Your work deserves
a clear explanation.

What stays on your computer, what reaches a model, and what the managed relay never keeps. The answers your security review will ask for, up front.

Local workspace.
Connected intelligence.

Local storage does not mean nothing leaves your device. To help with a task, Buddy sends relevant context to the model endpoint, and enabled tools may connect to other services.

A relay for the work.
Not a home for its content.

The managed relay forwards prompts and responses without retaining their content. Your workspace remains on your computer, and model processing is governed by the provider’s own terms.

Your Buddy app

Task context leaves your device.

Managed relay

Forwards content without storing it.

CONTENT TRANSIT · NO RETENTION

Model provider

The provider’s own terms apply.

Content and usage are different.

The relay does not retain prompt or response content. Account records, usage metadata, budgets and administrative audit records are still needed to run the service.

Access is invitation-based.

Sign-in with Google Workspace, Microsoft Entra ID, email and password, or passkeys. Sessions are bound to each device, and policies set the models, tools and connectors people can use.

Know your processing locations.

Discuss the managed service’s hosting requirements with us. The model provider’s processing location and terms must be checked separately.

Spending stays visible.

Per-person, department and company limits, with usage reporting by person, model and period. Usage records hold amounts and models, never conversation content.

A direct connection
to your provider.

Buddy workspace

Chat history, project context, settings and tool logs are stored locally.

Relevant task context

Model provider

Processes messages and context, then sends the response back to Buddy.

What can be sent?

Messages, relevant file contents, tool results and screenshots used in a task. Browser, search and connected tools may also send data to the services they use.

Who sets retention?

Your model provider or deployment. Check its retention, data access and review policies, including those of any gateway and connected service.

How are keys protected?

Desktop API credentials use the operating system’s secure storage facilities. Local chat history is not encrypted by Buddy; protect your device and disk accordingly.

Sensible defaults,
on every device.

You approve what matters.

Choose whether Buddy asks before every action or only before changes. Buddy treats pages, files and tool results as information to check, not as instructions.

Voice stays on your computer.

Speech recognition and Buddy’s voice run locally. Only the transcript goes to your model, like any message you type.

Your phone, encrypted end to end.

The iPhone app pairs with your computer using a code you confirm, and every message between them is end-to-end encrypted, including through Buddy’s servers.

Signed, pinned, updated.

The Mac app is signed and notarized by Apple. Buddy connects to its servers with a pinned certificate and tells you when an update is ready.

Make the setup
match the work.

  1. 01

    Choose your model endpoint.

    Confirm compatibility, processing location and retention terms.

  2. 02

    Review the tools you enable.

    Understand their access, external services and approval settings.

  3. 03

    Protect the local workspace.

    Use appropriate device access, disk protection and file permissions.

For Nemeda’s security and personal-data notice, read How we protect your data in the full privacy policy.

Let’s talk through your requirements.

Bring your security questionnaire. We walk your team through the data flow, the relay and the controls, and answer what your review needs.