Documentation

Privacy and your data

Nothing leaves your machine. No account. No cloud embeddings.

What never leaves the machine on the free tier

  • Your conversations. They are read from where their own tool already stores them and indexed in place. Tokenome does not upload them.
  • The embeddings. The model that turns text into vectors ships inside the download and runs on your own hardware. No text is sent anywhere to be embedded, and there is no GPU requirement.
  • The index. The search engine runs on your machine against a directory in your home folder.
  • The journal. Written locally. The default enricher needs no model at all; it finds stated reasons by their wording and quotes them. If you prefer better phrasing you can point it at a model running locally on your own machine. Neither path calls a hosted model.
  • Your identity. There is no account, no sign-up and no licence check. The product does not know who you are.

The exceptions, stated plainly

  • The update check. The desktop app and the AppImage ask the public releases page whether a newer version exists. That request carries no conversation data.
  • The Claude Desktop source. If you switch it on, Tokenome fetches your own conversations from the claude.ai API with your own session key. That is a call to your AI vendor for your own data, and it only happens if you set the key.
  • Team. Turning on Team means opting specific projects in to a server your organization runs. Nothing is shared until you do that, and what is shared passes the share gate first. See Team.

Where the files are

PathWhat is in it
~/.tokenome/dataThe search index, including the vectors.
~/.tokenome/journalThe daily entries, as markdown and JSON.
~/.tokenome/importExports you dropped in.
~/.tokenome/api.tokenThe local API token. Readable only by you.
~/.tokenome/sources.jsonWhich sources are switched on.
~/.tokenome/remote.json, device.keyTeam enrollment and this device's private key, when you use Team.

None of this is encrypted by Tokenome beyond the file permissions. Full-disk encryption is what protects a laptop that walks away, and it is worth having on.

Why localhost is authenticated

Without a check, any process on your machine could read your whole history over localhost:8741. The service mints a token, writes it to a file only you can read, and requires it. A browser tab gets in through a single-use launch link instead, which is why tokenome open exists and typing the address by hand does not sign you in. The token never reaches page script.

tokenome auth rotate replaces the token if you ever need it to change.

Deleting and re-indexing

What you wantHow
Remove one conversationThe Delete link on the conversation page. On an enrolled device this also retracts it from the team server.
Remove everything one source contributedPurge that source from the Sources page.
Start the index overtokenome clean, which drops and recreates the collection, then let it re-index.
Stop indexing a sourceTurn auto-ingest off for it on the Sources page.
Remove Tokenome entirelyQuit the app, delete the application, and delete ~/.tokenome. Your original transcripts are untouched.

Wiping the local index is not a retraction. tokenome clean and purging a source are index maintenance, and they are deliberately not mirrored to a team server. To take a project back off the server, use tokenome remote unshare <project> --purge.