Skip to content
Lazarus
Home Privacy Terms Notices

Privacy Policy

Last updated October 10, 2026 · Applies to Lazarus for macOS 1.0 and later, The Odyssey, and this website.

Lazarus is published by Odyssey Developments (Florida, USA), referred to here as "we" and "us". Privacy questions and requests go to dev@odysseydevelopments.dev.

The short version

  • The IDE has no account and no server of ours. Your code, chats and API keys stay on your Mac. We do not receive them.
  • When you message an agent, your content goes to the AI company behind that agent: Anthropic, xAI, Cursor (Anysphere), OpenAI or Google. Their privacy terms apply to it.
  • The Odyssey is the exception. It is optional, and it runs on a relay we operate. It stores your public GitHub name and avatar, the profile you build, and your direct messages.
  • This website sets no cookies for visitors and runs no advertising. It counts visits with our own cookie-free, anonymous page counts (see section 4).
  • The Lazarus app has no telemetry, analytics, ad tracking or crash reporting. We never sell your data.
  1. The Lazarus app on your Mac
  2. What leaves your Mac
  3. The Odyssey
  4. This website
  5. AI providers
  6. Legal bases (EEA and UK)
  7. Retention and deletion
  8. Your rights
  9. Children
  10. Security
  11. International transfers
  12. Changes and contact

1. The Lazarus app on your Mac

Everything below is stored locally, and you can delete all of it from Settings ▸ Privacy & data.

DataWhereWhy
Chat transcripts: your messages, agent replies, reasoning summaries, tool actions, token counts~/Library/Application Support/Lazarus/Transcripts/, readable by your user onlyRestore chats when you reopen the app
Settings, recent folders, chat titles, models, permission levels, usage countersmacOS preferencesRemember your setup
API keys you enter, your GitHub token, the Odyssey trial start datemacOS Keychain, this device only, not syncedCall providers, run git as you, keep the trial clock
Your GitHub username, display name and avatar link, if you link GitHubmacOS preferencesShow who is signed in
Shared agent context: short digests of what each agent did.lazarus/context.jsonl inside your project, git-ignored automaticallyTell agents what the others changed
Screenshots and Simulator snapshots you take; build output; Blueprint filesYour project's .lazarus folder or ~/Library/Caches/LazarusAttach to messages, speed up builds, show your project
Cookies and local storage of pages in the web previewWebKit storage in the appNormal browser behaviour

The code editor (Monaco) is bundled in the app, works offline, and its page is locked down so it cannot contact outside servers.

2. What leaves your Mac

Lazarus sends data only when you use a feature that needs it.

Messages to AI agents

When you send a message, Lazarus passes the agent you chose: your text; the open file or selection, and any files or screenshots you attach; a summary of what other agents or you changed since that agent's last turn (API agents receive diffs and the file tree); the project folder name; and the earlier messages of that chat.

  • API-key mode (Claude, Grok): sent over HTTPS to api.anthropic.com or api.x.ai with your key.
  • Sign-in (CLI) mode (Claude Code, Grok Build, Cursor, Codex, Gemini): Lazarus runs that company's command-line tool on your Mac with your message. The tool talks to its company under your account and can read and change files in your project according to the permission level you set. Lazarus does not see or store your sign-in with those tools. Codex signs in with your ChatGPT account.
  • Claude cloud sessions, if you start one, run on Anthropic's infrastructure under your account.

Other network use

  • Inline suggestions are off by default. If you turn them on, up to 4,000 characters before and 1,500 after your cursor, plus the language, go to Anthropic's API with your key.
  • Model lists: your API key is sent to the provider to fetch the models available to you.
  • GitHub. If you link GitHub (device sign-in, a pasted token, or the GitHub CLI's token), Lazarus requests the repo and read:user permissions. That lets it list your private repositories, clone, and run git as you. The token lives in your Keychain and is sent only to github.com and api.github.com. The Hub stores your team's chat, notes, snippets and tasks on a branch of your own GitHub repositories, so everyone with access to that repository can read them. GitHub's privacy statement covers that data. You can revoke Lazarus in your GitHub settings at any time.
  • Blueprint logos. The Blueprint is drawn locally, with no model call and nothing about your code sent anywhere. To show a logo for each technology it finds, Lazarus requests that technology's public icon by name (for example "react") from the jsDelivr CDN and caches it. jsDelivr sees your IP address and which public icon names were requested.
  • Phone push (optional). If you switch it on, notification titles and text are posted to a random topic on ntfy.sh (or a server you choose). Anyone who knows the topic name can read those messages, so keep it private.
  • Web preview loads whatever address you enter. Installers in Settings run the vendors' official install and sign-in commands only when you press them.
  • MCP servers and skills you install connect to their own services under their own terms.
  • Downloads and updates. The installer is served from GitHub Releases. Lazarus has no background update service of its own.

