What leaves your computer
Ora · privacy

What leaves your computer.

By default, your life in Ora stays on this PC: chats, files, history, settings, saved keys, and recordings. Nothing is sent anywhere unless a row below describes it.

What can leave is a short, expected list — and every kind of sending has a switch. Ora asks before anything sensitive, and the tables below tell you what is sent, to whom, when, and where the switch is.

Asks before it sends Every send has a switch No telemetry

Purpose by purpose · Local-only mode · What is never sent · The What left this PC list

The one-time ask

Screen content asks once. You can take it back.

The first time any screen content — a screenshot, or the text on your screen — would be sent to a model that runs somewhere other than this PC, Ora asks. The confirmation names the provider and model and describes the requested access. It does not show a preview of the exact capture before it is sent; after a task step you can review it in chat with View screenshot.

One accepted choice covers screen content from then on. Declining or revoking it keeps screen content on this PC — revoke any time under Settings → Privacy & Safety → Screen & Voice privacy. Local-only blocks every cloud screen route too, even with the choice accepted. And a request made without the Ora window open can never share screen content, because it cannot show you the ask.

Spoken requests work the same way: your words are recognized on this PC, and the recognized text only travels as part of a request, behind its own consent choice. The audio recording is not sent.

Asked once Names the provider and model Revocable any time Local-only overrides it
Purpose by purpose · 8 tables

Every kind of sending, row by row.

If a kind of sending is not listed here, Ora does not do it on its own.

Talking to an AI model you chose

What is sentTo whomWhenHow to turn it off
Your message, plus the context the task needs — for example text from a file you attached, or the names of files in a folder you asked Ora to tidyThe AI service you chose in Settings → Models → API KeysEvery time you send a message or run a task with a cloud modelPick a local (on this PC) model in the model picker, or turn on Local-only mode
A title for a new chat, made from your first messageThe same AI serviceOnce, after the first message in a chatLocal-only mode — Ora names the chat on this PC instead
The list of model names shown in the pickerThe same AI service; your key is used only to sign in, no task content is sentWhen you open or refresh the model pickerLocal-only mode — Ora shows its built-in list instead
A screenshot or on-screen text, when a task needs Ora to look at your screen; or the pages of a file, when the optional cloud file-reading fallback is onThe AI service you chose, or an image-reading serviceOnly after your screen-content choice; Local-only blocks bothRevoke the choice under Settings → Privacy & Safety → Screen & Voice privacy; keep file reading local under Settings → Integrations → File reader

Choose a local model and the whole conversation is answered on this PC.

Web research

What is sentTo whomWhenHow to turn it off
Requests for the web pages a research task needs, plus one built-in search service used to find themThe public websites themselves; the search step talks to one pinned search serviceWhile a research run you started is working; only the sites the run admits, each page size-capped, site rules respected, and no cookies, sign-ins, or page scripts sent or runLocal-only mode refuses before the first request; or press Stop research on the progress card
A read of one specific site you point Ora atThat site only — pages at the site's own addressWhen a task asks Ora to harvest or rebuild that siteLocal-only mode; or cancel the run

Portal chores

What is sentTo whomWhenHow to turn it off
The same page loads, downloads, form submissions, and file uploads your own browser would perform on the portalThe portal site you named — for example a school or work portalDuring a chore run you started; every file the portal offers asks before it lands, every upload and submit shows an approval card naming the exact file, and a sign-in parks the run for you to typeDeny the approval card, or press Cancel on the run's status card; a chore only ever runs for sites its mission card names

Email

What is sentTo whomWhenHow to turn it off
Reads, drafts, and — only ever with a per-send approval — sends, on your mailboxYour own mail server, at the connection details you enteredReading and drafting happen while a bot works with your mail; a send only at its approval card, which names the exact recipientKeep the mailbox draft-only; turn off Allow sending; disconnect the account under Settings → Integrations → Personal connectors (that deletes the stored password at once); Local-only mode blocks the connection entirely

