Pendant Privacy Policy
Effective date: July 11, 2026
This Privacy Policy explains privacy practices for:
- the Pendant extension for Visual Studio Code, VSCodium, and other VS Code-compatible editors (the "Extension");
- the Pendant website (the "Website"); and
- the Pendant issue tracker (the "Issue Tracker").
It does not cover GitHub, Open VSX, the Visual Studio Marketplace, VS Code, VSCodium, Pi, model providers, Hugging Face, pi.dev, your operating system, your editor, your local runtime, or other third-party services. Those products and services are governed by their own policies.
1. The Short Version
The Extension does not collect anything for Pendant. The Extension does not use Pendant-operated servers.
The Extension does not send telemetry, analytics, crash reports, prompts, source code, files, images, audio, transcripts, diagnostics, credentials, usage events, or identifiers to Pendant, because Pendant does not operate a backend service for the Extension.
That said, the Extension is a local client for a local Pi-compatible coding agent and for third-party services that you configure or choose to use. Data can remain local, be stored by your editor or local Pi runtime, or be sent to third parties such as your configured model providers, the pi.dev update/news service, Hugging Face, the VS Code Marketplace, Open VSX, or your external browser. This policy describes those local and third-party flows so you can make informed choices.
2. Controller and Contact
For the privacy statements in this policy, the contact is:
Cem Dervis, Email: cem@dervis.de
Because the Extension does not collect personal data for Pendant and there are no Pendant-operated Extension servers, Pendant normally has no Extension-held personal data to access, correct, export, or delete for you. Most privacy controls for Extension use are local controls on your device, in your editor, in your Pi runtime, or with third-party providers.
3. What Pendant Collects
Pendant collects nothing through the Extension for Pendant-operated systems.
Specifically, the Extension does not:
- operate an Extension backend;
- create Pendant accounts;
- collect Extension telemetry;
- collect analytics;
- collect crash reports;
- collect advertising identifiers;
- collect or sell user profiles;
- collect prompts, messages, code, files, images, or audio for Pendant;
- collect model-provider credentials for Pendant;
- collect diagnostics logs for Pendant;
- collect marketplace installation data for Pendant;
- use cookies for the Extension; or
- sell or share Extension personal information for advertising.
4. Website and Issue Tracker
The Pendant Website and Issue Tracker are operated by Pendant.
4.1 Website hosting and server logs
The Website is hosted on Hetzner servers located in Germany. When you visit the Website, Hetzner processes standard server log information such as your IP address, request date and time, requested URL, HTTP status code, referrer URL, and browser user agent. This processing is necessary to deliver the Website and to maintain its security and stability (Art. 6(1)(f) GDPR).
Hetzner may process this data as a processor under a data processing agreement. Server logs are retained only as long as necessary for security, troubleshooting, and legal defense, typically up to 30 days.
4.2 Issue tracker
The Issue Tracker is hosted on Supabase and uses AWS
eu-central-1 (Frankfurt, Germany). When you sign in to the Issue Tracker
with GitHub or Google, the only user profile data stored in Supabase is the email
address and display name provided by your GitHub or Google profile. No other user
profile data is stored by Pendant in Supabase.
The Issue Tracker also stores the issue or support-request content that you intentionally submit, such as issue titles, issue bodies, comments, labels, attachments, and related timestamps, so that the tracker can function.
This processing is necessary to provide support and to improve the Extension (Art. 6(1)(b) and Art. 6(1)(f) GDPR). Issue data is stored in the EU/EEA and is not transferred to third countries by Pendant.
4.3 Cookies and analytics
The Website does not use third-party analytics, advertising, or tracking cookies.
