Skip to content
Download

Data and network

This technical guide complements the public Privacy Policy and Terms of Service.

CLIO runs on the computer or server you connect to. Your sessions, files, memory, and results are stored on that machine. Whether data leaves it depends on the model provider, connected sources, and tools you choose. With a remote CLIO installation, uploads go to that server even when the interface is in your local browser.

  • The CLIO backend listens on 127.0.0.1 (port 17800 when started by the clio command), so other computers cannot reach it by default.
  • Sessions, messages, memory, and artifacts are stored in your user configuration folder and in each workspace’s .clio folder.
  • The desktop app, web page, and terminal UI all talk to that local backend.

CLIO does not include a product-usage telemetry or analytics service. Configured providers and tools still receive requests, and the installation can retain diagnostic and provenance records.

What When Where it goes
Prompts, files you attach, and tool results sent to the model Every model call Only the provider you chose. With a local provider such as LM Studio or Ollama, this stays on your machine.
Requests made by tools and tool servers When you add a tool or tool server that uses the network Whatever that tool contacts
Update check by the clio command About once a day, on macOS and Linux PyPI, to see whether a newer clio-agent exists
Model information catalog When CLIO needs model limits, cached for 24 hours models.dev
Update check by the desktop app When the app checks for updates GitHub releases

Choosing a cloud provider means the content of your conversations is sent to that provider under its own terms. Choose a provider on your machine if that is not acceptable for your data.

Set CLIO_NO_UPDATE_CHECK=1 in your environment to stop the clio command from checking PyPI.

Terminal window
export CLIO_NO_UPDATE_CHECK=1

The desktop app checks GitHub releases for its own updates. That check is separate from the variable above.

The agent’s file tools can only use certain folders. By default these are the workspace folder, the folder CLIO was started in, and your system’s temp folder. A path outside them fails with outside_allowed_roots. Symbolic links are not followed unless you turn that on, and there is a maximum file size.

Change these with CLIO_ALLOWED_ROOTS, CLIO_ALLOW_SYMLINKS, and CLIO_MAX_FILE_SIZE_BYTES. See Configuration. For what the agent may write or run, and the optional OS-level write fence, see Permissions and sandbox.

The backend refuses cross-site browser requests it cannot trust. Pages served by the backend itself, the desktop app, and local development servers work without any setup. A browser app on any other origin must be allowed explicitly with CLIO_GACT_CORS_ORIGINS, a comma-separated list:

Terminal window
export CLIO_GACT_CORS_ORIGINS=http://localhost:4173,tauri://localhost

Requests addressed to a host name other than localhost, 127.0.0.1, or [::1] are refused unless you list the name in CLIO_GACT_ALLOWED_HOSTS. This protects against a web page that points its own domain at your machine.