Privacy & Security
Your work stays yours.
Nova can see and act across everything you do, so the defaults have to be right. It is local-first by design, honest about the line between on-device and cloud, and built so you can see and erase everything it holds. This page is the detailed version.
On-device by default
Nova reads your screen and files on the machine that renders them. Understanding your work does not require sending it anywhere — the default is local, not a setting you have to find.
The cloud is opt-in
When a task genuinely needs more than local reasoning, Nova can use the cloud — but only with your say-so, per task. Every cloud call is named, encrypted in transit, and never retained on our side.
You own your memory
The memory index is a file on your disk, encrypted at rest. You can open it and read what Nova holds in plain terms, correct any part, and erase all of it with one command.
You grant the permissions
Nova sees and acts only within the scope you allow, and it pauses to ask before anything irreversible. What's out of scope stays invisible to it.
Data residency
Where every kind of data lives.
The honest map most tools won’t show you: what Nova touches, where it sits, whether it’s encrypted, and whether it ever leaves your machine.
One row is the exception, and it’s highlighted for a reason: a cloud task payload is the only thing that ever leaves — and only that task, only encrypted, only with your permission.
Encryption
Encrypted at rest, encrypted in transit.
Two different jobs, handled two different ways.
At rest, the memory index is encrypted on your disk, so what Nova has learned isn’t sitting in the clear for another program — or another person at your machine — to read.
In transit, the one time anything travels — an opt-in cloud call — it’s encrypted on the way. Your files themselves stay where you keep them, under your operating system’s own protection; Nova doesn’t make a second copy to hold onto.
Permissions
You hold the dial.
Nova is powerful because it can see and act. That only works if the control over what it sees and does is unambiguous, and yours.
You grant scope
Nova sees and acts only in the apps and folders you allow. Access is something you give, not something it takes.
Out of scope is invisible
What you don't grant, Nova can't see. There's no shadow copy of the apps and files you kept out.
It asks before irreversible acts
Anything Nova can't cleanly undo pauses for your confirmation first. Reversible by default; explicit when not.
You can revoke anytime
Narrow or withdraw access whenever you want. Permissions are a dial you hold, not a door you opened once.
Cloud boundaries
What an opt-in cloud call does and doesn't carry.
Most tools blur this line. Here it is, drawn sharply — the two lists that matter when anything leaves your machine.
What a cloud call includes
- Only the specific content that task needs
- Encrypted in transit
- Used once to produce the result
- Named to you before the call is made
What it never includes
- Your memory index or files wholesale
- Anything used to train a model — ever
- A background sync you didn't ask for
- A retained copy on our side
Ownership
The memory is yours
It’s a file on your disk, not a row in our database. You can read it, correct it, and take it with your machine. See memory.
Deletion
Gone means gone
Erase any single record or wipe everything with one command. Because it's local, there's no server copy to outlive the delete.
Offline
The core runs without a network
Memory and perception are built to work on-device, so the everyday loop doesn't stop when you're offline. Cloud reasoning is the only part that needs a connection.
Providers & transparency
Named, not hidden.
You should be able to see what an intelligence is doing and where anything goes.
When you enable a cloud call, the provider that handles it is named — you’re not sending your work into an anonymous pipe. Providers may change as the product matures; we’ll disclose them plainly, and the rules around them don’t change: opt-in, per task, never trained on.
Transparency is the same idea applied inward. Nova’s memory is inspectable in plain terms, and it’s built to show what it’s doing rather than act in the dark. Some of the fine-grained audit surfaces are still in active development, and we’ll say so until they’re done.
The line we won't cross
What Nova never does.
A short list, stated plainly, because trust is made of defaults — not disclaimers.
- Send your screen or files off your machine without permission
- Use your data to train a model — ever
- Phone home in the background
- Require an account to run locally
- Hide what it's doing or what it knows
Nova is early. The local-first architecture and these commitments are the design today; some of the fine-grained controls and audit surfaces are in active development. The Privacy Policy covers this website; a dedicated application policy will accompany general availability.
Questions
Privacy, answered plainly.
Does Nova send my screen or files to the cloud?
Is any of my data used to train models?
Can I use Nova fully offline?
Who can see what Nova remembers?
When I delete something, is it really gone?
Which cloud providers process opt-in calls?
Is there a formal privacy policy?
See it do real work.
Nova is in private preview. Request access, and we’ll write when it’s your turn.
Request access