ncode CLI Help
Data and privacy
What stays on your Mac#
ncode is local-first. There is no account to create and no ncode server in the middle: everything it keeps is on your Mac.
- One SQLite database,
~/Library/Application Support/SwarmCode/swarm_code.db, holds your conversations, runs, agent steps, settings, provider and search keys, MCP settings, schedules and usage. See where your keys are kept. - Pasted or dropped images are saved as files in
attachmentsinside~/Library/Application Support/SwarmCode; global memory and global commands live in the same folder. - Project memory, custom commands, workflows and agent definitions you add to a project live in its
.swarm_codefolder, next to your code.
What leaves your Mac, and where it goes#
Only what the features you set up need:
| Destination | What is sent | When |
|---|---|---|
| Your model provider | the conversation, instructions, and whatever the agents read or produced (file contents, command output) | every model turn |
| The search engines and readers you enabled | search queries and page addresses | when an agent searches or reads a page through a reader |
| Any web page an agent opens | an ordinary web request | when an agent uses web_fetch |
| The MCP servers you added | the tool calls agents make to them | when an agent uses one of their tools |
Opening a designed research report may also load web fonts from Google Fonts.
Commands the agents run on your Mac get a cleaned environment by default, so secrets in your shell variables are not handed to them.
What the terminal adds#
cli.json, beside the database, holds this terminal's own settings (theme, side panel, mouse, keys). It is readable only by you (mode0600) and at most 64 KB.- A log file,
cli.log, in the app's logs folder (see Names you may still see), readable only by you and rotated.ncodenever writes log lines to your terminal.ncode config pathprints its exact location. - Files
ncodecreates for itself are private to you: it runs with a077umask. Commands the agents run in your project keep your own umask, so the files they create look like yours.
Where your keys are kept#
Provider keys, search-engine keys and the environment variables or headers you give an MCP server are stored in the local ncode database on your Mac, ~/Library/Application Support/SwarmCode/swarm_code.db. They are not stored in the macOS Keychain.
What that means for you:
- Protect the database like the rest of your home folder: it holds your keys. Anyone who can read your files can read them.
- The provider list shows a key only in masked form, and when fetching a model list fails, the key is removed from the endpoint's error text before you see it.
- Commands an agent runs get a cleaned environment by default: variables whose names look like secrets are hidden from them.
GITHUB_TOKENandGH_TOKENare kept unless you change the list. - Deleting a provider or an MCP server deletes its stored secrets with it.
Keys reach ncode only by pasting them into Settings or through ncode config secret … --stdin; they are never read from command-line arguments, and never appear on screen, in the log, in undo, in search or in exports.
Names you may still see#
ncode had a different name before this release. The app and the command are new, but a few places keep the earlier name so your data, your projects and your scripts keep working. You do not need to rename anything.
| What | Name that stays |
|---|---|
| The app's data folder | ~/Library/Application Support/SwarmCode |
| The database | ~/Library/Application Support/SwarmCode/swarm_code.db |
| The per-project folder | .swarm_code in each project |
| Your own agent definitions | ~/.swarm_code/agents/ |
| The earlier app | SwarmCode.app (replace it with ncode.app) |
| The earlier terminal command | swarmcode (still works, as an alias of ncode) |
| Environment variables | NCODE_… are read first; the older SWARM_… names still work |
Two more paths still carry the earlier name:
- Deep research writes each research to
~/.swarmcode/research/<id>/. - The app's logs are in
~/Library/Logs/SwarmCode/.