Home Features Pricing Privacy policy Contact Log in
Privacy guide

What each feature sees — and how to switch it off

The privacy policy is the legal document. This page is the practical one: feature by feature, what it can access, where that data actually goes, the switch that turns it off, and how we recommend using it. Aerenium is local-first — most of what it does never leaves your machine — and the honest way to keep it that way is to know exactly which features reach out.

The one rule that matters more than every toggle on this page

Whatever privacy layer sits in the middle — ours included — the company running an AI model reads every prompt sent to it, because a model cannot answer what it cannot read. Modern providers can identify a person from the content of text alone. So treat every AI like a stranger on the phone: never send passwords, license or ID numbers, medical or financial records, or details that could identify a person, unless you would hand the same page to an outside vendor. This applies to Aerenium, to our credit proxy, and to every AI product on earth.

The map

What runs where

Stays on your machine
  • Your conversations and chat history
  • The 4×4 memory matrix and dream consolidation
  • Snapshots and rollback state
  • Settings, budgets, and licenses
  • Files, clipboard, and screen reads the app performs
Leaves only when you use it
  • LLM requests — to our proxy or your own key
  • Vision analysis you ask for — the image goes to the model
  • Cloud backup — only if you bought storage
  • Discord messages — only in channels you connect
  • License checks — a signed token, every 5 days
Never exists anywhere
  • Prompt or reply logs on our proxy
  • Training on your content
  • Sale or sharing of your data
  • Telemetry of your conversations
Feature by feature

Every feature, its reach, and its off switch

Chat & the executive loop

Sees
What you type, plus the working context the assistant builds (memory excerpts, tool results).
Goes to
The model you selected — through the Aerenium credit proxy, or directly to the provider on your own key. Nowhere else.
Off switch
Stop the executive loop from the dashboard; the app stays usable as a plain local tool. The loop also parks itself when your balance is empty.
Recommend
Keep autonomous-spend caps on (they ship off-by-default for spending, capped for models). Let the budget page pace your balance.

Vision — screen, window & region capture

Sees
Exactly what is on the screen region you point it at, only when a capture runs.
Goes to
Stays local for OCR; goes to the model only when you ask for an AI analysis of the capture.
Off switch
Vision toggles in Settings; the assistant can also simply never be asked to look.
Recommend
Close sensitive documents, password managers, and private chats before asking anything that captures the screen.

Microphone & voice

Sees
Audio while listening is active; the wake word is detected locally.
Goes to
Speech-to-text runs locally by default. Text produced from your speech follows the same path as typed chat.
Off switch
Speech settings; wake-word autostart is a toggle, and the mic indicator always shows when listening.
Recommend
Disable wake-word autostart in shared spaces.

Memory, dreams & the matrix

Sees
Your conversations, distilled into memory cells over time.
Goes to
Nowhere — memory lives on disk, on your machine. One exception: optional LLM-assisted dream consolidation sends memory summaries to your selected model when you enable it.
Off switch
Dream toggles in Settings (micro-dreams and auto-dreams are separate); LLM consolidation is its own switch. The Memory page shows and edits everything held.
Recommend
Skim the Memory page occasionally — it is the honest inventory of what your assistant knows about you, and everything there is deletable.

Cloud backup (Aerethis Cloud)

Sees
The snapshots you pin plus one rolling daily save — nothing else on your machine.
Goes to
Our servers, tied to your subscription, only if you bought storage. Off by default, never required.
Off switch
Simply don't buy it — or delete snapshots from the app; lapsed plans get a read-only grace window, then permanent deletion.
Recommend
Great for the assistant's own working state; keep truly sensitive files in your own backup system instead.

The credit proxy

Sees
Your prompts pass through it to the model. We log the bill — model, token counts, credits, timestamp — never the content.
Goes to
The upstream model provider, who reads the prompt to answer it. Their retention is governed by their policy, not ours.
Off switch
Use your own API key (Settings, Budget & API) or a local model — then our proxy never sees a byte.
Recommend
The proxy is the convenient default; your own key with a provider you trust is the confidential-work option; local models are the nothing-ever-leaves option.

Discord co-pilot

Sees
Messages in the channels you explicitly connect, and voice when you invite it into a channel.
Goes to
Discord's own servers (that is how Discord works) plus the model for replies.
Off switch
Disconnect the bot in Settings; it is off until you connect it.
Recommend
Connect only servers where everyone knows an assistant is present.

Sub-agents, swarms & skills

Sees
Only the task they are given, inside a jailed workspace with a scrubbed environment.
Goes to
Network access is denied by default; skill code is statically scanned; elevation is explicit and logged. Model calls follow the same path as chat, capped to economy-band models unless you grant more.
Off switch
Sub-agent spawn limits and model-band caps in Settings, Budget & API; individual swarms stop from the dashboard.
Recommend
Leave the sandbox defaults alone — they exist so a skill can never quietly do what the executive itself is not allowed to do.
Recommendations

Five habits that cover almost everything

Questions this page didn't answer? The privacy policy has the formal commitments, and the contact form reaches a human who will answer plainly.