What each feature sees — and how to switch it off
The privacy policy is the legal document. This page is the practical one: feature by feature, what it can access, where that data actually goes, the switch that turns it off, and how we recommend using it. Aerenium is local-first — most of what it does never leaves your machine — and the honest way to keep it that way is to know exactly which features reach out.
Whatever privacy layer sits in the middle — ours included — the company running an AI model reads every prompt sent to it, because a model cannot answer what it cannot read. Modern providers can identify a person from the content of text alone. So treat every AI like a stranger on the phone: never send passwords, license or ID numbers, medical or financial records, or details that could identify a person, unless you would hand the same page to an outside vendor. This applies to Aerenium, to our credit proxy, and to every AI product on earth.
What runs where
- Your conversations and chat history
- The 4×4 memory matrix and dream consolidation
- Snapshots and rollback state
- Settings, budgets, and licenses
- Files, clipboard, and screen reads the app performs
- LLM requests — to our proxy or your own key
- Vision analysis you ask for — the image goes to the model
- Cloud backup — only if you bought storage
- Discord messages — only in channels you connect
- License checks — a signed token, every 5 days
- Prompt or reply logs on our proxy
- Training on your content
- Sale or sharing of your data
- Telemetry of your conversations
Every feature, its reach, and its off switch
Chat & the executive loop
- Sees
- What you type, plus the working context the assistant builds (memory excerpts, tool results).
- Goes to
- The model you selected — through the Aerenium credit proxy, or directly to the provider on your own key. Nowhere else.
- Off switch
- Stop the executive loop from the dashboard; the app stays usable as a plain local tool. The loop also parks itself when your balance is empty.
- Recommend
- Keep autonomous-spend caps on (they ship off-by-default for spending, capped for models). Let the budget page pace your balance.
Vision — screen, window & region capture
- Sees
- Exactly what is on the screen region you point it at, only when a capture runs.
- Goes to
- Stays local for OCR; goes to the model only when you ask for an AI analysis of the capture.
- Off switch
- Vision toggles in Settings; the assistant can also simply never be asked to look.
- Recommend
- Close sensitive documents, password managers, and private chats before asking anything that captures the screen.
Microphone & voice
- Sees
- Audio while listening is active; the wake word is detected locally.
- Goes to
- Speech-to-text runs locally by default. Text produced from your speech follows the same path as typed chat.
- Off switch
- Speech settings; wake-word autostart is a toggle, and the mic indicator always shows when listening.
- Recommend
- Disable wake-word autostart in shared spaces.
Memory, dreams & the matrix
- Sees
- Your conversations, distilled into memory cells over time.
- Goes to
- Nowhere — memory lives on disk, on your machine. One exception: optional LLM-assisted dream consolidation sends memory summaries to your selected model when you enable it.
- Off switch
- Dream toggles in Settings (micro-dreams and auto-dreams are separate); LLM consolidation is its own switch. The Memory page shows and edits everything held.
- Recommend
- Skim the Memory page occasionally — it is the honest inventory of what your assistant knows about you, and everything there is deletable.
Cloud backup (Aerethis Cloud)
- Sees
- The snapshots you pin plus one rolling daily save — nothing else on your machine.
- Goes to
- Our servers, tied to your subscription, only if you bought storage. Off by default, never required.
- Off switch
- Simply don't buy it — or delete snapshots from the app; lapsed plans get a read-only grace window, then permanent deletion.
- Recommend
- Great for the assistant's own working state; keep truly sensitive files in your own backup system instead.
The credit proxy
- Sees
- Your prompts pass through it to the model. We log the bill — model, token counts, credits, timestamp — never the content.
- Goes to
- The upstream model provider, who reads the prompt to answer it. Their retention is governed by their policy, not ours.
- Off switch
- Use your own API key (Settings, Budget & API) or a local model — then our proxy never sees a byte.
- Recommend
- The proxy is the convenient default; your own key with a provider you trust is the confidential-work option; local models are the nothing-ever-leaves option.
Discord co-pilot
- Sees
- Messages in the channels you explicitly connect, and voice when you invite it into a channel.
- Goes to
- Discord's own servers (that is how Discord works) plus the model for replies.
- Off switch
- Disconnect the bot in Settings; it is off until you connect it.
- Recommend
- Connect only servers where everyone knows an assistant is present.
Sub-agents, swarms & skills
- Sees
- Only the task they are given, inside a jailed workspace with a scrubbed environment.
- Goes to
- Network access is denied by default; skill code is statically scanned; elevation is explicit and logged. Model calls follow the same path as chat, capped to economy-band models unless you grant more.
- Off switch
- Sub-agent spawn limits and model-band caps in Settings, Budget & API; individual swarms stop from the dashboard.
- Recommend
- Leave the sandbox defaults alone — they exist so a skill can never quietly do what the executive itself is not allowed to do.
Five habits that cover almost everything
- Never give any AI sensitive identifiers. Passwords, ID and license numbers, medical or financial records, other people's private details — out of every prompt, on every product, always.
- Match the channel to the work. Everyday tasks: the credit proxy is fine. Confidential work: your own key with a provider whose policy you accept. Truly private work: a local model — nothing beats a request that never leaves the machine.
- Mind the screen before you share it. Vision sends what it sees. Close what should not be in the frame first.
- Visit the Memory page now and then. It is the full inventory of what your assistant remembers — prune what should not be there and the dreams will keep it tidy.
- Leave the guardrails on. Autonomous spending defaults to off, swarms run sandboxed, and budgets pace your balance. Every one of those is a promise the app keeps so you don't have to think about it.
Questions this page didn't answer? The privacy policy has the formal commitments, and the contact form reaches a human who will answer plainly.