Rainspeed Labs / Product Notice
ONeNas Code Product Notice
Product-specific terms for the ONeNas Code desktop, CLI, TUI, local server and relay components.
Last updated: 12 August 2026
1. Relationship with the central policies
This Product Notice supplements the Rainspeed Labs Terms of Use, Privacy Policy, Service Terms, Acceptable Use Policy, Cookie Policy, Subprocessors register and any applicable open-source notices. It applies to ONeNas Code whether you use it locally, with a direct provider, with a managed AtlasFlux provider or with an external MCP or connected service.
2. Local-first operation and permissions
ONeNas Code is a local-first coding agent. Depending on the commands, tools and permissions available on the device, it may read and write project files, inspect directories, run shell commands and PTY processes, access the network, use local sessions, copy projects and interact with connected services. It may modify files or cause effects in a repository, account, device, infrastructure or third-party service.
Permission prompts are a user-awareness feature, not a security sandbox or isolation boundary. The local agent is not sandboxed by default. Use backups, version control, least privilege, separate development credentials and a trusted environment. You remain responsible for commands, approvals, local configuration, generated code and effects of execution.
AtlasFlux-hosted workflows may use a temporary E2B sandbox when that feature is enabled. That sandbox applies to the hosted workflow only and does not make local ONeNas execution sandboxed.
3. Local account state, credentials and logs
The desktop stores authentication state and related bootstrap information on the local device using the operating system's encrypted storage facility when it is available. Other ONeNas components may use a local database or token files, including authentication material under the user's `.onenas-code` directory. Protect the device, local database, configuration files and backups. Removing the hosted account does not automatically remove local files or local history.
ONeNas may write structured logs, local session history, tool events, errors, causes, spans, annotations and debug information to local application directories. Crash dumps and diagnostic logs may also be created locally. Review or delete local logs before sharing them because they may contain paths, commands, model context, error details or other operational information. A local logging or crash feature does not mean that all local content is uploaded to Rainspeed Labs.
4. Managed AtlasFlux provider and relay
When you sign in to the managed AtlasFlux provider, ONeNas may receive account/profile information, plan and Credits information, available model and feature configuration, device or run authorisation and a temporary relay authorisation. A managed run may transmit the prompt, selected files or context, tool parameters, model selection, run and device identifiers, status, errors and assistant Output through the AtlasFlux route and relay.
Managed prompt and assistant data may be written to AtlasFlux session and event records and is subject to the connected AtlasFlux retention and deletion rules. The relay authorises a device and run/model combination and forwards the operation to the configured AtlasFlux provider route; it is not a separate ownership or billing system. Managed runs may consume AtlasFlux Credits where the product interface says so.
5. Direct providers, MCP and connected services
ONeNas can support direct provider configurations and custom OpenAI-compatible endpoints depending on the build and configuration. Examples may include OpenAI, Anthropic, Google, OpenRouter, xAI, Groq, Mistral, NVIDIA, GitHub Copilot and ILMU. When you choose a direct provider, your credentials, prompts, selected context and Output may be sent directly to that provider and may be subject to its own retention, training, safety, billing and privacy terms. Direct providers are not necessarily Rainspeed Labs subprocessors.
An MCP server, plugin, tool, repository integration or connected service is a separate trust boundary. It may receive queries, files, tool parameters, credentials or other data according to your configuration. Review the provider or integration before enabling it and do not assume that managed AtlasFlux controls apply.
6. Software licence and updates
ONeNas Code includes components derived from OpenCode and other open-source projects. The applicable licence, copyright notice and third-party notice continue to apply to those components. Rainspeed Labs may update, replace, disable or remove providers, features, relay versions, model routes and supported versions. Keep the software and connected credentials updated and review release or provider notices where relevant.
7. ONeNas data rights and contact
Local files, local sessions, local logs and local credentials are normally controlled by you and the device. Managed session, event, billing, support, security and relay records are subject to the connected Rainspeed Labs service and applicable retention rules. To request access, correction, deletion or clarification for managed ONeNas data, use https://support.atlasflux.my or email hello@rainspeedlabs.com. Do not send project secrets, passwords, private keys or full provider credentials to Support.