Skip to content
🪶Pivra Desk

Privacy, and where your data lives

Everything is in a local database on your computer. What leaves, when, and the one list of exceptions.

Updated 4 Oct 2026

The short version: your agents, chats, runs, memory, rules and routines are in a local database in Pivra Desk's data folder on your computer. Keys, sign-in tokens and logins are in a vault sealed with a key that lives in your Mac's login keychain (a key file readable only by your user, on Windows). Nothing is sent to Pivra by default. We never train on your data.

The full account, written from the code of the released app and kept in step with each release, is Security and privacy, in plain words. The legal version is the privacy policy, section 9A.

What leaves your computer, and only when

WhatWhenWhere it goes
Chats, memory, rules, routines, filesNeverThey stay in the local database. Delete the data folder and they are gone.
A model running on this computerNeverNowhere. It runs through llama.cpp on your machine.
A cloud model with your own keyOnly when the agent uses itFrom your computer to the provider you chose, under your account. Not through Pivra.
Web search and reading a pageOnly when the agent uses those toolsThe query goes to DuckDuckGo; the page address goes to that site. Private and local addresses are refused.
Connected apps (Google, GitHub, MCP)Only when the agent uses themStraight to that service, with tokens from the vault.
Signing in to a planOnly if you sign inpivra.ai, once, to exchange a short code for a signed entitlement. Pivra learns the computer name and plan, not your work.
Anonymous usageOnly if you turn it onA fixed list of events (app started, onboarding step, provider chosen, agent created, routine created, approval decided, run finished) with fields limited to known values or counts. Never prompts, replies, file names, addresses, emails or names.
Checking for updatesRoutine, no contentdownloads.bluebirdtec.com, to read the version manifest.

Settings that matter

  • Settings → General → Anonymous usage: off unless you turned it on during setup. Turn it off any time.
  • Settings → Safety → Internet for its programs: whether programs the agent runs can reach the internet, not at all, through a filtering proxy on your computer with an allowlist, or openly.
  • Settings → General → Copy diagnostics: if support asks, this copies version and system details to paste into your message. They never include keys, files, or what your agents read.

Where the files are

The data folder is inside the app's own data directory for your user (on a Mac under ~/Library/Application Support, on Windows under %APPDATA%). Files the agent works on stay where they are, or in a work folder it is given. Each agent's browser profile is separate from yours and from other agents, and its sessions never leave the machine.

What is kept for how long

Once a day, finished runs older than a week drop their full message history (the reply, the trace and the usage stay); runs, approval cards and notifications older than 90 days are deleted; logs rotate at 10 MB, three kept. All of this is on your computer.

What we have not done yet

No third-party security audit, penetration test, SOC 2 or ISO 27001 report; Docker rather than a built-in sandbox on Windows; Google's verification of our sign-in app still pending; the Pivra relay for Teams and webhooks built but not switched on; no bug bounty. The list, in full and kept current, is on the security page.

Found something? Email support@pivra.ai with "Security" in the subject.

Was this helpful?

If you have questions or suggestions, email us at support@pivra.ai .