Privacy

What Conduit does with your data

Short version: it stays on your computer. The application has no servers, no accounts, and no telemetry. There is nothing for us to collect because there is nowhere for it to go. This website is a separate thing, and it does use analytics — see below.

What we collect

Nothing. Conduit is a desktop application with no backend. We operate no service that receives your conversations, your keys, your usage, or your identity, and there is no telemetry running in the background.

What stays on your machine

All of it lives in your platform's application data directory. Deleting it is a matter of deleting those files; the app also offers a reset that takes a backup first.

What leaves your machine

Only what you ask for, and it goes directly to the service concerned — never through us.

TrafficGoes toWhen
Your prompts and attachments, plus the system prompt, saved memory items, retrieved document passages, and skills text when those are in play The chat provider you picked When you send a message, to the provider you selected. Pick Ollama or LM Studio and it stays on your machine. Local-only mode refuses cloud providers
Model list requests The same provider When you open the model picker
The full text of a document, for embedding OpenAI, Gemini, or OpenRouter — Ollama embeds on-device and sends nothing Inert until you create a document collection, then only after you consent, provider by provider. Local-only mode forces Ollama
The image prompt, for image generation OpenAI, Gemini, or OpenRouter When you generate an image — Conduit asks once, before the first one
Hosted web search query Anthropic, OpenAI, Gemini, or OpenRouter's own search Off by default; asks for consent when you turn it on
Local web search query Exa by default (no key needed; Exa may keep queries under its terms), or Tavily, Brave, your own SearXNG instance, or DuckDuckGo Same toggle as hosted search — off by default, and disabled in local-only mode
Web fetch, when the model reads a page it found Whatever site the model picks Follows the web search toggle — off by default
Research: its search queries, and the text of the pages and PDFs it reads Queries go to your local search backend, as above; page text goes to the chat provider you picked, and the pages are fetched from their own sites Only when you turn Research on for a message and approve its brief. It needs web search on, so it is off by default and unavailable in local-only mode
A request an HTML artifact makes — its address and anything it sends. Conduit makes it on the page's behalf, without cookies or credentials, so the site sees your IP address The site the page asked for, over https, never a local or private address Nothing until you allow that site for that page, or let the page reach any public site. Permissions belong to one page. Refused in local-only mode, and can be switched off in Settings → Privacy & data
MCP tool calls, prompts, and resource requests The MCP servers you add Nothing until you add one. A tool asks first unless its server marks it read-only
MCP OAuth sign-in The server's authorization server, which in turn fetches Conduit's client metadata document from conduitllm.com Only when you connect an MCP server that uses OAuth
MCP registry search registry.modelcontextprotocol.io Only when you search the registry
Update checks The update manifest host Only when you press Check now, or about once a day if you turned background checking on

Your provider will have its own policy on what it does with what you send it. That relationship is between you and them — Conduit is not in the middle of it, and never proxies or resells access.

Local-only mode refuses every cloud provider — only a local model such as Ollama or LM Studio can answer — and switches off web search, web fetch, cloud document indexing, and page network access. It's on by default for a fresh install; picking a cloud provider turns it off. With it on, a local provider selected, and update checks left on manual, Conduit makes no internet requests whatsoever.

How your API keys are handled

Keys go into Windows Credential Manager, macOS Keychain, or Linux Secret Service. Conduit's settings store a reference to the entry, never the secret itself.

The interface layer never receives a key at all. Credentials, network calls, and storage are handled entirely by a separate core process; the interface can request a completion but has no way to read a credential or open a connection. This is enforced by how the application is built, and you can verify it in the source.

On systems without a working keychain, an encrypted file-backed store is available. It is an explicit opt-in requiring you to supply a key through the environment — Conduit will never silently fall back to it.

Encryption at rest

Conduit offers optional AES-256-GCM encryption at rest, with the master key wrapped by your OS keychain, plus key rotation. Here is the honest scope:

If your threat model includes someone with access to your disk reading your conversations, use full-disk encryption. Conduit's own encryption is not a substitute for it today.

Diagnostics

Diagnostics bundles are generated only when you ask for one, and only after you acknowledge what they contain. They deliberately exclude API keys and other secrets, provider base URLs, your domain allow and block lists, and the content of your conversations. Nothing is transmitted — you get a file, and it is yours to share or not.

Updates

Update checks are opt-in. When enabled, Conduit fetches a manifest and verifies the cryptographic signature on any payload before applying it, so an update cannot be tampered with in transit. A check reveals your IP address to the host serving the manifest, as any network request would; nothing about you or your usage is included.

Checking is manual by default: nothing is contacted until you ask for it. Background checking, and installing an update when you quit, are options you switch on yourself. Conduit never restarts itself to apply one.

This website

This site uses Google Analytics to count visits and see which pages get read. It sets cookies and sends your IP address and the pages you view to Google. That applies to this website only — it is not in the application, and installing Conduit does not carry it with you. Fonts are served from this domain rather than a third party.

Your theme preference is stored in your browser and never leaves it. Whoever hosts these pages will see standard web server request logs.

Changes

If any of this changes, it changes here and in the repository's history at the same time. Because Conduit is open source, you never have to take this page's word for it — the behaviour it describes is in the code.

Read the documentation