Privacy
This is an operator draft, not a lawyer-reviewed policy. It describes how the current product is built.
Desktop
The desktop app runs the agent on your machine. Provider API keys live in the OS keychain. Runtime telemetry on a user-owned machine is local-only; nothing uploads it.
Account and hosted sessions
Signing in is optional on desktop and required on the web app. Hosted identity is Clerk. Hosted sessions and account data live in Postgres with row-level isolation on the Gambalf server.
Waitlist
Cloud signup is Clerk Waitlist mode. Your email goes to Clerk so an operator can send an invite. There is no second mailing list on this site.