Pivra Desk · Security and privacy
Where your data lives, what leaves, and what we have not done yet.
This page is written from the code of the released app, not from a brief. It says where Pivra Desk keeps things, exactly when something leaves your computer, how the agent is kept in check, and the gaps we still have. It changes in the same release as the app.
Checked against Pivra Desk 0.2.15. The legal version is in the privacy policy, section 9A.
In one screen
- Default
- On-device. Nothing is sent to Pivra unless you turn something on.
- Actions
- Reads run freely. Sends, payments and changes wait for your approval. Money needs Touch ID or a typed phrase.
- Honesty
- No audit yet, Docker on Windows, relay not live. The list is below, in full.
Where your data lives
Everything the agent knows is in a local database in Pivra Desk’s data folder on your computer: your agents, chats, runs, memory, rules and routines. Files the agent works on stay where they are, or in a work folder it is given.
Keys, sign-in tokens and logins are kept in a vault sealed with a 256-bit key. On a Mac that key is in your login keychain; on Windows it is a key file in the data folder readable only by your user. The vault never silently switches where its key comes from; if the keychain is locked, saved logins are simply unavailable until it opens.
Nothing is sent to Pivra by default. Every exception is something you turn on, and each one is in the table below.
What leaves your computer, and when
One row per thing the app can do that involves anything beyond your computer.
| What | Leaves? | Where it goes, and what we know |
|---|---|---|
| Chats, memory, rules, routines, files | Stays on your computer | A local database in Pivra Desk’s data folder on your computerPivra does not receive them. Delete the folder and they are gone. |
| A model running on your computer (Offline mode) | Stays on your computer | Nowhere. Gemma 4 or Qwen runs through llama.cpp on your machineThe model file is downloaded once from Hugging Face and checked against a pinned SHA-256 checksum before use. |
| A cloud model with your own key | Only when the agent uses it | From your computer to the provider you chose (Anthropic, OpenAI, OpenRouter, or an OpenAI-compatible endpoint)Under your own account and their terms. Not through Pivra. The request carries what the agent needs for that turn. |
| Web search and reading a web page | Only when the agent uses it | The search query goes to DuckDuckGo; a page address goes to that siteOnly when the agent uses those tools. Private and local addresses are refused. |
| Connected apps (Google Calendar, GitHub, MCP servers) | Only when the agent uses it | From your computer straight to that service, with tokens from the vaultGoogle: calendar read-only and your account email, nothing else. GitHub: public repositories unless you opt in to private. |
| Signing in to a plan | Only if you turn it on | pivra.ai, once, to exchange a short code for a signed entitlementThe entitlement is checked offline afterwards and is bound to this computer. Pivra learns the computer name and plan, not your work. |
| Product analytics in the app | Only if you turn it on | PostHog (EU region), only if you said yesA fixed list of events (app started, onboarding step, provider chosen, agent created, routine created, approval decided, run finished) with fields limited to known values or counts. Never prompts, replies, file names, addresses, emails or names. |
| Checking for updates | Routine, no content | downloads.bluebirdtec.com, to read the version manifestThe signed app checks for a new build. No account or content is involved. |
| The Pivra relay (Teams and webhooks) | Only if you turn it on | Not switched on yet. When it is: Pivra’s relay, only for channels you turn onContent is never logged; while your computer is offline it is kept encrypted for at most 24 hours and deleted on delivery. Described in the privacy policy before it ships. |
How the agent is kept in check
The model proposes; policy decides. A model’s output is treated as a typed proposal. Rules, permissions, approvals and idempotency decide whether it runs. No skill, web page, email or model reply can grant itself authority.
- Reading and searching run on their own: looking at a file, a calendar or a web page never needs a click.
- Sending, publishing, paying and changing wait for your approval on a card that shows exactly what will happen (the recipient, the text, the file, the command).
- Money, deletes and deploys are critical: they need Touch ID on a Mac, or a phrase you type. No agent moves money on its own; the money-transfer tool itself has no payment rail connected.
- Your rules are plain words (“never email anyone at example.com”). A “never” rule stops the action at once; an “ask” rule turns an automatic step into a card.
- Cards in Slack or Teams. If you connect your own bot, a card can be answered from there. Only the channel’s owner can press a button, a card can be decided once, and sign-ins and blocked actions never get buttons: they need the desk.
