Privacy and security
The model runs on your computer: your questions, your documents and your email are not sent to an AI service.
ConnectionsWhere data isProtectionsTips
The only connections the app makes
The app has no accounts and sends no usage statistics. It connects to the internet only to:
| What | Where to | When |
|---|---|---|
| Browse the Models page | Hugging Face, only to read the public catalog: nothing about your chats is sent | When the app starts (at most every 12 hours) and when you search the Models page |
| Download a model | Hugging Face, where the models are published | When you choose Download and start |
| Download the CUDA engine | The project's servers | When you choose it, once |
| Your email provider's servers | When the chat or agents use an account you linked | |
| Find email servers | DNS (only the domain name of the address) | When you type an address with an unrecognized domain |
| Remote MCP servers | The addresses you add | When an agent uses them, with confirmation |
Once model and engine are downloaded, the chat and agents also work offline.
Where data is
On Windows, in %LOCALAPPDATA%\HotMoE (in Settings: Open the data folder).
| File or folder | Content |
|---|---|
settings.json | The settings. Deleting it, the app starts again from first launch. |
app.db | Chat history, agent conversations and the action log. |
agents\ | One file per agent, readable and shareable. It also holds the copies of changed or deleted files, for undo. |
chat\ | The chat's access and the attachments saved when the chat has no granted folders. |
mail-accounts.json | Email accounts: address and servers, without passwords. |
secrets\ | Email passwords and sign-ins, encrypted with your user's Windows protection. |
models\, engine\ | Downloaded models and the CUDA engine. |
To remove everything, just close the app and delete the folder.
With memory on, the notes the chat saves about you are in app.db too: you see and delete them in
Settings › Memory.
Protections on files, commands and email
- Granted folders: the chat and agents see only the folders you grant, and the check holds against paths and links trying to get out. Details.
- Confirmations: replacing, moving and deleting files, running commands, using external tools and sending email ask for your permission. Full table.
- Log and undo: every action is logged, denied ones too; files can be restored, and undo stops if the file changed in the meantime.
- Commands: only for those who enabled them; each is shown to you first; they stop after 2 minutes and close with the app.
- Email: encrypted passwords, always-encrypted connections, sending never allowed forever, email content never treated as instructions. Details.
- Local engine: the model's engine listens only on your computer, with a random key that changes at every start, and closes together with the app.
Tips
- Grant specific folders (a project, a documents folder), not the whole disk or your user folder.
- Use Always allow only for agents you trust and for actions that can be undone; revoke it when no longer needed.
- Only add MCP servers from reliable sources: they run with your permissions.
- Reread the message, and correct it if needed, before confirming an email send: a sent email can't be undone.
HotMoE is a Virsion project. This guide describes the app as it is today: what is still on the way is marked as such.