Privacy and usage analytics
What stays on your computer, what leaves it and where it goes, and how usage analytics work: none today, anonymous and opt-out when they arrive.
Murage keeps your bots, conversations, memory, files and settings on your computer, in the .murage folder in your home folder. There's no Murage server holding your work. Some things do leave your computer, and this page lists each one.
Usage analytics
Today's releases send no usage analytics. Anonymous, opt-out analytics are planned.
When they arrive, they will be product events such as "app opened" and which features get used. They will never include your conversations, prompts, file contents or bot output. Your email is attached only if you gave it during setup. We'll say so in the release notes first.
The switch is already there: Settings → General → Usage analytics. Turn it off and Murage never starts the analytics library on that computer, so nothing is sent.
What leaves your computer
The AI engine you choose
When a bot works, it sends what it needs for that turn to its engine: your message, its instructions, relevant memories and the files it's working on. That engine is your choice, per bot:
- Claude Code, Codex, Hermes and other agent engines send it to their maker, under your own account and their terms.
- Provider keys (Anthropic, OpenAI, OpenRouter and others) send it to that provider.
- Flux Router sends it to Flux Router, which routes it to a model.
- Local models through Ollama, LM Studio or llama.cpp keep it on your computer.
For work that must not leave the building, put that bot on a local model. See Engines.
Services you switch on
Each of these is off until you set it up, and each one receives only what you ask your bots to do there:
- Connected apps such as Gmail, Slack and Notion, through Flux Router or your own connected-apps key.
- Web search. Bots search the web through a free search service by default, or through Flux Router or your own Tavily, Exa or Firecrawl key.
- Voice, through Flux Router or your own OpenAI, xAI, Groq, OpenRouter or ElevenLabs key. The built-in Mac and Windows system voices stay on your computer.
- Telegram, Slack and Discord, when you pair them with your Chief of Staff.
- Off-site backups, to storage you own: an S3-compatible bucket or your own server over SFTP. Backups are encrypted before they leave.
- A cloud computer, if you give a bot one.
Update checks
Murage checks the public Murage releases page on GitHub for new versions. Downloading and installing an update is always your choice.
Your email, if you give it
The first-run welcome asks for your name and email, so Murage can tell you when there's something new it can do. The email is optional: choose Skip for now and nothing is sent. If you enter it, your email and first name go to our sign-up service at accounts.murage.ai, which adds them to our mailing list with our email provider, Sendlane. Nothing else is sent with them.
Phone access
When you pair a phone over Tailscale or on the same Wi-Fi, your phone talks straight to your computer. There's no Murage server in the middle. During setup Murage may also offer secure access by emailing you a one-time code. That route signs you in through accounts.murage.ai. See Use Murage on your phone.
What stays on your computer
- Your keys. Engine sign-ins and API keys are kept on your computer and used only with the service each one is for.
- Your memory and conversations, apart from what a bot sends to its engine for a turn, or what you send through a channel or app you connected.
- Your data in exports. Exports of bots and teams leave out credentials, conversations and memory. See Share a team with your staff.
Forgetting
Forget a memory in Murage and it's removed from your computer. It can't pull back text that was already sent to a hosted engine in an earlier turn. If that matters for a piece of work, use a local model for it.
Check for yourself
Murage is open source under the AGPL. Anyone can read the code on GitHub and see exactly what it sends. The full legal detail is in our privacy policy.