What ShardStitch reads.
Depending on the workflow and tools you enable, ShardStitch reads local Git state, changed files, recent commits, project notes, and local session evidence already written by the tools you use. It uses those inputs on the machine to build a continuation packet.
What it writes.
ShardStitch may write local recovery packets and tool pickup files such as CLAUDE.md, AGENTS.md, GEMINI.md, or .cursorrules when you choose an injection workflow. Bedrock records live in .shardstitch/bedrock.db when the project uses that directory, or in a local per-project state record otherwise.
The license check is separate from recovery.
Activation and a periodic license re-check use Polar's license endpoint. The validation request sends the license key and organisation identifier. Normal project recovery does not send code, session content, or telemetry to ShardStitch.
If you explicitly configure a cloud model or import content from a hosted chat share, that external service's own network and privacy terms apply to that opt-in workflow. See AI coding chat history risk for why ShardStitch treats transcripts as optional evidence, not durable project memory.
Local does not mean invisible.
Bedrock uses an append-only, hash-chained record. ShardStitch can verify the chain later and report the first broken entry. You retain normal control of the local files and can remove ShardStitch project or state data from disk.