Reference / HANDBOOK
Data & permissions
Understand local storage, model requests and action approvals.
This website
This static product website has no analytics integration, advertising scripts, account system or newsletter form. The illustrative companion does not call a model. Supported text-file excerpts are read in your browser and are not uploaded by the preview.
Your browser and the hosting service make ordinary page requests. Clicking GitHub or provider links takes you to that service, where its policies apply.
The desktop app
Desktop settings and configuration are stored locally. Prompts, selected file content and other context sent to a model are processed by your chosen provider. Connected apps and websites have their own data policies.
Saved browser credentials use the desktop’s encrypted device store and are bound to the exact origin. The vault is local and does not sync. Secure-store availability depends on the operating system; the Linux plaintext fallback is refused.
Tools have real effects
File tools enforce workspace boundaries. Approved shell commands and MCP processes run with your operating-system permissions. Review proposed commands, diffs and connected-app actions before approving them.
Secret scrubbing protects supported secret shapes in saved history, logs and exports. It is not a guarantee for arbitrary unlabeled secrets, and pasted content can still reach a live model request. Use provider settings and secure credential controls instead of chat for secrets.
Based on Ankita’s maintained product guides. Settings and availability can vary by version.
Read the source guide Get help or suggest an improvement