What the desktop can see
A workspace folder you choose, meeting audio you start, the in-app browser pages you open, and the MCP servers you add. It does not get a silent tour of the whole disk.
[security]
This page is the adoption objection, written as the implementation actually behaves. The legal language lives on Privacy and responsible disclosure.
Approval before sendA workspace folder you choose, meeting audio you start, the in-app browser pages you open, and the MCP servers you add. It does not get a silent tour of the whole disk.
Markdown vault files, capture audio, on-device Whisper transcripts, local embeddings, and ~/.rowboat/ config. Delete the folder and those copies are gone.
When you sign in: account identity via WorkOS, relationship observations you allow, and credit-gated model calls if you use the hosted gateway instead of your own keys.
BYOK goes to the provider you configured. Signed-in hosted LLM calls go through the credit-gated /v1/llm routes. Prompts can contain relationship context you asked the assistant to use.
Connectors start as reads. Gmail, Slack, and HubSpot writes are proposed and held. Slack DMs are out of the first beta. Finance MCP write scopes are limited to development and staging.
PostHog analytics is fail-closed until you enable it. You can turn it off. We do not invent a SOC 2 badge or a HIPAA claim on this page.
It can be. Bring your own model keys and keep the vault on disk. Signing in syncs relationship state to the API so web and desktop match. Those are different setups.