5. Local Data Stored or Processed by the Extension
Although Pendant does not collect data for Pendant, the Extension can read, write, display, or pass local data as part of its normal editor workflow. Depending on your settings and usage, this may include:
-
VS Code or VS Code-compatible editor settings under the
pendant.*configuration namespace; - extension state stored by the editor, such as remembered runtime status, update-check state, release-presentation state, and cached command metadata;
-
provider credentials stored in the active Pi runtime's local
auth.jsonwhen you configure them through supported flows; -
local display-config files for optional usage or credit features, such as
chatgpt-usage-config.jsonandopenrouter-credits-config.json, stored in the Extension's global storage area; - environment variables visible to the editor extension host;
-
your configured Pi agent directory, commonly
~/.pi/agent, including Pi settings, models, auth configuration, sessions, and other Pi-managed files; - chat sessions, transcript data, message history, session names, fork metadata, and session statistics exposed by the local Pi Runtime;
- prompts and messages you type;
- selected editor text, active file metadata, cursor position, visible range, open tabs, diagnostics, Git branch/status counts, explicitly mentioned files or folders, pasted images, and other workspace context when enabled or attached;
- file previews and image previews that the Extension reads from your workspace for display inside the editor;
- local dictation model files downloaded to the Extension's model cache;
- microphone audio processed locally by native dictation helpers when you use dictation;
- local dictation transcripts inserted into the chat input;
- output from an optional custom notification hook, including its command, event, session path, stdout, stderr, exit, errors, and timeout status, written to the local Pendant Hooks output channel.
This data is processed locally in your editor environment and local runtime environment. Pendant does not receive it.
6. User Prompts, Files, Images, and Workspace Context
Pendant is designed to pass chat input and selected context to your local Pi Runtime. Pi may then send that data to whichever model provider, model endpoint, tool, package, or service you have configured.
Depending on your settings and actions, the data passed to Pi may include:
- your prompt text;
- prior conversation context;
- selected text from the active editor;
- active file metadata and file paths;
- diagnostic messages from the editor;
- Git status summaries;
- explicitly referenced files or folders;
- pasted image attachments;
- command output, tool output, diffs, or generated edits; and
- system prompts, appended prompts, skills, prompt templates, and extensions configured for Pi.
Pendant does not proxy this data through Pendant servers. Any onward transfer is determined by your local Pi Runtime, selected model/provider, enabled tools, and provider configuration.
You should not send confidential, regulated, personal, customer, secret, or proprietary data to a model provider unless you have reviewed and accepted that provider's terms and privacy practices.
7. Model Providers and Provider Credentials
The Extension can help the local Pi Runtime use provider credentials from local
configuration, environment variables, Pi-managed auth.json, or other local
provider login files. Supported provider environment variables may include keys for
providers such as OpenAI, Azure OpenAI, Anthropic, Google/Gemini, OpenRouter, DeepSeek,
Groq, Mistral, xAI, Z.ai, Cerebras, Vercel AI Gateway, OpenCode, Hugging Face, Kimi,
MiniMax, and others supported by the runtime.
For Kimi Coding usage checks, the Extension may read a cached Kimi Code OAuth token from
~/.kimi-code/credentials/kimi-code.json if that file exists.
These credentials are not sent to Pendant. They may be passed to the local Pi process or to provider-specific endpoints when you use the related provider or feature.
Current provider credentials are not stored in VS Code SecretStorage. On startup, the
Extension deletes known legacy pendant.apiKey.* SecretStorage entries
without reading their values; current credentials remain in the active Pi runtime's
local auth.json.
Provider traffic is governed by the provider you choose. Pendant does not control provider logging, retention, training, abuse monitoring, billing, security, data location, or account policies.
8. Optional Subscription Usage and Credit Checks
The Extension can display subscription usage limits or credit balances for supported providers. These features are designed to help you see usage information inside the editor. They are not Pendant telemetry.
When enabled and relevant to the active provider, the Extension may contact:
-
ChatGPT/Codex usage endpoints at
https://chatgpt.com/backend-api/wham/usage(under thehttps://chatgpt.com/backend-apibase URL) with the relevant bearer token and, when provided by the runtime, an account identifier; -
Kimi Coding usage endpoints at
https://api.kimi.com/coding/v1/usages, using a Kimi Code OAuth token or configured access token; and -
OpenRouter endpoints at
https://openrouter.ai/api/v1/creditsorhttps://openrouter.ai/api/v1/auth/key, using your OpenRouter API key.
