Twoody
Security and privacy

What stays on your computer, what leaves it, and how to check.

The first protection of your documents is that they are read on your computer, Mac, Windows or Linux, by a model installed on it. Here is what the app does for that, what leaves the computer and when, its limits, and how to check it yourself.

Last updated: October 03, 2026

Your documents are read on the computer

They are read and indexed on the spot, by a model installed on your computer. No online AI service receives them; in a conversation you keep on your account, the text used for an answer is kept with it, encrypted end to end since version 0.13.20 (beta).

A server closed by default

The server built into the app only listens to this computer until you tick “Let my other devices reach this computer”; then only the devices that type its pairing code get in, and their exchanges are sealed. The model engine only ever listens to this computer, with a new key at each launch.

Signed updates

On a Mac, the app is notarized by Apple, and macOS only installs an update signed by Twoody's publisher; on Windows, the installer and its updates are signed by Osmove. The app checks at most once a day whether a new version exists, without any identifier of your computer, and asks you before installing it. On Linux, you install new versions yourself.

Verified models

A model installed from Twoody is downloaded from Hugging Face, then its fingerprint (SHA-256) is checked before it is used.

Code asks before acting

Twoody Code works in the folder you open. By default, it asks before it changes a file or runs a command; in “Auto edits”, it applies its file changes without asking, but a command always waits for your approval. Driving it from the iPhone stays off until you turn it on.

Your data on disk

It lives in Twoody's data folder, in your user account; on a Mac, only your macOS user account can read it. Twoody does not encrypt its database itself: encrypt your disk, with FileVault on a Mac, BitLocker on Windows or LUKS on Linux.

  • On your computer
    Documents read by a local model
  • No account needed
    The account is optional
  • Diagnostics without content
    On during the beta, can be turned off
  • Notarized and signed
    By Apple on Mac, by Osmove on Windows
  • Free
    Personal and professional use

Everything that leaves your computer

The list is complete. What is not on it does not leave: no statistics about your content, no crash reports, no ad tracking.

What Where to When
The update check: a small file read, with no identifier of your computer downloads.twoody.com At most once a day; can be turned off in Settings
Downloading a model huggingface.co When you install a model
Downloading the voice model (whisper.cpp) huggingface.co The first time you press the microphone
Your search, then reading the pages found DuckDuckGo by default, Brave or your SearXNG server, then the sites found Only if you turn web search on
The online account, with the conversations you keep on it twoody.com Only if you sign in to an account, which is optional; private conversations stay on the computer
Your exchanges with your other devices, sealed end to end Your account's relay, on twoody.com Only with an account, if you tick “Reachable away from home”; the relay cannot read them
Technical diagnostics: measurements of the answers (model, durations, token counts, cache, tools used, errors, version), never a question, an answer or a document Your account; without one, twoody.com under a number drawn at random by the installation On by default during the beta, can be turned off in Settings (Privacy); every 15 minutes
The whole of each answer (question, instructions, memories, tools, answer), for audits Your account; without one, twoody.com under the installation's number Only if you tick "Also share the whole of each answer" (unticked by default)
What a connector's tool receives (the arguments shown) The service of the connector you added (Notion, GitHub, J-Way…) Only if you add a connector, at each call you allow (or "Always allow" for that tool)
Your home commands (turn on, turn off, read a state) Your Home Assistant, at the address you give Only if you turn on the Home capability

Encrypted end to end, between your devices

Your iPhone asking your computer, one computer asking another, a person of your household to whom you lend your computer: these exchanges are sealed by the device that sends them, and only the device that receives them can open them.

Why HTTPS is not enough

HTTPS protects a message between your device and the server that receives it, and then that server reads it in clear. Away from home, your devices reach each other through the Twoody account's relay, and through the host and the network that carry it: with HTTPS alone, they could read your questions. So Twoody seals them with keys only your devices hold. The relay sees that your devices talk, when and how much — never what they say.

A computer gets in with a code

A phone or another computer only joins yours with a code shown by the computer itself. Before adding a computer to your account, Twoody shows you its name, system and fingerprint, to compare with what it shows: if anything differs, do not add it. A phone asking to reach your computer waits for your approval, given on the computer.

No trust by default

A computer added to your account receives only the conversation: not your memories, your contacts, your calendar or your documents, until you tick, for that one alone, “Trust this computer” (Devices). Computers other people share with you are never picked automatically. A headless computer linked to the account sends it its status — its models, its load, its speed — so that your devices know where to send a question.

Check it for yourself

You do not have to take our word for it. Three checks anyone can make.

Turn Wi-Fi off

Once the model is installed, disconnect your computer from the internet: Twoody keeps answering and reading your documents. Only web search stops.

Watch its connections

An application firewall shows every connection an app opens: LuLu (free, by Objective-See) or Little Snitch on a Mac, OpenSnitch on Linux; on Windows, the Network tab of Resource Monitor lists them. Twoody's are those of the table above, and no other.

Check who signed it

On a Mac, in Terminal, the command below must answer "accepted" and "Notarized Developer ID": the app is Osmove's, checked by Apple. Installed before version 0.11.5, it may still be called "Twoody Desktop.app". On Windows, the installer's properties, "Digital Signatures" tab, must name Osmove.

spctl -a -vv /Applications/Twoody.app

Where your data is

Conversations, memories, the document index and models live in Twoody's data folder: ~/Library/Application Support/twoody-desktop on a Mac, %APPDATA%\twoody-desktop on Windows, ~/.config/twoody-desktop on Linux, in your user account. Twoody makes no backup of its own: if you back up your computer, the backup includes them, so encrypt it. The conversations you keep on your optional account are also on the account. To erase everything, follow these two steps(in English).

The licence

Twoody is free, for personal and professional use. Its code is not published. Models keep their own licence (Apache 2.0 for Qwen3.5) and the llama.cpp engine is under the MIT licence: every licence is listed in Settings › About. The details are in the terms of use(in English).

The online account (optional)

Twoody does not need it. The online Twoody account is optional and free: it links your devices, and uses the models of your computers only. Since version 0.13.20, the new conversations you keep on it are synced encrypted end to end (beta): your devices share a key the account never sees. A conversation kept on the account before this encrypted history — with the text of what you attach and of the passages Twoody reads for it — stays readable there. It is hosted by Heroku (Salesforce), in its Europe region (Ireland), behind Cloudflare. What the account does with your data is described in its own policy(in English).

Report a vulnerability

Write to support@twoody.com, with "Security" in the subject and what we need to reproduce the problem, and give us time to fix it before making it public.

support@twoody.com