Privacy
backpropagate is a local tool. It has no account, no analytics and no telemetry, and it does not send your data anywhere unless you ask it to do something that needs the network, such as downloading a model or pushing one to the Hugging Face Hub. This page lists every case.
It applies to every way of installing backpropagate: pip, Docker, and the Microsoft Store package.
What leaves your machine, and when
Section titled “What leaves your machine, and when”| When | Where it goes | What is sent |
|---|---|---|
| You train on, or download, a model or dataset by its Hugging Face name | Hugging Face Hub (huggingface.co) |
Requests for that model or dataset, with your Hugging Face token if one is set. This happens even when the model is already downloaded: the library asks the Hub whether the files changed. Set HF_HUB_OFFLINE=1 to work from the cache with no request. |
You push a model (backprop push, push_to_hub(...), or an export with a Hub repo) |
Hugging Face Hub | The model files you chose to push, to the repository you named. |
You install an experiment tracker and leave tracking on its default (report_to="auto") |
That tracker’s service, e.g. Weights & Biases | Training metrics and run configuration. Off unless a tracker is installed: the [monitoring] extra installs Weights & Biases; the Microsoft Store package includes no tracker. Pass report_to="none" to turn it off. |
| You export to Ollama | The Ollama server on your own machine (localhost:11434) |
The exported model. Nothing leaves the machine, unless you have set OLLAMA_HOST to another machine: the ollama command follows it. |
You start the UI with backprop ui --share |
Cloudflare’s tunnel service (*.trycloudflare.com) |
Your UI’s traffic, so that people with the URL and password can reach it. Only with --share; see Security. |
| The UI starts | The Python Package Index (pypi.org) |
The UI framework (Reflex) checks whether a newer Reflex release exists. Set REFLEX_CHECK_LATEST_VERSION=false to turn this off. The check gives up quietly after two seconds when you are offline. |
The UI starts for the first time after a pip install or upgrade |
GitHub (raw.githubusercontent.com for the runtime’s install script, github.com for the runtime itself) and the npm registry (registry.npmjs.org) |
The UI framework fetches its JavaScript runtime (bun), if it is not installed yet, and the page’s JavaScript packages, to build the page once per version. The Microsoft Store package ships both ready-made and makes no such request; if its bundled frontend cannot be used, it says so at startup and falls back to the same build. |
Since 1.8.1 the UI framework’s own usage telemetry is switched off (telemetry_enabled=False). Versions before 1.8.1 left it on, and each UI launch sent an anonymous usage event to Reflex’s analytics service.
By default the web UI listens only on 127.0.0.1, so other machines cannot reach it, and it requires the token printed at startup. The token leaves the address bar after the first request and is not written to the server’s access log.
Your Hugging Face token
Section titled “Your Hugging Face token”backpropagate reads your token from, in order: the --token flag, HF_TOKEN, HUGGING_FACE_HUB_TOKEN, or the file huggingface-cli login writes (~/.cache/huggingface/token). It uses the token only for requests to the Hugging Face Hub. It does not copy it anywhere else. A token you type into the web UI’s Export page is kept in memory only and is never written to disk; a training or export job the UI starts receives your HF_TOKEN through its environment, as it would from a terminal. A token-file path given to the Export page must name an existing file inside ~/.backpropagate/; only its file name is shown in the browser, and the file is read when the push starts. In normal (non-verbose) mode, error output is scrubbed of tokens and keys before it is printed.
What is stored on your machine
Section titled “What is stored on your machine”| What | Where |
|---|---|
Training outputs, checkpoints and run_history.json |
The output folder you choose (./output by default). |
Files the web UI saves (adapters, exports, datasets you upload in uploads/, cleaned copies in datasets/) |
~/.backpropagate/ui-outputs, or BACKPROPAGATE_UI__OUTPUT_DIR. |
| The web UI’s build and state files (the form values of open pages; never a Hub token) | %LOCALAPPDATA%\backpropagate\ui\ on Windows, ~/.cache/backpropagate/ui/ on Linux and macOS (or under $XDG_CACHE_HOME), or BACKPROPAGATE_UI_WORKDIR. |
| The JavaScript runtime the UI uses (bun) | %LOCALAPPDATA%\reflex\ on Windows, ~/.local/share/reflex/ on Linux, ~/Library/Application Support/reflex/ on macOS. |
| The UI’s launch token, while the UI runs | %LOCALAPPDATA%\backpropagate\session-<port>.lock on Windows, $XDG_RUNTIME_DIR/backpropagate/ on Linux, ~/Library/Application Support/backpropagate/ on macOS. Deleted when the UI stops. |
| Downloaded models and datasets | The Hugging Face cache, ~/.cache/huggingface (or HF_HOME). Shared with other Hugging Face tools. |
Measurements from backprop estimate-vram --calibrate or the UI’s Measure on this GPU (what training cost on your card; no dataset content) |
~/.backpropagate/vram-calibration.json, or BACKPROPAGATE_VRAM_CALIBRATION. |
| Log files | Only if you set BACKPROPAGATE_LOG_FILE. |
Your datasets and models stay where you put them. backpropagate does not upload them unless you push.
The Microsoft Store edition
Section titled “The Microsoft Store edition”The Store edition never runs code that ships inside a model repository: trust_remote_code stays off whatever a setting, an environment variable or a .env file says, and a model that needs such code does not load there (CONFIG_TRUST_REMOTE_CODE_REQUIRED names the pip install, which keeps the opt-in). It installs the library and the web UI only, with no experiment tracker, so nothing is sent to one. Everything it writes stays in your user profile, in the folders listed above.
Removing everything
Section titled “Removing everything”Uninstalling backpropagate (pip uninstall backpropagate, or uninstalling the Microsoft Store app) removes the program but not the files listed above, like most desktop tools. To remove them too, delete:
%LOCALAPPDATA%\backpropagateand%LOCALAPPDATA%\reflexon Windows;~/.cache/backpropagateand~/.local/share/reflexon Linux;~/.cache/backpropagate,~/Library/Application Support/backpropagateand~/Library/Application Support/reflexon macOS~/.backpropagate- your output folders
- models in the Hugging Face cache that you no longer want (
huggingface-cli delete-cache). Other Hugging Face tools share this cache.
Questions
Section titled “Questions”Open an issue at github.com/mcp-tool-shop-org/backpropagate/issues. To report a security problem privately, follow SECURITY.md.