Skip to main content
Vortex
The loop How it works Control Docs Compare Changelog FAQ
Join the waitlist
The loop How it works Control Models Docs Compare Changelog FAQ Join the waitlist

Privacy

Privacy Policy

Last updated: September 26, 2026

Vortex is an agentic coding platform for macOS that plans, edits, verifies, and ships inside your workspace. This policy explains what data the Vortex desktop application collects and sends, what stays on your machine, and what happens when you use the website or companion web account.

Summary

  • Your code stays on your machine unless you explicitly send it to a third-party LLM provider you configure, such as OpenAI, Anthropic, OpenRouter, or a custom endpoint. Vortex itself does not upload your files or prompts.
  • Vortex-operated services (website, waitlist, update feeds, and companion web account) are hosted in the EU.
  • Closed-beta desktop sign-in & device heartbeat: The desktop app requires a one-time GitHub sign-in to activate closed-beta access. The desktop sends a minimal periodic heartbeat (version, OS, architecture, last seen timestamp) to app.usevortex.dev. Workspaces, code, prompts, chats, and usage analytics stay on-device.
  • Vortex collects crash and error reports through Sentry during the closed beta. This is enabled by default and can be turned off at any time. Crash reports remain anonymous and unlinked to your GitHub identity.
  • Vortex does not collect app usage analytics, performance traces, or a behavioral profile of how you use the desktop app.
  • The website collects a waitlist email only when you submit it. Optional website analytics stay off until you consent.
  • Vortex is proprietary software — it is not open-source and the source code is not publicly available. Closed-beta installer packages and update feeds are distributed on an invite-only basis.

1. Data that stays on your device

The following is stored locally on your computer and is not transmitted to the Vortex authors:

  • Your workspace files, folders, and project contents.
  • The canonical SQLite database at ~/.vortex/vortex.db (workspaces, chats, messages, runs, traces, pending review patches, UI metadata, and a local usage ledger of token counts, provider cost, and model id). You can override the parent directory with VORTEX_HOME. The ledger stays on this machine. It is not included in crash reports and is never sent to Sentry. Deleting a chat does not delete the spend row.
  • Saved workspace directories under ~/.vortex/workspaces/<id>/ (checkpoints and resumable agent session artifacts).
  • Your chat history, agent turns, plans, and todos.
  • Prompts and responses sent to LLM providers, as described below.
  • Locally configured API keys, model settings, and MCP server configurations such as ~/.vortex/mcp.json or the active Cursor-compatible configuration.
  • Deterministic symbol-cache data and on-device code search.
  • Repository-local .vortex/ data, including memory, skills, notepads, plans, and canvases.
  • Downloaded local model files, including GGUF files.

2. Data sent to third-party LLM providers

When you choose a cloud model and send a message, Vortex sends your prompt and any attached context to the provider you selected: OpenAI, Anthropic, OpenRouter, or a custom OpenAI-compatible endpoint you configured. That transmission is governed by the provider's own privacy policy and terms.

Vortex does not route this traffic through a Vortex-operated server. When you use a local model, prompt data stays on your machine.

The stop check and the docs-only question send the task goal, the end of the agent's reply, or the user instruction to the same helper model you already use. Vortex records the latency and the probability. It does not log that text. The stop check is skipped when that helper is the main model.

Settings → Usage can ask OpenRouter for your key's credit balance and spending limit. That request goes directly to OpenRouter with your OpenRouter API key, the same way a model request does. Vortex shows the numbers in the app and does not store them as telemetry.

3. Crash and error reports

To fix bugs during the closed beta, Vortex sends anonymous crash, panic, and error reports to Sentry, a third-party error-monitoring service hosted in the EU. This is enabled by default.

A crash report may include the app version, operating system name and version, CPU architecture, a stack trace, the error message that caused the crash, a minidump, and the Vortex release identifier. A crash report does not include your source code or file contents, prompts, chat history, agent transcripts, API keys, authentication tokens, or GitHub account identity (crash reports remain anonymous and unlinked).

Performance tracing is disabled. Vortex does not send timing or profile data about how you use the app.

