Governance · Effective September 28, 2026
Security & privacy
MoneyBug App Events Guard runs locally.
- It does not include telemetry or analytics.
- It does not make network requests.
- It does not upload repository files, event JSON, findings, credentials, or tokens.
- It reads supported source files under the selected repository path.
first-runalways writes a local report;scanandvalidate-eventwrite only when--outputis supplied;initwrites.moneybug.jsononly when explicitly run. - Reports can contain relative filenames, line numbers, rule evidence, and short source-derived labels. Fixed idempotency-key values are not copied into evidence; only their length is reported.
- Order and payment information is processed by the merchant of record shown at checkout, under that provider's privacy terms. The CLI never receives it.
Review a report before publishing it because it can contain repository-specific filenames and evidence labels.