Skip to content →

[security]

The data is yours. Connections are explicit. Sends wait.

This page is the adoption objection, written as the implementation actually behaves. The legal language lives on Privacy and responsible disclosure.

Approval before send
  • What the desktop can see

    A workspace folder you choose, meeting audio you start, the in-app browser pages you open, and the MCP servers you add. It does not get a silent tour of the whole disk.

  • What stays on the machine

    Markdown vault files, capture audio, on-device Whisper transcripts, local embeddings, and ~/.rowboat/ config. Delete the folder and those copies are gone.

  • What reaches Oppulence servers

    When you sign in: account identity via WorkOS, relationship observations you allow, and credit-gated model calls if you use the hosted gateway instead of your own keys.

  • What reaches a model provider

    BYOK goes to the provider you configured. Signed-in hosted LLM calls go through the credit-gated /v1/llm routes. Prompts can contain relationship context you asked the assistant to use.

  • Permissions and writes

    Connectors start as reads. Gmail, Slack, and HubSpot writes are proposed and held. Slack DMs are out of the first beta. Finance MCP write scopes are limited to development and staging.

  • Telemetry

    PostHog analytics is fail-closed until you enable it. You can turn it off. We do not invent a SOC 2 badge or a HIPAA claim on this page.

The short versions

It can be. Bring your own model keys and keep the vault on disk. Signing in syncs relationship state to the API so web and desktop match. Those are different setups.