Data and network
This technical guide complements the public Privacy Policy and Terms of Service.
CLIO runs on the computer or server you connect to. Your sessions, files, memory, and results are stored on that machine. Whether data leaves it depends on the model provider, connected sources, and tools you choose. With a remote CLIO installation, uploads go to that server even when the interface is in your local browser.
What runs locally
Section titled “What runs locally”- The CLIO backend listens on
127.0.0.1(port 17800 when started by thecliocommand), so other computers cannot reach it by default. - Sessions, messages, memory, and artifacts are stored in your user configuration folder and in each workspace’s
.cliofolder. - The desktop app, web page, and terminal UI all talk to that local backend.
CLIO does not include a product-usage telemetry or analytics service. Configured providers and tools still receive requests, and the installation can retain diagnostic and provenance records.
What can leave your machine
Section titled “What can leave your machine”| What | When | Where it goes |
|---|---|---|
| Prompts, files you attach, and tool results sent to the model | Every model call | Only the provider you chose. With a local provider such as LM Studio or Ollama, this stays on your machine. |
| Requests made by tools and tool servers | When you add a tool or tool server that uses the network | Whatever that tool contacts |
Update check by the clio command |
About once a day, on macOS and Linux | PyPI, to see whether a newer clio-agent exists |
| Model information catalog | When CLIO needs model limits, cached for 24 hours | models.dev |
| Update check by the desktop app | When the app checks for updates | GitHub releases |
Choosing a cloud provider means the content of your conversations is sent to that provider under its own terms. Choose a provider on your machine if that is not acceptable for your data.
Turn off update checks
Section titled “Turn off update checks”Set CLIO_NO_UPDATE_CHECK=1 in your environment to stop the clio command from checking PyPI.
export CLIO_NO_UPDATE_CHECK=1The desktop app checks GitHub releases for its own updates. That check is separate from the variable above.
File access limits
Section titled “File access limits”The agent’s file tools can only use certain folders. By default these are the workspace folder, the folder CLIO was started in, and your system’s temp folder. A path outside them fails with outside_allowed_roots. Symbolic links are not followed unless you turn that on, and there is a maximum file size.
Change these with CLIO_ALLOWED_ROOTS, CLIO_ALLOW_SYMLINKS, and CLIO_MAX_FILE_SIZE_BYTES. See Configuration. For what the agent may write or run, and the optional OS-level write fence, see Permissions and sandbox.
Browsers and other origins
Section titled “Browsers and other origins”The backend refuses cross-site browser requests it cannot trust. Pages served by the backend itself, the desktop app, and local development servers work without any setup. A browser app on any other origin must be allowed explicitly with CLIO_GACT_CORS_ORIGINS, a comma-separated list:
export CLIO_GACT_CORS_ORIGINS=http://localhost:4173,tauri://localhostRequests addressed to a host name other than localhost, 127.0.0.1, or [::1] are refused unless you list the name in CLIO_GACT_ALLOWED_HOSTS. This protects against a web page that points its own domain at your machine.