Skip to content

Privacy ​

Cully watches your coding sessions, so it is specific about what it keeps. Your conversations are not Cully's database.

text
Agent conversation
       │
       │  hooks send one small event per tool call
       ▼
┌──────────────────────────────┐
│ Session journal (local)      │   when · agent · kind of tool
│                              │   passed or failed
│                              │   file path + operation
│                              │   program + subcommand
└──────────────────────────────┘

Never recorded:  prompts · file contents · diffs · command arguments
                 tool output · environment values · URLs · credentials

The session journal ​

RecordedExampleWhy
Time and agent10:34, Claude CodeTimeline and replay
Kind of tooledit, check, search, memory callLoop detection, status
Passed or failedcheck failedVerification and risk
Project-relative file path and operationinternal/auth/resource.go, editedReplay and file activity. Taken from file tools only, never from shell text
Program and recognized CLI subcommand of a commandgo test, git commitReplay
A one-way hash of a normalized command3f9a1c07Spotting the same failing command repeated, without keeping the command
Fixed notesa loop was detectedTimeline

Paths outside the project are dropped, as are URLs and other schemes. Paths longer than 200 characters are dropped. Shell commands contribute a program and, when it matches a fixed list of CLI verbs, a subcommand. Free-form targets and script names are omitted.

Not recorded: prompts, file contents, diffs, command arguments, tool output, environment values, URLs, credentials and transcripts.

The journal is stored in your Cully directory on your machine, readable only by you, bounded in size per session, and pruned after 30 days or beyond the newest 40 sessions. It is never uploaded by Cully.

Turn path and command recording off ​

sh
export CULLY_JOURNAL_PATHS=0

With this set, the journal still records the kind of tool and whether it passed. Replay then shows activity without file names or commands, and says so.

Project memory is separate ​

The journal is local and automatic. Project memory is different: your connected agent chooses what is worth keeping and saves a short summary through its own MCP connection. Hooks do not upload transcripts. See memory for what a saved note contains.

The local advisor does not hold your agent's OAuth credentials.

Explicit team sharing ​

Workspace tasks, criteria, selected checkpoints, branch/artifact references and reported checks are visible to authorized project members. Separate workspace actions author this content; the journal and private memory are never imported automatically. Do not include transcripts or credentials. The same credential-pattern validation used for memory applies; it cannot guarantee arbitrary prose is safe to share.

Draft lessons are visible only to their author while that author retains project access. learning_publish shares the lesson with its project; learning_edit makes it private again, and learning_unshare or learning_delete removes it from shared lookup immediately. Dependent playbooks stop appearing. There are no shared semantic projections or managed lesson caches yet. Membership removal denies subsequent reads and writes; Cully cannot erase material already read or exported.

Audit events contain actor, action, target IDs and timestamp, without checkpoint or lesson text. Operators access them in the private database; they are not a coworker activity feed. Agent/session metadata is declared, with no inferred productivity scores or automatic journal uploads.

Where file names can appear ​

  • In cully replay, cully timeline, cully handoff and cully rescue output on your machine.
  • In the advisor's prompt only as part of an evidence block you can read in the command's output. File contents are never sent.
  • In a replay HTML file you generate. It contains paths and command names, no file contents. Treat it like a build log before you share it.

Built in the open. Apache 2.0 licensed.