LokalBot connection privacy
Effective October 9, 2026. This notice covers the optional ChatGPT connection operated by the LokalBot project (stevyhacker).
What you share
After you pair a Mac and allow external meeting-library access in LokalBot, your connected client can request meeting titles, dates, summaries, selected transcript excerpts, saved commitments, and people. The complete library is not synchronized. Screen history, recordings, library writes, remote inference, and Agent Mode are not exposed.
Where results go
The companion makes an outbound encrypted connection from your Mac to this Cloudflare-hosted relay. Requested results pass through the relay to ChatGPT or the client you authorized. The relay can process their plaintext; this is not end-to-end encryption against the operator. Cloudflare and your client's own terms and data controls apply. LokalBot does not use these results to train models.
Storage and retention
The application does not persist meeting payloads or application request logs. It stores device identifiers, hashed device credentials, OAuth client registrations, consent transactions, and grants needed to route and authorize requests. Cloudflare processes network metadata to provide and protect its service. We do not promise that the infrastructure retains no network metadata.
Pairing codes expire after ten minutes and work once. Access tokens last fifteen minutes; refresh grants last up to thirty days. Unused devices expire after one day, and previously connected devices expire after up to ninety days offline. Revocation deletes the device record immediately and denies subsequent reads; remaining OAuth records follow the provider's retention rules.
Your controls
Stop the helper, disable meeting-library access in LokalBot, or run the helper's revoke command to block future reads. Disconnect LokalBot in your client as well. These actions cannot recall results already shared; use that client's controls for its saved conversations.
Questions and deletion requests
Use LokalBot support to request a private contact channel for account metadata questions or deletion. Do not post pairing codes, credentials, device files, or meeting content in a public issue. There is no self-service OAuth metadata deletion page in this preview.