Two ways to run it, and an honest gradient.
The disclosures further down are about the model you connect. This is the prior question: where Laedis itself runs and processes your record, before any model is called. There are two ways to run it, and privacy is a gradient across them — not one blanket promise. Each level is stated as a fact.
Laedis runs on your own hardware. Nothing leaves that machine except the calls to the model you connect; there is no Laedis server in the middle. This is the only path that guarantees complete privacy — and the one we recommend.
On a machine someone else manages or monitors — a work computer under an employer's control — that environment limits your privacy independently of Laedis. "Local" does not mean private if the machine itself is not. The limit there is the machine's: Laedis neither adds to it nor can remove it.
Your isolated instance runs on infrastructure we operate, reached over a private URL. Your data is processed on our infrastructure before it is sent to the model you connect. Choosing this path forfeits the complete-privacy guarantee. We don't call this "secure" or "protected"; we state it as what it is — processed on machines we run.
What stays the same across all of them: you connect your own model account, Laedis stores no key beyond the call, there is no telemetry or analytics or third-party call beyond your model, and you keep complete export and permanent deletion. What changes is only where Laedis runs and processes — and, on the hosted path, who operates that machine.
The intelligence comes to your data — never the other way around.
Laedis's reasoning runs on a model you connect: one on your own machine, or one in your own cloud account under your own key. You pick the provider. Before that choice is committed, Laedis shows you the data-handling statement for it, so the decision is informed and yours. Below are the three statements, word for word.
Exactly what you're shown at setup.
"Runs on your machine via Ollama. Nothing leaves it — no data is sent over the network."
No network call to a model at all — the model runs alongside Laedis. On a local install that's your own hardware; on a hosted instance, the machine we operate (see the gradient above).
"Your data is sent to Anthropic under YOUR account and their terms. Laedis stores nothing externally and never sees your key beyond using it to call your own account."
Anthropic's terms govern that processing. Laedis is only making the call on your behalf.
"Your data is sent to [the endpoint you configure] under YOUR account and its terms. Laedis stores nothing externally and never sees your key beyond using it to call your own account."
Covers OpenAI, Azure OpenAI, and compatible endpoints. The chosen provider's terms govern that processing.
Stored by you; used only to call your model.
- A cloud model's key is held in your own local store, covered by the same export and deletion as your record.
- It is never written in plain text into the program, never logged, and never put in an error message.
- It is sent nowhere except to the provider you chose, to make the call — and removed when you erase everything.
Laedis waits, quietly.
Until you connect a model, the reasoning part of Laedis is dormant — it shows a calm "connect your model" state rather than inventing anything. Nothing is sent over the network on either run path: on a local install, on your own machine; on a hosted instance, on the machine we operate.
Pilot-stage draft · pending review by a qualified lawyer before any paying engagement · not legal advice. The gradient and the provider statements above are the same facts Laedis shows at setup, before you commit. If a provider changes its terms, consult that provider directly — those terms, not this page, govern the provider's processing of your data. The hosted path's processing terms are to be set with counsel before any paying engagement.