Local-first AI products try to keep the durable center of your work on your device: files, history, settings, and the record of what happened. That can reduce unnecessary cloud storage and give you clearer ownership. But it does not automatically make the entire AI workflow offline or private.

If a product uses a cloud language model, the model provider must receive the prompt and enough context to answer. If the task searches the web, the search and page requests leave the device. If it reads a connected calendar or drive, that service processes the request. Good privacy starts by naming each boundary honestly.

The five layers of AI data flow

1. Durable local data

This includes the files you already have, outputs the agent creates, task history, cached previews, and local preferences. In a local-first design, these should remain on the Mac unless you intentionally sync or share them.

2. Model requests

A cloud model receives your instruction plus selected context: perhaps a paragraph, a document, or the result of a tool call. The important questions are which provider receives it, whether requests go directly or through the product’s service, how long the provider retains it, and whether it may be used for training under your plan.

3. Credentials

API keys and connection tokens are different from content. They should be stored in a protected credential store such as the macOS Keychain, kept out of the interface after entry, and never exposed to tools the agent can run. A product should not put secrets into prompts or ordinary log files.

4. Web activity

Research sends queries to a search service and requests to the pages opened. Browser automation may also involve cookies or signed-in sessions. A visible, task-specific browser is easier to understand than invisible access to your everyday browsing profile.

5. Connected apps

Google Drive, Gmail, Calendar, Slack, Notion, and similar services each have permissions and data flows. Prefer narrow scopes, short-lived access where possible, and explicit approval before the agent sends, publishes, deletes, or changes shared information.

What “local-first” should mean

The term is most useful when it describes durable ownership and product behavior rather than claiming zero network use. Look for concrete statements:

  • task history is stored on the Mac;
  • generated files are written to folders you control;
  • credentials live in the system keychain;
  • the agent has a visible file or workspace boundary;
  • only task-relevant context is selected for a model request;
  • networked tools can be disabled or limited;
  • you can delete local history and disconnect external accounts.

A privacy page should also describe the exceptions plainly. “Your files stay local” can be technically true while portions of those files are sent to a model because the task requires them. The better question is: what leaves, for which purpose, through which provider, and under whose control?

Questions to ask before installing an AI agent

  1. Where is task history stored? Local database, vendor cloud, or both?
  2. Which model provider processes prompts? Can you bring your own API key?
  3. How is context selected? Entire folders, whole files, or only relevant excerpts?
  4. What can agent tools access? One chosen folder or broad disk permissions?
  5. Where are secrets stored? System keychain, encrypted service, configuration file, or environment variable?
  6. What requires approval? Sending, publishing, deletion, purchases, sharing, and permission changes should be clear.
  7. Can you inspect and delete your data? Look for straightforward controls and a specific policy.

How to reduce exposure in daily use

  • Use the smallest useful folder. Copy task inputs into a dedicated workspace instead of granting access to a broad archive.
  • Remove unnecessary secrets. Redact account numbers, keys, or personal identifiers that the task does not need.
  • Turn off web access when it adds no value. A task using only your sources should not browse by default.
  • Prefer drafts before external actions. Let the agent prepare a message or record, then review it before sending.
  • Use separate browser sessions. Task isolation reduces accidental access to unrelated tabs and accounts.
  • Review connected-app permissions. Disconnect services you no longer use.

Privacy is a workflow property. Even a carefully designed tool needs a narrow task, appropriate inputs, and a deliberate review step.

Does local-first mean offline AI?

No. A fully offline AI system runs the model and every tool locally without network access. A local-first system may use cloud intelligence while keeping durable user data and control on the device. Both approaches can be valid; they optimize for different combinations of model quality, hardware requirements, speed, cost, and privacy.

If offline operation is a hard requirement, confirm that the exact model and features you need run without a network connection. Do not infer it from “desktop,” “native,” or “local-first.”

How Wavy handles the boundary

In Wavy, task history and generated files stay on your Mac. You choose the working folder. Prompts and required context are processed by the selected model provider, and web or connector requests go to the services involved. Credentials are stored through the macOS Keychain or the relevant connection service, not exposed to the agent’s workspace tools.

Wavy shows the work trace and asks before consequential actions. You can bring your own Anthropic API key, turn web access off for a task, and disconnect connected services. The exact, current details live in the Wavy privacy policy.

The bottom line

Local-first is valuable when it gives you durable ownership, smaller access boundaries, and clearer control. Treat it as the beginning of the privacy conversation. The complete picture includes model requests, credentials, web activity, connected apps, approvals, and deletion.