Kyalulu/docs
GitHub JA
Browse guides⌄

Reference

Data and privacy

Understand local storage, provider requests, Hub fetching, exports, and the limits of Remote.

At a glance

  • The local runtime stores authoritative conversations, characters and memories.
  • Local models and external APIs have different data destinations. Hub access also involves network requests.
  • Remote encryption does not secure a compromised endpoint. Browser drafts are not an encrypted vault.
On this page
  1. At a glance
  2. Distinguish local storage from network traffic
  3. Manage keys and Hub access
  4. Review memory, history, and exports separately
  5. Understand Remote encryption and outstanding validation

Distinguish local storage from network traffic#

Kyalulu centers on local storage. The Runtime manages conversations, the character library, and memories, using SQLite and image assets. Default locations differ between a development checkout and a Desktop distribution build, and can be configured. Check the active location in Status connection diagnostics.

Local-first does not mean there is no network traffic. Choosing an external model API sends the inputs needed for generation to that endpoint. These can include character settings, persona, world, visible conversation history, selected Lore, and retrieved memories. Even when you connect through local LE or LM Studio, an external backend still means an external destination.

ActionBoundary to check
Mock Echo chatNo external model API required.
Local-model generationCheck the engine and its actual destination.
External API generationPrompts go to the endpoint; retention and terms depend on its provider.
Hub search or URL importSearch and file-fetch requests reach the distributor.

See Models and connections for routing. Experiment data is not sent externally by default, but that does not keep generation inputs local when an experiment uses an external model.

Manage keys and Hub access#

Keep API keys in API-side configuration such as your own .env. Do not paste them into shared instructions, screenshots, or character cards. LE tokens also remain on the API side and are not passed to the normal web interface. Verify that the configured model URL points to the local or external destination you intend.

Public materials state that the initial library view does not contact Hubs. Selecting a Hub to search or import sends information such as search terms, content IDs, and file paths to the distributor. The design does not send conversation history or model credentials to Hubs. Opening an external Hub in a new tab also subjects that visit to the site's own network behavior and terms.

Review imported content and its source before saving. Imports do not automatically execute card scripts, authentication, or model loading. External image URLs are retained as references rather than downloaded automatically. These behaviors do not guarantee the safety of an entire third-party site. See Characters for migration limits.

Review memory, history, and exports separately#

Memory is off by default. Enabling it allows stored items to be retrieved and potentially included in inputs to the selected model. Turning it off is not deletion. Deleting a memory also does not erase existing conversation text, original files, or backups. Check each stored artifact according to what you want to remove.

  1. Inspect memory entries for personal information and errors; correct or remove them if needed.
  2. Check shared history and persona JSON for names, contact details, and private events.
  3. Confirm whether you are exporting a card, CHARX, Kyalulu backup, or original. Their coverage of images, settings, and selected history differs.
  4. Manage exported files and backups. Inspect prompts and stored content before sharing Debug output or experiment results as well.

Original files may retain unselected history and unsupported elements. Do not decide whether they are safe to share based only on the edited view. There is also no guarantee that all ordinary local data is encrypted at rest. Protect your PC account, device access, and backups. See Memory for the editing workflow.

Understand Remote encryption and outstanding validation#

The public Kyalulu Remote implementation is a development candidate. Noise encrypts communication between the PWA and PC Host, while the Relay routes traffic. Conversations and memories remain on the Host; Remote itself does not replace inference with cloud generation. A sleeping or offline PC is unavailable, and switching Hosts does not synchronize history automatically.

Transport encryption hides message content from the Relay. It does not hide metadata such as IP addresses, timing, or transfer sizes, or prevent plaintext capture if an endpoint or PWA distributor is compromised. Phone storage of keys and drafts should not be treated as secure encrypted storage on a shared device.

If a registered phone is lost, revoke its registration from the PC. Deleting a key on the phone alone does not revoke the server-side registration. To begin locally, follow Getting started, or consult the documentation index for guides based on public materials.

Sources for this article

Edited from public GitHub materials. Links are pinned to the reviewed commit.

Search the docs

↑ ↓ select · Enter open · Esc close