Privacy
Last updated 2026-09-26.
We align our handling of personal data with the strictest privacy requirements that apply in the markets we serve (for example, GDPR-level standards). This describes how we work; it is not a certification.
What leaves your computer, by mode
Your raw files are never uploaded to Locus. What else leaves your computer depends on the features you use. Each row below is one way of running Locus.
| Mode | What leaves your computer | Through Locus's servers? | Stored by Locus? | In plain words |
|---|---|---|---|---|
| Local engine with the local embedder and a desktop AI client (Claude Desktop, Claude Code, Cursor…) | Search results go to the AI client you chose and on to its model provider: up to 25 results per search, carrying at most 19,500 characters of file text in total (whole indexed passages), file text in pieces of up to 40,000 characters per read (a whole file can be read piece by piece), and file paths. Each time the engine loads its embedding model while you are online, it contacts Hugging Face (and downloads the model the first time); Hugging Face sees your IP address and the model name, not your files. | No | No | Indexing and embeddings run on your computer. When your AI assistant searches, the matching excerpts go to that assistant, as they would if you pasted them in. |
| Your own Voyage or OpenAI key | The text chunks of every file you index, and each search query, go to that provider's API. Search results still go to your AI client, as in the row above. | No | No | Chunk text goes straight from your computer to the embedding provider you chose, under your own account. |
| Managed embeddings (Locus account) | The text chunks of every file you index, and each search query, go to Locus's relay on Vercel and then to Voyage AI under Locus's account. Vectors come back. | Yes, in transit | No. We keep one usage record per request (time, number of chunks, token count, status), the time your API key was last used and, if you are in an organization, your last-seen time and Locus version. | On managed plans, chunk text passes through Locus's relay to Voyage AI to be embedded. We don't store it; we keep only usage counts. |
| Remote connection (in testing): a web or phone AI app reaching your computer through the Locus relay | Your AI app's request (tool name, search text, file paths) and your computer's reply travel through Vercel and Supabase Realtime. The reply can be excerpts, file text in pieces of up to 40,000 characters per read (an assistant can read a whole file piece by piece), file paths, lists of indexed files, and, when the assistant asks, your account status (plan, trial end, usage, number of API keys) and setup details (operating system, Python and Locus versions, embedder, number of indexed chunks). | Yes, in transit | No content. We keep a per-account request count for the current minute and day (rate limiting) and, if you are in an organization, your last-seen time and Locus version. Our log lines keep only request metadata: time, request type, tool name, success or failure, duration, and shortened account and computer IDs. | When you reach your computer from another device or a web AI app, your question and the matching excerpts travel through Locus's relay (Vercel and Supabase) to and from your computer. They are encrypted in transit and we don't store them. |
| Account (only if you create one) | Email and sign-in details (with Google or GitHub sign-in, also your name, profile picture URL, the provider's account ID and, for GitHub, your username), plan and subscription status, API keys (stored as hashes), usage records, feedback you send, deletion requests, and organization membership, invites (including the invited person's email) and audit log. | Yes | Yes, while your account exists | Your account details are stored with Supabase. Your files are not. |
| Always | The raw files themselves are not uploaded in any mode. Their text can still reach your AI client in excerpts, as described above. | Never | Never | Your raw files are never uploaded to Locus. |
What leaves your machine, and when
- Your raw files: never uploaded to Locus. Locus reads them from disk on your computer. When your AI assistant asks for a file, it receives that file's text in excerpts.
- Chunk text: embedded on your computer by default (
LOCUS_EMBEDDER=local). Withvoyageoropenaiit goes straight to that provider under your own key. Withmanagedit passes through Locus's relay to Voyage AI, and we don't store it. - Search results (chunk excerpts + file paths): returned to whichever AI assistant you're using when it calls Locus — that's the feature. We don't control what that assistant's provider does with it once received. If you use remote connection, these results pass through Locus's relay (Vercel and Supabase Realtime) on the way. We don't store them.
- Content from a connected source (e.g. Notion): fetched directly from that service's API to your machine using a token you granted. Locus's servers are not involved.
