Comigo / Docs / Set up

Privacy and data

Comigo is built to be local-first: what it learns about your work stays on your Mac. This page explains exactly what leaves your Mac, and when.

Stored on your Mac only

In a local database (~/Library/Application Support/copilot/):

  • tasks, goals, progress and advice;
  • observations: app name, window title, recognized text, audio transcripts and (depending on your storage setting) small screenshots;
  • memories, task chats and voice conversations;
  • ratings and feedback;
  • app-to-app workflow history and usage statistics;
  • settings.

API keys for OpenAI and Anthropic, and your Comigo sign-in, are kept in the macOS Keychain.

Sent to the AI model you chose

To write advice, Comigo sends the model the context it needs for that moment: recognized text, the app and window name, relevant task and memory text, and — if your model supports images or you chose cloud vision — the screenshot. Only allowed apps are ever included.

  • With your own key, this goes straight from your Mac to that provider under their terms.
  • With LM Studio, it never leaves your Mac.
  • With Comigo credits, it goes through AI2's server to the model (via OpenRouter). See below.

What AI2's server receives (Comigo credits and account)

Data Why Kept for
Email / phone and sign-in info (via Clerk) Your account While the account exists
Payments and saved card (via Stripe; AI2 never sees the full card number) Credits As required for accounting
The prompt, reply and images of each billed AI call Billing, support and abuse prevention 7 days, then deleted automatically
Model, token counts and credits of each call Your balance and usage While the account exists
Product events: app opened, signed in/out, setup finished, provider chosen, checkout opened Improving Comigo While the account exists
Your 👍/👎 ratings: suggestion title, type and the reason you picked Improving advice quality While the account exists

Prompts, transcripts, window titles, screenshots and suggestion text are not sent with events or ratings. If you use your own key or LM Studio, AI2's server receives no AI calls at all. Builds may include crash and error reporting that masks all on-screen text.

Your controls

  • Pause monitoring at any time: menu bar icon or ⌘⇧P. While paused nothing is captured and nothing is shared over MCP.
  • Choose what Comigo can see (Settings → Privacy): which displays, active window or entire screen, and an exclude list or an allow-only list of apps.
  • Built-in shields: password managers (1Password, Bitwarden, KeePass, Keychain Access), private/incognito browser windows, and banking/vault windows are excluded by default.
  • Storage (Settings → Storage): keep only text and transcripts, small thumbnails, or a full archive; set a size limit; use Clean Storage Cache to delete the oldest data. Tasks keep working after their screenshots are removed.
  • Memories: review, dismiss or delete any memory.
  • Microphone is used only when you press a microphone or Talk button. System audio needs Screen Recording and can be turned off.
  • MCP is off by default and read-only — see MCP.

Delete your data

  • On your Mac: quit Comigo and delete ~/Library/Application Support/copilot/ (see Uninstalling).
  • Your account: email [email protected] to close your Comigo account and delete its server data.

Captured content and Comigo's own text are treated as information, never as instructions: text on your screen cannot tell Comigo to do something.