Privacy Policy
Version 1.8 - Updated September 25, 2026
Local-first by default
Boollm is a desktop AI workspace for Windows, Linux and macOS developed by saz3 Labs. Local chats, notes, project files, browser state, settings, screenshots, recordings, model files, response feedback, and project-learning records stay on your computer when you use local features available in your edition. No language model is included: on a computer with none, Boollm reads how much memory and free disk space that PC has and offers one model that fits, which you can download in a single click - that check stays on your computer, and only the download itself contacts the model's host. On every platform, choosing a cloud model sends that conversation and its attachments to the provider you selected, under that provider's own terms. Boollm has no saz3 Labs account or sync service and does not include telemetry, advertising analytics, tracking, or automatic crash reporting.
Information stored on your computer
Boollm stores conversations, settings, provider and connector credentials, model files, task plans and checkpoints, schedules, generated files, optional email OAuth tokens, and optional local learning or Education records under your Windows user profile. Some feature-specific secret stores use local encryption; other provider keys are part of the protected local Boollm profile. API responses expose only whether a secret is present, not its value. You can clear chats and learning records, disconnect provider accounts and connectors, disable project learning, or uninstall Boollm using the controls provided in the app, the provider, and Windows.
The separate direct-download release can also store local screen recordings; Monitor evidence, OCR text, incidents, and screenshots; Avatar portraits, projects, source media, and outputs; and an encrypted Browser & Passwords vault with local Chrome-extension pairing records. The Microsoft Store edition does not include Automations, Monitors, Browser & Passwords or its Chrome extension, or Avatar Studio. The Linux edition does not include those features either. It runs local models on your CPU by default, stores its data under your Linux user profile, and can also use cloud model providers with your own API key, the Codex and Claude Code coding engines, Cloudflare, cloud hosting and email sign-in. Snip and screen recording are available in Linux builds that include them, subject to desktop portal support and your permission. There is no private code or developer login that enables excluded features in either edition.
Linux screenshots, recordings and keyring permissions
Snip uses your desktop's screenshot dialog. Screen recording uses its screen-sharing dialog; you choose the source and may cancel or stop. Linux recordings contain video only, without microphone or system audio. Screenshots, recordings and incomplete recording files are stored locally with private file permissions. These media files are not encrypted by Boollm. Starting a capture does not automatically upload it. Copying, attaching, exporting or sharing is a separate action you choose. Review captured content before sharing: visible pages or windows may contain personal information or secrets. Content you deliberately send to a paired Cluster worker or another service may leave this computer according to that feature's permissions.
Linux chat and Notes records are stored in an encrypted local database. Your desktop keyring protects Boollm's profile key: the Snap keeps that key as a single item held by the desktop Secret Service, and other editions use Electron's secure storage. Neither falls back to unprotected storage. The Snap password-manager-service permission grants broad desktop-keyring access, not an operating-system restriction to only Boollm's secret. Boollm uses it for its own profile protection and does not offer password importing or enumeration. It refuses unprotected storage or replacement of an existing missing or invalid key. The Chromium-sandbox permission retains isolation for web content inside the Snap.
The Snap has a separate profile under ~/snap/boollm/common, retained across revisions. It does not copy the private Linux preview's profile. Removing the application may leave local data or package-manager snapshots; remove retained data deliberately using the appropriate application or operating-system tools.
Mac App Store edition
The Mac App Store edition runs in the macOS App Sandbox. Its data is stored in the app's own container under your macOS user account (~/Library/Containers/com.boollm.desktop.mac). Chats and Notes are kept in an encrypted local database whose key is protected by your macOS Keychain; Boollm refuses to fall back to unprotected storage. Accounts and data on the Mac are separate from your other computers and are never imported automatically. Updates arrive through the App Store.
The Mac edition includes cloud model providers with your own API key, Home Cluster over your own local network, and the Codex coding engine. The official Codex CLI is bundled; you sign in to your own ChatGPT plan through OpenAI's sign-in, and Boollm never sees that token. Codex commands and file edits run inside separate sandboxed helpers limited to the project folder you choose; network access for them is available only when you choose Full access. Like the Microsoft Store edition, the Mac edition does not include Automations, Monitors or Avatar Studio, and it also does not include a terminal, the Claude Code coding engine, or Browser & Passwords and its Chrome extension; there is no hidden unlock for them.