- Account data (only if you create a locus-web account): your email and sign-in details, plan and subscription status, API keys (stored as hashes, never in plaintext), usage records, feedback you send, deletion requests, and organization membership, invites (including the invited person's email) and the organization's audit log. If you sign in with Google or GitHub, that provider shares your name, email address, profile picture URL and account ID (and, for GitHub, your username) with us, and we keep them with your sign-in details. Supabase Auth also keeps a record of each signed-in session, with its IP address and browser details, and logs sign-in events in its own logs. Your account details are stored with Supabase. Your files are not. Account data is stored in our Supabase database (ap-southeast-2, Sydney). Row Level Security limits each account to its own rows, except for what organizations share: If you join an organization, its members can see your email, your role, when you joined, whether you are still a member, when you last used Locus's hosted features and which Locus version you ran. Its admins can also see its invites and audit log, and can revoke your Locus API keys. Nobody in the organization can see your files or searches, because Locus doesn't store them.
- Request logs: Vercel keeps standard request logs for this site and its API (time, path, status, IP address). Vercel keeps these logs for at most one day (1 hour on its Hobby plan, 1 day on its Pro plan, under Vercel's documented defaults). Our own log lines in those logs don't contain chunk text or excerpts.
Giving us personal data
You are not under any legal obligation to give us personal data. However, the data marked as required (your email address, and for paid plans the billing details our payment provider collects) is necessary to create an account and provide the service. Without it we cannot provide the service. Where the law requires us to collect or keep data (for example tax records of your purchases), we do so to meet that obligation. Everything else is optional.
Paid plans and billing are not live yet. The table below lists every place Locus collects personal data: whether it is required, what we use it for, who receives it and why, and what happens if you don't provide it. The last column is the legal basis we rely on under the GDPR.
| What we collect | Required? | Why | Who receives it, and why | If you don't provide it | Legal basis |
|---|---|---|---|---|---|
| Email address and password, when you create an account, and the plan and trial status we keep with your account | Required for an account | To create your account, sign you in, send account emails (confirmation, password reset) and contact you about your account. | Supabase stores the email and runs sign-in; it keeps your password only as a hash. The form sends them straight to Supabase; Vercel only serves the page. | We cannot create an account. The local engine works without one; managed embeddings and remote connection need one. | Contract |
| Your Google or GitHub identity, if you sign in with them instead: name, email address, profile picture URL, the provider's account ID and, for GitHub, your username | Required to create a new account for now: email sign-up is paused until our email service is set up | To identify you and sign you in. | Supabase stores it with your sign-in details. | We cannot create a new account for you yet. The local engine works without one. | Contract |
| If you connect an assistant such as Claude.ai or ChatGPT to Locus: which assistant (its client ID), whether it may reach all your computers or only the ones you list (their 8-character Locus computer tags), and when you chose. It is off today | Optional: only if you connect an assistant | To record what you approved on the connection screen and which computers the assistant may reach. | Supabase stores it with your account; Supabase Auth also keeps the connection itself. | The assistant cannot be connected; local assistants keep working. | Contract |
| Technical data sent with every request to the website or its API: IP address, browser or client details (user agent), time and page or API path; for signed-in users, sign-in session records | Required to use the website and hosted features (your browser or the Locus engine sends it automatically) | To deliver the site and API, keep your account secure and prevent abuse. | Vercel (hosting and its request logs) and Supabase (your sign-in sessions, and its platform logs, which include sign-in events). | The hosted website and features cannot work. The local engine with the local embedder and a desktop AI client sends none of this to us, except when you ask it to check the connection to our servers. | Legitimate interest (security, abuse prevention); contract |
| API keys you create | Required for managed embeddings and remote connection | To let your computer prove it acts for your account. We store a hash and the first characters, never the key itself. | Supabase stores the hash, the prefix, and when the key was created, last used and revoked. | You cannot use the hosted features; the local engine works without a key. | Contract |
| Managed embeddings: the chunk text of files you index and your search queries, plus one usage record per request (time, number of chunks, token count, status) | Required only if you choose managed embeddings | To compute embeddings for your index and searches, and to count usage against your plan's limits and prevent abuse. | Vercel runs the relay (in transit). Voyage AI computes the embeddings. Under Voyage AI's standard terms, Voyage may keep the text it receives and use it to train its models unless the account holder opts out; with the opt-out on, Voyage deletes the text once it has processed it. We have not yet confirmed that opt-out for Locus's account, so for now assume Voyage may keep chunk text and search queries sent through managed embeddings. Supabase stores the usage records. | Use the local embedder (the default) or your own Voyage or OpenAI key instead. | Contract; legitimate interest (abuse prevention) |
