Effective 16 July 2026

Privacy

Short version: the project website contains no analytics or advertising code. The desktop app runs locally. Data leaves your device only when you configure and use a remote provider, connector, MCP server, or network-enabled tool.

Project website

This static site does not set its own cookies, create user accounts, load third-party fonts, or include analytics, advertising, pixels, or session-replay scripts. It is hosted by GitHub Pages. GitHub may process technical request data such as IP addresses and browser information under the GitHub Privacy Statement.

Desktop app data

LocalAI Cowork stores application state, task history, audit information, and selected workspace context locally on the computer. The app does not operate a LocalAI Cowork cloud account or synchronization service.

Model providers and connected tools

When you choose a remote model provider, connector, MCP server, webhook, or web-enabled tool, the app sends the information required to perform your requested action to that endpoint. The recipient and its privacy terms depend on the endpoint you configure. Ollama can be used locally to avoid sending model prompts to a hosted provider.

Credentials

On Windows, supported provider keys and connector secrets are stored through Windows Credential Manager. Sensitive values are removed from ordinary persisted frontend state. Backend audit and diagnostic paths redact common secret fields and token formats before storage.

Telemetry

The current release has no implemented telemetry sender, and the telemetry preference defaults to disabled. Future releases must update this notice before introducing any project-operated analytics or telemetry transport.

Local permissions

LocalAI Cowork can work with local files, terminals, processes, and connected tools. These capabilities are powerful. Review workspace access, permission settings, approval prompts, and third-party configurations before using the app with sensitive material.

Security reports

Do not publish credentials or sensitive data in a public issue. Report security vulnerabilities privately through GitHub Security Advisories.

Questions

For non-sensitive privacy questions, open a privacy question. This notice describes the open-source project and is not a substitute for the terms of any model provider or service you connect.