Transparency
Your work stays on your computer. Your prompts travel.
The whole map on one page: what stays, what leaves, and what we keep.
The data flow
What one request actually does.
Your team works on your machine. When it needs to think, the prompt travels through our model proxy to a model provider, and the answer comes back.
The ledger
Every item, in two columns.
Stays on your computer
- Conversations: everything you say to your team and everything it says back
- Files your agents read, write, or process
- Team memory: what they have learned about your preferences, patterns, and priorities
- Agent configuration, skills, and personalisation
- Workspace data: emails fetched, calendar entries cached, research compiled
Unless you grant a time-limited support session, we can't see, access, or retrieve any of it.
Leaves your computer
- Prompts, routed through our proxy to the model provider: your message, the relevant conversation history, the task instructions, and excerpts of your local data when the task needs them
- Account and billing: name, email address, plan tier. Stripe holds the card, and we don't see the full number
- Usage metadata: model name and token counts, buffered up to 7 days, for your plan budget and your dashboard. Not content
- Service metadata: deployment status, agent health checks, error logs. No conversation content
- Diagnostics: whether setup finished, which model answered, which screen you were on, which marketplace item you installed. Never message, prompt, or file content, and you can turn them off
The minimum needed to run the service.
The honest part
The thinking happens in the cloud.
An AI team has to reason, and that runs on models far too large for a laptop. So the prompt leaves. This is how every cloud AI works. The difference is that we draw you the map.
- Routed, not stored. API calls pass through our infrastructure for authentication and usage management. We don't store the content of these calls.
- No training, on any route. We use only providers that don't train on customer data. Cheaper routes exist through providers with weaker data policies, and we don't take them. When privacy and price pull in different directions, we pay the difference.
- Metadata, not content. Model name and token counts, buffered up to 7 days, so your plan budget and your dashboard work.
The small print
The rest of it, in short.
No standing access
We can't reach your computer. If support needs to see your agent's configuration or logs, we ask for your explicit permission first, and the session is time-limited.
If you leave
Your local data stays on your computer, whether you uninstall or not. We delete your account information within 30 days. Billing records are kept for 6 years, as the law requires.
Where it runs
Our cloud services and CDN run on Cloudflare's global network, and we operate no data centres of our own. Some providers sit outside the UK and EEA; where personal data is transferred, we rely on Standard Contractual Clauses.
On your computer
Secrets and credentials are written with restricted file permissions, and stored in your operating system's secure credential store where one is available. Skills run with scoped permissions, and high-impact actions wait for your approval.
Welcome email
When setup finishes, your email address goes once to our welcome-email service so it can send you a getting-started email. It runs in the background and won't hold up your setup if it fails.
Want the formal version?
Our privacy policy covers the same ground in legal language.
Lanoko AI is a product of PolyTrader Ltd (England & Wales), a data controller under UK and EU GDPR, with a designated EU representative under Article 27.