Skip to content
Make it yours

Permissions and privacy

Follow what an agent can access and where task information is processed.

In this topic

Mellow can run models and agents on your Mac, connect to cloud models, call external tools, pair devices, and submit work to a Cloud workspace. Each path has a different boundary. Choose the features and connections a task needs, then check the corresponding permissions.

“Local model” describes where inference runs. It does not mean a task cannot access the network: search, messaging, remote tools, and cloud delegation can still transmit information.

Map a task before running it

PathInformation involvedMain controls
Local inferenceConversation and supplied context on the MacAgent capabilities, local storage, model selection
Remote inferencePrompt and selected context sent to the providerProvider settings, Privacy Filter, account permissions
External toolArguments sent to a tool service; results returnedService credentials, tool policy, resource permissions
Paired deviceRequests and results exchanged with the hostPairing identity, access grant, Secure Channel
Cloud taskExplicit task and supplied context sent to the workspaceWorkspace role, selected agent, task submission
Channel messageContent delivered to a messaging serviceAllowed conversations, destination policy, Outbox

A user instruction can authorize a task, but text found inside a webpage, file, or incoming message should not be treated as new authority to change permissions or send information elsewhere.

Set a practical starting posture

Enable only the capabilities needed by each agent. Keep consequential operations reviewable while you evaluate a new workflow. Use a named working folder where a task needs files and inspect generated changes before publishing or sharing them.

For network clients, use scoped grants with recognizable labels and expiry. Review paired devices and saved services periodically. Revoke grants for retired clients rather than only deleting their shortcuts or closing their windows.

In macOS Privacy & Security, grant Accessibility, Screen Recording, Automation, and other permissions only for features you intend to use. Mellow's agent setting and the operating-system permission are independent checks.

Protect data on disk

The normal local data root is ~/.mellow/. Databases default to plaintext SQLite; FileVault is the operating-system disk-encryption layer. Optional SQLCipher encryption changes the database protection and introduces a storage-key dependency. Not every configuration or index file becomes encrypted when that option is enabled.

Backups have their own security properties. A plaintext export deliberately contains readable data even if the live database is encrypted. Store it accordingly. See Storage and recovery for conversion, recovery, and limitations.

Understand remote privacy

The Privacy Filter can replace detected sensitive text before supported remote model requests. It is an experimental text-protection layer, not a universal network firewall or proof that every attachment is anonymous. Review the proposed redactions and the destination provider.

Secure Channel protects supported peer requests between devices. It does not extend automatically to unrelated provider calls. A regular HTTPS public-link client has a different trust boundary from a Mellow peer using encrypted inner requests.

Cloud workspace access is scoped by the server and signed-in account. Signing in does not authorize a cloud agent to copy arbitrary local history or files. Supply only the context the task requires.

Inspect activity without exposing it again

Insights and operation feeds help explain requests, tools, approvals, and failures. Depending on logging configuration, local diagnostics can include sensitive context. Review exports before attaching them to an issue, and prefer the smallest reproducer that shows the failure.

Usage analytics and crash reporting have separate controls from local activity logging. Turning one off does not necessarily change the others. See Diagnostics and telemetry.

Handle uncertain results

A timeout after a write, send, or submission can leave the outcome unknown. Check the target system before retrying. Stopping a task prevents future work but does not automatically undo an action already committed.

If credentials may have been exposed, revoke the affected grant at its issuing service and replace it where needed. If a host identity changes unexpectedly, verify the host before accepting a new pairing. Do not erase local databases as a first response to an authentication error.

Report a security concern

Use the private security contact or reporting flow published by the Mellow project. Include the affected version, a minimal reproduction, the boundary crossed, and the expected behavior. Remove credentials and private content from the report; arrange a protected channel if sensitive evidence is necessary.

This reference describes controls in the application, not a guarantee that all deployments, providers, plugins, or user-authored workflows have identical security properties. Review the configuration used for the task in front of you.

Continue exploring · Make it yoursFiltering sensitive text →Configure outbound filtering and understand what the filter can and cannot cover.