Documentation/Security & data
On this page
What stays local and what is processed
“Local-first” does not mean no information ever leaves a device. It means local files and secrets are not uploaded merely because they exist, and each cloud path has a specific purpose.
Stays on your devices by default
- Local files, drafts, and workspace material not selected for a task
- Website passwords and connection secrets stored by Desktop
- Local task records and resources when encrypted sync is not enabled
Processed by Aihper
Content relevant to the task you ask Aihper to perform is sent to Aihper for processing. Other files on the machine are not automatically scanned or uploaded. Model access is provided through Aihper; Desktop does not ask you to configure a provider API key.
Account and presence data
The cloud handles account identity, authentication credentials, basic instance identifiers, and which Desktop, App, and Node instances are online. This makes sign-in, device lists, pairing, and real-time routing work.
Optional encrypted sync
When encrypted sync is enabled, Aihper stores encrypted payloads in the cloud. The data key required to open them remains on your devices; the login password does not decrypt them.
Website credentials
Credentials supplied through a connection card travel to Desktop over the real-time channel, are encrypted for local storage, and are not written into the task record.
See the public Privacy Policy for retention and deletion rules.
