Skip to content

Privacy and where keys live

The binding statement is PRIVACY.md in the repository, rendered on this site unchanged. This page is the short version with the practical details.

  • Requests to the provider you chose. When you send a message, the prompt, the context you attached and the files the agent reads go to that provider’s API — Anthropic, Google, OpenAI, OpenRouter, Groq, DeepSeek, Mistral or xAI — directly from your machine, under that provider’s terms. Sirius runs no relay or proxy in between.
  • Nothing, with a local model. With Ollama, LM Studio, llama.cpp or vLLM the request goes to the local endpoint you configured and no prompt, file or fragment of code reaches a third party.
  • The update check, on every install: platform, channel and build commit, no identifier — see Updates. update.mode: "none" turns it off.
  • Extension queries to Open VSX when you search, install or auto-update extensions.
  • Extensions you install from Open VSX are third-party software with their own behaviour; nothing in Sirius’s statement constrains them.

There is no telemetry, no crash reporting, no analytics and no account. The editor’s inherited telemetry.telemetryLevel setting is inert: the build has no telemetry destination configured, so nothing is sent whatever it says. The crash reporter never uploads: it has nowhere to upload to.

Provider keys are set with Sirius: Set API Key and kept in the editor’s secret storage, encrypted with the operating system’s own facility — DPAPI on Windows, the Keychain on macOS, libsecret or KWallet on Linux — not in settings.json, not in Settings Sync, and never sent anywhere but the provider they belong to (Gemini’s travels in a request header, not the URL). On Linux that needs a Secret Service provider (GNOME Keyring or KWallet); without one the editor says so and asks before falling back to weaker encryption — see Troubleshooting.

The old sirius.ai.<provider>.apiKey settings are deprecated: a key in one of them still works for now, but a key in a settings file is a key on disk in plain text, so move it with Sirius: Set API Key and delete the setting.

To remove a key, run Sirius: Set API Key, pick the provider and choose Remove key.

The site holds to the same rule: no third-party scripts, no cookies, no analytics. It is static files behind a strict content-security policy; the only requests it makes are for its own assets.