The application uses an HttpOnly cookie to associate requests with a private workspace. Theme, mode and the last session identifier are stored in browser localStorage. Conversations, facts, documents, rules, learned functions, examples and translations are stored in the server SQLite database. This is server-side storage, not a promise that all data stays inside your browser.
Source learning and practice
Explicit Q:/A: source entries are indexed privately, including supported chat submissions when learning is enabled. The workspace stores a bounded unanswered-question list and self-rated flashcard schedules. Source deletion removes its index and review schedule. Conversation recall searches only the current workspace user messages. Portable exports include source documents; gaps and review schedules remain in full database backups. study my sources rebuilds the index and resets its review schedules.
Private and shared language learning
Eligible chat prose is retained in a separate private language corpus and updates word-sequence counts. It can be retrieved as quoted source text and used for bounded class-logic reasoning. Pause learning stops collection. Forget language learning clears this corpus and its counts, while transcripts and separately saved documents remain separate. The explicit share language command publishes only the supplied text for public wording predictions. Public samples remain after workspace deletion until operator removal; never share confidential text. Portable exports include private text samples and imports rebuild counts.
Learned conversation replies
Private taught replies and their versions are stored with your workspace. Operator-reviewed shared dialogue lessons are available to all users but resolve memory placeholders only against the current user. The optional offline teacher receives an operator-supplied topic, not private transcripts. Live deterministic chat never calls that teacher. Active private replies are exported and can be imported; version history remains in the database backup.
Conversation and shared learning
Conversation learning is on by default for supported personal statements in deterministic chat. Pause it in Framework or say pause learning. Facts and learning receipts remain private to the workspace. Obvious secret-shaped statements are excluded by a heuristic, but chat transcripts still store the messages you send: do not paste credentials. Shared learning uses only explicitly contributed function names and numeric examples, with consent:true; use fictional, non-personal numbers. No transcripts, personal facts, documents, recovery keys or assistant replies are automatically published. Consented numerical candidates can activate automatically after eight distinct examples, held-out validation and regression checks. Other candidates require operator review. Withdraw removes pending contributions; previously published versions require operator retirement. Export includes your learning audit and contributions for inspection; import restores preferences and facts but does not restore undo authority or re-publish contributions.
Access and recovery
Workspace ownership is checked on private API operations. A downloaded recovery key grants access to the associated identity and should be kept secret. Removing browser cookies does not delete server records and can remove access to an existing workspace unless a recovery key is available.
Exports and deletion
The memory panel supports export and individual memory removal. The authenticated API also supports deleting sessions, documents, rules and the entire workspace. Learned functions can be removed with the forget skill command, subject to stored dependencies. A deleted live record may remain in operator-managed backups or logs until those copies are separately managed; this release does not promise a backup-erasure schedule.
Optional models and infrastructure
Deterministic operations do not call a language model. Explicitly selected Ollama requests send the current message and limited conversation history to the configured loopback model service. Hosting, reverse-proxy and backup infrastructure may also process request metadata. This page describes application behavior, not an independent audit of the operator infrastructure or a complete legal compliance assessment.
Operator information: LiMiT. Read the private-memory guide before deleting identity data.