
Privacy
Your passwords never leave your computer. Here is how that works.

An agent that controls your computer will sooner or later meet a login screen. The easy way out is to ask you to paste the password into the chat. Then it sits in a conversation log, travels to an AI provider and possibly into someone's training data. Auten does not do that.
Asked once, with hidden input
When a site needs a login that Auten does not have yet, it asks you once in your terminal, with hidden input, the same way sudo does. Nothing is typed into a chat window and nothing is shown on screen.
Stored on your machine
On a Mac the secret goes into your own Keychain. On Linux it goes into a private local vault that only your user can read. It is not uploaded to our servers, and it is never part of a skill Auten learns or shares.
Typed in locally
When the login is needed again, the runner on your computer fills it in by itself. The AI only knows that a password field was filled; it never receives the value.
Hidden even when it is on screen
Sometimes a secret is visible, for example an API key on a settings page. Before the screen contents reach the model, known secrets are replaced with a placeholder. The AI can still say copy that key into this field, and the runner does the copying locally.
What does leave your computer
To plan the next step, the AI needs a description of the screen: the names of buttons, fields and headings. That text is sent to the model for the current step and not stored on our servers. Your task history stays on your computer. When a skill is shared so other users can benefit from it, only the generic steps travel: which button, which field. The values you typed are removed first.
If you want the details, our privacy policy lists exactly what we collect and why.