Privacy and security
Every connection the desktop app makes, what each agent can do on your machine, what sharing sends, and what Sundial holds in the cloud.
Your text leaves your machine in three cases
You share it, you use Sundial Agent, or you use inline AI. Everything else, including every Claude Code and Codex chat in a local project, runs without Sundial in the loop.
Claude Code and Codex run on your machine under your own login, and their requests go to Anthropic or OpenAI directly. Sundial never sees those prompts or your files. Their chats are stored on your Mac under ~/.sundial/desktop.
What the desktop app connects to
Sundial Desktop is a native shell around the web app. It loads its interface from sundial.md the way a browser loads a site, and that is the one connection it needs to open. Your files never travel with it: a helper on your Mac reads and writes them, and only the three cases above ever send your text anywhere.
The interface also talks to Sundial for the ordinary reasons an app does:
Updates. A version check at launch and about once an hour, sending the app's version and platform. A new version installs only when you choose Relaunch.
Usage analytics. Which screens are used and which errors the interface hits, with sign-in tokens and share links stripped. Off with the same switch as error reports.
Your browser, once. On first launch the app opens sundial.md/continue, so an invite link you were sent can open in the app.
Error reports. Only when you are signed in, never file contents; see the last section.
What each agent can do on your machine
Claude Code and Codex. They can run shell commands in the project folder without asking each time, the way they do in your terminal. Their shell runs as you, so like a terminal it can read what you can read. Their file tools stay inside the folder you opened. File edits still arrive as suggestions. View mode removes their write and shell tools entirely. In a cloud workspace a chat on the Claude Code or Codex tab runs on Sundial's servers, never on your Mac.
Sundial Agent. The model runs on Sundial's servers. In a cloud workspace its commands run in a sandbox, one per agent, never on your machine; the sandbox stops after 15 minutes idle and never lives past 24 hours. In a local project its tools run on your machine, so every message, and every file it reads for that turn, is sent to Sundial. The chat itself stays on your disk.
Ollama. A chat on an Ollama model runs on this computer. Nothing leaves it.
Inline AI (/ai, Cmd+G, Tune, Resize, autocomplete) runs on Sundial's servers, also in a local project; how it works is on Write and review, and what it keeps is under Your data in the cloud below.
What sharing sends
| You share | What uploads |
|---|---|
| A file | The file and its comments |
| A folder | The files inside it |
| The project | The files, and each chat's full history the first time you use it after sharing |
| A chat | That one chat |
Only what you picked syncs. The rest of the project stays on your machine.
From the desktop app, .env and .env.* files never sync, except templates such as .env.example. No other filename is treated as secret: check the share's file list before you turn it on. In a cloud workspace a .env you upload is an ordinary document; keep credentials in Workspace secrets instead.
Text files (Markdown, LaTeX, code, CSV) sync as live documents with edit history; images, PDFs and other binaries sync as files without it; node_modules/, .git/, dist/, build/, .venv/, .claude/, lockfiles, *.min.js, *.map and *.aux never sync.
Who can read, comment or edit is set per person or per link, for people and agents alike; the roles are on Sharing.
Review is the boundary
Every edit is attributed to the human or agent that made it. Chats write suggestions by default, and View mode removes the agent's write tools.
An agent connected from outside gets exactly what its share link covers, at the link's role: on a suggest link every write lands as a suggestion, on a file link it sees nothing else, and it cannot run commands. You can also switch any connected agent to Suggest only from its chip: every write then lands as a suggestion and delete, rename, commands and uploads are blocked, whatever token it holds. Stop sharing cuts it off at once, on its next request; so does removing it from the Share window.
In a cloud workspace a deleted text file comes back from History with Restore. Undoing a suggestion, and going back to an earlier version, are on Write and review.
Your data in the cloud
Where. Files, chats and history in Sundial's database and file store (Supabase); the agent on Fly and its sandbox on Modal.
Who. A cloud chat's model call goes through the Vercel AI Gateway to the provider of the model you picked (Anthropic, OpenAI, Google, xAI or an open model). Sign-in is Clerk; analytics is PostHog.
Secrets. Workspace secrets are encrypted at rest (AES-256-GCM), and when an agent needs a credential from you it sends a link that expires in 15 minutes, so secrets never sit in chat history. Your own provider keys are stored encrypted and used only for runs billed to you.
Inline AI. Sundial keeps the passage you selected, the paragraphs around it, the variants it produced, and which one you chose.
Storage. 5 GB per free workspace, 50 GB on Pro.
Deleting. Delete a workspace from its row menu on the dashboard (owner only); it disappears from every listing for everyone with access. Delete your account from the profile page in a browser; that removes your account, tokens and workspaces.
Retention, subprocessors and anything this page does not state are in /privacy and /terms.
Error reports, and the switch that turns reporting off
When you are signed in, the desktop app sends error reports: log lines that mention a failure, never file contents, with every path removed. They travel under your account and are stored against a random install id. Not signed in, nothing is sent. Send anonymous usage and error reports, in the account menu, turns error reports and usage analytics off together; SUNDIAL_NO_DIAGNOSTICS=1 in the environment turns error reports off as well.