their recent changes to the privacy policy broke their promise of zero data retention. specifically, they offered chatgpt luna under a zero data retention privacy policy. luna was later shown to be 30 days retention.
their privacy policy has never guaranteed your prompts will not be logged and when asked they have failed to revise it.
when challenged about sending data to openrouter without listing it as a 3rd party processor they offered a dismissive response. the same with running prompts through cloudflare. seems trivial, but signifies general disinterest in security.
by default if you run the harness outside your config file by accident, it will automatically run silently with a free model that sends your prompts and local data to an endpoint with training enabled. on top of that it used to dump all the prompts sent to free models into an s3 bucket, the feature was literally called 'datadumper' in the source.
For instance, this "marketing" claim that it'll take 24y to break even if a user only uses 100m tokens/day (~$1.14 in DeepSeek v4 Flash usage) ignores the fact that OpenCode Go has 5h & weekly throttles. Besides, folks who self-host models usually run automated jobs [0]. I think the GPU setup could possibly serve 10+ "users" concurrently, bringing down the break even by 22y (10x).
[0] For comparision, we routinely do 200m to 500m tokens ($2 to $5) on merely 3 to 8 automated code reviews per day with DeepSeek v4 Flash on max.