GDP is local-first, not offline-only or zero-knowledge. Selected context can transit the AI host and temporary gateway relay when you use hosted GDP tools, while material repository execution remains local to the authorized GDP Desktop path.
Know what data can move
When an AI host uses GDP repository tools, the selected data needed for that call can leave the local machine. Depending on the tool, this can include open-repository metadata, repository-relative paths, selected file contents, diffs, context or search output, Patch Doctor reports, patch text, Suggested Check metadata, check output, and queue status.
The hosted MCP gateway acts as a relay between the AI host and the connected GDP Desktop session. It is not designed as a permanent source-code host, but it is not zero-knowledge while a request is in flight. The AI provider separately processes the context you send to that provider under its own terms.
Do not connect a private repository or request sensitive file content unless that selected context is acceptable to send through the configured AI-host and gateway flow.
Keep material repository effects local
GDP Desktop owns the local repository target and material execution boundary. The hosted gateway can relay bounded requests, results, patch candidates, queue state, and account metadata, but it does not mount the computer as a general filesystem and it does not become unrestricted apply, rollback, commit, push, reset, clean, or terminal authority.
Demo Workspace is a separate safe evaluation path built from seeded sample data. It does not read a user's local filesystem and should be used when you want to test the connector without exposing a private repository.
Repository tools are bounded to repositories intentionally open in GDP.
Local policy still governs material Desktop execution.
Hosted account, billing, queue, or connector state cannot manufacture local mutation authority.
A remote result still needs fresh local evidence before you claim a repository effect occurred.
Minimize sensitive context and secret exposure
Privacy masking can reduce the amount of sensitive context exposed in tool output, but it is not a complete provider-residency or Data Jurisdiction system. Treat masking as one layer, not as permission to send secrets carelessly.
Keep credentials, gateway or OAuth tokens, private keys, secret local paths, and unrelated private source out of prompts, screenshots, support reports, demos, and public documentation. Prefer the smallest file and output scope that can answer the task.
Do not publish GDP gateway tokens, OAuth tokens, passwords, private keys, or secret configuration values.
Review screenshots for sensitive account, repository, path, conversation, and credential data before publication.
Use repository-relative scoped context instead of arbitrary local filesystem disclosure.
When a provider-residency or legal data-jurisdiction requirement matters, evaluate that requirement explicitly rather than assuming local-first alone satisfies it.























