Data and privacy
Olyvr is local-first. There is no Olyvr account, no Olyvr cloud service, and no telemetry. Your workspace lives in a folder on your computer.
What stays on your machine
Section titled “What stays on your machine”Everything Olyvr stores is in your data folder:
| OS | Folder |
|---|---|
| macOS | ~/Library/Application Support/Olyvr Workspace |
| Windows | %APPDATA%\Olyvr Workspace |
| Linux | ~/.config/Olyvr Workspace |
Inside state/:
atlas.sqlite3: your sources, document text, search index, chats, projects, memory, preferences, tasks and settingsblobs/: Olyvr’s copies of imported files and saved documentscredential.key: the key that encrypts your stored credentialslocal/: local models and the llama.cpp runtime, if you installed themsubscription/: the subscription proxy’s configuration and sign-in tokens, if you signed in
On macOS and Linux the state folder can only be read by your user account.
What leaves your machine
Section titled “What leaves your machine”Olyvr only contacts the services you set up:
| When | Sent to | What |
|---|---|---|
| You use the agent or generate memory or tasks | Your chosen model provider | Your message, recent conversation, memory notes, matching preferences and skills, and passages from documents the agent reads |
| You connect or refresh an account | Google, Microsoft or GitHub | Sign-in and read-only API requests |
| You install a local model | GitHub and Hugging Face | Downloads of llama.cpp and the model file |
| You connect a plugin | That plugin’s server | Tool calls and their arguments |
| You click a link | Your browser | The link |
With a subscription, requests go through the local proxy on your machine directly to OpenAI or Anthropic. With a local model, model requests never leave your computer.
Credentials
Section titled “Credentials”API keys, account tokens, and plugin secrets and tokens are encrypted at rest with a key stored in your data folder. Saved keys are never shown again in full.
Signing out of an account deletes its token from your machine. It doesn’t revoke access on the provider’s side; do that in your account’s security settings.
The local engine
Section titled “The local engine”Olyvr’s engine runs on your machine and listens only on 127.0.0.1, on a port between 9420 and 9429. It only accepts requests from the Olyvr window that started it, using a random session token created at each launch, and rejects requests from websites and other apps. The app window can’t access your camera, microphone or location.
Deleting your data
Section titled “Deleting your data”- Remove a source to delete its documents from the workspace.
- Delete chats and projects from the sidebar.
- To delete everything, quit Olyvr and delete the data folder.