What it never does.
DeckHQ runs on your machine and talks to your machine. Each line below is true of the package on npm today, and the section after them says how to check.
Binds anything but 127.0.0.1.
There is no --host flag and there never will be one. It is not reachable from
your network, and it refuses cross-site requests, so a page in another tab cannot drive
it.
Leaves the machine.
No analytics, no telemetry, no update checks, no crash reporting, no fonts or scripts from a CDN. The only sockets are the loopback listener and the runtime processes DeckHQ starts on your behalf.
Asks who you are.
No sign-up, no sign-in, no email, no billing, no licence check. Install it and it works.
Simulates work.
Every figure on the floor is a session that exists on your disk. A number DeckHQ has
nothing behind is printed as no data, never as a confident zero.
Writes to your settings without asking.
It reads your transcripts. It writes a hook block into
~/.claude/settings.json only after showing you the literal JSON and the exact
file, backs the file up first, tags what it wrote, and removes only what it tagged.
Renders what an agent said as HTML.
Conversation content stays on the machine and is shown as text and markdown. A script tag in a reply is the characters it is.
Check it.
deckhq doctor ends with a line named egress: the sockets DeckHQ
has open to anywhere but your own machine.
- The source is public, under MIT. The package has zero dependencies, so there is nothing underneath it to read.
- The installers are two short files. install.ps1 and install.sh, served here byte for byte.
- This site keeps the same rule. No web font, no CDN, no analytics. Your browser's network panel will show one origin.
$ deckhq doctor ... state ~/.deckhq/state.json, writable egress none. no outbound sockets.
What it reads, and what it writes.
Reads
-
Claude Code transcripts under
~/.claude/projects/, in bounded chunks: the head for the title, the tail for state. Never a whole one. claude agents --json, for which sessions are alive.-
Codex session files under
~/.codex/sessions/, when Codex is installed. - Gemini CLI and OpenCode sessions, when those are installed. Both adapters are unverified and say so.
Writes, always
-
~/.deckhq/: your queue, names, settings, a disposable cache, and a local ledger with no paths and no project names in it.
Writes, only after you say yes
- A tagged hook block in
~/.claude/settings.json, after a backup. -
The Desktop, Start Menu and login entries that
deckhq shortcutanddeckhq autostartname before they write them. -
.deckhq/studio/inside one project, afterdeckhq studio enable.
Found a vulnerability? The security policy says how to report it and what happens after you do.