MindDuck is built so that your data stays with you by default. This page collects what goes where when you use the app.
On the device
The entire workspace is stored locally and encrypted:
- chats, documents, facts, attachments and the search index are stored encrypted;
- keys are kept in the system's secret storage (Keychain, Keystore, Credential Manager, Secret Service).
Memory search and index building run on the device with a built-in model. Search queries aren't sent anywhere.
What encryption on the device protects against. It protects the files: if the device is stolen while switched off or locked, if the app's folder was copied into a backup or onto another drive, if another program tries to read the files. It doesn't protect an app that is already open on an unlocked device: MindDuck opens the workspace by itself. A separate lock with a PIN or biometrics is planned. Until then you can close the workspace manually: Close workspace in the menu at the bottom of the sidebar.
What goes where
| To whom | What they receive | When |
|---|---|---|
| The AI provider of the chat model | Your message, the conversation history (with the older part compressed), the memory fragments found, suitable facts, personal instructions, the project description, attached images and PDF text | With every answer |
| The AI provider of the chat model, when working with MCP | Descriptions of allowed tools and their results. When you ask for help with setup: the list of connections with commands and addresses (without key values), personal instructions, the model list, the diagnostics report and the sync log; the MCP server's log only after Share log | When the assistant uses tools |
| The AI provider of the chat model, when working with project folders | The list of files and the content of files the assistant opened or found in project folders | When the assistant reads a folder |
| MCP servers you connected | The parameters of calls you allowed. Local programs run on the computer with your permissions; remote servers receive requests over the network | When the model calls their tool |
| The background model's provider | Parts of the conversation used to write titles, summaries and topics | When background tasks run |
| The speech recognition service | The recording's audio | When you dictate |
| The provider describing images | The chosen images (original or preview) | When you start Describe images for search |
| Google Drive | Only encrypted packets. No keys, text or search queries | During sync, if it's on |
| The search service (Wikipedia, Brave, Tavily, Exa) | The search query the model wrote | When the model searches the internet through fallback search |
| Jina Reader | The page address | If the page reading mode allows it and the page couldn't be read on the device; never the addresses of local servers |
| mindduck.app: account and access | Your email, information about your access and its terms; for the device: its name, platform, app version, check time and a random installation number | When you sign in and when access is checked |
| mindduck.app: updates | The app version, platform and system language; if you're signed in in the app, confirmation of the connected device to choose the available versions | When checking for updates |
| mindduck.app: support | The text of your message and, if you chose to attach them, the diagnostics report, the sync log or attachments on the site | When you send a message |
Your account and your data
mindduck.app has an account for access to the app, licenses, the device list and support messages. As with any network request, the site receives your IP address.
Signing in and access checks don't send the workspace's content to the site: chats, documents, memory, files and AI service keys. The site also doesn't receive the workspace's encryption keys. Its content syncs through your Google Drive in encrypted form, with no MindDuck server in the chain. Your MindDuck account and your Google connection are different things. See Account.
Diagnostics files and the sync log are saved only where you choose. When you send a message from the app, they can be attached with your consent; the text of the message and the chosen attachments are stored on the site. You decide what to send to support. See Support and diagnostics.
How to reduce what goes out
- Private chats and documents don't get into the context of other conversations.
- Web access mode: Off turns off the internet for the model.
- Reading mode: Local only doesn't send page addresses to third-party services; pages built by scripts are then read by the background browser on the device.
- Ollama or LM Studio keep the model on your computer, and there is no model provider in the chain at all.
- With OpenRouter, check the privacy settings: which providers may store requests.
Keys and providers
API keys are encrypted in the workspace and sent only to the service they were created for. If sync is on, the keys reach your other devices in encrypted form.
What the model provider itself does with requests is governed by its own rules. It's worth reading them in the provider's account.
Updated October 9, 2026 · for version 0.2.12 · Found a mistake? Write to us