and the VS Code “Score a GitHub Repo” command read the repo you name from GitHub. IfGITHUB_TOKENorGH_TOKENis set, claude-faf-mcp and faf-mcp send it to GitHub with the request - Anthropic: the optional
faf aicommands send yourproject.fafto Anthropic, using your own API key - xAI: grok-faf-mcp's
rag_querytool sends your question to xAI, using your own API key - FAF bench:
faf bench grade --submitsends your bench result (date, model, project name, scores) to mcpaas.live, where it is kept - rust-faf-mcp via npm: downloads its binary from GitHub Releases on first run
- gemini-faf-mcp Python client:
FAFClient(not used by the MCP server) sends a start-up ping — package name and version — to our Google Cloud service only if you setFAF_TELEMETRY=1. Its remote mode sends your requests there. Versions before 2.8.2 sent the ping by default; setFAF_TELEMETRY_OFF=1on those
What Our Websites and Hosted Services See
Like any website, ours see some request data. Here is what they see and keep.
faf.one
- Cloudflare hosts it and counts visits without cookies. Serving pages means it processes request data, such as your IP address
- If you sign up or use the contact form: your email, via Formspree and Resend
- FAFb Drive: if you request access, we email you a password through Resend. Signing in sets a sign-in cookie for 14 days
- If you buy FAF Pro or n8n.faf: Stripe takes the payment, and we keep a license record (email, license key, Stripe customer ID) in Supabase
- Some pages show GitHub's Sponsors button, loaded from github.com
- faf.one/webmcp scores in your browser — what you paste isn't sent to us
mcpaas.live and ide.faf.one
Hosted MCP endpoints (including hosted claude, grok, and gemini FAF servers) and namepoints. They process the tool arguments you send, and keep:
- Request counts per Cloudflare location (for the Globe) and per host, for about 13 months
- IP addresses, in short-lived rate-limit keys. Cloudflare Turnstile (bot protection) also sees your IP
- Task inputs and results, for 1 hour
- Your GitHub profile (username, name, email), for 1 hour after you sign in with GitHub
- Your email: for 90 days if you register interest in a namepoint, and with your Stripe IDs if you claim one or buy slash. A free claim adds you to our update list
The slash feature forwards your prompt to the AI provider you pick: Anthropic, OpenAI, or xAI.
builder.faf.one
- Your browser fetches the public repo you enter straight from GitHub
- GitHub sign-in is used once, to commit your
project.faf— the token isn't kept - We count page views and browser user-agents, and keep the names of repos that reach 100%. Cloudflare keeps request logs
gemini-faf-mcp hosted service (Google Cloud)
- Update requests, including what you send, are stored in Google BigQuery
If you give us your email, we use it only to talk about your account or purchase, and to send rare product updates. We never sell or share it. Unsubscribe anytime.
Services We Use
- Cloudflare: hosting, visit counts (no cookies), and bot protection
- Google Cloud: the gemini-faf-mcp hosted service
- Formspree: email signup
- Resend: email delivery
- Stripe: payments — we never see your card details
- Supabase: license records
- Upstash: FAF Builder counters
- GitHub: repos you ask for, GitHub sign-in, and the Sponsors button
- Anthropic, OpenAI, xAI: only when you use a feature that sends to them
Each has its own privacy policy.
Cookies
- faf.one: no tracking cookies. FAFb Drive sets a sign-in cookie for 14 days when you sign in. The GitHub Sponsors button on some pages loads from github.com, under GitHub's own policy
- mcpaas.live: a sign-in cookie, for 1 hour, when you sign in with GitHub
- No advertising cookies
Your Rights
You can always access, correct, export, or delete your data, and opt out of communications. Email team@faf.one for any data request.
Children's Privacy
FAF products are not intended for users under 13. We don't knowingly collect data from children.
Changes to This Policy
We update the date above when this page changes. If you've given us your email, we'll tell you about significant changes.
Contact Us
Privacy questions or concerns? Email team@faf.one.
Location: Atlanta, GA, USA
Our Commitment — All FAF Products
Across every FAF product — faf-cli, the MCP servers, the VS Code and Chrome extensions, MCPaaS, and FAF Builder — we will never:
- Upload your source code to FAF — local tools read it on your machine; hosted tools see only what you send them
- Use your data for AI training — we have no training pipeline
- Sell your data
- Add telemetry without listing it on this page
- Use dark patterns
- Hide important details
Your code is yours. Your context is yours. No BS. No exceptions.