Screenshots and screen recordings use Apple's content-sharing picker: nothing is captured until you choose a screen or window, and recordings are video only. Dictation uses the microphone only while you dictate and uses on-device speech recognition; if on-device recognition is unavailable it stops rather than sending audio online, and audio is not saved or uploaded. Home Cluster listens on your local network only after you turn it on and pair another computer. Captured screenshots and recordings are stored locally and are not encrypted by Boollm; review them before sharing.
What saz3 Labs receives
Boollm has no sign-in or saz3 Labs account service, so saz3 Labs does not receive or store identity sessions, synchronized notes, preferences, chats, or credential backups. If you deliberately send an AI content report or support email, saz3 Labs receives the information you choose to include when you send it.
When information leaves your computer
Information leaves your PC only when you choose a network feature. Examples include cloud AI providers, provider authorization, model downloads, web browsing and research, image generation, remote MCP or HTTP-agent connections, API connectors, scheduled webhooks, installation helpers, email connectors, or asking an online provider to inspect a screenshot, page, note, project file, or selected email. Boollm sends the task content and credentials needed for the selected operation. The destination service's terms, retention practices, charges, and privacy policy apply.
Optional Gmail and Outlook connectors send OAuth and mail requests directly between your PC and Google or Microsoft. Draft-only mode disables sending; otherwise sends require confirmation. If you ask a local model to work with mail, inference stays on your PC. If you select Codex, another cloud AI provider, or a remote connector, relevant mail content, instructions, and generated context may be sent to that service. Transactional security, support, or service messages may be delivered using Cloudflare Email Service.
In the direct-download release, online Monitor investigation sends selected evidence and context to the provider you choose. Browser & Passwords can inspect or operate pages you permit but does not give stored password values to models. Avatar Studio sends the selected portrait and camera or uploaded video to Decart only after its in-app Generative Live consent step. Opening a provider or social-media handoff contacts that website; a final post or upload remains a separate user-controlled action.
Google-connected features
Gmail and Google Cloud developer connections are separate optional features. Connecting one does not automatically connect the other. For Gmail, Boollm may request the identity scopes shown by Google and the gmail.modify scope. This can allow Boollm, at your direction, to identify the mailbox; list, search, and read messages and metadata; create and send drafts; manage labels; and move messages to or restore messages from Trash. Review the exact permissions on Google's consent screen before authorizing.
Boollm uses Google user data to provide the Google-connected feature and AI-assisted task you request. Boollm does not sell Google user data, build advertising profiles from it, or itself use Gmail content to train a general-purpose AI model. When you deliberately use a cloud model or remote connector for a Gmail task, that selected third party receives the content needed for the task, and its privacy, retention, account, and model-training terms apply.
You may disconnect Gmail in Boollm and revoke Boollm's access in your Google Account settings. Disconnecting or revoking access stops future mailbox access but does not automatically delete local chats, drafts, task results, or content already sent to a provider or recipient. Remove those separately using Boollm, Windows, Google, or the destination service's controls.
Use of Google-connected features is subject to Google's applicable terms, policies, permissions, quotas, and enforcement. See Google's Terms of Service and the Google API Services User Data Policy.
Software and model downloads
Microsoft Store installations receive application updates through Microsoft Store and do not use Boollm's GitHub installer updater. Snap installations receive updates through snapd and the Snap Store, subject to Canonical's policies; the private preview updater is not included. Direct-download editions may check the saz3 Labs GitHub release service, download an approved installer, verify its SHA-256 hash, and offer installation after Boollm closes. Update checks do not upload chats, files, notes, credentials, or models. Downloading a model contacts its host; importing a local model contacts nothing.
AI output, feedback, and reports
AI output may be inaccurate or inappropriate. Optional response feedback and correction notes stay on your PC and may be reused as local prompt context; they do not retrain the underlying model. The report control opens an email draft containing the concern, provider/model labels, and a short response excerpt. Nothing is transmitted until you review and send the email. Do not include passwords, API keys, private files, or other secrets.
Security, retention, and your choices
Boollm uses HTTPS for supported online services. Protect your Windows account and local Boollm profile like a password. You decide which providers, connectors, provider accounts, schedules, files, permissions, and approval modes to enable. Local information remains until you remove it or uninstall the app. Third-party retention depends on the enabled service and applicable law. Review provider permissions and generated actions, and revoke third-party access when it is no longer needed.
Children and changes
Boollm is a developer and productivity tool and is not directed at children under 13. This policy will be updated when Boollm's data practices materially change; the current version is published on the Boollm website and included with the software.
Contact
Questions, privacy requests, and AI content reports may be sent to [email protected].