Data and privacy

Conversations and settings are saved locally. To answer a request, fx sends the relevant context to your selected provider. Networked tools send data to the services they use.

Model request data

Each model request includes your prompt and the context assembled for that turn. Context can include conversation history, applicable AGENTS.md and skill instructions, attached images, and file or tool content already loaded into the session.

fx does not automatically package or upload your workspace, Git history, session files, traces, or recordings. That data can still leave the machine when it is loaded into model context or sent by a networked tool.

Context compaction sends older prompts, responses, tool calls, and tool results to the current session model for summarization. Reviews in auto mode, vision fallback, and generated session titles can also make additional model requests. Titles use up to 2 KiB of the first prompt; disable them with session_titles: false. See Additional model requests.

Where requests go

Your selected connection determines where model requests go:

ConnectionWhere fx sends model context
CodexThe service associated with your ChatGPT subscription
GrokThe service associated with your Grok subscription
AI GatewayGateway, which forwards the request to the selected model provider
Custom connectionThe endpoint configured in base_url

Remote requests are subject to the selected service’s data controls and retention policy. MCP servers and web search send requests to their own services.

Local credentials and sessions

fx stores settings, saved sign-ins, conversations, prompt history, usage records, MCP configuration, and installed skills under ~/.fx/. Debug traces and opt-in recordings also go there by default.

On macOS, a saved API key lives in Keychain. On Linux, it lives in ~/.fx/api-key with 0600 permissions. MCP OAuth credentials also use Keychain on macOS when available; see OAuth configuration for the file fallback.

Session files remain local, but fx sends the relevant conversation context again when you continue a session. Use fx ask --no-save when a one-off request should not create a session.

Product telemetry

fx does not send product telemetry or usage analytics to a separate fx service. fx usage reads local usage records, and /trace assembles diagnostics locally.

Update checks

Automatic updates are on by default. Native fx reads static release metadata after startup and every 30 minutes until an update is ready. The request contains no fx-generated machine or installation identifier. Set FX_AUTO_UPGRADE=0 to turn automatic updates off.

Local inference

Use a custom connection to send model requests to a local server such as Ollama. Update checks, web search, and remote MCP servers can still contact external services.

Sharing diagnostics

/trace creates a local diagnostic report and copies it to your clipboard when supported. If clipboard copying fails, fx leaves the report in a local temporary file. /feedback opens the feedback form without uploading diagnostic data.

Review and redact prompts, code, paths, commands, model output, and secrets before sharing a trace or recording. See Share feedback for details.

AI Gateway controls

For a Gateway connection, account and team settings apply to requests from fx. See Gateway's Zero Data Retention settings for its routing and retention controls. Those settings apply to Gateway requests, not to separate Codex or Grok connections.