bdibranding Privacy
Last reviewed: 2026-07-25, against the shipping code.
bdibranding is a local-first desktop app. It runs a small server (the "sidecar") on your own
machine (localhost) and does the agent work there. There is no bdibranding cloud, no bdibranding
account, and no bdibranding server that receives your data. This document is written in plain
English and is grounded in an audit of the actual code — not aspirations.
Support questions: info@bdibranding.com.
The short version
- The app does not track you. There is no telemetry, no analytics, no crash reporting, or ad SDK. We verified this by searching the whole codebase for the usual suspects (Sentry, PostHog, Mixpanel, Segment, Google Analytics, Amplitude, Datadog): none are present. The desktop app does make the automatic update-manifest request described below; that request carries no user data or app identifier.
- Your data stays on your machine, under your OS user's app-data directory —
Windows:
%APPDATA%\ai.bdibranding.harness\workspaces\; macOS:~/Library/Application Support/ai.bdibranding.harness/workspaces/; Linux:~/.local/share/ai.bdibranding.harness/workspaces/. (The developer-mode sidecar uses%LOCALAPPDATA%\bdibranding\on Windows.) - The app talks to the network for the configured or requested work described below, plus the desktop app's automatic update-manifest check. These are the only outbound cases.
What leaves your machine — and only these
bdibranding makes outbound network requests in exactly these situations. Nothing else.
1. Your chosen AI model provider (using your key)
When an agent runs, bdibranding calls the model provider you configured, authenticated with your API key (or your ChatGPT sign-in). Your prompts, conversation, and any content the agent works with are sent to that provider so it can generate a response — the same as any app that uses that provider. bdibranding is a pass-through here; it does not sit in the middle.
Depending on what you set up, that provider is one of:
- OpenRouter (
openrouter.ai) - OpenAI (
api.openai.com) - Anthropic (
api.anthropic.com) - Google Gemini (
generativelanguage.googleapis.com) - ChatGPT via sign-in (
chatgpt.com/auth.openai.com) - or another OpenAI-compatible provider you point it at (xAI, Groq, Mistral, DeepSeek, Together, Fireworks, Perplexity, Cerebras).
Your key, your data, your account. bdibranding never sees a bdibranding-owned copy — the key is yours and the request goes straight to the provider you picked.
2. Chat channels — only if you connect them
If you connect a chat channel, bdibranding talks to that platform to send and receive messages on the channel you set up, authenticated with the token (or endpoint) you provide. Nothing is contacted unless you connect it:
- Discord / Telegram — bdibranding calls that platform's API (
discord.com,api.telegram.org) with your bot token. - Slack — bdibranding calls the Slack API (
slack.com) with your bot token. - Matrix — bdibranding talks to the homeserver you point it at — whatever URL you configure,
whether
matrix.orgor a server you run yourself — using your access token. bdibranding does not pick a server; you do. - Signal — bdibranding talks to the signal-cli REST endpoint you run (the URL you configure for your own signal-cli bridge), using the account you registered there.
If you never connect a channel, bdibranding never contacts any of these services.
3. Spotify — only if you enable it
If you enable the Spotify integration and authorize it, bdibranding calls the Spotify API
(api.spotify.com, accounts.spotify.com) to read what's playing and control playback, using
the token you granted. If you don't enable Spotify, no Spotify requests are made.
4. Web search / web fetch — only when an agent uses that tool
If an agent uses its web tools, bdibranding fetches results through independent, keyless services
— web search via Mojeek (mojeek.com, with DuckDuckGo as a fallback) and page reading via
Jina Reader (r.jina.ai) — or, if you have an OpenRouter key, OpenRouter's web plugin. If the
Jina reader is unavailable or rate-limits, the page is fetched directly from its own host
as a fallback, so the site you asked to read may see the request come from your machine. Only
your search query or the URL you asked to read is sent, and only when an agent actually runs a
web search or fetch. (The fetch tool also refuses to reach private/internal network addresses,
as an anti-abuse guard.)
5. Voice — two different paths, and they behave differently
Spoken agent lines use local Kokoro when the built-in voice engine is available. Other spoken lines use your configured model provider (OpenRouter, OpenAI, or Gemini), or ElevenLabs when you configure an ElevenLabs voice, so the line of text is sent to that service. If those paths are unavailable, bdibranding can use Microsoft's keyless Edge Read Aloud service, which sends the line of text to Microsoft. Voices off means no TTS requests at all.
Hands-free Live Voice does not use a vendor realtime-voice session. Listening runs on local
Whisper when installed; on Windows, offline System.Speech dictation can serve as the fallback. On those
paths, your recorded audio never leaves your machine. The open Whisper and Kokoro weights may
be fetched from huggingface.co on first use and cached in your user profile; that download carries
no audio or transcript. Once cached, listening is offline. Speaking is also offline while Kokoro is
available; if it is not, the Edge Read Aloud fallback described above may send only the answer text
(not your recorded audio) to Microsoft.
