Your code stays in the tab

When you paste, three files already in your browser do the detecting, transforming and rendering: /extension/detect.js, /extension/transform.js and /web/app.js. Compilers load on demand, as described below. All of them run locally. There is no upload, no form submission, no API call and no CodeRush server-side endpoint that receives what you typed.

The pad loads its own static files from this same domain. Pasting adds no request of its own. An empty pad does not fetch the compilers or boot a sandbox; those load the first time they are needed. A markdown snippet downloads /extension/vendor/marked.min.js, and the first JSX or TSX snippet downloads /extension/vendor/babel.min.js, because it is 2.8 MB and an empty pad should not pay for it. Both are plain GETs for files that ship with the site, and they carry nothing of yours — the compiling happens here, in your browser. AI editing is the deliberate exception: pressing the AI send button makes a direct request to the provider you selected. The separate Refresh models control contacts OpenRouter for its public catalogue without sending your source, prompt or key. Both actions and their boundaries are described below.

Rush links never become server files

A Rush puts its complete payload after the # in the URL. Browsers do not send URL fragments in HTTP requests, so Vercel and CodeRush never receive that payload. The recipient’s browser reads the fragment and reconstructs the source locally. Rushes are limited to 64 KB so the result remains a practical browser link.

A public Rush is encoded, not encrypted. A private Rush is encrypted with AES-GCM and includes its random decryption key in the complete link, so possession of the link is access. A password-protected Rush is encrypted with a key derived from the password; the password is not in the link and should be sent separately. None of these links can be revoked because there is no server-side copy to delete. Share them with the same care you would share the source itself.

AI editing is direct and opt-in

Nothing is sent to an AI provider while you type, paste, run, switch views, open the AI panel or create a Rush. When you press the AI send button, your request and current source are sent directly from this browser to the selected provider: OpenRouter, OpenAI, Anthropic or Google. CodeRush has no proxy in that path and cannot read the request, response or key. The provider’s own data-use and retention terms apply to that deliberate request.

Refresh models is another explicit network action. It sends a plain GET to OpenRouter for the current public model list. It does not carry your source, prompt or API key, but OpenRouter can receive ordinary connection metadata such as your IP address, browser details and request time. The bundled choices and custom model field work without using it.

API keys live in memory for the current tab by default. If you choose Remember keys in this browser, they are stored as plain text in this device’s localStorage under cr:ai-settings. They are not encrypted and anyone who can access this browser profile or run code in this page’s origin may be able to read them. Forget saved keys removes that record. Use restricted, low-limit keys and provider spending controls whenever possible.

Nothing is kept on a server

The only place your snippets are saved is your own browser's localStorage, under three keys: hr:history holds up to 24 local snapshots, hr:last holds the combined source in the pad, and cr:project holds the optional index.html, style.css and script.js workspace so a reload returns to the same file. Files are combined locally before a preview, snapshot or Rush link is made; no project archive is uploaded. Running creates a snapshot automatically; Save lets you name one, and snapshots can be renamed or pinned. Before a restore replaces an unsaved current draft, CodeRush checkpoints that draft locally and offers Undo. If the checkpoint cannot be stored, the restore is cancelled and the editor stays unchanged. All of it lives on this device only.

Download backup exports those snapshots as a local JSON file; importing that file merges its snapshots back into this browser. Clear shows the number of snapshots, offers that backup first, and deletes all three snippet keys only after confirmation. That is the complete erasure — there is no server copy to ask anyone to restore. If you keep typing afterwards, the pad starts saving your current draft again.

Problems checks source in this tab without creating a preview. JavaScript, JSX and TSX are parsed by the vendored Babel file; markup and styles are inspected in a detached document. The check does not execute source or make a network request.

Usage analytics: counts, never content

CodeRush.run measures how the product is used with BetterMeter, a privacy-first analytics service built by the same team. It counts page visits and named actions such as run, paste, view or ai_request, with small facts next to them: the detected format, the view, a line count, a model name. An event never carries your source, a Rush fragment, an API key, a password or a prompt; the pad scrubs every property before it leaves, and a test pastes a marker and proves it never appears in an analytics request.

The tracker is served from this domain at /bm/, which forwards to BetterMeter, so the page never contacts another host on its own. The tracker sets no cookies and uses no browser storage; it honours Do Not Track and Global Privacy Control. There is no session recorder, no advertising code and no third-party script on this site. A selected AI provider sees a request only after you press send; that request is product functionality, not analytics.

The extension watches only sites you enable

Installing the Chrome extension grants no blanket access to websites. Page buttons are an optional permission for the single site named in the popup. Once enabled, a local content script scans code blocks on that site and watches new streamed text so it can attach Run controls. It does not send the page or those blocks anywhere.

The site grant persists in Chrome so the buttons return after reload. Turning it off removes the injected controls, stops the page observer, unregisters future injection and removes that site's permission. Running selected text from the context menu and pasting into the popup do not need page access.

The snippet runs locked in

Your snippet renders inside an <iframe> with a sandbox attribute that permits scripts but withholds allow-same-origin. The frame therefore has an opaque origin: code inside it cannot read this page, its localStorage, or its cookies. Trying throws a SecurityError, and a test in this project asserts that it does.

Images, styles, frames, forms and links pause before their first network request, including requests back to the hosting origin. The review surface names each host. Run offline removes those destinations and applies a restrictive document policy with no scripts, forms, popups or connections. After you allow JavaScript, that code can construct further network requests dynamically, so review active code just as you would before opening an .html file.

What the host can see

The static files are served by Vercel. Like any web host, it records ordinary request logs: your IP address, the time, the path requested, and your browser's user agent. Those entries describe which files your browser asked for — /, /web/app.js, and so on.

Running code is never part of those requests, and Rush fragments are never sent in them. AI requests go straight to the chosen provider, not through the host, so the host’s request logs still do not contain your source or API key.

Optional password protection

A deployment of this site can be put behind a password. When it is, the password is checked at the edge, before the page loads, and your browser is given a session cookie recording only that a correct password was entered. The password itself is not stored in the cookie. This is a lock on the front door; it changes nothing about where your code is processed.

Don’t take our word for it

Open your browser's developer tools, switch to the Network tab, then paste some code and run it. With no network destinations in the snippet, you will see requests for this site's own files and nothing else, all of them GET, none carrying your snippet. Paste a remote image and CodeRush pauses before requesting it; choose Run offline and the request stays absent. If you send an AI request, you will see one POST directly to the provider you selected.

The source is plain, unminified JavaScript you can read: /web/app.js, /web/ai.js, /web/rush.js, /extension/detect.js, /extension/transform.js. And the claim is tested, not just written: a test in test/web.test.mjs records every single request the page makes from load through render, and fails if any request is not a same-origin GET during ordinary run operations, or if any request URL or body contains the pasted code. Separate tests assert that network hosts pause before contact, Safe Mode stays offline, Console commands stay inside the current sandbox and its tab-only history, Rush content stays in the fragment and AI goes only to the provider the user explicitly chose.