Security & privacy

Your data, your rules.

Zero telemetry, keys in Windows’ own vault, and an agent that asks before it acts.

Your data

Only where you send it.

Each line below exists only when you choose it. With a local model, your prompts never leave your computer.

What leaves your computer when you use AlelyonOn the left, what stays on your computer. On the right, five services you can choose to use, each with the one kind of thing that goes to it. No line exists until you turn the service on.Your computerStays hereYour files and foldersLocal models (llama.cpp)Conversations and projectsThe research archiveKeys, in Credential ManagerCaptions and transcriptsModel services you chooseYour prompt and the files you add · OpenRouter, Hugging Face, Groq and others, with your keyClaude Code and CodexWhat the agent sends on your plan · Anthropic and OpenAI, on your own accountsResearch sourcesYour search terms · OpenAlex and arXivAlelyon sign-in and friendsYour account, friends and messages · Alelyon’s identity serviceAlelyon hosted previewYour prompt, through the gateway · Alelyon’s model service
Nothing on the right is reached until you turn it on: a provider key, a sign-in, a search, a friend. The sign-in screen only asks whether Alelyon’s sign-in service is up. The app sends no analytics.

The one request the app makes on its own: the sign-in screen asks Alelyon’s sign-in service whether it is up and which ways to sign in are on. It carries no account details.

Built in

Eight guardrails, built in.

  • Review every change

    Keep or undo the agent’s edits by part, by file or all at once.

  • Approve before it acts

    Commands, tools, posts and purchases ask you first.

  • One-key stop

    Ctrl+Alt+End stops every running turn, from any program.

  • Works offline

    Local models, your files, the IDE and saved research.

  • Zero telemetry

    No usage analytics, no tracking.

  • Keys in Windows

    API keys live in Windows Credential Manager.

  • Sealed sessions

    “Stay signed in” is sealed to your Windows user.

  • Nothing types for you

    A model never types in your terminal or presses Save.

Approvals

What asks you first

A command the agent wants to run
Every time, unless you always allowed that exact command.
A tool from an MCP server
The server starts only once you enable it; each call asks unless you always allowed that tool.
A change to your files
Waits in review until you keep it, by part, by file or all.
Posting, messaging, buying, deleting
In the agent’s browser and in auto mode: a card in the chat, then a confirmation.
A purchase, payment, sign-in or account change
Still asks in auto mode. The agent never types a password or card details.
Images to a model off your computer
Every time: the app cannot check a picture for passwords or keys.

What the agent never does

  • It never type into your terminal, your editor, or press Save.
  • It never act on Alelyon itself, a password manager or Windows’ sign-in prompts.
  • It never run a plugin’s hooks.
  • It never start an MCP server you have not enabled.
  • It never open this computer or its network in the agent’s browser.
  • It never send usage analytics or telemetry.

Ctrl+Alt+End stops every running turn at once, from any program.

Auto mode

Auto mode, on your terms.

Off until you say so

Only the app’s own confirmation turns it on. Until then the agent sees no screen.

What it does alone

In Agent mode it sees your screen, uses the mouse and keyboard, and posts, sends, edits and deletes without asking.

What still asks

Purchases, payments, sign-ins, security and account changes. It never types a password, and one key stops it.

Accounts and sessions

GitHub, Google, Hugging Face or LinkedIn, or a QR code from a phone that is already signed in. Provider sign-ins open in your own browser, never the agent’s. “Stay signed in” is sealed to your Windows user; “Use offline” skips accounts.

Friends and messages

Found by exact username, never by email. Messages are stored on Alelyon’s server in plain text, not end-to-end encrypted; the service logs no token, search or message text.

Builds you can check

Each release lists its files with sizes and SHA-256 digests from its own manifest, and says whether it is code-signed.

Download and verify

This website

No third-party scripts and no analytics: the content-security policy allows this site’s own scripts only. Web chats and pasted keys live in the tab and are gone when you leave.

Report a vulnerability

Write to the security contact named in the Privacy Notice. A person reads it. Please do not test against other people’s accounts.

Privacy Notice
Choose your beta

One build. Two tiers.

The Windows build downloads with no sign-in, no LinkedIn and no key. Which tier you are in is decided when the app signs in: without a beta key you run everything locally, and a key — issued automatically to a signed-in, LinkedIn-verified account — is what adds Alelyon’s hosted DQC-OS.

Open beta

Run the app without a beta key.

There is one build, and this is the same one the closed beta uses — the tiers differ at sign-in, not at download. Sign in without a beta key and you get the local tier: Terminal UI, Lattice workspace, local calculator, and visible tool traces. A beta key is what adds hosted DQC-OS issuance.

  • Local-first Windows interface
  • Open Alelyon toolkit and source
  • No hosted backend entitlement
The build is not being served yetOpen source toolkit
Closed beta

Verify identity with LinkedIn to unlock hosted DQC-OS.

LinkedIn OpenID Connect verifies control of the LinkedIn account; Alelyon does not scrape your profile. It records a verified access request, and when you verify from your signed-in account page, your hosted DQC-OS key is issued automatically — no review, no queue, nobody to wait for. It does not create or sign you into an Alelyon account, and an anonymous verification issues no key: the key needs a signed-in account to attach to.

  • Everything in the open beta
  • Hosted deterministic DQC-OS calculations, unlocked by your key
  • Signed envelopes and certified answer paths

Signing up uses Alelyon’s own email-and-password account flow, which is separate from LinkedIn verification below. One Alelyon account signs you in to every Alelyon application, and it keeps working until you delete it. Verifying with LinkedIn comes next and links that identity to this account.

Verify with LinkedIn

Verify from your signed-in account page and your hosted DQC-OS key is issued automatically — it appears on that page the moment verification completes. Copy it into a password manager and enter it when Alelyon Terminal asks during sign-in; if it expires, opening your account page issues a fresh one.

Available now

Ask, and a person reads it.

Prefer to talk to someone first, or need access sooner than the self-serve paths allow? Ask directly.

Nothing about access waits on a person. The build downloads with no sign-in and no key; a hosted DQC-OS key is issued automatically when a signed-in account verifies with LinkedIn, and it appears on that account’s page. This address is for everything else — questions, problems, deletion requests, and anything a page cannot answer. It is read by a person, so no response time is promised.

Do not include credentials, account numbers, API keys, or position data in the message.