| Remote connection: your AI app's requests and your computer's replies (excerpts, file text, file paths, lists of indexed files, and account and setup status when asked), plus a per-account request count | Required only if you use remote connection | To carry requests between the AI app you chose and your computer, and to rate-limit requests. | Vercel and Supabase Realtime carry the messages in transit. The AI app's provider receives whatever it retrieves. Supabase stores the request count. | Use Locus from a desktop AI client on the same computer instead. | Contract |
| Feedback you send from the dashboard: a 0-10 score and two optional text answers | Optional | To learn what works and what to fix in Locus. | Supabase stores it with your account. | Nothing changes. | Legitimate interest (improving the service) |
| Organizations: the organization's name, members' email addresses, roles, invites (including the email of the person invited), the audit log, and each member's last-seen time and Locus version | Required only if you create or join an organization | To run the organization: seats, invites, roles and admin actions. | Supabase stores it. Fellow members and admins see what the account-data part of "What leaves your machine, and when" describes. If you invite someone, you give us their email address; please tell them, and they can ask us to delete it. | You cannot use organizations; a personal account works without one. | Contract |
| Deletion and other privacy requests | Optional | To handle your request. | A deletion request made in the dashboard is stored by Supabase with your account, and is currently deleted along with your account. A request you email us stays in our mailbox (see "Email you send us"). | Nothing changes. | Legal obligation (answering privacy requests) |
| Email you send us (support, privacy requests, the business contact form, which opens an email to us, or anything else): your email address and whatever you include, such as your name, company and message | Optional | To answer you and, for a privacy request, to act on it. | Our mailbox is a Gmail account for now, so Google holds these emails under its own terms. | We can't answer you by email. For account deletion you can use the dashboard instead. | Legitimate interest (answering you); legal obligation for privacy requests |
| Partnership outreach, if we contact you about working with us (for example as a creator or partner): your name, public handle, the platform you publish on, your email address, our notes on why Locus may suit your audience (including a 1-5 fit rating), and the messages we draft and send you | Not collected from you: we take it from your public profiles, channels and website | To find people we'd like to work with, contact them, and keep track of whom we contacted and what we said. | Supabase stores it. Resend delivers the emails we send, each one only after a person approves it; LinkedIn messages we send by hand. We also keep a working list in our private code repository on GitHub, and we use AI assistants to research and draft the messages. | Tell us, by replying or at the address under "Contact", and we stop contacting you and delete your details, keeping only what we need so we don't contact you again. | Legitimate interest (finding partners for Locus). You can object at any time. |
| Billing, once paid plans launch (not live yet): name, email, country, card details, amount and VAT line. We also expect to record, as tax evidence, the country you give us and the countries of your IP address and your card's issuer, and a record of the terms and consents you accept at checkout | Required for a paid plan; keeping invoice records is a legal duty under Israeli tax law | To charge you and to issue the invoices and receipts the law requires. | Tranzila (Israel) takes and holds card details; we would keep only a payment token reference. Yesh Heshbonit (Israel) issues invoices and receipts. | You cannot buy a paid plan. The free local engine is unaffected. | Contract; legal obligation (tax records) |
| Where you came from, if you sign up after arriving through a partner or campaign link: the partner's referral code, the campaign tags in the link (source, medium, campaign), the domain of the site that sent you, the first section of our site you landed on, and when. A first-party cookie keeps it until you sign up; then we copy it to your account. It is off today | Optional: recorded only if you arrive through such a link | To credit partners who refer customers, and to count which channels bring sign-ups. | Supabase stores it with your account. | Nothing changes. | Legitimate interest (crediting partners, measuring channels) |
The providers named above process data for us under their own terms. The sub-processors page lists the ones that store account data or carry your content for the Locus service, with what each one receives; the providers for email you send us and for partnership outreach are the ones named in those rows. Separately, the AI assistant you connect to Locus, and its provider, receive the excerpts you let it retrieve. You choose that assistant, and its own terms apply. We don't sell personal data and we don't share it with advertisers.
The controller of the personal data described on this page is Yonathan Levy, a sole proprietor registered in Israel (business number 213635964), who operates Locus. Postal address: Stern 92B, Kiryat Ono 5560721, Israel. Contact details are under "Contact" below. Your rights, including the right to see and correct the data we hold about you, are under "Your rights and how to use them".
