Privacy and security
For Crews. Last updated 7 August 2026.
The short version
There is no Kadaken account, no advertising, no cloud sync and no built-in telemetry. Nothing about your work is sent to Kadaken.
What is stored, and where
Chats, attachments, settings, registered project paths, any keys you
choose to save, and artifacts all stay on your machine under
~/.config/agent-workbench-native/. A registered project
may also hold a gitignored .agent-workbench/ folder.
What can leave your machine
Crews runs AI coding tools you have already installed. Anything you send through a cloud-backed tool goes to that provider, under your own account and their terms - not through Kadaken.
Deleting your data
Deleting a chat removes the session data and artifacts the app owns.
History kept by a provider is controlled separately, with them. To
erase everything: close the app and its bridge, delete
~/.config/agent-workbench-native/, and remove any
.agent-workbench/ folders from your projects.
Security model
Crews is a launcher and a workspace. It is not a sandbox around every AI tool - a tool can act within the permissions your operating system and that tool already grant it.
- The local bridge listens on loopback only, and control routes need a random per-user token.
- App state is written with user-only permissions. Requests from foreign web origins are rejected.
- Protected credential paths are denied.
- Silent global client updates and unsigned in-place updates are off.
- Custom clients and MCP servers are executable code. Install only what you trust.
- Never put a secret in a command string.
- Raw diagnostic output, logs, diffs and screenshots can contain source code, paths, prompts and secrets. Check before you share them.
Beta limits
Keep your projects in version control and backed up. Avoid two things writing the same uncommitted file at once. Verify downloads against the release's SHA256SUMS - a checksum catches a corrupted download, but it is not publisher code signing.
Reporting a security problem
Report it privately, by email, to support@kadaken.com - not in a public forum. Never include real credentials, private source code, or anyone else's data in a report.