Skip to main content

Local execution & privacy

One of Imaginne's core ideas is local-first: on the app surfaces, the agent works on your machine. This page details what that means in practice and what actually leaves your device.

What runs locally​

On Desktop, in the terminal (TUI), and in VS Code:

  • The Engine (the agent) runs on your computer.
  • The tools run locally: read/write files, run commands, trigger skills.
  • Skills are executed on your machine, from ~/.imaginne/skills/ and from the project's .imaginne/skills/.
  • The session (history, actions, state) and the project memory live in local files in your project/user space.

What leaves your machine​

Only the prompt content — that is, what the model needs to "read" in order to respond — is sent, and only to the Gateway. This includes your message and, when relevant, excerpts of files the agent chose to put into context.

  • The files themselves are not sent by the local surfaces. The agent reads the content locally and sends the model only what is needed for the task.
  • The Gateway is the only component that talks to the model vendor.
The browser chat is different

In the web chat, since nothing is installed, the agent runs on Imaginne's servers. There, the session content travels to and is processed on the server. If your requirement is "nothing leaves the machine," use Desktop or the TUI.

Reducing secrets and personal data​

Before sending content to the model, Imaginne applies a content scanner that recognizes known sensitive patterns and replaces them with markers — emails, phone numbers, CPF/CNPJ, cards, session tokens, cloud keys, and PEM private keys. The matched text is not written to any log.

Treat this as a layer of defense, not an absolute guarantee: it is protection against accidental leakage of the recognized patterns, not a substitute for good judgment when sharing highly sensitive data.

Where your data lives (local surfaces)​

DataWhere it lives
Sessions / historyLocal project files (with a local index).
Project memory<project>/.imaginne/memory/*.md.
Skills~/.imaginne/skills/ (global) and <project>/.imaginne/skills/ (project).
Configuration and session token~/.imaginne/config.yaml.
Generated artifactsThe project's output folder (outputs/ by default).
Local state is not encrypted

Sessions and memory live in readable files on your disk — the same posture as any local project. Protect your machine the way you already protect your code and your documents.

What this guarantees for your organization​

  • File sovereignty. On Desktop/TUI/VS Code, files are not sent; only the content the model needs travels.
  • Single point of egress. All model traffic goes through the Gateway, where the organization enforces credentials and metering.
  • Credentials under control. You don't handle provider keys; skill secrets are injected in a restricted way (see Env-secrets).

Go deeper​