The Extension receives usage or credit information and displays it locally in the editor. Pendant does not receive this information.
You can disable these displays with settings such as:
pendant.subscriptionUsageEnabledpendant.openrouter.showCredits
9. pi.dev Update and News Checks
The Extension may contact pi.dev for Pi-related update and news information, including endpoints such as:
https://pi.dev/api/latest-versionhttps://pi.dev/api/available-packageshttps://pi.dev/news.xml- pi.dev changelog or news pages opened in the preview UI or external browser
For latest-version checks, the request may include a User-Agent containing Pi version, platform, Node.js version, and CPU architecture, because that is how the update-check request is built.
These requests go to pi.dev, not to Pendant. Pendant does not operate pi.dev.
You can reduce or disable startup network checks with settings or environment variables such as:
pendant.offlinePI_OFFLINE=1PI_SKIP_VERSION_CHECK=1
Opening external links may also involve your operating system, external browser, DNS provider, network provider, and the destination website.
10. Dictation and Whisper Model Downloads
Dictation is local. When you use the microphone button, the Extension uses native
helpers and whisper.cpp model files to transcribe audio on your device.
Pendant does not receive microphone audio or dictation transcripts.
The first time you use a dictation model, the Extension may download the model file from:
https://huggingface.co/ggerganov/whisper.cpp/resolve/main/<model-file>
That download request goes to Hugging Face. Hugging Face may receive ordinary network information such as IP address, request headers, timing, and requested file path under its own policies. Pendant does not receive the download request, audio, or transcript.
Available models include Tiny and Base variants, some English-only and some
multilingual, such as tiny-q5_1, base-q5_1,
tiny.en-q5_1, and base.en-q5_1. The Extension downloads the
specific ggml-*.bin file matching the selected model. Downloaded models are
stored in the Extension's voice-model cache. You can delete downloaded dictation
models from the Extension's info menu where that action is available. You can hide
or disable dictation with:
pendant.voice.enabledpendant.voice.model
Your operating system may also require microphone permission for the editor or native helper.
11. Custom Notification Hooks and Local Hook Logs
If you configure pendant.notifications.customHook, the Extension executes
the script or executable path you provide for the notification events selected in
pendant.notifications.customHookEvents. The hook receives the event, title,
message, and session path through environment variables and a JSON object on standard
input. The hook runs with your local user permissions and can contact third-party
services according to its own implementation.
The Extension records the configured command, event, session path, stdout, stderr, exit status, errors, and timeout status in the local Pendant Hooks output channel. This output remains in the editor session unless you copy or share it. Review it before sharing because it can contain local paths and hook output. Pendant does not upload hook output.
12. Marketplace, Editor, Operating System, and Browser Data
Installing, updating, searching for, rating, or using an extension through the Visual Studio Marketplace, Open VSX, VS Code, VSCodium, another editor, an operating system, an external browser, or a package manager may involve data collection by those third parties. That data is outside Pendant's control.
Examples may include marketplace account data, installation metadata, editor telemetry, crash reporting, update checks, IP addresses, device information, browser history, download logs, or extension-management logs, depending on your tools and settings.
Review the privacy settings and policies for your editor, marketplace, operating system, browser, network, and package-management tools.
13. No Sale, Sharing, Ads, or Profiling by Pendant
Pendant does not collect Extension personal information for Pendant. Therefore Pendant does not sell Extension personal information, share Extension personal information for cross-context behavioral advertising, serve targeted ads, profile Extension users, or make automated decisions about Extension users.
Third-party providers, marketplaces, editors, browsers, websites, or services may have their own advertising, analytics, personalization, profiling, or retention practices. Pendant does not control those practices.
14. Retention
Because Pendant does not receive Extension data, Pendant does not retain Extension data on Pendant servers.
