What Actually Leaves Your Machine When You Use an AI Coding Tool
A technical breakdown of what data IronCode sends to AI providers, what stays local, and how to verify it yourself.
When you use an AI coding tool, something leaves your machine. The question is what, and whether that's acceptable given your situation.
Most tools are vague about this. "We take privacy seriously" is a sentence that has never told anyone anything useful. This post tries to be specific.
What IronCode sends
IronCode sends prompts to your configured AI provider. A prompt contains:
- A system prompt — a description of what IronCode is and how the model should behave. This is the same for every user.
- Tool definitions — descriptions of the tools the model can use (read file, write file, run command, etc.). Also identical for every user.
- The conversation so far — your task description, the model's previous responses, and the results of tool calls. This includes file contents when IronCode reads files.
- Nothing else.
There is no background telemetry. No usage analytics. No automatic upload of your project structure. No persistent session storage on any server we control.
What a prompt actually looks like
When you ask IronCode to "add error handling to the login endpoint", a simplified version of what gets sent to the AI provider looks like this:
[system]: You are IronCode, an AI coding agent...
[user]: Add error handling to the login endpoint
[tool call - read_file]: app/api/auth/login/route.ts
[tool result]:
export async function POST(req: Request) {
const { email, password } = await req.json();
const user = db.users.findByEmail(email);
if (!user) return new Response("Not found", { status: 404 });
...
}
[tool call - read_file]: lib/errors.ts
[tool result]: ...
[assistant]: I'll add error handling using your AppError class...
The file contents of login/route.ts and lib/errors.ts leave your machine. Nothing else does.
What stays local
- All files IronCode doesn't need to read for the current task
- The output of commands you run (unless you explicitly paste them into the conversation)
- Your git history
- Your environment variables (IronCode reads
.envonly if you explicitly tell it to) - Everything in your system that isn't a file IronCode decides to read
How to verify this yourself
IronCode is open source. The code that constructs and sends prompts is in packages/ironcode/src/providers/. You can read it.
If you want runtime verification, run IronCode with a network proxy like mitmproxy and inspect every outbound request. You'll see exactly what goes to which host.
# Example: run IronCode through mitmproxy
mitmproxy --mode regular --ssl-insecure &
HTTPS_PROXY=http://localhost:8080 ironcode
Every request to api.openai.com (or your configured provider) will be visible in the proxy UI. There should be no requests to any other external host.
Choosing your provider
Because IronCode is just sending HTTP requests to an OpenAI-compatible API, you control where those requests go:
// .ironcode/ironcode.jsonc
{
"model": "gpt-4o",
"provider": {
"baseUrl": "https://api.openai.com/v1"
}
}
Change baseUrl to point at:
- Anthropic via their API (
claude-3-5-sonnet-20241022) - A local Ollama instance (
http://localhost:11434/v1) — zero external network calls - Azure OpenAI if your organization requires it
- Any OpenAI-compatible endpoint
If you run IronCode against a local Ollama model, nothing leaves your machine at all. The model runs locally, the inference runs locally, the output stays local.
For enterprise and regulated environments
The most common concern in regulated environments (healthcare, finance, legal) is about source code leaving the organization's network perimeter.
The practical options:
- Local models via Ollama — no external calls, but model quality is lower than GPT-4 or Claude
- Azure OpenAI — your data stays within your Azure tenant, subject to Microsoft's enterprise data handling commitments
- VPC deployments of compatible APIs — if your organization runs an internal model endpoint, IronCode can point at it
We can't make this decision for you — it depends on your threat model, your compliance requirements, and your tolerance for model quality tradeoffs. But these are the levers you have.
What we don't do with data
OpenAI, Anthropic, and other providers have their own data retention and training policies — read their documentation if that matters to you. IronCode itself:
- Stores conversation history locally in
~/.ironcode/sessions/— you can delete it - Sends no telemetry to any server we operate
- Has no account system, no login, no cloud storage
The only data flow is: your machine → your chosen AI provider → your machine.