At a glance#
The AI Workstation runs your agents on your own computer. Nothing about your conversations reaches the Console unless you choose to share it. This table summarizes where each kind of data lives.
| Data | Where it lives | Shared with Halofy? |
|---|---|---|
| Projects, threads and attachments | The computer running Halofy | No, unless you turn on Team activity. It shares new conversations, including tool results, but not file or image attachments. |
| Provider sign-ins and API keys | The computer that runs the provider | No. |
| Prompts and what the agent reads | Processed by the AI provider you chose, under your account | Not by Halofy. The provider handles them as it would in its own tool. |
| Team skills, instructions and policies | Published in the Console, read by the app for team conversations | Loading them uploads nothing. |
| Captured sessions | The Console, stored encrypted | Yes, only after you turn on Team activity or connect an agent that captures. |
| Product usage events | Sent by the Workstation | Yes, without prompt text, replies, file contents or file paths. |
What stays on your computer#
Halofy runs each provider's agent on your computer, or on another computer you connect to. Your threads, projects and the files you attach are stored on the computer that runs them. A few providers, such as Grok Bot, work on the provider's own remote computer instead.
- Provider logins stay in each provider's own storage on that computer. Removing a provider in Halofy removes Halofy's connection, not the provider's credentials on disk.
- API keys you enter for a provider, such as DeepSeek, are stored as secrets for that provider connection. Commands Halofy shows you never include stored secrets.
- The desktop app encrypts saved credentials for connections to your other computers with your operating system's secure storage. On macOS this is the Keychain item Halofy Safe Storage. If secure storage isn't available, those credentials aren't saved.
- Output from provider sign-in is kept in memory, not saved as terminal history. Provider tools may keep their own login logs.
- Your Halofy account sign-in is saved on the computer that runs Halofy.
What your AI providers receive#
When you send a message, the provider's agent processes it with your account, just as it would in that provider's own tool. That includes the files and command output the agent reads while it works. Your account with that provider governs this processing, and usage limits and billing stay with the provider.
Halofy adds some context of its own. Brief instructions about Halofy features go to the agent with your messages, and in a team conversation, the team's instructions, policies and any skills the agent reads become part of what the provider receives.
Your Halofy account and team configuration#
- Signing in to your Halofy account links your devices and lets the app read your team's configuration. It doesn't upload your conversations.
- Halofy reads team configuration fresh for each team conversation and doesn't copy it into your projects'
AGENTS.mdfiles. - When you connect to one of your other devices through your Halofy account, traffic passes through Halofy's connection service. It's encrypted in transit, but not end to end: the service can process the traffic it forwards. Files and provider credentials stay on each computer. For a direct connection, pair over your local or private network instead. See Remote access.
Team activity: what's shared and when#
Team activity is off until you open Set up, read What gets shared, check the consent box and choose Enable sharing. It then applies to new conversations on that computer, including ones you start from your paired devices.
What's included:
- User and assistant text of new conversations, including subagent conversations.
- Supported tool inputs, results and failures, recorded under the provider's tool name, with each result's outcome, and its exit code, duration and output size when available. Tool inputs and results can contain commands, file paths and text the agent read from files.
- Provider-reported token counts with their model and provider, and an estimated spend. Estimates aren't your provider invoice.
- Each conversation's permission mode, reasoning effort and context compactions. The working folder is identified by its name and a fingerprint, not its full path.
Not included
- File and image attachments. Large or unsupported payloads are replaced by a fingerprint of the content.
- Conversations from before you turned on sharing, imported histories, and activity while sharing is paused.
Who can see it
Captured conversations are attributed to the Halofy account signed in on that computer, so only turn on sharing on a computer and paired devices that you alone use. Your team's authorized managers can read captured content under your organization's retention and erasure policies.
Your controls
- Pause stops new capture and uploads. Resume restarts them; start a new conversation afterwards.
- Signing out or changing teams pauses capture.
- Content waiting to upload is encrypted on your computer. Queued batches that can't be delivered expire after seven days.
Agents connected from the Console#
Agents you connect from Agent connections with the installer command can also send supported conversation activity. Your activity may be retained for your authorized managers to review. Before connecting, review the installer’s capture details and type CONNECT to confirm before any changes are made.
In the Console#
- Sign-in. You sign in with Google, GitHub or email, depending on what the sign-in page offers. In Settings, you can connect or disconnect sign-in methods, as long as one stays connected.
- Access. Captured conversations are stored encrypted, and roles decide who can read them: the person a session belongs to, the organization's owner, and the admins who manage that team.
- Summaries. The Console creates a short summary of each captured session. Summaries appear in Sessions and in exports.
- Credentials. API keys you add in AI models are write-only. The Console shows Encrypted and stored, never the key itself.
- Assistant. Questions you ask the Assistant are answered by a model your workspace deployed in AI models, using only information you're allowed to see.
- Audit. Audit records every read, write, deletion and export of your organization's memory. See Audit log.
Retention, erasure and export#
Retention applies to all captured conversations in your organization. You'll find these controls in a connection's details under Agent Connections, and on the Export page.
| Control | What it does | Who can use it |
|---|---|---|
| Keep conversations | Sets how long captured conversations are kept: 30, 90, 180, 365 or 730 days, or Indefinite. Unless changed, conversations are kept for 365 days. Each session shows its Kept until date. | Owner |
| Place legal hold | Stops a session from being deleted when its retention period ends. Release legal hold applies the retention period again. | Owner |
| Erase | Permanently removes a captured session and its attributable derivatives. A reason code is required, and it can't be undone. | Owner, admin |
| Export | Downloads session details and summaries for the organization, a team or a person. A stated purpose is required and each export is recorded in the audit log. Raw messages and tool calls aren't included, and erased sessions never are. | Owner, admin |
Product usage data#
Separately from team activity, the Workstation sends product usage events that help Halofy understand how the app is used. Examples are the app starting, a thread being created, and an agent session starting or a turn finishing.
Events carry details such as the provider, model, permission mode, token counts, durations and counts of projects and threads, along with the app version, operating system and processor type. They're sent with a hashed identifier, not your name or email address, and they don't include your prompts, replies, file contents or file paths.