Where your data is processed (cross-border transfers)
If you create a locus-web account, the account data described above is processed outside Israel (where this project is currently based) and, depending on where you are, outside your own country too. If you use managed embeddings or remote connection, the content described above also passes through these providers in transit. Concretely, as currently configured:
- Supabase (our database/auth provider) hosts account data in its ap-southeast-2 (Sydney, Australia) region.
- Supabase Realtime (same Supabase project) carries remote-connection messages between our relay and your computer, in transit. Unlike the database, the Realtime service's serving region is not pinned to Sydney.
- Vercel (our hosting provider) runs this website and its server-side code, including the embedding relay and the remote-connection relay, in the United States (Washington, D.C. region). Chunk text, search requests, file text in excerpts, file paths and account/setup status pass through it in transit, and we don't store them.
- Voyage AI (US) receives chunk text and search queries from managed plans, under Locus's account. Under Voyage AI's standard terms, Voyage may keep the text it receives and use it to train its models unless the account holder opts out; with the opt-out on, Voyage deletes the text once it has processed it. We have not yet confirmed that opt-out for Locus's account, so for now assume Voyage may keep chunk text and search queries sent through managed embeddings. If you use the
voyageembedder with your own key, Voyage works for you directly, not for us.
We do not represent that a specific transfer mechanism (such as EU Standard Contractual Clauses or an adequacy decision) applies to these transfers.
How long we keep data
| Data | How long we keep it |
|---|---|
| Content passing through the relays (chunk text, search queries, excerpts, file text, file paths) | Not stored by Locus. Supabase Realtime does not write our relay messages to its message table (checked in production on 2026-09-23). For managed embeddings, see Voyage AI's terms: Under Voyage AI's standard terms, Voyage may keep the text it receives and use it to train its models unless the account holder opts out; with the opt-out on, Voyage deletes the text once it has processed it. We have not yet confirmed that opt-out for Locus's account, so for now assume Voyage may keep chunk text and search queries sent through managed embeddings. |
| Account: email, sign-in details and identity data, profile, plan and subscription status | Until your account is deleted. |
| Connected assistants and the computers each may reach | Until you disconnect the assistant or your account is deleted. |
| Sign-in sessions that Supabase Auth keeps in our database (with IP address and browser details) | Until you sign out or your account is deleted. Sign-in events also go to Supabase's own logs (see "Request logs kept by our providers"). Supabase Auth can also copy sign-in events into our database; that copy was empty when we checked on 2026-09-23, and we delete any entries about you when we delete your account. |
| API keys (hash, prefix, created, last used and revoked times), including revoked keys | Until your account is deleted. |
| Usage records (one per managed-embedding request) | Until your account is deleted. |
| Remote-connection request counters (rate limiting) | Short-lived: expired minute and day counters are cleared the next time you use remote connection, and all of them when your account is deleted. |
| Feedback | Until your account is deleted. |
| Deletion requests made in the dashboard | Until your account is deleted. They are deleted with it, so our database then keeps no record of the request. |
| Email you send us, including privacy requests | In our mailbox, with no fixed deletion period. |
| Partnership outreach records (name, handle, email address, notes, fit rating, messages) | No fixed period. If you object, we delete them, keeping only what we need so we don't contact you again. |
| Organization membership, invites and audit log | Until the organization is deleted. When a member's account is deleted, their membership goes with it, and we remove the invites they sent, invites to their email address and the audit-log entries that name them. Removed members' records, and expired, used or revoked invites, are not cleared automatically. |
| Request logs kept by our providers | Vercel keeps these logs for at most one day (1 hour on its Hobby plan, 1 day on its Pro plan, under Vercel's documented defaults). Supabase keeps its own platform logs of requests to our database and sign-in service, including sign-in events, IP address and browser details, for at most 7 days (1 day on its free plan, 7 days on its Pro plan). |
| Invoices and receipts (once billing is live) | For the period Israeli bookkeeping rules require, even if you delete your account. |
| Tax evidence and the record of what you agreed to at checkout (once billing is live) | The tax evidence is kept with the invoice records; the checkout record for as long as we may need it to resolve a dispute about the purchase. |
| Database backups | Data we delete can remain in Supabase's daily backups of our database for up to 7 days (its Pro plan keeps 7 days of backups; its free plan keeps none). |
| Your local index (~/.locus) | On your computer, until you delete it. We have no copy. |
| Where you came from (referral code, campaign tags, referring domain, landing section) | Until your account is deleted. |
We don't run an automatic deletion schedule: account data stays until the account is deleted.
