OpenCode privacy concerns mount over app.opencode.ai proxy
Users are raising alarms over OpenCode's "local-first" claims, discovering that the Web UI proxies all internal requests through app.opencode.ai by default. This "phone-home" behavior, coupled with automatic prompt uploads for session titling, has triggered a push toward privacy-focused forks like RolandCode.
The gap between OpenCode's marketing and its technical implementation is a major red flag for the local LLM community. The Web UI's reliance on a central proxy means sessions are never truly air-gapped without manual network intervention, while "Zen" session titling silently uploads user prompts to external servers. Maintainers' stance on data retention for free-tier models contradicts the privacy-first ethos many users expect, leading to the rise of community-led forks like RolandCode that strip telemetry and vendor the model catalog locally. For true isolation, users are forced to rely on firewalled Docker containers rather than the application's built-in settings.
DISCOVERED
5h ago
2026-04-20
PUBLISHED
6h ago
2026-04-19
RELEVANCE
AUTHOR
No_Algae1753