<!-- Generated from use-cases/private-ai.html. Do not edit by hand. -->

> Markdown twin of https://conduitllm.com/use-cases/private-ai.html
> A private AI assistant for confidential work — local SQLite storage, no Conduit account or server, no background telemetry, and offline use with Ollama.

---
1. [Conduit](https://conduitllm.com/)
2. [Use cases](https://conduitllm.com/use-cases.html)
3. Private AI

Privacy by architecture

# A *private AI assistant* that doesn't phone home

For work that can't go into a cloud chat account — client files, patient records, source material, unreleased financials, or anything under an NDA. Conduit keeps conversations in a local database, holds no account of yours, and doesn't run telemetry in the background. It's not a compliance certification; it's an app built so there's less to certify in the first place.

[Download Conduit](https://conduitllm.com/#get) See what leaves the machine

- No Conduit account or server
- No background telemetry, no analytics in the app
- Runs fully offline with a local model

The interface can request a completion. It cannot read a key, open a socket, or touch the database — that's all in a separate core process, and you can verify it in the source.

The problem

"We don't put client material into ChatGPT" is a policy at a lot of firms, and it's a reasonable one — a hosted chat account is someone else's server, someone else's retention window, and someone else's fine print about training data. The usual fix is to just not use AI for that work, which means the people with the most sensitive files get the least help from any of this.

What makes it private

## Precise claims, not a privacy badge

Every line below is a specific, checkable design choice — not a promise about intentions.

### The interface never holds a key

Credentials, the network client, and the database all live in a separate Rust core. The screen you type into can ask for a completion and nothing else — it has no way to read a key or open a connection, and that's enforced by how the app is built, not a setting you could turn off.

### Nothing leaves unless a feature needs it

Conversations, documents, and artifacts sit in a local SQLite database and blob store. There's no Conduit account and no Conduit server for any of it to sync to — and no background telemetry or analytics running inside the app.

### A real switch for air-gapped work

Local-only mode refuses cloud providers and switches off web search, cloud document indexing, and page network access in one toggle. Pair it with a local model in Ollama or LM Studio and turn update checks off, and Conduit makes no internet requests at all — it will run with the network cable out.

How it works

## Set it up for confidential work in three steps

None of this needs a config file or a command line.

### Turn on local-only mode

It's already on for a fresh install; picking a cloud provider during setup is what turns it off. Flip it back on in Settings → Privacy & data: cloud providers are refused, and web search, cloud indexing, and page network access switch off.

### Point it at a local model

Install Ollama or LM Studio, pick a model, and add it in Conduit with no key and no bill. If you still need a frontier model for some tasks, add that key later and turn local-only mode off when you switch to it — while it's on, a cloud provider is refused.

### Keep update checks manual

Checks are manual by default already. Leave the update policy on `manual` and nothing is contacted unless you press Check now — the last requirement for a machine with no route to the internet at all.

Every flow, not a vague promise

## What leaves your machine, and where

This is the short version of five of the flows the app can make. The [privacy page](https://conduitllm.com/privacy.html) has the complete table, including MCP and diagnostics.

| Flow | Goes to | Default |
| --- | --- | --- |
| Chat messages and attachments | The provider you picked for that chat | Needs a provider — stays on your machine with Ollama or LM Studio |
| Document embedding | OpenAI, Gemini, or OpenRouter — Ollama stays on-device | Inert until you build a collection; asks per provider, forces Ollama in local-only mode |
| Web search query | Anthropic/OpenAI/Gemini/OpenRouter's own search, or Exa (the default), Tavily, Brave, your SearXNG, or DuckDuckGo | Off by default; disabled entirely in local-only mode |
| Update check | The update manifest host, then a GitHub release asset | Manual — nothing is contacted until you press Check now |
| Diagnostics export | Nowhere — written to a local file, home path redacted | Only when you ask for one |

Whatever you send to a cloud provider is covered by that provider's own policy — Conduit isn't in the exchange, but that also means it can't protect you from it. This website, not the app, uses Google Analytics; see the [privacy page](https://conduitllm.com/privacy.html#this-website) for that distinction.

