Your memory.
A visible boundary.

Your Ninai vault stays on your Mac. Signing in unlocks the official installer; it does not upload your vault.

Effective 6 September 2026
Local

Stored on your Mac

Sign-in is required to access the installer and setup guide. After installation, the SQLite vault, sources, grants, and logs remain on your device and no automatic cloud sync runs.

If you ask a cloud AI to use selected context, that packet leaves the device and the provider's policy applies.

Coming later

Hosted vault

Public hosted storage and remote connectors are not offered in the MVP.

The infrastructure remains under evaluation until security and external acceptance gates are complete.

01

What we process.

  • Account identifiers supplied by Auth0, such as email, display name, and identity subject.
  • A minimal internal setup record used to unlock the authenticated installer.
  • Your account creation date, successful sign-in count, and latest sign-in time, visible to authorized Ninai administrators for support and service operation. We do not collect local vault content or local agent activity for this dashboard.
  • An installer-download receipt containing your account, platform, installer hash, and time. We do not store an IP address or browser fingerprint with this receipt.
  • Limited operational and security logs needed to run and protect the service.

We use this data only to provide, secure, troubleshoot, and improve Ninai. Ninai does not sell personal data, run behavioral advertising, or train a Ninai model on your local vault.

02

Who helps operate the service.

Auth0 provides authentication, Render hosts the account service and authenticated installer, Vercel hosts the public website, and GitHub hosts the public source repository. Their processing is governed by their own terms.

OpenAI or Anthropic receives selected local context only when a connected agent requests it. Provider retention and model-training choices are controlled by your provider account and its policy, not by Ninai.

03

Connected does not mean unlimited.

Ninai connects supported agents to the local engine. Project grants and approvals determine which memory an agent can read or propose. You can revoke access from the local app.

04

Your vault stays under your control.

The local vault remains on your Mac until you delete it. Account, sign-in, and installer-download records remain in the account service while the account is active and may remain temporarily in infrastructure backups after deletion until those backups rotate.

For access, correction, portability, deletion, or objection requests, email hello@ninai.io. We may need to verify the request.

05

Credentials are not memory.

Ninai blocks common secret patterns and applies local authorization. These controls reduce risk but do not make the beta suitable for passwords, private keys, health records, payment-card data, government identifiers, children's data, or other high-risk regulated information.

06

Account data may cross borders.

Our account, website, and source-hosting providers may process account and operational data in countries different from yours. The Ninai vault itself remains on your Mac unless you deliberately disclose selected context to an AI provider.

07

An MVP, not a certification.

  • No signed and notarized desktop package yet.
  • No independent security audit or compliance certification yet.
  • No prompt-injection classifier or guarantee that an AI provider will interpret context correctly.

We may update this policy as the service changes. Material updates will receive a new effective date on this page. Security reports: hello@ninai.io.

Keep the vault on your Mac.

The MVP is local-first. Cloud-hosted vaults are coming later.

Sign in for Mac setup ↗
Read the Terms of Service →