3. The Odyssey

The Odyssey is an optional multiplayer world inside Lazarus for people 18 and over. Unlike the rest of the app, it connects to a relay we operate, hosted on Render in the United States, and what you do there is visible to other players. You can use the IDE without ever opening it.

What we collect and store

DataWho can see itKept
GitHub login, display name and avatar URL, from "Sign in with GitHub". The sign-in requests no permissions. The relay uses GitHub's token once to read your public profile, then discards it, and keeps only its own signed 30-day session.Other playersUntil you erase it in the app (or ask us to)
Profile details you add: headline, what you are building, LinkedIn and website links, flairs, character look, petOther players. LinkedIn and website links are shown on your profile card.Until deleted
Your startup, office and decor, guestbook entries, ratings, hypothesis answers, event, office-hour and hackathon sign-ups, quest and rank progressOther players, as shown in the worldUntil deleted
Your first-seen date (it times the 30-day trial) and whether you hold the PassUsKept even after you erase your data, so a trial cannot be restarted and a Pass you bought is not lost. Email us to remove it too.
Connections and requests; direct messages that could not be delivered live (up to 200 per recipient)The people involved, and us when needed to run or moderate the service. DMs are not end-to-end encrypted.Until delivered or you ask for deletion
Images and showcase pages you upload (profile pictures, screenshots, pitch decks)Anyone with the file's address, not only playersUntil deleted
Your position, emotes and chat (local, global and event) while you are onlinePlayers in the same area, or everyone for global chatRelayed live; we do not keep a chat history
An aggregated summary of your Blueprint, only if you and the repository owner approve showing it. Never commit messages, emails or file paths.Other players, at your boothUntil you remove it

When you are offline, your character may appear in the world as an "away" stand-in so your HQ is not empty. Guests (no GitHub sign-in) get a random guest name and limited features.

Voice

Voice for meetings and events is peer to peer over WebRTC. Audio goes directly between participants and is not recorded or relayed by us; the relay only decides who may speak. To connect, your browser engine contacts Google's public STUN servers, and the other participants can see your IP address. Turn voice off if that matters to you.

Embedded media and links

A presenter can show a YouTube, Vimeo or Loom video or a web demo. Those providers load content on your Mac when it plays and can see your IP address. Links to LinkedIn and personal sites take you to those sites.

Payments

The Odyssey Pass is a one-time purchase made through Apple's in-app purchase system. Apple processes the payment and handles tax; we never see your card. We receive a signed receipt, verify it with Apple's certificate chain, and record that your GitHub login holds the Pass.

Hosting and moderation

Render hosts the relay and, as any host does, can see connection metadata such as IP addresses in its logs. A small number of administrators can see stored Odyssey data to moderate, approve startups and events, and fix problems. The relay applies rate limits, a chat filter and temporary mutes automatically.

4. This website

  • No cookies for visitors, no advertising, no tracking pixels, no third-party analytics. Fonts and images are served from this site.
  • Anonymous page counts. A small script on this site tells our own server which page you viewed, the website you came from (and any utm_ campaign tags in the link), your approximate location (country, region and city, from your IP address, which we do not store), your browser, operating system and device type, your window width and language, how long the page stayed in view, how far you scrolled, which sections you reached, and whether you clicked the download button or an outside link. It does not store anything on your device beyond a page counter and your first referrer in session storage, which your browser clears when you close the tab. To count "different people today" the server computes a one-way hash of your IP address and browser details mixed with a secret and the date; it changes every day, cannot be reversed, and cannot follow you from one day to the next. The counts are kept in aggregate (for example "42 page views from Germany today"), not as a list of individual visitors. We use them to see which pages help and what to fix. The script does nothing if your browser sends Do Not Track or Global Privacy Control, and it ignores bots.
  • Staff sign-in. Two Lazarus developers can sign in with GitHub to read these counts. That sets one cookie in their browser (a signed, HttpOnly session cookie). Nobody else gets a cookie, and visitors cannot sign in.
  • Hosting. Vercel serves the site and keeps standard server logs (IP address, browser, pages requested).
  • The download button. When the page loads, your browser asks GitHub's API for the latest release so the button always points at the newest installer. GitHub sees your IP address. The installer then downloads from GitHub Releases.
  • The feedback form. If you use it, we receive what you type: the type of message, your name and email (optional), subject, message, Lazarus and macOS versions (optional), screenshots you attach, the page address and your browser's user-agent string. To limit spam, the form also keeps a keyed one-way hash of your IP address and of your message for 24 hours; your raw IP address is not stored. It is filed in a private GitHub repository we control. We use it only to reply and to improve Lazarus. Screenshots may contain personal information, so please check them before attaching. To remove a message, email us.
  • Email. If you email us, we keep the correspondence as long as it is useful, then delete it.

