Understand Privacy and Data Storage
See what stays local, what can leave your PC, and how secrets are stored.
Follow the bold button names and numbered steps. Technical names are included only when you need to recognize a model or file inside the app.
Local Waifu is local-first, not “always local.” Local models, memories, and embeddings can remain on your computer, but cloud AI, cloud speech services, Telegram, and remote Ollama send selected data outside the local app.
Know what stays local and what can leave the computer
| Activity | Where data goes |
|---|---|
| Local chat through bundled Ollama | Processed on your computer |
| Memories and embeddings | Stored locally; embeddings remain local even when chat uses a cloud provider |
| Local image generation | Processed on your computer |
| Local speech recognition and voice | Processed on your computer |
| Cloud chat or image model | Prompt, relevant conversation context, and requested input go to the provider you selected |
| Cloud STT/TTS | Audio or text required by that service goes to the selected provider |
| Telegram | Messages and media pass through Telegram and the Local Waifu bot integration |
| Remote Ollama Host | Model requests go to the configured network computer |
| Model downloads and update checks | Network requests go to the relevant model host or update service |
Important: Offline Mode blocks configured cloud model routes, but it does not make Telegram operate without Telegram’s servers, stop model downloads already requested, or block a custom network Ollama Host.
Locate your Local Waifu data
- macOS:
~/Library/Application Support/com.lumizone.localwaifu/ - Windows:
%APPDATA%\com.lumizone.localwaifu\
The app data directory contains the database, character data, soul files, portraits, generated images, voice references, settings, logs, and secrets.json. Model files may occupy separate model directories shown under Settings → Hardware → Storage.
Soul files containing personality, memory, and knowledge are encrypted with cocoon encryption. Their key material is tied to the original computer environment. This is one reason a copied full data directory is not the recommended self-service migration method between computers.
The secrets.json file can contain cloud provider API keys, the Telegram bot token, and activation-related data. On Unix-like systems it is protected with owner-only file permissions, but anyone who can read your user account’s files may still read it. Protect the operating-system account and disk.
Review and control permissions
Goal
Enable only the operating-system permissions needed for the features you use.
Before you start
Permissions are requested when a related feature is first used, not simply because the application launches.
Steps
- Enable microphone access only for dictation, voice calls, or voice-message workflows.
- On macOS, open Settings → Advanced → Privacy and enable Proactive calendar reminders only if you want Local Waifu to check your calendar periodically.
- Approve Calendar access when macOS asks. Reminder access may be requested when a reminder feature is used.
- To revoke access later:
- macOS: use System Settings → Privacy & Security and select the relevant category.
- Windows: use Settings → Privacy & security and select the relevant permission.
- Keep Blur on Background enabled under Settings → General if you do not want conversation content visible when the window loses focus.
Expected result
Only the features you intentionally use have operating-system access. Disabling a permission blocks that feature but does not delete existing data.
If something goes wrong
If a feature remains denied after you change the operating-system setting, quit and reopen Local Waifu. For microphone failures, also verify the input device under voice-call settings.