Reference
Privacy & Data
The one-page version of the privacy story, with file paths. For the legal text, see the Privacy Policy.
The privacy model
Bring your own keys — no accounts, no Flunkey servers, no analytics. The trust boundary is your machine plus the provider you explicitly configure. Audio is RAM-only (opus Blob, never written to disk) with mic tracks stopped after every recording.
What is stored where
| Data | Location | Notes |
|---|---|---|
| API keys | Credential Manager → Flunkey service | DPAPI per-user encrypted; fail-closed if vault missing; legacy plaintext entries migrated then stripped |
| History & chats | %LOCALAPPDATA%\com.flunkey.desktop | Local text only; no audio retained |
| Settings & data | flunkey-data.json (plaintext) | Preferences, transcriptions, AI sessions, transforms, dictionary — no secrets |
| Model catalog | openrouter-catalog.json | Public OpenRouter listing, 24h cache |
| Preferences | Local app config | Hotkeys, provider choice, dictionary — no secrets |
| Audio | Nowhere | Transcribed in memory per request |
What leaves your PC
Audio/text for the active request goes directly to your configured provider (Groq, OpenAI, Gemini, OpenRouter) under that provider’s retention policy. Nothing is proxied through Flunkey infrastructure, because there is none. The network allowlist is exactly: api.groq.com, api.openai.com, generativelanguage.googleapis.com, openrouter.ai (plus localhost WS) — no analytics, crash reporting, or ads endpoints exist.
Regulated data
Wiping your data
Settings → Wipe all data removes keys, history, and preferences from the machine. Also rotate the key at your provider dashboard if it may have been exposed. Note: Windows clipboard history (Win+V) is owned by the OS and may persist — clear it there separately. Questions: flunkeymanager@gmail.com · Privacy Policy