Beware of the author of tweet, who happens to be author of OpenCode - OpenCode will leak all your data to themselves and to shady 3rd parties. Author feigned ignorance and never fixed the issue. OpenCode among other harnesses is the shadiest of all.
Yeah, the combo of hidden telemetry and other shenanigans along with general code bloat and other tradeoffs among the handful of available OSS harness options are what convinced us it was worth writing a new harness from scratch.
The RCE vulnerability drama made me never touch it, in any case.
Probably less of an issue but I always disliked with their paid plan/credits that they made I nonobvious that some of the Chinese models train off of your usage. It may have changed now but they would show all these great models you could use, somewhere have a bullet that everything is private adobe have an asterisk next to a handful of those models (including their own). I am sure some cost sensitive folks are ok with that but I disliked how there was not an easy way to tell and it was opt in automatically if you used those models.
[flagged]
It's not even possible to delete one's account!
I guess that's why they called OpenCode
I like OpenCode folks, but their marketing to ride DeepSeek's v4 moment is a pit they're digging themselves deep into.
For instance, this "marketing" claim that it'll take 24y to break even if a user uses 100m tokens/day (~$1.14 in DeepSeek v4 Flash usage) ignores the fact that OpenCode Go has 5h & weekly throttles. If you're running automated jobs [0], those throttles make it utterly useless. Besides, I think the local GPU setup in question could serve 10+ "users" at the same time, bringing down the break even by 22y (10x).
[0] For comparision, we routinely do 200m to 500m tokens on 3 to 8 automated code reviews per day with DeepSeek v4 Flash on max.
agreed. when using local models, they did send your prompts to openai with 30 day retention to make the titles, silently.
their recent changes to the privacy policy broke their promise of zero data retention. specifically, they offered chatgpt luna under a zero data retention privacy policy. luna was later shown to be 30 days retention.
their privacy policy has never guaranteed your prompts will not be logged and when asked they have failed to revise it.
when challenged about sending data to openrouter without listing it as a 3rd party processor they offered a dismissive response. the same with running prompts through cloudflare. seems trivial, but signifies general disinterest in security.
by default if you run the harness outside your config file by accident, it will automatically run silently with a free model that sends your prompts and local data to an endpoint with training enabled. on top of that it used to dump all the prompts sent to free models into an s3 bucket, the feature was literally called 'datadumper' in the source.