AI code review that does not upload my code?
Last updated September 24, 2026
DiffGuardian never uploads your code to its own servers for AI review: your diffs go only to the AI backend you choose — your own cloud provider key, or nowhere at all with a local model. DiffGuardian's servers handle only sign-in, billing, and plan status.
#Where your code goes
| What | DiffGuardian's servers | Your chosen cloud provider | A local model |
|---|---|---|---|
| Code, diffs, AI prompts and AI responses | Never | Sent directly from your machine to the provider, authenticated with your own key | Never — stays on your machine; requests go to localhost only |
| API keys and code-host tokens | Never — encrypted in your operating system's credential store, used only on your device | Used to authenticate you directly to the provider | Not applicable |
| Account sign-in, billing and plan status | Yes — this is what DiffGuardian's servers handle | Not applicable | Not applicable |
#Limits
- DiffGuardian's servers still handle sign-in, billing and plan status — the app is not offline entirely, only the AI review path is private by design.
- With a cloud provider key, your code is governed by your agreement with that provider, not DiffGuardian's.
- A fully local, no-upload setup needs a model server running on your machine — Ollama, LM
Studio, llama.cpp's
llama-server, or vLLM.
FAQ
Does my code ever touch DiffGuardian's servers?
No. Code, diffs, prompts and AI responses never reach DiffGuardian's servers. They go only to the AI backend you choose — your own cloud provider key, or nowhere at all with a local model.
What do DiffGuardian's servers actually receive?
Only what's needed for sign-in, billing and your plan status. They never receive your source code, diffs, prompts, or AI responses.
Is there a way to keep my code fully on my own machine?
Yes. Point DiffGuardian at a local model server — Ollama, LM Studio, llama.cpp's llama-server, or vLLM — and requests go to localhost only; nothing is transmitted anywhere. This is available on every plan.
If I use my own API key, who can see my code?
Only you and the provider you chose. Requests go directly from your machine to that provider, authenticated with your key, and are governed by your agreement with them, not DiffGuardian's.