# What leaves your machine when you use Canopy?

> A plain-language map of local workspace data, coding CLI traffic, optional GitHub and team services, remote tunnels, and on-device dictation.

Canonical HTML: https://canopyide.dev/use-cases/what-leaves-your-machine-when-using-canopy
Article date: 2026-09-28

Local-first describes Canopy's workspace state. It does not mean a coding agent never contacts its model provider. The right privacy question is which component sends what, and when you enable that component.

## Workspace state stays local by default

The public Canopy README says projects, workspace state, notes, research, session context, and search indexes stay on your machine. No Canopy account is required, and the app says it has no telemetry. Those are properties of Canopy-owned data, not a blanket statement about every tool you run inside it.

## Installed agent CLIs have their own network behavior

Claude Code, Codex, OpenCode, and other installed CLIs run in Canopy's real terminals. They use their own accounts, model providers, settings, and network services. If you ask one to read a repository and send context to a hosted model, that provider's terms and configuration govern the transfer. Inspect the CLI and provider you choose; Canopy does not make hosted inference local merely by wrapping the terminal.

## Optional integrations cross their own boundaries

Connecting GitHub or Linear uses those services for the relevant repository or ticket work. Canopy Remote is off by default and, when enabled, exposes a PIN-protected interface to your running host. LAN access stays on your network; optional public access can traverse a selected Cloudflare, ngrok, or Tailscale tunnel. Stop or rotate Remote access after use because the current PIN grants access to its permitted surface.

## Team relay is an explicit collaboration path

A host can invite teammates to share project chat, files, and review requests. LAN sessions connect directly; Internet sessions can use an optional tunnel. The app documents end-to-end encryption for team payloads and says the shared file owner remains the only disk writer. Team relay is not a way to share model-provider credentials or subscriptions.

## Dictation has a different boundary

On supported systems, Canopy's dictation models and transcription run on the device. The resulting text can be inserted into an agent prompt; sending that prompt through a hosted CLI then follows that CLI's network behavior. Intel macOS builds do not include the dictation feature. Check platform and release notes before treating voice as available everywhere.

## The website has a separate privacy boundary

The Canopy desktop app's no-telemetry statement does not describe canopyide.dev. The public website uses analytics, third-party fonts, and ordinary hosting logs, as its privacy policy explains. The session-cost calculator disables website analytics on that page and calculates from your entries in the browser. Do not put private prompts or repository content into public web forms unless their handling is clear.

## A practical privacy check

List the CLIs, integrations, and tunnels enabled for the project. Confirm which accounts each CLI uses and where its model runs. Review Remote and Team state when sharing a screen or repository. For sensitive work, verify the provider's data handling and your organization's policy before sending code to an agent.

## Frequently asked questions

### Does local-first mean all AI inference runs offline?

No. Canopy's own workspace data is local by default, while installed agent CLIs may contact their model providers.

### Is Canopy Remote always exposed to the internet?

No. Remote is off by default; optional public access requires enabling Remote and a chosen tunnel.

## Sources and further reading

- [Canopy app README: privacy and security boundaries](https://github.com/FluidWorksApp/canopy-ide/blob/main/README.md)
- [Canopy security policy](https://github.com/FluidWorksApp/canopy-ide/blob/main/SECURITY.md)
- [Canopy website privacy policy](https://canopyide.dev/privacy)

## Related Canopy pages

- [Can Canopy work offline with a local coding agent?](https://canopyide.dev/use-cases/canopy-offline-local-coding-agent-workflow.md)
- [Share agent work with a team without sharing AI accounts](https://canopyide.dev/use-cases/share-agent-work-with-a-team.md)
- [My coding agent committed an API key. What now?](https://canopyide.dev/guides/coding-agent-committed-api-key-to-github.md)
- [Resume a local coding agent from your phone](https://canopyide.dev/use-cases/resume-coding-agent-from-phone.md)
- [Can I use voice with a coding agent in Canopy?](https://canopyide.dev/use-cases/voice-dictation-for-coding-agents.md)

Canopy runs installed coding CLIs; CLI accounts, model selection, and provider billing remain separate. Check the installed release before relying on version-specific behavior.
