Agent Desktop/Account and help/Privacy and security in Agent Desktop

Privacy and security in Agent Desktop

Ask AI about Vinkius

Understand what stays on your computer, what a connected service can receive and which decisions require your approval.

Agent Desktop gives you several controls over how an agent works, but local generation does not mean every feature is local. This page explains the user-visible boundary.

Profile

Your Vinkius account

Account identity

Renato

Managed by your sign-in provider

Your email is managed by your sign-in provider.

Danger zone

Delete account

Permanently delete your account, cloud data, tokens, and settings.

Account keeps Profile, Billing and Memory together, with plan usage visible from the same workspace.

Local or online model

With a local model runtime, generation can happen on your computer. With an online provider, your prompt and the context you send to that provider are handled by that provider.

Choose the model that matches the sensitivity of the task. The model picker shows which model is active for the current chat.

Connector data

A connected service receives the request that its AI Capability needs. The app does not send a connector action until its execution policy allows it. Review the connector and capability before connecting a service with sensitive data.

Credentials

Connector credentials and model API keys are kept in protected desktop storage and are not displayed in the chat. Never put reusable secrets in an MCP install link or a prompt.

Browser data

The agent browser can retain cookies, site storage and history for its browser profile. Treat it like a browser you use for the same accounts: sign out of sites and clear the session when another person will use the computer.

Memory data

Memory notes are kept with your workspace data. Semantic memory search may send text to the Vinkius embedding service even when generation uses a local model. Disable or avoid embedding-based Memory when your policy requires every piece of processing to stay local.

Approval is a control

Use ask for new or sensitive capabilities. Use allow only when you trust the repeated action. Use deny when the action should never run. A denied action cannot be unlocked by a confirmation click.

Account security

Sign in only through the Vinkius account flow. The desktop accepts account verification pages over trusted HTTPS Vinkius domains. Sign out from the account menu when you finish on a shared computer.

Next steps