Data and privacy

What stays on your agent's machine, and what leaves it.

Read as Markdown

Optakt One runs on your agent's machine. What your agent knows is stored in your own database, and nothing of it reaches Optakt Labs.

What stays on your agent's machine

  • Memory, archive and every conversation, in your own database. By default it runs on your agent's machine; if you configure a separate database server, that knowledge is stored there instead.
  • Every file sent to your agent, and every file it works on.
  • Credentials, encrypted in the vault.

What leaves it

These are the outside services used during normal operation, and what each receives:

ServiceWhat it receivesWhy
Your model providerThe conversation and the context your agent works with, on every stepTo think and answer. Under your own key or subscription, and that provider's terms
TelegramYour messages and your agent's answersIt is the chat you talk in
Voyage AIText from memory and the archive, the names in it, and what your agent searches for. Not the conversationsTo turn it into embeddings for search. We provide a shared key during launch, but it may be withdrawn if costs become unsustainable. Your own key is highly recommended
ElevenLabs, if connectedYour voice and video notesTo transcribe them. Without it, they are transcribed on your agent's machine
Keygen, our licensing serviceYour licence and account details, a hashed id of your agent's machine, and a check-in every hourTo validate your licence
The services you connectWhat each job needsYour agent uses them on your behalf

With a model running on hardware you control, the conversation is not sent to an outside model provider. Telegram still carries your messages. To stop sending text to Voyage AI, disconnect it under Integrations. New text is then no longer embedded, and search keeps working by wording and connections, with less reach by meaning.

See Voyage AI and ElevenLabs for how to connect your own accounts and manage their usage.

What your agent can do on its machine

Your agent runs commands on its machine, as the service's own user (optakt on Linux, you on a Mac), with that user's rights. That is how it does real work: files, scripts, tools, the services you connect.

There is no sandbox around those commands yet. Give the agent only the access its work needs: run it on a machine of its own, or keep that user's rights limited. A sandboxed environment for every space is coming soon.

Documents and voice notes are a different matter: the tools that convert them always run sandboxed, without network.