What lives on your device
Your Spaces, documents, conversations, preferences, and attached media begin on your device. Locus uses versioned local storage so your work can continue without a connection.
When data is processed elsewhere
When you ask the agent to work, your prompt, the current document, selected attachments, and the bounded conversation context shown in the app are sent through Locus services and an AI gateway to the configured model provider. If you allow web search and the agent uses it, a generated query is sent to a search provider; the resulting sources return to the model as context. You can turn web search off in the app.
Accounts and sync
An account is used for online agent access and optional Space sync. Turning sync off removes that Space’s server copy while keeping the local Space on your device. Signing out does not erase local Spaces.
Purchases and credit
Purchases require a Locus account. Apple or Google processes payment, and Locus gives RevenueCat your Locus account ID so a verified store event can be matched to that account. Locus does not receive your card or bank details.
Locus keeps the store, product and transaction IDs, fixed credit grant, settlement state, event ID, and content-free ledger entries needed to grant exactly once and handle refunds. It does not store receipt bodies, localized prices, currency, or RevenueCat aliases. A refund removes the original fixed grant and may leave a negative balance; Apple may later reverse that refund.
Diagnostics
Locus has no product analytics or session replay. Sentry can receive allowlisted crash details and failed-run diagnostics: app and system versions, stack locations, environment, model, timing and count metrics, error category, and HTTP status. Prompts, replies, documents, attachments, breadcrumbs, screenshots, view trees, user IDs, and network request bodies are excluded. Hosting, store, AI, gateway, and search providers may keep their own operational records under their terms.
Retention and deletion
You can delete your account from the app. Account deletion removes your account, synced workspace data, private media, detailed run and credit ledger, and account-linked purchase records from Locus services. Local Spaces remain on your device unless you remove them there. Content-free purchase event and transaction identifiers may remain where needed to prevent duplicate settlement and support store refund accounting. Locus may also retain pseudonymous grant-eligibility records and aggregate usage needed to prevent repeated promotional grants and understand overall service use.
Device protection
You can require Face ID, a fingerprint, or your device passcode when reopening Locus. This app lock uses the security capabilities of your device.
Contact
Questions about privacy or a deletion request can be sent to hello@trylocus.space.