Skip to content

Privacy & Security

Your work stays yours.

Nova can see and act across everything you do, so the defaults have to be right. It is local-first by design, honest about the line between on-device and cloud, and built so you can see and erase everything it holds. This page is the detailed version.

On-device by default

Nova reads your screen and files on the machine that renders them. Understanding your work does not require sending it anywhere — the default is local, not a setting you have to find.

The cloud is opt-in

When a task genuinely needs more than local reasoning, Nova can use the cloud — but only with your say-so, per task. Every cloud call is named, encrypted in transit, and never retained on our side.

You own your memory

The memory index is a file on your disk, encrypted at rest. You can open it and read what Nova holds in plain terms, correct any part, and erase all of it with one command.

You grant the permissions

Nova sees and acts only within the scope you allow, and it pauses to ask before anything irreversible. What's out of scope stays invisible to it.

Data residency

Where every kind of data lives.

The honest map most tools won’t show you: what Nova touches, where it sits, whether it’s encrypted, and whether it ever leaves your machine.

Screen contents
Where it livesIn memory, on your machine
EncryptedWhile in use
Leaves your device?No
Your files
Where it livesWhere you already keep them
EncryptedBy your OS / disk
Leaves your device?No
Memory index
Where it livesA file on your disk
EncryptedAt rest
Leaves your device?No
Preferences
Where it livesInside the local index
EncryptedAt rest
Leaves your device?No
Cloud task payload
Where it livesSent only when you opt in
EncryptedIn transit
Leaves your device?That task only, with permission

One row is the exception, and it’s highlighted for a reason: a cloud task payload is the only thing that ever leaves — and only that task, only encrypted, only with your permission.

Encryption

Encrypted at rest, encrypted in transit.

Two different jobs, handled two different ways.

At rest, the memory index is encrypted on your disk, so what Nova has learned isn’t sitting in the clear for another program — or another person at your machine — to read.

In transit, the one time anything travels — an opt-in cloud call — it’s encrypted on the way. Your files themselves stay where you keep them, under your operating system’s own protection; Nova doesn’t make a second copy to hold onto.

Permissions

You hold the dial.

Nova is powerful because it can see and act. That only works if the control over what it sees and does is unambiguous, and yours.

You grant scope

Nova sees and acts only in the apps and folders you allow. Access is something you give, not something it takes.

Out of scope is invisible

What you don't grant, Nova can't see. There's no shadow copy of the apps and files you kept out.

It asks before irreversible acts

Anything Nova can't cleanly undo pauses for your confirmation first. Reversible by default; explicit when not.

You can revoke anytime

Narrow or withdraw access whenever you want. Permissions are a dial you hold, not a door you opened once.

Cloud boundaries

What an opt-in cloud call does and doesn't carry.

Most tools blur this line. Here it is, drawn sharply — the two lists that matter when anything leaves your machine.

What a cloud call includes

  • Only the specific content that task needs
  • Encrypted in transit
  • Used once to produce the result
  • Named to you before the call is made

What it never includes

  • Your memory index or files wholesale
  • Anything used to train a model — ever
  • A background sync you didn't ask for
  • A retained copy on our side

Ownership

The memory is yours

It’s a file on your disk, not a row in our database. You can read it, correct it, and take it with your machine. See memory.

Deletion

Gone means gone

Erase any single record or wipe everything with one command. Because it's local, there's no server copy to outlive the delete.

Offline

The core runs without a network

Memory and perception are built to work on-device, so the everyday loop doesn't stop when you're offline. Cloud reasoning is the only part that needs a connection.

Providers & transparency

Named, not hidden.

You should be able to see what an intelligence is doing and where anything goes.

When you enable a cloud call, the provider that handles it is named — you’re not sending your work into an anonymous pipe. Providers may change as the product matures; we’ll disclose them plainly, and the rules around them don’t change: opt-in, per task, never trained on.

Transparency is the same idea applied inward. Nova’s memory is inspectable in plain terms, and it’s built to show what it’s doing rather than act in the dark. Some of the fine-grained audit surfaces are still in active development, and we’ll say so until they’re done.

The line we won't cross

What Nova never does.

A short list, stated plainly, because trust is made of defaults — not disclaimers.

  • Send your screen or files off your machine without permission
  • Use your data to train a model — ever
  • Phone home in the background
  • Require an account to run locally
  • Hide what it's doing or what it knows

Nova is early. The local-first architecture and these commitments are the design today; some of the fine-grained controls and audit surfaces are in active development. The Privacy Policy covers this website; a dedicated application policy will accompany general availability.

Questions

Privacy, answered plainly.

Does Nova send my screen or files to the cloud?
Not by default, and not without you. Perception and the everyday loop run on-device. The only thing that ever leaves is an opt-in cloud task payload — the specific content one task needs, when you allow it.
Is any of my data used to train models?
No — not local data, not cloud payloads, not ever. That's a line we don't cross, on our side or with the providers a cloud call passes through.
Can I use Nova fully offline?
The core — memory and desktop perception — is designed to run on-device, so the everyday loop doesn’t depend on the network. Optional cloud reasoning is the exception, and it’s yours to enable. More on the split at local + cloud.
Who can see what Nova remembers?
You. The memory index is local and encrypted at rest — it isn’t on our servers to read. You can open, correct, and erase it; see memory for how.
When I delete something, is it really gone?
Yes. Because the index is local, deletion happens on your disk, not as a request to a server that may keep a copy. Wipe everything with one command, and a reload proves it.
Which cloud providers process opt-in calls?
When you enable a cloud call, it's named — you see where it goes. Providers may evolve as the product does, and we'll disclose them plainly; what won't change is that calls are opt-in, per task, and never used for training.
Is there a formal privacy policy?
Yes — the Privacy Policy covers this website and the request-access list. The local-first architecture and the commitments on this page are the design for the application today; some fine-grained controls and audit surfaces are still in active development, and a dedicated application policy will accompany general availability.

See it do real work.

Nova is in private preview. Request access, and we’ll write when it’s your turn.

Request access