Local retention is controlled by your device, editor, workspace, file system, Pi Runtime, provider credentials, exported files, and settings. Examples:
- local session history remains in the configured Pi agent directory until you or Pi delete it;
- VS Code settings remain until you change or remove them;
-
provider credentials in
auth.jsonremain until you or Pi remove them; - downloaded dictation models remain until deleted;
- hook output remains in the editor output channel for the editor session; and
- provider-side data remains according to provider policies.
Uninstalling the Extension may not delete all local settings, Pi files, session history, credentials, models, logs, provider data, marketplace data, or editor state. You may need to delete those separately.
15. Security
The Extension relies on local editor, operating-system, and file-system security features for local data. File-preview operations resolve paths relative to the active session and workspace, while explicit links and attachments can refer to files outside the workspace.
No local system is perfectly secure. You are responsible for securing your device, editor profile, workspace, shell environment, provider credentials, agent directory, backups, exported logs, and third-party accounts.
Be careful when using coding-agent tools in sensitive repositories. AI tools can read context, run commands, modify files, and transmit data to configured model providers depending on your settings and approvals.
16. Your Choices and Controls
Important Extension controls include:
pendant.context.autoAttachpendant.context.includeEditorpendant.context.includeSelectionpendant.context.includeDiagnosticspendant.context.includeGitpendant.toolPresetpendant.customToolspendant.disableContextFilespendant.offlinependant.subscriptionUsageEnabledpendant.openrouter.showCreditspendant.voice.enabledpendant.voice.modelpendant.notifications.customHookpendant.notifications.customHookEvents
You can also:
- avoid typing or attaching sensitive data;
- disable automatic context attachment;
- disable specific context sections;
- avoid using provider usage or credit displays;
- avoid dictation or delete downloaded dictation models;
- review local hook output before sharing it;
-
remove provider credentials from Pi
auth.jsonor other local provider config; - change or delete local Pi agent directory contents;
- configure provider privacy settings directly with the provider;
- use editor, marketplace, browser, and operating-system privacy controls; and
- uninstall the Extension.
17. International Transfers
Pendant does not transfer Extension data internationally because Pendant does not receive Extension data.
Third-party services you use with the Extension may transfer or process data in other countries. This may include model providers, the pi.dev update/news service, Hugging Face, marketplaces, editors, browsers, and network providers. Review their policies for transfer mechanisms and data locations.
18. Children
The Extension is a developer tool and is not directed to children. Pendant does not knowingly collect personal information from children through the Extension. Because Pendant does not collect Extension data, Pendant does not maintain Extension-held child data.
19. Privacy Rights
Privacy laws may give you rights to access, correct, delete, restrict, object to, or port personal data.
Because Pendant does not collect Extension data for Pendant and has no Pendant-operated Extension servers, Pendant normally has no Extension-held personal data to provide, correct, export, or delete.
For Website and Issue Tracker data held by Pendant, contact cem@dervis.de to exercise your rights. Pendant will respond in accordance with applicable law.
If you are in the EU/EEA or otherwise protected by the GDPR, you have the right to request deletion of personal data held by Pendant where applicable. To request deletion of your Website or Issue Tracker data, contact cem@dervis.de and the data controlled by Pendant will be deleted.
For local Extension data, you can use your device, editor, workspace, and Pi controls. For third-party data, contact the relevant third party, such as your model provider, marketplace, editor vendor, browser vendor, Hugging Face, or pi.dev.
You may contact cem@dervis.de with privacy questions about this policy. If you contact Pendant outside the Extension or Issue Tracker, identify the relevant communication so it can be handled.
20. Changes to This Policy
This policy may be updated from time to time. Updates may be distributed with the Extension, shown in documentation, linked from marketplace listings, or made available through other reasonable means.
If Pendant ever adds new collection, telemetry, analytics, accounts, hosted services, or server-side processing for the Extension, Website, or Issue Tracker, this policy should be updated before or when that behavior is introduced.
21. Contact
For privacy questions about this policy:
Cem Dervis, Email: cem@dervis.de