Dyad logo
No Low Code · Code Generation

Dyad

Dyad is an open-source desktop app builder that turns plain-language ideas into working web apps. It runs locally, works with any AI model, and hands you exportable code with zero lock-in.

Active Free plan Freemium No public API Verified by Guidaio
Overview

What is Dyad?

Dyad is an open-source desktop application that builds web apps from plain-language instructions. It is published by Dyad Tech, Inc. and its public face is its creator, Will Chen. The pitch is compact: the open-source AI app builder on your desktop, turning ideas into web apps without coding, with your own choice of AI models, code you own, and zero lock-in.

It installs on macOS, both Apple Silicon and Intel, and on Windows. Linux support exists but is experimental, untested and without auto-updates. The current release is 1.10.0, and more than sixty stable versions have shipped since 0.1.1, alongside a beta channel. The source is public at github.com/dyad-sh/dyad, where the project claims around 21,000 stars and lists 27 contributors.

Dyad is deliberately model-agnostic. You bring an API key from OpenAI, Anthropic, Google Gemini or OpenRouter, or you point it at a local model through Ollama or LM Studio. An Auto mode picks whichever configured model suits the task. Setup requires Node.js and one AI credential; nothing else.

Generated applications land in ~/dyad-apps/, each as an ordinary Git repository, which is what makes the no-lock-in claim concrete rather than rhetorical. The scope is narrow on purpose: JavaScript only, no native mobile, though hybrid mobile apps are supported. Supabase and Neon supply databases, authentication and server functions; GitHub and Vercel handle publishing; MCP servers from the Dyad Hub extend the tool. A built-in security review looks for SQL injection, XSS and authentication misconfigurations.

The app is free with your own API key. Dyad Pro costs 20 USD a month and adds 200 AI credits, Pro modes for large codebases and the Dyad Academy. Dyad Max costs 79 USD a month for 900 credits and priority office hours. The distinction matters for privacy: on the free tier nothing passes through Dyad's servers, while Pro proxies prompts and code through them. The documentation compares Dyad openly with Lovable, v0, Bolt.new and Bolt.diy.

What it does

  • Describe an app idea in plain language and get a working web application back
  • Pick your AI model freely: OpenAI, Anthropic, Google Gemini, OpenRouter, or a local model via Ollama or LM Studio
  • Add a database, authentication and server functions by connecting Supabase or Neon
  • Run a built-in security review that flags SQL injection, XSS and broken authentication, and proposes fixes
  • Publish to GitHub and Vercel in a few clicks, or deploy to your own cloud
  • Import an existing app, or export yours at any moment, since each project is a plain Git repository
  • Extend the tool with any MCP server from the Dyad Hub, such as Chrome DevTools, Context7 or Brave Search
Audience

When to use Dyad / When not to

A quick filter to help you decide if Dyad is the right fit.

When to use Dyad

  • Non-developers who want to build a working web app without writing code, and who are willing to install a desktop application to do it
  • Developers who want AI assistance but insist on keeping the generated code as an ordinary Git repository on their own machine
  • People who already pay for an AI API key from Google, OpenAI, Anthropic or OpenRouter and want to reuse it instead of buying another subscription
  • Privacy-conscious builders who can run a local model through Ollama or LM Studio, so nothing leaves the computer at all
  • Indie makers and founders on a tight budget, since the app itself is free and Google Gemini's free tier covers roughly 250 requests a day

When not to use Dyad

  • Anyone building native mobile apps: Swift and Kotlin are not supported, only JavaScript, including hybrid mobile
  • Teams working in Python, Ruby, Go or any language other than JavaScript, which Dyad explicitly does not handle
  • Organisations that need a hosted platform with nothing to install, since Dyad is a downloadable desktop program
  • Linux users who need a dependable daily driver, as Linux support is experimental, untested and has no auto-updates
  • Companies whose procurement requires a signed DPA, a formal subprocessor list or a written GDPR commitment, none of which Dyad publishes
Get started

How to use Dyad

A typical end-to-end flow, from setup to results.

