Documentation
Privacy and your data
Nothing leaves your machine. No account. No cloud embeddings.
What never leaves the machine on the free tier
- Your conversations. They are read from where their own tool already stores them and indexed in place. Tokenome does not upload them.
- The embeddings. The model that turns text into vectors ships inside the download and runs on your own hardware. No text is sent anywhere to be embedded, and there is no GPU requirement.
- The index. The search engine runs on your machine against a directory in your home folder.
- The journal. Written locally. The default enricher needs no model at all; it finds stated reasons by their wording and quotes them. If you prefer better phrasing you can point it at a model running locally on your own machine. Neither path calls a hosted model.
- Your identity. There is no account, no sign-up and no licence check. The product does not know who you are.
The exceptions, stated plainly
- The update check. The desktop app and the AppImage ask the public releases page whether a newer version exists. That request carries no conversation data.
- The Claude Desktop source. If you switch it on, Tokenome fetches your own conversations from the claude.ai API with your own session key. That is a call to your AI vendor for your own data, and it only happens if you set the key.
- Team. Turning on Team means opting specific projects in to a server your organization runs. Nothing is shared until you do that, and what is shared passes the share gate first. See Team.
Where the files are
| Path | What is in it |
|---|---|
~/.tokenome/data | The search index, including the vectors. |
~/.tokenome/journal | The daily entries, as markdown and JSON. |
~/.tokenome/import | Exports you dropped in. |
~/.tokenome/api.token | The local API token. Readable only by you. |
~/.tokenome/sources.json | Which sources are switched on. |
~/.tokenome/remote.json, device.key | Team enrollment and this device's private key, when you use Team. |
None of this is encrypted by Tokenome beyond the file permissions. Full-disk encryption is what protects a laptop that walks away, and it is worth having on.
Why localhost is authenticated
Without a check, any process on your machine could read your whole history over
localhost:8741. The service mints a token, writes it to a file only you can
read, and requires it. A browser tab gets in through a single-use launch link instead,
which is why tokenome open exists and typing the address by hand does not
sign you in. The token never reaches page script.
tokenome auth rotate replaces the token if you ever need it to change.
Deleting and re-indexing
| What you want | How |
|---|---|
| Remove one conversation | The Delete link on the conversation page. On an enrolled device this also retracts it from the team server. |
| Remove everything one source contributed | Purge that source from the Sources page. |
| Start the index over | tokenome clean, which drops and recreates the collection, then let it re-index. |
| Stop indexing a source | Turn auto-ingest off for it on the Sources page. |
| Remove Tokenome entirely | Quit the app, delete the application, and delete ~/.tokenome. Your original transcripts are untouched. |
Wiping the local index is not a retraction. tokenome clean and
purging a source are index maintenance, and they are deliberately not mirrored to a
team server. To take a project back off the server, use
tokenome remote unshare <project> --purge.