Local-first: what stays on your Mac
Projects, documents, diagrams, whiteboards, task boards, memory indexing and Meetings transcripts live on your Mac. Editing a document, a diagram or the whiteboard never contacts an AI agent by itself.
Security and privacy
An honest summary of what stays on your Mac, what can leave it, and under which decision of yours.
Projects, documents, diagrams, whiteboards, task boards, memory indexing and Meetings transcripts live on your Mac. Editing a document, a diagram or the whiteboard never contacts an AI agent by itself.
A conversation with Claude Code or Codex sends your chosen provider the message and whatever project context you decide to share — that's inherent to using any remote AI agent, with any application. Generating meeting notes, answering a copilot question or indexing files for memory use short turns of the same engine, scoped to the needed fragments, never the full audio recording (which, in Meetings, is never kept at all).
Installing a skill, adding an MCP server or publishing to a cloud folder are always actions you decide, each with its own explicit confirmation — they never happen quietly in the background.
When an agent uses the built-in browser, every action (reading a page, typing into a field, clicking a button, downloading something) shows a prompt you must approve; you're never shown the contents of a password field. For a login or a payment, the agent can ask you to take control directly.
Before indexing a file, Talo looks for credential patterns (API keys, tokens, passwords, connection strings) and replaces them with "[secret omitted]": that text never reaches the index, a profile, or the agent. Each project's "Sources" tab shows how many secrets were omitted per file.
Memory, instructions and conversations are separated by project. In People, one project never sees another project's data in the same view. A sensitive fact (health, religion, ideology, union membership) is marked "outside the AI" and never reaches an agent or a briefing. This separation organizes context; it is not an absolute sandbox from everything a file-permissioned agent might be able to read on the Mac.
What an automation creates starts paused and runs on an isolated copy of the project, never on the real folder. If anything changes, it stays "pending review" until you open the diff and press "Apply".
Beta builds are signed with a Developer ID certificate and notarized by Apple before shipping; spctl recognizes them as "Notarized Developer ID". Gatekeeper may take a few seconds to verify the app the first time you open it — the same behavior as any other signed app outside the App Store.
The app's "Report a problem" button shows you exactly what will be sent — comment, screenshots and logs, already redacted — before it leaves your Mac, and it only sends if you tick the consent checkbox.
There is no proprietary end-to-end encryption beyond what macOS itself offers (FileVault) for the disk; separation between projects is a logical organization inside Talo, not an OS-level sandbox. See the full guide page (Spanish) for case-by-case technical detail.