- Every run is recorded on your computer: the steps, the tools called, what was read, and what you decided. The Activity screen shows it.
Commands and code
When an agent runs a command, it runs inside a sandbox, and the kind of sandbox is shown in Settings.
- Mac (default, built in). The operating system’s own sandbox, the same mechanism behind App Sandbox. Everything is denied by default. A command may read system programs, libraries and settings, but not any home folder, other volumes or other apps’ temporary files; it may write only inside its own work folder; and it reaches the network only as you set: not at all, through a filtering proxy on your computer with an allowlist, or openly. The keychain and the pasteboard are off limits.
- Windows (for now) and optional on Mac: Docker. A container on an internal network whose only way out is a proxy sidecar that applies the same network setting. A built-in Windows sandbox is planned.
- Host mode runs commands directly on your computer with no isolation. It is off unless you turn it on, and the app says so.
- Private addresses are refused. The web tools and the sandbox proxy will not talk to loopback, private, link-local or cloud-metadata addresses, in any IPv4 or IPv6 spelling. Unparseable input counts as private: the check fails closed.
The browser
When an agent acts on the web it uses a browser on your computer, in its own profile, separate from yours and from other agents. Its sessions never leave your machine. Booking, buying, sending, cancelling and deleting are approval-tier actions, and you can take over the browser at any moment.
Connected accounts, least privilege
- Google. Pivra’s built-in sign-in asks for your calendar (read only) and your account email, nothing else. Data goes from Google to your computer. Gmail needs your own Google sign-in app until Gmail access passes Google’s security assessment. Disconnecting deletes the tokens and asks Google to revoke access.
- GitHub. Signs in with the device flow, so no secret ships in the app. Public repositories only unless you opt in to the broader scope for private ones.
- MCP servers. Remote servers sign in with OAuth (PKCE and dynamic client registration); write tools sit behind approval like any other.
- Slack and Teams. Your own bot, with its tokens in the vault. Slack connects outbound over Socket Mode. Teams posts to your computer and needs a public address for now; the Pivra relay will remove that need when it ships.
- Which tools a model can see is shown per app. A connected app the model in use cannot call says so, rather than showing “Connected” next to something that will never be touched.
Updates and signing
The Mac app is signed with our Apple Developer ID and notarised by Apple. The Windows app is signed through Azure Artifact Signing under the company named on our Terms page; because the app is new, Windows may still show a SmartScreen notice the first time. Updates come from downloads.bluebirdtec.com; the updater checks that a new build carries the same signature before installing it, never downgrades, and never installs pre-releases. By default an update downloaded while you work is installed when you are away; you can turn that off and install by hand.
What is kept, for how long
Everything is on your computer, so retention is about keeping the app from growing without bound. Once a day:
- Finished runs older than a week drop their full message history; the reply, the trace and the usage stay.
- Runs, approval cards and notifications older than 90 days are deleted; event and dedupe records after 30 days.
- Logs rotate at 10 MB, three kept.
Delete the data folder and nothing remains. A lapsed or cancelled plan turns paid features off; it never locks you out of your own data.
What we have not done yet
We would rather say this here than have you find out.
- No third-party security audit, penetration test, SOC 2 or ISO 27001 report. We will say so here when one exists.
- On Windows, commands run in Docker rather than a built-in operating-system sandbox. A built-in Windows sandbox is the next item on that list.
- Pivra’s Google sign-in app is still going through Google’s verification, so the consent screen may warn that the app is unverified, and Gmail needs your own Google sign-in app for now.
- The Pivra relay for Microsoft Teams and inbound webhooks is built but not switched on for anyone.
- Skills are short pieces of prompt text that you can read in full; they are not yet signed packages with their own permissions.
- No bug bounty programme. If you report a problem we will reply, fix it and credit you if you want.
Found something?
Email support@pivra.ai with “Security” in the subject. Tell us what you found and how to reproduce it. We reply, we fix it, and we credit you here if you want. Please give us a reasonable time to ship a fix before publishing.
The principles behind this page
Private by default. The model proposes, you decide. Never lose your work or your money.
- Your agent, its memory, your files and your sign-ins live on your computer.
- Anything leaving the computer is opt-in and visible where it happens.
- We never train on your data, and we say so in the privacy policy.
- Every action is sorted by what it could do, and asks accordingly.
- Paid features that cost us per use are capped below their price.
- Say what was checked and what could not be; no dead ends.