Use free models with less exposure
Free models can be useful for personal coding projects. With a remote provider, your requests still leave your computer. Mandri offers two separate settings: pseudonymization replaces automatically detected sensitive values in text before sending it to the model; Docker execution runs the agent’s tool in a disposable container. You can use either setting or combine them.
Before you start
Section titled “Before you start”Connect a provider, for example OpenRouter in the app or OpenRouter in the terminal. Choose a model currently marked as free in its catalog and check its data policy. Availability, usage limits and policies can change. OpenRouter’s privacy policy describes its role and the model providers’ handling of requests.
Use a small personal project without critical data. For Docker execution, Docker must be available on the machine running the Mandri daemon, with the required worker image and security configuration. If startup reports a missing prerequisite, resolve it before continuing.
In the app
Section titled “In the app”- Open New chat, select your project folder, then choose Codex or another available agent tool and the free model from your provider.
- Open Standard below the prompt. This is the Session protection menu, separate from approval permissions.
- For surrogate mode, keep Standard selected and enable Pseudonymized. The agent runs on the daemon machine, while detected values in model-bound text are replaced.
- For container execution, select Docker sandbox. Enable Pseudonymized in the same menu if you want both settings. Docker alone does not pseudonymize model requests.
- Check your approval setting, write your task and send it. Wait for the selected environment to finish preparing.
These modes require a model connected through Mandri’s provider gateway. A tool’s native connection is not enough.
During a pseudonymized session, open its protection menu and select the information button labelled View protected data. Mandri detects values automatically and lists them in Protected data. The app displays partially masked values so you can inspect what was detected without showing each value in full. An empty list does not establish that your project contains no sensitive data.
In the terminal
Section titled “In the terminal”Set up the CLI and provider first. Run the command from your project folder and replace <model-id> with the exact ID of a currently free model in your OpenRouter catalog.
Surrogate on the host
Section titled “Surrogate on the host”mandri run --model "openrouter/<model-id>" \ --execution-backend host \ --privacy-mode surrogate \ codexDocker without pseudonymization
Section titled “Docker without pseudonymization”mandri run --model "openrouter/<model-id>" \ --execution-backend docker \ --privacy-mode none \ codexDocker with surrogate
Section titled “Docker with surrogate”mandri run --model "openrouter/<model-id>" \ --execution-backend docker \ --privacy-mode surrogate \ codexMandri prepares the selected environment and opens the agent’s terminal interface. Enter your task there and respond to its approval prompts. The options appear before codex because arguments after the tool name are passed to that tool.
What surrogate does not cover
Section titled “What surrogate does not cover”Adding your own values to replace is part of the privacy roadmap. It is not a setting available in this guide today.