LIVARIANTGitHubexternal
SecurityLocal-firstDocumented network boundaries

Privacy starts with visible data flows

You should know when Livariant leaves your machine.

Project knowledge is not automatically uploaded. Every network path has a documented purpose, and optional GitHub or AI-provider connections remain explicit.

No automatic project uploadNo product analyticsOptional connections remain explicit
01

Data paths

What stays local. What uses the network. What you connect yourself.

Local-first is not a blanket promise that Livariant never uses the network. It means every supported network path has an explicit purpose and documented boundary.

01Local

No Livariant usage analytics

The current Runtime and Desktop implement no Livariant usage analytics, crash reporting, advertising identifiers or automatic Project Brain upload.

02Network

Bounded operator-safety channel

The Desktop automatically requests one fixed signed HTTPS resource shortly after startup and approximately every five minutes afterwards. The request contains no project content and no request body. The channel can carry bounded service notices and version-specific update safety blocks. It is not a remote command channel.

03User initiated

Desktop update checks

Remote update discovery starts only when the user explicitly chooses Check for updates. Updater identity and target state are rechecked before installation.

04Optional

GitHub connection

The connection begins through an explicitly started GitHub Device Flow. Livariant can read supported account and repository information according to the granted GitHub access. Repository content is cloned only when the user explicitly selects a repository.

05Provider-aware

External AI providers

Livariant supports Codex, Claude Code, Gemini CLI and bounded Custom provider connections. Provider capabilities are intentionally not treated as identical. Project Context is prepared locally. External processing begins only when a provider tool or service is deliberately used.

06Local

Bounded diagnostics

Diagnostics remain project-scoped and local by default. The supported export is designed to exclude application credentials, raw prompts, project-file contents, local paths and free-form reasoning text. Provider-owned telemetry is only shown when that provider exposes reliable evidence. Missing data remains missing.

02

Scope

General boundaries

Current integrated product

Describes the currently supported local, provider and network trust boundaries.

Release-specific evidence

Desktop Preview rc.29

The published Preview remains independently qualified against its immutable release source.

Technical details

Every supported data path is documented in the repository.