  1. Download Dyad from the download page and open it, choosing macOS Apple Silicon, macOS Intel or Windows
  2. On Windows, expect a Microsoft Defender SmartScreen warning: click More info, then Run anyway
  3. Install Node.js, the JavaScript runtime that will execute the apps you generate
  4. Set up AI access by creating an API key, with Google Gemini recommended for its free tier of roughly 250 messages a day on Gemini 2.5 Flash
  5. Alternatively, point Dyad at a local model running through Ollama or LM Studio, keeping everything on your machine
  6. Check the banner on the home screen, which tells you which setup steps are still outstanding
  7. Type your idea into the chat box and send it, or pick one of the suggestions below the input
  8. Review the code the AI produces and approve it, since nothing is saved or run before you do
  9. Watch the preview open on the right-hand side, then keep iterating in the same conversation
  10. Publish by connecting GitHub and Vercel, or deploy to your own cloud instead
Quick read

Pros & Cons

Pros

  • The source code is public and auditable, which is unusual among AI app builders
  • No lock-in in any practical sense: every project is a plain Git repository you can import or export at will
  • Everything runs on your own machine, and on the free tier no data reaches Dyad's servers at all
  • Model-agnostic by design, so you supply your own key and switch providers whenever you like
  • The desktop app is free and needs no account, and prices for the paid tiers are published openly with no contact form
  • A visible and fast release cadence, with more than sixty stable versions and a documented beta channel
  • Substantial documentation, over thirty-five pages of guides, integrations, troubleshooting and release notes

Cons

  • No postal address is published anywhere on the site, and there is no contact page and no about page
  • GDPR is never mentioned, and there is no DPA, no formal subprocessor list and no EU representative
  • No security certification is claimed, neither SOC 2 nor ISO 27001
  • JavaScript only, with no native mobile apps and no server-side deployment of Dyad itself
  • Linux support is experimental, untested and without auto-updates, and the Windows installer trips SmartScreen
  • A single generic email address, hi@dyad.sh, covers support, legal and privacy requests alike
  • On Dyad Pro, prompts and code pass through Dyad's servers and may be logged temporarily, and there is no service-level agreement
Pricing

Pricing & Plans

A permanent free plan is available. The Dyad desktop application is free, open source and requires no sign-up, provided you supply your own AI API key. The lowest paid entry point is Dyad Pro at 20.00 USD per month, which adds 200 monthly AI credits, Pro modes for large codebases and full access to the Dyad Academy. Dyad Max, at 79.00 USD per month, is offered as an upgrade from Pro. All prices are exclusive of taxes. No free trial is advertised for the paid tiers, the permanent free plan serving that purpose instead.

Plan 1
  • Dyad Free — free — local open-source app builder
  • downloadable for macOS and Windows
  • no sign-up required
  • bring your own API key
  • community support
Plan 3
  • Dyad Max — 79 USD per month — everything in Pro
  • plus 900 AI credits per month
  • prioritised access to office hours and credit reloads at any time at the same price
Special offers — Referral programme reserved for Dyad Pro subscribers: extra AI credits for both the referrer and the person referred, for every referral made · A permanent free tier of the application, with no sign-up required and no time limit · Indirect costs can be cut to zero using free provider tiers: roughly 250 requests a day on Google Gemini 2.5 Flash, or free models on OpenRouter such as DeepSeek v3 · Super Value routing on Pro, advertised as building at 20% of the cost by directing requests to cost-efficient models · Dyad Max subscribers can reload AI credits at any time at the same price
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Dyad handles your data.

GDPR overview

The letters GDPR appear nowhere on this site. There is no compliance claim, no certification, no Data Processing Agreement, no formal subprocessor list and no EU representative under Article 27. That silence is not a refusal, and the policy in practice grants a full set of rights to everyone: to know, access, correct, erase, complain, restrict processing, object, port data, escape automated decisions and not be penalised for asking. EEA and UK visitors get a genuine cookie banner, with attribution cookies set only after consent. Transfers to the United States rest on unnamed "appropriate safeguards", with no mention of standard contractual clauses or the Data Privacy Framework. European buyers with a compliance checklist will find the paperwork missing, whatever the underlying practice.