If you're in the EU/EEA or UK (GDPR)
The General Data Protection Regulation (GDPR) applies to the account data described above when you create a locus-web account and you're in the EU/EEA or UK. It also covers the content that passes through our relay when you use managed embeddings or remote connection; we handle that content in transit only and don't store it. The local engine on its own (local embedder, desktop AI client) sends nothing to us.
- Lawful basis. We process that account data, and relay content in transit, to perform the contract you enter into by signing up (providing sign-in, subscription, API-key, managed-embedding and remote-connection functionality). We rely on legitimate interest for security and abuse prevention (for example, request logs and limiting how many API keys an account can create) and for the feedback you choose to send. We rely on legal obligation for tax records once billing is live and for answering your privacy requests. The table under "Giving us personal data" gives the basis for each kind of data. We don't currently rely on consent for any of this processing, and we send no marketing email to account holders.
- Your rights. Access (what we hold about you), rectification (correction), erasure (deletion), restriction of processing, data portability, and objection. See "Your rights and how to use them" below for how to exercise any of these today, and how to complain to a supervisory authority.
- Cross-border transfers. See "Where your data is processed" above for which providers, in which regions, receive this data.
- No Data Protection Officer appointed. We have not appointed one.
If you're in the US (CCPA/CPRA and other state privacy laws)
California's CCPA/CPRA gives California residents the right to know what personal information we hold about them, request its deletion, request correction of inaccuracies, and opt out of its "sale" or "sharing" (as those terms are defined by the law). We don't sell personal information, and we don't share it for cross-context behavioral advertising — there's no ad network or analytics pixel on this site to share it with (see "No telemetry" below). Exercising any of these rights will never result in different pricing or a different quality of service from us.
No telemetry
There is no analytics or tracking in the local engine. Locus explicitly disables the vector database's own built-in telemetry rather than adding any of its own. Each time the local engine loads its embedding model while you are online, it contacts Hugging Face (and downloads the model the first time); Hugging Face sees your IP address and the model name, not your files. When you use managed embeddings, we record when your API key was last used. If you belong to an organization, its members can see when you last used managed embeddings or remote connection and which Locus version you ran.
People under 18
Locus is not directed to anyone under 18, and we do not knowingly collect personal data from people under 18. If we learn that we have, we delete it, except records the law requires us to keep. If you believe someone under 18 has an account or has given us personal data, contact yonilev2003@gmail.com.
Your rights and how to use them
You can ask us to show you the personal data we hold about you and to correct it (sections 13 and 14 of Israel's Privacy Protection Law). Depending on where you live you may also have the right to have it deleted, to get a copy in a portable format, to restrict or object to how we use it, and, in California, to know what we collect.
- Delete your account. If you're signed in, use "Delete your account" on your dashboard. This logs a timestamped request that you can cancel while it's pending. It is not instant, automated deletion: someone reviews and processes each request by hand. We delete your account and the data kept with it (see "How long we keep data"), except records the law requires us to keep, such as invoices. If you are or were in an organization, we also remove the invites you sent, invites to your email address and the organization's audit-log entries that name you.
- See, correct or get a copy of your data, or object to how we use it. Email us at the address under "Contact", from the email address on your account.
- How fast. We answer within 30 days of receiving your request, and tell you if we need longer and why.
- Data on your computer. Your local index is yours to manage: delete it at any time by removing your data directory (default
~/.locus). We have no copy of it. - Complaints. You can complain to a data protection authority: in Israel, the Privacy Protection Authority (Ministry of Justice); in the EU/EEA, the authority of the country where you live or work; in the UK, the Information Commissioner's Office (ICO).
Contact
The controller of the personal data described on this page is Yonathan Levy, a sole proprietor registered in Israel (business number 213635964), who operates Locus. Postal address: Stern 92B, Kiryat Ono 5560721, Israel. For privacy questions and for access, correction, copy or deletion requests, contact yonilev2003@gmail.com.