Catalog/Tabby

Config & secrets · Transcripts

Tabby

Tabby writes verbatim completion and chat events (prompts and code context) to dated JSON files under ~/.tabby/events.

TabbyML Linux · macOS · Windows files · SQLite

Exposure

High
Stores found
2
Holds
API keys · personal data · source code
Confidence
likely

Where it writes

2 stores in the current signature database. Paths shown for a typical macOS install.

Transcripts high

files may hold personal data · source code

  • all OSes ~/.tabby/eventsdir

Tabby writes verbatim completion and chat events (prompts and code context) to dated JSON files under ~/.tabby/events.

  • Set TABBY_ROOT to relocate the store, or prune ~/.tabby/events to limit retention.

Source: tabby.tabbyml.com

Config & secrets high

SQLite may hold API keys

  • all OSes ~/.tabby/ee/db.sqlite

Tabby's server database holds user accounts and auth/registration tokens.

  • Restrict permissions on ~/.tabby and keep it off cloud sync.

Source: tabby.tabbyml.com

What to do about it

PromptDust flags these stores and leaves them in place; cleanup is your call. If a store holds a live secret, rotate the secret first, since deleting the file won’t un-leak a key that already sat in plain text.

For ongoing work, keep sensitive material out of sessions where you can, and prune old transcripts and caches now and then.

This describes where Tabby stores data. Metadata only, never your content. Confidence: likely. Spot a mistake? Tell us.

See if this one’s on your machine.

One pass finds every store, for this tool and the other 51.