Who owns the data?

You own what Dyad produces. Generated apps are written straight to your own disk under ~/dyad-apps/, each one an ordinary Git repository you can open, fork or abandon at will. The terms claim ownership only of the Dyad service itself, not of the applications you build with it. The privacy policy is equally explicit that it does not govern the apps you publish: their privacy notices are your responsibility. On the free tier your prompts and code never touch Dyad's servers, because you supply your own API key or point at a local model. On Dyad Pro they are proxied through Dyad before reaching the model providers.

Reuse rights

Nothing in the terms restricts what you do with the code Dyad writes for you: you may export it, modify it, publish it and sell what you build, without asking permission. Dyad's own codebase is open source and may be inspected, forked and extended for personal or non-competing use, with one request attached, that a redistributed fork not be called Dyad. The restrictions run the other way: you may not copy the HTML, CSS, JavaScript or visual design of Dyad's site and product, and you must ask before using its logos, at hi@dyad.sh. Reselling access to the service itself is prohibited without written permission.

Data retention & training

Retention summary
Some periods are stated precisely, others are not. Troubleshooting logs you upload yourself, containing chat transcripts and parts of your codebase, are deleted after about one month. Marketing attribution cookies last around 90 days, and your cookie consent choice around six months. Dyad Pro service logs are kept only as long as necessary, with no figure attached. The general rule is that information is held for as long as the purpose requires, then deleted or aggregated, with longer retention where law, disputes or contracts demand it. Legal preservation copies are destroyed once the period lapses without a warrant. You may request erasure, with the caveat that fulfilling it may mean closing your account. Email correspondence is kept indefinitely as a support history. The policy took effect on 22 June 2026.
Trains on customer data
Configurable
Training opt-out available
Yes
Subprocessors disclosed
Yes
GDPR contact

Hosting summary

Dyad states plainly that it is a U.S. company and that its own infrastructure sits in the United States, where its products and web properties are operated. If you are in the European Union, the United Kingdom or anywhere outside the United States, your information is transferred there and stored there. For EEA and UK individuals, the policy says transfers rely on appropriate safeguards, without naming the mechanism. Some third-party processors may operate in the U.S. or the E.U. Four are named: PostHog for desktop telemetry, Umami Cloud for cookieless web analytics, Mailgun for transactional email and ConvertKit for mailing lists. Card details never touch Dyad's servers, going directly to the payment processor. One important nuance: on the free tier Dyad hosts nothing of yours at all, since your data either stays on your machine or goes straight to the model provider whose key you supplied. The domain resolves to a Cloudflare anycast address, which identifies a CDN node and says nothing about where data is stored.

Hosting countries
🇺🇸 United States
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Dyad.

  • No postal address appears anywhere on the site, so you cannot establish where the publisher is based from its own pages alone
  • GDPR is never mentioned, and there is no Data Processing Agreement, no formal subprocessor list and no EU representative under Article 27
  • Data is hosted only in the United States, with no European residency option, and transfers rely on unnamed appropriate safeguards
  • On Dyad Pro your prompts and code travel through Dyad's servers and may be logged temporarily for abuse investigation or diagnostics
  • Some models permit provider-side training; the interface flags them, but the vigilance is left to you at the moment you pick a model
  • There is no service-level agreement, and the terms let the company suspend or terminate an account for any reason at any time
  • Generating code you have not read is a real habit-forming risk: approving the AI's output without understanding it erodes the very skill you would need to fix it later
Setup

Setup & Integrations

Technical difficulty

Moderate, and front-loaded. You install a desktop application rather than opening a browser tab, and two setup steps are mandatory: install Node.js, then supply an AI key or point at a local model. A banner on the home screen tracks what is still outstanding, and a three-minute video walks through it. Windows users must click past a Microsoft Defender SmartScreen warning. No coding skill is needed afterwards, though you must approve each batch of generated code. Local models add real friction: a weak machine produces poor results, and Dyad says so.