Limits

## What it does, and what it doesn't

### What it does

- Stores conversations, attachments, and artifacts in a local SQLite database and blob store — no Conduit account, no Conduit server.
- Keeps API keys out of the interface layer entirely; keys live in your OS keychain, read only by the Rust core.
- Runs no background telemetry and no analytics inside the app.
- Checks for updates manually by default, and verifies the signature on any payload before applying it.
- Refuses cloud providers, and switches off web search, cloud document indexing, and page network access, with one local-only mode switch.
- Makes no internet requests at all once you're on a local model with update checks off — genuinely usable air-gapped.
- Offers optional AES-256-GCM encryption at rest, key wrapped by your OS keychain.
- Exports diagnostics only when you ask — to a local file, redacted, after an explicit acknowledgement.

### What it doesn't

- Isn't HIPAA, GDPR, or SOC 2 certified, and doesn't make your organization compliant by itself.
- Encrypt at rest unless you turn it on — off by default, and even on, it doesn't cover message text, the event log, compaction summaries, or the search index.
- Control what a cloud provider does with what you send it — that's their policy, not a Conduit setting.
- Keep documents fully local unless you pick Ollama for embedding — the other three options send the full text to build the index.
- Keep a web search query private from the search backend it's sent to.
- Sync anything between devices — there's no account to sync through.
- Ship code-signed installers yet — expect a SmartScreen or Gatekeeper prompt, release-candidate stage.

## Private AI assistant questions

**Is Conduit a private AI assistant?**

It's local-first and architecturally private, not privacy-certified. Conversations live in a local SQLite database on your machine, there's no Conduit account or server, and the interface layer never holds an API key — a separate Rust core does. There's no background telemetry and no analytics in the app. But whatever you send to a cloud model provider is covered by that provider's own policy, not Conduit's; Conduit is not in the middle of that exchange, but it isn't a substitute for it either.

**Can Conduit run fully offline, air-gapped?**

Yes. Pick a local model in Ollama or LM Studio, turn on local-only mode, and leave update checks on manual, the default. Local-only mode refuses cloud providers outright — even one picked by mistake can't answer — and switches off web search, cloud document indexing, and page network access. With all three set, Conduit makes no internet requests at all.

**Does Conduit have telemetry or send usage data anywhere?**

No. There's no background telemetry and no analytics running inside the app, and no usage reporting to us or anyone else. Update checks are manual by default — nothing is contacted until you press Check now — and any update payload is signature-verified before it's applied. The [privacy page](https://conduitllm.com/privacy.html) lists every network flow the app can make and its default.

**Is data encrypted at rest?**

Optionally, and it's off by default. Turning it on in Settings applies AES-256-GCM with the key wrapped by your OS keychain, and it covers attachment and artifact blobs, document chunks, saved memory, saved prompts, custom instructions, and tool results. It does not yet cover message text, the event log, compaction summaries, or the search index — with the setting off, all of that is plain SQLite on disk, same as any local database.

**Can I use it for HIPAA or GDPR-regulated work?**

Conduit isn't HIPAA, GDPR, or SOC 2 certified, and no software vendor's marketing page can make you compliant by itself — that's a program your organization runs, not a checkbox in an app. What Conduit can honestly say is that it's built to keep data off third-party servers by default — no Conduit account, local storage, and a local model when you need nothing to leave the machine. Whether that's sufficient for your obligations is a question for whoever owns compliance where you work.

**What about my documents — do they stay private too?**

Only if you pick a local embedding model. Adding a file to a document collection is fully on-device with Ollama; with OpenAI, Gemini, or OpenRouter, the full text of the document is sent to that provider once, to build the index, after you consent provider by provider. Local-only mode forces Ollama and refuses the cloud options. [How document chat works](https://conduitllm.com/use-cases/chat-with-documents.html) covers the rest.

Related

## Other ways teams use Conduit

For air-gapped work

### Local models, with a real app around them

Ollama, LM Studio, or your own server — no key, no bill, no internet.

[Run models locally](https://conduitllm.com/use-cases/local-llm.html) For confidential files

### Ask your own files

PDF, Word, CSV, Markdown, and text, parsed on your machine, with cited passages.

Chat with your documents For security-conscious developers

### An MCP client that asks first

Local and remote servers, consent gating, and output redaction on every tool call.

Conduit as your MCP client

## Try it on your own machine

Free and open source. No account, no telemetry, and a switch that takes it fully offline.

[Download Conduit](https://conduitllm.com/#get) [Read the privacy page](https://conduitllm.com/privacy.html)

A release candidate: installers aren't OS code-signed yet, so expect a SmartScreen or Gatekeeper prompt on first launch.