6. A version check for updates (no personal data)
Automatic update checks are on by default. On first run and at the configured interval, the
desktop app's updater runs to check for a newer version. When a release feed is configured, this is
a plain GET for a small public update-manifest file — no user data, no
identifier, and no telemetry are sent, the same request your browser would make to view
that file — and each update's integrity is cryptographically verified against a key baked into the
app before anything is installed. You can stop automatic checks by turning off
AUTO-CHECK FOR UPDATES in
SYSTEM > SETTINGS > UPDATES; the Update Center still lets you check manually.
What bdibranding stores on your machine (and how)
Everything below lives under your per-user app-data directory (see the paths in "The short
version" above for Windows/macOS/Linux). It never leaves your machine except as described
above. Where this document says "OS keychain," that means Windows Credential Manager, the
macOS Keychain, or the Linux Secret Service (e.g. GNOME Keyring), depending on your platform —
always under the service name ai.bdibranding.harness.
| What | Where | How it's stored |
|---|---|---|
| Conversation transcripts | transcript.jsonl |
Plaintext JSON on disk |
| Run history + cost ledger | runs.jsonl, ledger.jsonl |
Plaintext JSON on disk |
| Agent memory / beliefs / to-dos | <agent>.notebook.json, <agent>.todo.json, dossier/goals |
Plaintext JSON on disk |
| Voice cache (spoken-line audio) | voice-cache/ |
Plaintext audio files on disk |
| Discord / Telegram bot tokens | OS keychain (desktop) | OS keychain (Windows Credential Manager); plaintext fallback in bare/dev mode — see below |
| Your model-provider API keys | OS keychain (desktop) | OS keychain (Windows Credential Manager); loaded into app memory at launch, never written to disk by the app |
| Spotify OAuth token | .secrets/spotify.json |
Plaintext JSON on disk |
| ChatGPT / Codex sign-in token | codex/tokens.json |
Plaintext JSON on disk |
| Grok sign-in token | grok/tokens.json |
Plaintext JSON on disk |
| Kimi sign-in token | kimi/tokens.json |
Plaintext JSON on disk |
| Channel message history (Discord/Telegram chats the bot saw) | channels/*.history.json |
Plaintext JSON on disk |
| Agent memory ledgers (accepted/declined memory proposals, dossiers, goals) | per-agent *.json |
Plaintext JSON on disk |
| Station state (widgets, sub-agents, routing, quests, XP) | various *.json |
Plaintext JSON on disk |
| Settings, roster, permissions, cron, connectors | various *.json |
Plaintext JSON on disk |
Secrets: keychain vs. plaintext — the honest picture
On the desktop build, your provider API keys and your Discord/Telegram bot tokens are held
in the OS keychain (Windows Credential Manager, under service ai.bdibranding.harness), not in
a plaintext file. When you upgrade from an older build, any bot token found in the old
plaintext channels/secrets.json is migrated into the keychain and stripped from that file.
If you instead run the bare sidecar directly (developer mode / node sidecar/index.js /
tests), the OS keychain isn't reachable, so those bot tokens fall back to a plaintext file
(channels/secrets.json). This is called out plainly in the code rather than hidden.
These integration secrets are plaintext even on desktop today: the Spotify OAuth token
(.secrets/spotify.json) and the ChatGPT/Codex, Grok, and Kimi sign-in tokens
(codex/tokens.json, grok/tokens.json, and kimi/tokens.json). If that matters to you,
keep those integrations off. (Transcripts are run through a redaction step at write-time to avoid
capturing secret-shaped tokens in your chat history, but the transcript file itself is plaintext.)
Because this data sits in plaintext files under your user profile, anyone with access to your Windows user account can read it. Protect your machine account accordingly.
What we do NOT do
- We do not run analytics or telemetry of any kind.
- We do not collect crash reports.
- We do not have a bdibranding account system or a bdibranding backend that stores your data.
- We do not sell, share, or transmit your conversations, keys, or files to anyone — the only outbound traffic is the specific, purpose-built requests listed above.
Deleting your data
Your data is just files. To wipe it, uninstall bdibranding and delete the ai.bdibranding.harness
app-data folder for your OS — Windows: %APPDATA%\ai.bdibranding.harness\
(C:\Users\<you>\AppData\Roaming\ai.bdibranding.harness\); macOS:
~/Library/Application Support/ai.bdibranding.harness/; Linux: ~/.local/share/ai.bdibranding.harness/.
If you ever ran the developer-mode sidecar on Windows, also delete %LOCALAPPDATA%\bdibranding\.
Provider API keys and channel tokens held in the OS keychain can be removed there too (search
your credential manager / keychain for ai.bdibranding.harness).
This website (ai.bdibranding.com)
The website you're reading is a static site with no accounts, no cookies, no analytics, and no tracking scripts. Two things are worth stating plainly:
- It's served through Cloudflare, which — like any host/CDN — processes standard request logs (IP address, user agent) to deliver the pages. We add nothing on top.
The "live preview" on the homepage is the real app running entirely in your browser from a seeded demo save; anything you do in it stays in your browser's local storage and goes nowhere.
Changes
If this changes, we'll update this document. Questions: info@bdibranding.com.