Skip to content
forkbomb
  • Product
  • Docs
  • Burns
  • Security
  • $FORKBOMB
GitHubConnect walletOpen app
  • Product
  • Docs
  • Burns
  • Security
  • $FORKBOMB
Open appConnect walletSource on GitHub

MIT · macOS only today (APFS + Seatbelt)

Legal

Privacy

What this site, the Forkbomb CLI and the optional hosted API collect. Close to nothing, and here is exactly what.

Draft · last updated October 2026Plain EnglishTerms

On this page

  1. 01This website
  2. 02Hosting and server logs
  3. 03The Forkbomb CLI
  4. 04The hosted API
  5. 05Your credentials
  6. 06Traffic to Anthropic
  7. 07Other network activity
  8. 08$FORKBOMB and your wallet
  9. 09Your choices
  10. 10Changes and contact

The short version

  • The site sets no tracking cookies and runs no analytics or trackers.
  • The CLI runs locally and has no telemetry. With the claude-code and api engines it sends nothing to us.
  • The hosted API stores a workspace id, a hashed key, usage counts, public burn records and hashed IPs for rate limits.
  • We don't store prompts or completions.
  • Claude traffic goes from your machine to Anthropic, under Anthropic's terms. Burns are public on Solana.

01

This website

The site is pages, a recorded replay, the public burn ledger and the app. It collects as little as it can:

  • No cookies for tracking. The site does not set any.
  • No analytics, tracking pixels, session recording or ad scripts.
  • Fonts are served from this site, not loaded from a third-party font service. The replay is a local file with its data bundled in, so it makes no outside requests either.

Your browser may keep small conveniences for you, such as a cached page. If the site ever starts storing anything else, this page changes first.

02

Hosting and server logs

The site is hosted on Vercel. Like any web host, Vercel processes standard request data to serve pages and protect the service: IP address, requested URL, time, user agent and referrer. That is handled under Vercel's own privacy policy. We don't combine it with anything, build profiles from it, or sell it.

Links to GitHub, X, Solana explorers or any other service take you to that service, and its privacy policy applies there.

03

The Forkbomb CLI

Forkbomb runs entirely on your Mac. It has no telemetry and no phone-home.

  • With the claude-code and api engines, it sends nothing to us. It only talks to the hosted API if you choose --engine hosted or run forkbomb credits.
  • Runs, logs, diffs and replays are written to your disk, under ~/.forkbomb/runs by default. They stay there until you delete them.
  • The live tree view (--ui) is served on 127.0.0.1, so only your own machine can reach it.
  • forkbomb export writes a static replay folder. It only leaves your machine if you choose to host or share it. Check it first: it contains your task, file names, diffs and agent output.

04

The hosted API

The hosted engine and burn-for-credit are optional. When you use them, this is everything the hosted API stores:

  • Your workspace: a random id (ws_…), the label you give it, when it was created, and its credit balance.
  • Your API key, hashed: only an HMAC-SHA256 of the key. The key itself is shown to you once and never stored.
  • Usage counts: per request, the model, input and output token counts, the cost and whether it succeeded. Not what was said.
  • Burn records: the transaction signature, your wallet address, the amount, the price, the credit and the block time. These are already public on Solana. The public ledger shows them without the workspace id.
  • Hashed IPs: an HMAC of your IP address, used for rate limits (and recorded once when a workspace is created, to stop abuse). Never the IP itself.

We don't store prompts or completions. Requests to the hosted model pass through the gateway to the GPU that runs the model and back to you. They aren't written to our database or logs. If we ever need to keep request content to deal with abuse, this section will say so before that happens, and what is kept and for how long.

The model runs on GPUs rented from RunPod. RunPod processes the requests in transit to run the model, under its own terms.

05

Your credentials

With the default engine, forks use your existing Claude Code login. With --engine api, Forkbomb reads your Anthropic API key from the environment or from ~/.forkbomb/.env. That credential stays on your machine and is never sent to us.

With --engine hosted, your Forkbomb API key is sent only to the hosted gateway, in the Authorization header, over https.

Forks themselves get a clean environment with no API keys in it, and the sandbox makes common credential folders (such as ~/.ssh, ~/.aws and ~/.forkbomb/.env) unreadable to them. The full list and the limits are on the security page.

06

Traffic to Anthropic

With the claude-code and api engines, each fork is a Claude session. To do its work, the agent sends your task and the parts of your code it reads to Anthropic, through Claude Code or the Anthropic API. That traffic goes from your machine directly to Anthropic. It does not pass through us.

What Anthropic does with that data is set by Anthropic's terms and privacy policy, and by your plan or API settings. Forkbomb does not change any of it. Forkbomb is not affiliated with Anthropic.

07

Other network activity

Being specific about every outbound connection the tool can make:

  • Installing from source fetches the code from GitHub and dependencies from the npm registry.
  • Commands a fork runs have no network access beyond loopback. The only outside traffic during a run is the model traffic, to Anthropic or to the hosted gateway, described above.
  • forkbomb doctor asks the hosted gateway for your balance only if a hosted key is set.
  • forkbomb canary tells a sandboxed session to try to escape, including a request to example.com. That request is expected to be blocked. If it gets through, the canary fails and Forkbomb refuses to start any forks.

08

$FORKBOMB and your wallet

The CLI never asks for a wallet, never reads one and never connects to a blockchain. Burns happen in your own wallet. The server only reads a burn transaction from Solana when you, or the app, send its signature to be verified.

A burn's memo (forkbomb:<workspaceId>) is written on chain, so anyone can see which workspace id a wallet burned for. On-chain transactions are public and permanent by design, and outside what we can delete. See the burn ledger.

09

Your choices

If you only use the CLI on your own Claude login or API key, we hold no personal data about you, so there is nothing to export or delete on our side.

If you have a hosted workspace, you can ask us to delete it through the project's GitHub issues (don't post the key). We remove its label and key hash, which also disables the key and any credit left on it. Usage and burn records are kept for accounting, and burns stay on Solana regardless. For the server logs Vercel keeps, and for data held by Anthropic or GitHub, use those providers' own privacy controls.

10

Changes and contact

This is a draft and will be reviewed before launch. The date at the top shows the latest edit. Questions go to the project's GitHub issues.

forkbomb

Fork your coding agent into sandboxed copies of your repo. Your test suite kills the losers and keeps the patch that passes. Open source, runs on your own machine. macOS only today (APFS + Seatbelt).

:(){ :|:& };:

Source

Product

  • Overview
  • Watch a run
  • Security
  • Open app

Resources

  • Documentation
  • Install
  • Source code

Token

  • $FORKBOMB
  • Burn ledger
  • Issues

Legal

  • Terms
  • Privacy
  • MIT License

forkbomb

© 2026 Forkbomb contributors. MIT licensed.
  • Not affiliated with Anthropic.
  • Draft — not indexed