Deployment

Desktop app

Integrations

GitHub Vercel Supabase Neon OpenAI Anthropic Google Gemini OpenRouter Ollama LM Studio Chrome DevTools Brave Search Context7
Company

Behind Dyad

Company name
Dyad Tech, Inc.
Founded
14/01/2025
Country of origin
🇺🇸 United States
UBO
Will Chen
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Dyad.

L LovableV v0B Bolt.newB Bolt.diy
FAQ

Frequently asked questions

Is Dyad actually free, or is there a catch?
The desktop application is genuinely free and open source, and it needs no sign-up. The catch, if it is one, is that you supply your own AI API key and pay whatever your chosen provider charges. Dyad Pro at 20 USD a month and Dyad Max at 79 USD a month add AI credits, Pro modes and Academy access on top.
Where does the code Dyad writes actually live?
On your own computer, under ~/dyad-apps/ followed by the app name. Each project is an ordinary Git repository, which means you can open it in any editor, push it anywhere and keep working on it if you ever stop using Dyad.
Which AI models can I use with it?
OpenAI, Anthropic, Google Gemini and OpenRouter are all supported, as are local models running through Ollama or LM Studio. An Auto mode picks a suitable model from whichever providers you have configured, and you can switch at any time.
Which operating systems does it run on?
macOS on both Apple Silicon and Intel, and Windows. Linux is supported experimentally: Dyad says it is not tested there, may have bugs, and receives no auto-updates, so you would need to download new versions by hand.
Can I build mobile apps with Dyad?
Not native ones. Swift and Kotlin are out of scope because Dyad only handles JavaScript-based apps, though hybrid mobile apps built in JavaScript are covered. The same limit applies to other programming languages, which Dyad does not support at all.
Will my prompts and code be used to train AI models?
Dyad states it never uses your data to train its own models. Model providers will not train on it either, except for specific models flagged in the model selection interface as allowing provider training, so the choice stays visible and yours.
Do my prompts pass through Dyad's servers?
Not on the free tier. With your own API key or a local model, your data goes straight to the provider or stays on your machine. On Dyad Pro it is proxied through Dyad's infrastructure, and may be logged briefly for abuse investigation or troubleshooting.
How do I get support if something breaks?
Use the Help button inside the app: Report a Bug files a GitHub issue with your system information and logs, while Upload Chat Session sends the conversation for debugging. There is also the r/dyadbuilders subreddit, and hi@dyad.sh for written enquiries.
Can I fork Dyad and make my own version?
Yes. The project is open source and you may inspect, fork and extend it for personal or non-competing use. Dyad asks only one thing of anyone redistributing a fork: do not call it Dyad, to avoid confusing users.
Is there a free trial of the paid plans?
None is advertised. The permanent free plan plays that role instead, and subscriptions can be cancelled at any time with immediate effect. Note that unused time in the final billing month is not automatically prorated.
Conclusion

Should you pick Dyad?

Dyad is one of the more verifiable tools in a category full of promises. The binary is downloadable, more than sixty releases are archived, the source is public, the documentation runs to dozens of pages and the prices are printed in plain figures rather than hidden behind a contact form. Its central claim, that you keep your code and your choice of model, is not marketing: every project is an ordinary Git repository on your own disk, and on the free tier nothing reaches Dyad's servers at all. For an individual maker, a founder prototyping quickly, or a developer who wants AI help without surrendering the codebase, that combination is genuinely rare.

The reservations are about the company rather than the product. There is no postal address anywhere on the site, no contact page and no about page, and a single generic mailbox handles legal, privacy and support alike. GDPR is never mentioned: no compliance claim, no Data Processing Agreement, no formal subprocessor list, no EU representative, and data hosted exclusively in the United States. None of that means the practice is poor, and the privacy policy is unusually candid about what is logged and when. It does mean a European buyer with a procurement checklist will find the paperwork absent.

The scope is narrow by choice: JavaScript only, no native mobile, Linux experimental, no public API. Treat those as deliberate boundaries rather than gaps. Dyad is a young company, its domain registered in September 2024 and first archived in January 2025, so judge it as a fast-moving open-source project with a visible maintainer, not as an established vendor. For personal and small-team work it is a strong, honest choice. For regulated or European enterprise use, ask for the missing documents first.