User-submitted feedback

The Report a bug dialog saves the description you enter to ~/.vortex/logs/feedback.jsonl and the main Vortex log. When telemetry is enabled, that description is also forwarded to Sentry as feedback. The automatic debug-info snapshot does not include source code, prompts, or file contents, but the description is user-entered text and can contain sensitive information. Do not paste secrets, credentials, source code, or private prompts into it.

Turning telemetry off

You can disable crash reporting at any time in Settings → General, or by creating an empty file at ~/.vortex/disable_telemetry. If you override the Vortex home directory, use $VORTEX_HOME/disable_telemetry. The change takes effect the next time Vortex starts.

4. Auto-updates

Vortex checks the update feed for the channel you select in Settings → About → Update channel. Stable checks https://usevortex.dev/updates/latest.json; Beta checks https://usevortex.dev/updates/latest-beta.json (the desktop UI is currently locked to Beta during the closed beta). Update feeds and installer packages are served from EU-hosted infrastructure.

This request reveals your current app version and IP address to the hosting provider in the same way any HTTPS request does. Vortex does not attach a unique device identifier to update checks. You can override the host with VORTEX_UPDATE_HOST.

5. Web account & desktop sign-in (app.usevortex.dev)

The companion web service at app.usevortex.dev runs on EU-hosted infrastructure. It provides closed-beta downloads, web account management, and desktop device authorization. Access is restricted to invited GitHub accounts on the closed-beta allowlist (not by waitlist email address).

During the closed beta, the Vortex desktop app requires a one-time sign-in using GitHub OAuth device authorization. The desktop receives a dedicated, revocable token saved locally at ~/.vortex/account.json (mode 0600). On startup and periodically (~every 6 hours), the desktop sends a lightweight heartbeat containing your device ID, application version, OS, CPU architecture, and last seen timestamp. Workspaces, code, prompts, chats, agent traces, and usage analytics stay strictly local on your machine.

When you sign in to the web app with GitHub, the web service stores the GitHub provider account identifier and, when GitHub makes them available, your email address, display name, login handle, and avatar URL. It also stores the session data required to keep you signed in, hashed desktop device tokens, and a minimal plan profile: plan (beta or pro, currently defaulting to beta) and a nullable stripe_customer_id reserved for a future paid product.

Signing out from the web browser clears only your web session cookie; desktop installations remain authorized until you explicitly click Sign out in Settings → About within the desktop app or revoke access.

6. Website data

Beta waitlist

When you submit the waitlist form, the website sends your email address to /api/beta-signup. We store that email on EU-hosted servers to manage closed-beta access and contact people about access. The website and waitlist API run on EU-hosted infrastructure. The email is not part of the Vortex desktop application's local-first workspace data.

Analytics and necessary storage

The website uses strictly necessary browser storage and cookies needed for core operation, including remembering your cookie choice. Google Analytics is configured in consent mode with analytics storage denied by default. It is enabled only after you choose to allow analytics in the cookie dialog. You can change that choice with Cookie settings in the footer.

7. Data retention

Crash reports sent to Sentry are retained for the duration of the beta program to support debugging and then deleted according to Sentry's default retention policy. Vortex does not maintain a separate database of desktop-app user data. Waitlist emails are retained as needed to manage beta access.

8. Children's privacy

Vortex is a developer tool and is not directed at children under 16. We do not knowingly collect data from children.

9. Source code and distribution

Vortex is proprietary software. It is not open-source and its source code is not publicly available. During the closed beta, official pre-built desktop installer packages (DMGs) and update feeds are distributed on an invite-only basis.

10. Contact

For privacy questions or data requests, open an issue on the Vortex project repository or contact the project maintainer.

Vortex

You describe the work. Vortex plans, edits, verifies, and ships inside your workspace. The editor, terminal, diffs, and browser are how you watch and steer — not where you are expected to write the solution.

Product

The loop How it works Control Models Get Vortex

Resources

FAQ Join the waitlist Changelog

Company

Privacy

© Vortex. Made in the EU. Hosted in the EU.

Privacy

Choose your cookies

Strictly necessary storage keeps the site working. Optional analytics stay off until you allow them. See our Privacy Policy.

Strictly necessary

Required for the site to work. Always on.

Always on

Google Analytics measures visits after you allow it.