Transparency
Your work stays on your computer. Your prompts travel.
The whole map on one page: what stays, what leaves, and what we keep.
The data flow
What one request actually does.
Your team works on your machine. When it needs to think, the prompt travels through our model proxy to a model provider, and the answer comes back.
The ledger
Every item, in two columns.
Stays on your computer
- Conversations: everything you say to your team and everything it says back
- Files your agents read, write, or process
- Team memory: what they have learned about your preferences, patterns, and priorities
- Agent configuration, skills, and personalisation
- Workspace data: emails fetched, calendar entries cached, research compiled
Unless you grant a time-limited support session, we can't see, access, or retrieve any of it.
Leaves your computer
- Prompts, routed through our proxy to the model provider: your message, the relevant conversation history, the task instructions, and excerpts of your local data when the task needs them
- Account and billing: name, email address, plan tier. Stripe holds the card, and we don't see the full number
- Usage metadata: model name and token counts, buffered up to 7 days, for your plan budget and your dashboard. Not content
- Service metadata: deployment status, agent health checks, error logs. No conversation content
- Diagnostics: whether setup finished, which model answered, which screen you were on, which marketplace item you installed. Never message, prompt, or file content, and you can turn them off
The minimum needed to run the service.
The honest part
The thinking happens in the cloud.
An AI team has to reason, and that runs on models far too large for a laptop. So the prompt leaves. This is how every cloud AI works. The difference is that we draw you the map.
- Routed, not stored. API calls pass through our infrastructure for authentication and usage management. We don't store the content of these calls.
- No training, on any route. We use only providers that don't train on customer data. Cheaper routes exist through providers with weaker data policies, and we don't take them. When privacy and price pull in different directions, we pay the difference.
- Metadata, not content. Model name and token counts, buffered up to 7 days, so your plan budget and your dashboard work.
The small print
The rest of it, in short.
No standing access
We can't reach your computer. If support needs to see your agent's configuration or logs, we ask for your explicit permission first, and the session is time-limited.
If you leave
Your local data stays on your computer, whether you uninstall or not. We delete your account information within 30 days. Billing records are kept for 6 years, as the law requires.
Where it runs
Our cloud services and CDN run on Cloudflare's global network, and we operate no data centres of our own. Some providers sit outside the UK and EEA; where personal data is transferred, we rely on Standard Contractual Clauses.
On your computer
Secrets and credentials are written with restricted file permissions, and stored in your operating system's secure credential store where one is available. Skills run with scoped permissions, and high-impact actions wait for your approval.
Welcome email
When setup finishes, your email address goes once to our welcome-email service so it can send you a getting-started email. It runs in the background and won't hold up your setup if it fails.
Background work that spends your AI budget
Three features run on their own, without a prompt from you, and each is on by default. Self-learning reviews substantial conversations and may create or refine workspace skills, then reviews your whole skill collection once a week (off switch: skills.workshop.autonomous.mode). A session observer writes a short status note after each session, using the cheapest model in your configuration (off switch: gateway.controlUi.sessionObserver). Memory dreaming is set to run a nightly consolidation pass at 03:00 local time (off switch: plugins.entries.memory-core.config.dreaming.enabled); see Local memory search below for how it runs on your own machine. All three call the same model provider as your normal conversations and are billed the same way. No new destination for your data.
Personal recall
Personal recall is on by default on an install used by one person, so your agent can draw on your other private conversations with it when it answers you. See Local memory search below for how that recall runs on your own machine. On an install several people share with the same agent, it's off by default, so one member's conversations don't surface in another's.
A few messages still say OpenClaw
Lanoko runs on OpenClaw, and a handful of failure messages your agent posts into chat, for example about a full disk or a broken credential store, currently name OpenClaw instead of Lanoko. We've accepted that for the beta.
Local memory search
Your install downloads a 340 MB local embedding model once, so your agent's memory is searchable on your own machine. On most machines, memory content never leaves it. On machines with less than 8 GB of memory or 2 GB of free disk, memory search runs through the same model provider that already answers your agent's conversations, and the app tells you when that is the case.
Web search
Your agent's search queries go to OpenRouter and its search partner and are billed to your existing OpenRouter allowance, a fraction of a cent per search.
Inviting a colleague
When you invite a colleague by email, their email address is sent to Lanoko so the invitation can be delivered, and their membership is recorded there. No conversation, no file and no other detail about them leaves the machine. A colleague invited through your team's own chat workspace has nothing sent at all.
Shared-machine memory indexing
If the built-in memory index cannot run on a machine that several people use, conversations, including your colleagues', are sent for indexing to the same provider that already answers them.
An unrecognised device
A device of a colleague that Lanoko does not recognise waits for the owner's approval. Nothing is sent to Lanoko for that; the approval happens on the owner's machine.
Connecting another assistant
An assistant you connect can ask your assistant about anything it knows, on this machine; nothing about it is sent to Lanoko.
Want the formal version?
Our privacy policy covers the same ground in legal language.
Lanoko AI is a product of PolyTrader Ltd (England & Wales), a data controller under UK and EU GDPR, with a designated EU representative under Article 27.