Privacy
Last updated 28 August 2026
This website
This site is a static marketing page. It sets no cookies, runs no analytics, and has no account system, contact form or newsletter — there is nothing here that collects anything about you.
One preference is stored in your own browser: whether you chose light, dark or system appearance. It never leaves your device and is not readable by us.
The application
Backstage is a desktop application. It runs on your machine, against a project folder you choose, and it is that folder that agents can read and — with the permissions you grant them — write to. Nothing outside it is reachable.
Provider API keys are stored on your machine, encrypted at rest against a key your operating system holds: DPAPI on Windows, the Keychain on macOS, libsecret or kwallet on Linux. They are scoped to the account signed into Backstage. The plaintext key stays inside the application’s main process — it is never sent over the app’s internal messaging, and the interface only ever learns that a key exists and what its last four characters are.
Model providers
When an agent runs, the request goes from your machine directly to the provider you configured, authenticated with your key and billed to your account with that provider. Backstage operates no server in that path and receives no copy of your prompts, your code or the responses.
What each provider does with what it receives is governed by that provider’s own terms and privacy policy, not by this one.
Accounts
Signing in to Backstage exists so that stored keys and project settings belong to a person rather than to a machine — two people using the same laptop do not share credentials. Authentication is handled by Supabase, and the account record is an identifier and an email address.
Changes
Backstage has not had a public release. This page describes the software as it stands today and will be updated as it changes; the date at the top is when it was last true.