CodeOtter respects your privacy and is committed to absolute data sovereignty.
CodeOtter does not send your source code, pull request diffs, review comments, or developer metrics to any central server or telemetry service. All data resides within your local deployment or designated database.
When configuring hosted LLM providers (e.g. Claude, OpenAI, MiniMax, OpenRouter), requests are sent directly from your server to the provider API using your private API keys. When using local sidecars (GGUF, laya, llama-server), no external traffic is generated.
Sign-in is managed via GitHub OAuth directly to your self-hosted PocketBase instance. OAuth tokens and user records are stored exclusively in your local database.
Autonomous PR scoring with Dual-Engine rubrics (System One + LLM) and air-gapped local GGUF sidecars.