Agent Desktop/Account and help/Privacy and security in Agent Desktop
Privacy and security in Agent Desktop
Understand what stays on your computer, what a connected service can receive and which decisions require your approval.
Agent Desktop gives you several controls over how an agent works, but local generation does not mean every feature is local. This page explains the user-visible boundary.

Profile
Your Vinkius account
Account identity
Renato
Managed by your sign-in provider
Your email is managed by your sign-in provider.
Danger zone
Delete account
Permanently delete your account, cloud data, tokens, and settings.
Local or online model
With a local model runtime, generation can happen on your computer. With an online provider, your prompt and the context you send to that provider are handled by that provider.
Choose the model that matches the sensitivity of the task. The model picker shows which model is active for the current chat.
Connector data
A connected service receives the request that its AI Capability needs. The app does not send a connector action until its execution policy allows it. Review the connector and capability before connecting a service with sensitive data.
Credentials
Connector credentials and model API keys are kept in protected desktop storage and are not displayed in the chat. Never put reusable secrets in an MCP install link or a prompt.
Browser data
The agent browser can retain cookies, site storage and history for its browser profile. Treat it like a browser you use for the same accounts: sign out of sites and clear the session when another person will use the computer.
Memory data
Memory notes are kept with your workspace data. Semantic memory search may send text to the Vinkius embedding service even when generation uses a local model. Disable or avoid embedding-based Memory when your policy requires every piece of processing to stay local.
Approval is a control
Use ask for new or sensitive capabilities. Use allow only when you trust the repeated action. Use deny when the action should never run. A denied action cannot be unlocked by a confirmation click.
Account security
Sign in only through the Vinkius account flow. The desktop accepts account verification pages over trusted HTTPS Vinkius domains. Sign out from the account menu when you finish on a shared computer.