5. AI providers

What an AI company does with your content, including retention, training and where it is processed, is set by your agreement with that company, not by us, and often depends on your plan and settings. Please read their policies: Anthropic, xAI, Cursor, OpenAI and Google. Do not send secrets, other people's personal data or regulated data to an agent unless your agreement allows it. In sign-in modes, agents can read any file in your project folder. We do not sell your data, share it for advertising, or use it to train models.

6. Legal bases (EEA and UK)

For the IDE we hold no personal data on our servers, so we are generally not a controller of what you send to AI providers or GitHub. For the Odyssey relay and for support email and feedback, we are the controller. We rely on performance of a contract (running the Odyssey features you ask for), our legitimate interests (security, abuse prevention, answering you) and, for optional features such as showing your profile, your consent, which you can withdraw by deleting the data or asking us to.

7. Retention and deletion

  • On your Mac: data stays until you delete it. Use Settings ▸ Privacy & data to remove chats, keys and GitHub sign-in, project files, web data, or everything at once. Deleting the app does not remove the files it made.
  • The Odyssey: Settings ▸ Privacy & data ▸ Erase All Data also asks the relay to delete your profile, startups, messages, connections, votes, guestbook notes, events, bookings and team seats, and disconnects you. The relay keeps only your first-seen date and whether you hold the Pass (see section 3); email us to remove those as well. Uploaded images and showcase pages are kept until we remove them, so email us to have them deleted. Deletion requests by email are handled within 30 days, except what we must keep for legal reasons or security (for example a moderation record).
  • Third parties: data already sent to an AI provider, GitHub, ntfy or others must be deleted with them. Revoke the GitHub token in your GitHub settings.

8. Your rights

Depending on where you live (GDPR, UK GDPR, California's CCPA/CPRA and similar laws) you may have the right to access, correct, delete, restrict, object to and port your personal data, to withdraw consent, and to complain to your data protection authority. Email dev@odysseydevelopments.dev. We verify requests against the account or email involved and respond within 30 days, or 45 where California law allows. We will not penalise you for exercising a right.

California and other US states: we do not sell or share personal information for cross-context advertising, and we have not in the last 12 months. We do not use or disclose sensitive personal information to infer characteristics about you. We honour "Do Not Track" and Global Privacy Control signals on this website by not counting your visit.

9. Children

Lazarus is a developer tool for people 16 and over. The Odyssey is for people 18 and over because it includes open chat, direct messages and meetings with strangers. We do not knowingly collect data from anyone younger. If you believe a child has used the Odyssey, email us and we will delete the data.

10. Security

API keys and tokens are stored in the macOS Keychain for this device only. Transcripts and context files are readable by your user only. Network calls use HTTPS or secure WebSockets. Lazarus uses the macOS Hardened Runtime, but it does not use the App Sandbox because it must run git, Xcode tools and agent CLIs, so it can access any file your user can. The Odyssey relay rate-limits and signs sessions, but no system is perfectly secure. Report vulnerabilities to dev@odysseydevelopments.dev (see security.txt).

If a breach of the Odyssey relay put your personal data at risk, we will tell affected users and regulators as the law requires.

11. International transfers

The IDE transfers nothing to us. If you use the Odyssey from outside the United States, your data is sent to and stored in the United States. Your chosen AI providers, GitHub and other services may process data in the United States or elsewhere; see their policies.

12. Changes and contact

When this policy changes we will update the date above, and describe material changes in the release notes. Questions: Odyssey Developments, dev@odysseydevelopments.dev. We have not appointed a data protection officer or an EU/UK representative; write to the address above for anything privacy-related.

© 2026 Odyssey Developments
Home Privacy Terms Notices Support