Transparency

Your work stays on your computer. Your prompts travel.

The whole map on one page: what stays, what leaves, and what we keep.

We don't read your conversations We don't train models on your data We don't sell or share your information with third parties We don't store conversation content on our servers Your agent reaches local files with no cloud connection Your agent's model-catalog refresh and its startup update check are both switched off Your sandbox blocks the plugin-catalog request by default No favicon fetching, no location requests, no triggers running until you set them up

The data flow

What one request actually does.

Your team works on your machine. When it needs to think, the prompt travels through our model proxy to a model provider, and the answer comes back.

Data-flow diagram. On your computer: conversations, files, team memory, agent configuration and workspace data, none of which we can see, access or retrieve. One path leaves the machine and the prompt travels it: your message, the relevant conversation history and the task instructions, routed through Lanoko's model proxy, which handles authentication and usage management and does not store the content of the call, on to a model provider that does not train on customer data and keeps the call only briefly. The answer comes back the same way. Lanoko keeps your account, billing and usage metadata; the ledger below lists them.

The ledger

Every item, in two columns.

Stays on your computer

  • Conversations: everything you say to your team and everything it says back
  • Files your agents read, write, or process
  • Team memory: what they have learned about your preferences, patterns, and priorities
  • Agent configuration, skills, and personalisation
  • Workspace data: emails fetched, calendar entries cached, research compiled

Unless you grant a time-limited support session, we can't see, access, or retrieve any of it.

Leaves your computer

  • Prompts, routed through our proxy to the model provider: your message, the relevant conversation history, the task instructions, and excerpts of your local data when the task needs them
  • Account and billing: name, email address, plan tier. Stripe holds the card, and we don't see the full number
  • Usage metadata: model name and token counts, buffered up to 7 days, for your plan budget and your dashboard. Not content
  • Service metadata: deployment status, agent health checks, error logs. No conversation content
  • Diagnostics: whether setup finished, which model answered, which screen you were on, which marketplace item you installed. Never message, prompt, or file content, and you can turn them off

The minimum needed to run the service.

The honest part

The thinking happens in the cloud.

An AI team has to reason, and that runs on models far too large for a laptop. So the prompt leaves. This is how every cloud AI works. The difference is that we draw you the map.

  • Routed, not stored. API calls pass through our infrastructure for authentication and usage management. We don't store the content of these calls.
  • No training, on any route. We use only providers that don't train on customer data. Cheaper routes exist through providers with weaker data policies, and we don't take them. When privacy and price pull in different directions, we pay the difference.
  • Metadata, not content. Model name and token counts, buffered up to 7 days, so your plan budget and your dashboard work.

The small print

The rest of it, in short.

No standing access

We can't reach your computer. If support needs to see your agent's configuration or logs, we ask for your explicit permission first, and the session is time-limited.

If you leave

Your local data stays on your computer, whether you uninstall or not. We delete your account information within 30 days. Billing records are kept for 6 years, as the law requires.

Where it runs

Our cloud services and CDN run on Cloudflare's global network, and we operate no data centres of our own. Some providers sit outside the UK and EEA; where personal data is transferred, we rely on Standard Contractual Clauses.

On your computer

Secrets and credentials are written with restricted file permissions, and stored in your operating system's secure credential store where one is available. Skills run with scoped permissions, and high-impact actions wait for your approval.

Welcome email

When setup finishes, your email address goes once to our welcome-email service so it can send you a getting-started email. It runs in the background and won't hold up your setup if it fails.

Background work that spends your AI budget

Three features run on their own, without a prompt from you, and each is on by default. Self-learning reviews substantial conversations and may create or refine workspace skills, then reviews your whole skill collection once a week (off switch: skills.workshop.autonomous.mode). A session observer writes a short status note after each session, using the cheapest model in your configuration (off switch: gateway.controlUi.sessionObserver). Memory dreaming is set to run a nightly consolidation pass at 03:00 local time (off switch: plugins.entries.memory-core.config.dreaming.enabled); see Local memory search below for how it runs on your own machine. All three call the same model provider as your normal conversations and are billed the same way. No new destination for your data.

Personal recall

Personal recall is on by default on an install used by one person, so your agent can draw on your other private conversations with it when it answers you. See Local memory search below for how that recall runs on your own machine. On an install several people share with the same agent, it's off by default, so one member's conversations don't surface in another's.

A few messages still say OpenClaw

Lanoko runs on OpenClaw, and a handful of failure messages your agent posts into chat, for example about a full disk or a broken credential store, currently name OpenClaw instead of Lanoko. We've accepted that for the beta.

Local memory search

Your install downloads a 340 MB local embedding model once, so your agent's memory is searchable on your own machine. On most machines, memory content never leaves it. On machines with less than 8 GB of memory or 2 GB of free disk, memory search runs through the same model provider that already answers your agent's conversations, and the app tells you when that is the case.

Web search

Your agent's search queries go to OpenRouter and its search partner and are billed to your existing OpenRouter allowance, a fraction of a cent per search.

Inviting a colleague

When you invite a colleague by email, their email address is sent to Lanoko so the invitation can be delivered, and their membership is recorded there. No conversation, no file and no other detail about them leaves the machine. A colleague invited through your team's own chat workspace has nothing sent at all.

Shared-machine memory indexing

If the built-in memory index cannot run on a machine that several people use, conversations, including your colleagues', are sent for indexing to the same provider that already answers them.

An unrecognised device

A device of a colleague that Lanoko does not recognise waits for the owner's approval. Nothing is sent to Lanoko for that; the approval happens on the owner's machine.

Connecting another assistant

An assistant you connect can ask your assistant about anything it knows, on this machine; nothing about it is sent to Lanoko.

Want the formal version?

Our privacy policy covers the same ground in legal language.

Lanoko AI is a product of PolyTrader Ltd (England & Wales), a data controller under UK and EU GDPR, with a designated EU representative under Article 27.