Privacy
Ódinn Forge has no built-in product telemetry. By default, configuration, memory, sessions, goals, audit history, the run ledger, browser profile, approvals, recovery records, and credentials live in the configured local state directory.
Local-first does not mean every request stays on the machine.
What can leave the machine
Section titled “What can leave the machine”When you use a cloud model provider, it receives the prompts, recalled context, tool results, and other request material sent to produce a response. The provider’s retention, training, billing, and account policies apply.
Websites receive ordinary search, fetch, or browser traffic. An account you open in Ódinn’s isolated browser sees activity from that browser profile.
A remote multi-user host moves tenant state and traffic to the machine running that host.
What stays local by default
Section titled “What stays local by default”- accepted and suggested memory;
- projects, sessions, goals, and improvement records;
- the signed audit journal and run ledger;
- the isolated Chromium profile;
- gateway bearer tokens and audit signing keys;
- OAuth tokens and provider configuration;
- job, approval, and browser-recovery state.
Sensitive material
Section titled “Sensitive material”Never publish or attach:
- the
.odinnstate directory; - OAuth files or API keys;
- gateway tokens or audit signing keys;
- browser profiles or cookies;
- raw prompts containing private data;
- unsanitized diagnostic bundles;
- backups of Ódinn state.
Use odinn doctor for a redacted report. It deliberately omits state paths, tokens, prompts, cookies, and provider secrets.
Imported and external content
Section titled “Imported and external content”Model output, public web pages, imported skills, extensions, MCP servers, capsules, and manifests are untrusted input. A page instruction is not operator authorization.
Before connecting private accounts, review Web and browser work, the security model, and your chosen provider’s privacy policy.
