Updated July 2026
Privacy
Your context works for you, and only where you said it could.
Scope isolation
Every conversation, Agent, and automation runs against the scopes you select. Protected areas such as Journal and Finances stay outside project context unless you add them for that session.
Memory approval
Long-term memories require your approval. Each memory keeps its provenance and retention details, and source deletion can remove derived records.
Agents
Agents use only their approved sources and granted tools. Public or external channels require an explicit release, carry disclosure, and can be revoked.
Automations and data movement
Workflow nodes expose the data and account involved in an action. Configured external side effects pause in Approval Inbox before execution.
External providers
The local demo keeps provider adapters disabled. Hosted adapters must disclose their provider, data scope, retention, and expected cost before activation; credentials remain server-side.
Analytics
Anonymous product analytics are opt-in and limited to operational metadata. Prompts, files, private scopes, and generated content are excluded.
Export and deletion
You can export workspace data and delete the local account from Settings. Deletion requires typed confirmation and clears the local workspace copy.