Throughspec v1.0 - spec-driven development for Claude Code, now on npm + PyPIRead the docs
Legal

Privacy Policy

Last updated 12 June 2026

Throughspec is a command-line scaffolding tool that runs entirely on your machine. It is not a hosted service. We do not operate servers that receive your code, prompts, or project files.

Scope

This policy covers the Throughspec command-line tool and this marketing website. The tool executes locally; the website is a static informational site.

Because the Kit is a local scaffolder, the vast majority of your activity - prompts, source code, specs, and memory files - never reaches us.

Data that stays on your machine

All files the Kit generates - the claude/ memory layer, design/ assets, CHANGELOG.md, and your source - are written to your local filesystem and version control. We never receive them.

Your interactions with Claude Code are governed by Anthropic’s own terms and privacy policy, not ours.

Information we may collect

Package registries (npm and PyPI) record standard, anonymized download counts when you install the Kit. We may view these aggregate totals; they do not identify you.

If you opt in to telemetry during init, the CLI may send anonymous, aggregate usage events (such as which command was run). Telemetry is off by default and can be disabled at any time.

Website analytics

This site uses privacy-respecting, cookieless analytics to count page views in aggregate. We do not build advertising profiles and do not sell data.

Third parties

Optional integrations such as Graphify and Obsidian run locally and are configured by you. Activating them does not transmit data to us.

We do not share information with advertisers or data brokers.

Security

Reports of vulnerabilities go through the repository’s SECURITY.md. Because the Kit runs locally with no server component, the attack surface is limited to the CLI itself and its published packages.

Your choices

You can disable CLI telemetry, run the tool fully offline after install, and remove any generated configuration at any time. Since we hold almost no personal data, there is little for us to delete - but requests can be directed to the maintainers.

Questions about this policy? See the Terms of Service or reach the maintainers via the repository’s SECURITY.md.