Privacy

What we send, and what we never do.

An AI coding agent has to be told things you would not tell most websites. That is a fair thing to be nervous about, so this page is specific on purpose: every claim below can be checked against the source.

The only thing LambAI sends is your key

When the agent starts, it asks us one question: is this key allowed to run? The whole request is this, and nothing else:

{ "key": "lk_1f3c…" }

One field. No hostname, no username, no path, no project, no version, not even which model you are using. A test in our own suite decodes the bytes the server receives and fails if a second field ever appears, which is the closest thing to a guarantee we can offer.

A key is required to run LambAI, so this call is not optional: the agent makes it when it starts, and a copy that has never registered a key will not start until it has one — so the first run has to be online. After that it happens on each start to confirm, which is what makes revocation real. If we cannot be reached, the agent carries on anyway rather than stopping you working.

The answer comes back as one of four things: accepted, revoked, not registered, or no answer. That last one matters, and it is covered below.

What we store

Everything on this list, and nothing else. If a field is not on it, there is no column for it in our database.

Your name and email

When you sign up.

So you have an account, so the key belongs to somebody, and so we can answer you.

A hash of your password

When you sign up.

To log you in. We never store the password itself, so we cannot read it or send it to you.

Your plan, the model you use, your experience level, and your language

When you sign up.

The plan and model decide what you get. The language decides how we write to you. The experience answer only tells us who is using it.

Whether you ticked the newsletter box

When you sign up.

Off unless you tick it. That is the only marketing you will ever get from us.

The date you signed up

When you sign up.

Added by the database along with the record.

A login session token

While you are signed in.

So you stay signed in. It expires, and it is useless without the matching row in our database.

A hash of your API key, the four-character hint, and when it was last used

While you hold a key.

Never the key itself — the same idea as the password. The hint is the "…1f3c" you see on your account page. The last-used time is what tells you a key is still in play, and you can revoke it at any moment.

A timestamp and your email, each time the agent checks its key

Every time you start LambAI.

This is the usage signal — it is how we can tell whether anyone actually uses the thing. Without it we would be guessing.

We do not store your IP address

Not as a privacy flourish — as a fact about the code. There is no line in our server that reads the request's address, so there is none to leak. The web server software in front of us (Apache) keeps ordinary access logs, which do include IP addresses, and those are the machine's logs rather than ours; we host this ourselves and do not mine them.

What never leaves your machine

This is the list that matters, and it is the reason we wrote the first section so precisely.

Your prompts and your code do go to whichever model you have configured — DeepSeek, or a local model through Ollama that keeps everything on your own disk. That is between you and your model provider, and it happens whether or not you have ever heard of us. The licence check is not part of it and cannot see any of it.

When we cannot reach you

If our site is down, or you are on a train, the check gets no answer — and you keep working. LambAI only refuses to start when our server has positively said the key is revoked.

We chose that on purpose. The alternative — treating "no answer" as "no" — would mean that one bad deploy on our side, or one flaky train wifi, stopped every copy of the program everywhere at once. That is a failure mode we are not willing to build, even though it would be slightly better for us commercially.

Turning it off

/license clear forgets the key on your machine. We stop hearing from you — and since a key is required to start, the next launch will ask for one. If you would rather keep running unregistered, you can, by setting allow_no_license in your config; we would rather tell you that than pretend the choice is not there.

To have your account and everything in it deleted, email hello@lambai.dev and we will remove it. Deleting your own account from the website is a button we still owe you; until it exists, we will do it by hand within a few days. We would rather say that plainly than imply a feature that is not there.

If you have not signed up, none of this applies to you: /license clear removes the only thing that would ever have been sent.

One honest caveat

This page describes what the software does, precisely, because we wrote it from the source. It is not a lawyer's policy. If you need one for procurement or compliance, ask and we will get a proper review done — and if what you find here disagrees with the code, the code is what happens, so please tell us and we will fix the code or the page.