Updates and model downloads

What is sentTo whomWhenHow to turn it off
A check for Ora updates, and the update itselfOra's public release feedOnly when you ask, from Settings → General → About; the check carries none of your content, and Ora never checks on its ownDon't run the check — there is nothing to turn off
Local AI engine and model packages — including Compass-1, which downloads once after you say yes, then works offlineDownload addresses pinned inside OraOnly while an install you started is running; every file is size- and hash-checked before it is keptDon't start the install
Ora's own helper model, used by some automation featuresOra's release feedThe first time a feature that needs it runs; Local-only mode blocks the downloadLocal-only mode; or don't use the feature

Help links

What is sentTo whomWhenHow to turn it off
Nothing but the open itself: Ora asks your browser to open one of three pinned pages — the getting-started guide, the troubleshooting page, and the issue trackerOra's public help pagesOnly when you click a help link; no content of yours is attachedDon't click the link — nothing else is sent

Blender

What is sentTo whomWhenHow to turn it off
Nothing leaves this PC: scene commands travel between Ora and Blender over a private connection on your computer, checked by a fresh token each sessionBetween Ora and Blender on this PC onlyWhile you are using the Blender bridgeUninstall the add-on from Settings → Integrations → Personal connectors → Creative apps, or simply don't connect; the add-on has no network access of its own

Browser access

What is sentTo whomWhenHow to turn it off
Page content from tabs you place in an Ora browser workspace, handed to OraOra itself, over a private connection on this PC — nothing goes to the internet through the bridgeWhile a tab you placed in the workspace sends its page to OraRemove the Ora extension from your browser, or disconnect browser access under Settings → Automations → Browser access
Local-only mode

One switch keeps every cloud call off.

Local-only is the one switch that keeps task content on this PC by pausing every cloud call. It lives under Settings → Privacy & Safety → Screen & Voice privacy, and it overrides the individual sharing choices.

With it on
  • Chat, bots, and Ora Build answer only with local models.
  • Screens and files are never read by a cloud service — even a saved screen-content choice is not used while the mode is on.
  • Chat titles are made on this PC, and the model picker uses its built-in list.
  • Helpers that would run elsewhere are unavailable or fall back to doing the work on this PC.
  • A connected mailbox is not contacted at all — reads and sends both wait.
  • Web research refuses before its first request, and the refusal is recorded in the What left this PC list.
What still works
  • Local models, and everything that runs on this PC: speech recognition, on-PC image reading, file work with Undo, and demonstration recordings.
  • The Blender bridge — it never used the network in the first place.
  • Browsing and portal chores you approve: Local-only governs cloud AI, not the sites you send Ora to.
  • Checking for updates when you ask, and the help links.
  • The What left this PC list keeps recording — including every blocked attempt, so you can watch the mode working.
The switch · a demonstration
Cloud models · allowed Flip the switch
Cloud calls
On this PC

Chat answers with the model you chose. Screen content follows its consent choice.

A demonstration, not a setting — the real switch lives in Settings → Privacy & Safety → Screen & Voice privacy.

What is never sent

Four things never leave, in any mode.

  • Passwords, one-time codes, and card numbers. They are redacted before logs, digests, or anything sent to a model is built, and a demonstration recording never captures typing into password or code fields.
  • Your API keys. Stored encrypted on this PC, used only to sign in to the service they belong to, never included as message text, and never written into the What-left record.
  • Your files — unless you approved that exact upload or send. Uploads and sends are hard stops in every mode: Ora asks, the card names the destination, and an "approve for this session" choice covers only repeats to that same destination.
  • Telemetry. There is none: no usage statistics and no automatic crash reporting. A diagnostic file is created only when you ask for it, and saving it opens your system's save dialog.
What left this PC · a live list

Watch every send, including the blocked ones.

Under Settings → Privacy & Safety, the What left this PC list records what Ora sent off this PC, newest first. Each row names the destination, the kind of request, the outcome — sent, blocked by Local-only, or blocked by consent — and the size. Messages, files, and keys are never stored in the record. The list is limited to the latest 500 events over 7 days, and clearing it yourself is the only way to remove it.

Example rows
  • The AI service you chose2 KBmodel request · sent
  • A school portal4 KBpage read · sent
  • Ora's release feed1 KBupdate check · sent
  • The AI service you chose0 KBmodel request · blocked by Local-only

Blocked attempts appear in the list too, so the switch is visible doing its work.

Next: the private beta.