Research / Technology explained

Private AI on a Mac: follow the data through four places

The word “local” can describe where a model runs, where a database lives, or both. A four-part map makes those differences visible.

By KluroResearch through 28 September 2026Published 2026-09-29

The app is on your Mac. Its icon sits in the Dock. Its window looks native. None of those observations tells you where the next answer will be computed.

A privacy comparison becomes much clearer when you follow one piece of information through four places: where it is collected, where it is saved, where it is processed, and what remains elsewhere afterward. “Local” may apply to one of those steps without describing the others.

We reviewed Apple’s architecture documentation, Queue’s sync explanation and Kluro’s own published data-flow explanation. The result is a worksheet for reading privacy claims more precisely. It is not an independent security audit of any of the products.

Boundary one: the source

Begin with the material the app is allowed to read. A calendar connection, a local message database and an uploaded document have different boundaries. The right question is specific: which account, folder or source does this permission cover?

Write down one example: a meeting invitation, an email exchange or a note. Then ask whether the app reads it once, polls for changes, or keeps a continuing connection. This is a useful evaluation question even when the product’s answer is simple.

Do not treat a familiar operating-system permission dialog as a complete description of downstream use. Permission to obtain information and the subsequent handling of that information are separate decisions.

Boundary two: the saved copy

A product can save a database locally and synchronize a different artifact elsewhere. A short summary is still information about a conversation, even when it omits the original wording.

Queue’s documentation offers a concrete example. It says message and email content is analyzed on the Mac with Apple’s on-device models; conversation summaries are stored in private iCloud, while activity metadata such as participants and timestamps reaches Queue’s servers. That is a more informative description than simply saying that everything is on-device. [1]

The point is not that synchronization is inherently wrong. It is that a reader should know what is being synchronized. “Audio never leaves” would not answer a question about transcripts. “The transcript stays here” would not answer a question about derived summaries.

Boundary three: inference

Ask where the model performs the operation. It may run on the device, use a remote service, or choose between them.

Apple’s Private Cloud Compute documentation explicitly distinguishes on-device processing from requests handled in its cloud architecture. Its stated PCC requirements include using personal data for the request and not retaining it after processing. Those guarantees concern the documented PCC system; they do not automatically apply to every third-party Mac app or model provider. [2] [3]

Kluro’s explanation makes a different distinction: saved relationship memory is encrypted on the Mac, while enabled hosted AI processes relevant content for answers and background understanding. Local saved memory therefore should not be read as a promise that every inference occurs on the device. [4]

Neither description supplies a universal winner. Someone may prioritize offline operation; another may accept a documented processing service for a particular task. The comparison becomes possible once the execution path is explicit.

Boundary four: the material left behind

The remaining questions concern service logs, retained inputs, saved outputs, training use and deletion. These are separate fields in our worksheet because one reassuring answer cannot stand in for all of them.

A no-training statement does not, by itself, specify a retention period. A short retention period does not establish who can access the material while it exists. A deletion action in the app does not automatically describe every backup’s lifecycle.

Treat those as questions to resolve in the product’s documentation. Where an answer is missing, mark it unknown rather than supplying the most favorable interpretation. For a sensitive source, that may be reason to leave it disconnected until you have an answer.

Boundary The question to ask Evidence to look for
Collection What exactly can this connection read? Source scope and permission explanation
Storage and sync Which originals, summaries or metadata persist, and where? Storage architecture and sync description
Inference Which operations run locally or remotely? Model/processing documentation for the selected feature
After processing What is retained, reused or deleted? Retention, training and deletion terms

A small test before connecting a large history

Choose a non-sensitive sample you are entitled to use. Record the source, make one request, and inspect the resulting artifacts. Does the summary appear on another device? Is there an export? Can you disconnect the source and find the relevant removal control?

This exercise tests usability and exposes questions. It is not proof of a service’s internal security or a substitute for an audit. Avoid drawing conclusions from a network icon or a successful offline request alone: one working feature does not describe every feature.

The same worksheet is useful when plans or settings change. A product can add a cloud-backed capability without changing its desktop shell. Revisit the row affected by the new feature rather than assuming the earlier answer still covers everything.

For meeting tools, distinguish the audio, transcript and summary before applying the worksheet. Our meeting-notes data-flow review follows that path. For relationship history, Kluro’s AI explanation identifies its own storage and processing boundary.

Scope of this review

The four-boundary worksheet is Kluro’s editorial framework. The product examples reflect first-party documentation checked as of 28 September 2026, not independently inspected servers or measured breach risk. We do not rank encryption implementations, infer regional legal compliance, or claim that a native interface establishes privacy.

The practical result is a question you can answer: for this source and this task, do I understand where my information goes?

Sources

  1. Queue sync and data flow — Queue. Living documentation. Checked against the 28 September 2026 research cutoff.
  2. Private Cloud Compute core requirements — Apple Security Research. Living documentation. Checked against the 28 September 2026 research cutoff.
  3. Private Cloud Compute — Apple Security Research. 2024-06-10. Checked against the 28 September 2026 research cutoff.
  4. How Kluro uses AI — Kluro. Living documentation. Checked against the 28 September 2026 research cutoff.