Your documents stay on the Mac
They are read and indexed on the spot, by a model installed on your Mac. No online AI service receives them.
The first protection of your documents is that they do not leave your Mac. Here is what the app does for that, its limits, and how to check it yourself.
Last updated: 25 September 2026
They are read and indexed on the spot, by a model installed on your Mac. No online AI service receives them.
The server built into the app and the model engine only listen to this computer, and the engine requires a new key at each launch. Other devices on your network cannot reach them.
The app is notarized by Apple. It checks at most once a day whether a new version exists, without any identifier of your Mac, and asks you before installing it; macOS only installs an update signed by Twoody's publisher.
A model installed from Twoody is downloaded from Hugging Face, then its fingerprint (SHA-256) is checked before it is used.
The coding agent works in the folder you open, and asks you before it changes a file or runs a command.
It lives in Twoody's data folder, readable only by your macOS user account. Twoody does not encrypt its database itself: turn on FileVault so that your disk is.
The list is complete. What is not on it does not leave: no telemetry, no usage statistics, no crash reports.
| What | Where to | When |
|---|---|---|
| The update check: a small file read, with no identifier of your Mac | downloads.twoody.com | At most once a day; can be turned off in Settings |
| Downloading a model | huggingface.co | When you install a model |
| Your search, then reading the pages found | DuckDuckGo by default, Brave or your SearXNG server, then the sites found | Only if you turn web search on |
| The online account and the iPhone app's relay, end-to-end encrypted | twoody.com | Only if you sign in to an account (private beta) |
You do not have to take our word for it. Three checks anyone can make.
Once the model is installed, disconnect your Mac from the internet: Twoody keeps answering and reading your documents. Only web search stops.
An application firewall, such as LuLu (free, by Objective-See) or Little Snitch, shows every connection an app opens. Twoody's are those of the table above, and no other.
In Terminal, the command below must answer "accepted" and "Notarized Developer ID": the app is Osmove's, checked by Apple.
spctl -a -vv "/Applications/Twoody Desktop.app"
Conversations, memories, the document index and models live in ~/Library/Application Support/twoody-desktop, readable only by your macOS user account. Time Machine backs them up with the rest of your files: encrypt your backups so that they stay protected. To erase everything, follow these two steps.
Twoody is free, for personal and professional use. Its code is not published. Models keep their own licence (Apache 2.0 for Qwen3) and the llama.cpp engine is under the MIT licence: every licence is listed in Settings › About. The details are in the terms of use.
Twoody for Mac does not need it. The online Twoody account is closed to new sign-ups; in a private beta, it links the iPhone app to your Mac. It is hosted by Heroku (Salesforce), in its Europe region (Ireland), behind Cloudflare. The relay the iPhone app uses away from home is end-to-end encrypted between phone and Mac: it does not see the content of the messages. What the account does with your data is described in its own policy.
Write to support@twoody.com, with "Security" in the subject and what we need to reproduce the problem, and give us time to fix it before making it public.
support@twoody.com