Privacy

Privacy Statement

Data Collection

Uppidi Fleet collects no personal data, no telemetry, and no usage analytics. It is a self-hosted Paseo plugin that runs entirely on your infrastructure.

What Runs on Your Machines

  • Paseo daemon — runs locally or on your server; manages agents, worktrees, and the plugin.
  • Uppidi Fleet plugin — runs inside the Paseo process; includes the webhook router (Node HTTP server on localhost by default).
  • Hook router — receives Forgejo/Gitea webhooks; queues and delivers events to Paseo agents. No external connections.
  • Agents (LLM calls) — your configured AI provider (OpenAI, Anthropic, local models, etc.) receives prompts you send. Review your provider's privacy policy.
  • Forgejo/Gitea — your self-hosted or third-party forge; stores issues, comments, labels, and webhook secrets.

Network Connections

Component Outbound Connections
Paseo daemon Your AI provider API (per your config); your Forgejo/Gitea API
Hook router None (listens on localhost by default); Forgejo posts webhooks to it
Cockpit UI None (served by Paseo's internal static server)

No connections to uppidi.com, paseo.dev, or any third-party analytics.

Stored Data

  • Queue files — ~/.paseo/plugin-data/xpufx/uppidi-fleet/queues/ (persisted webhook messages, deduplicated, capped at 50 per repo)
  • Router state — ~/.paseo/plugin-data/xpufx/uppidi-fleet/orchestrators/ (frontdesk registration, orchestrator registrations, router config)
  • Router config (legacy) — ~/.config/uppidi-fleet/router-config.json (fallback location)
  • Paseo agent state — ~/.paseo/agents/ (agent metadata, worktrees, lifecycle)
  • Role models — ~/.paseo/uppidi-fleet-role-models.json (your model selections per role)
  • Metrics rollup — ~/.paseo/plugin-data/xpufx/uppidi-fleet/metrics.json (per-provider/model usage receipts)

All stored locally on your machine/server. No cloud sync.

Webhook Secret

The router reads FORGE_HOOK_SECRET but does not currently verify the X-Forgejo-Signature header. Keep the listener on loopback (127.0.0.1) or place an authenticating reverse proxy in front if exposed publicly.

Third-Party Services

Uppidi Fleet itself integrates with no third-party services. Your configured AI provider and Forgejo/Gitea instance are under your control.

Changes

This policy may be updated as the plugin evolves. Check the GitHub repository for the latest version.

Contact

Questions: open an issue on github.com/xpufx/paseo/issues.