Palmer
Security & privacy

Palmer works on your machine, so the boundaries are yours.

An agent with your files and your shell has to earn trust step by step. Here is exactly what Palmer can reach, what it asks for, and what leaves your computer.

How access works

Files stay in the folders you choose

Every task has a working folder, plus any folders you add on purpose. Reads, edits, shell commands, and previews are authorized against those roots and nothing else.

Actions ask before they change things

Commands that write, install, or reach the network stop for an approval you can allow or deny. You can trust a task for routine steps; destructive ones always ask.

Browsing happens where you can see it

Palmer browses in a visible panel on your machine. Mini-apps get web or site access only after you accept a prompt naming the app and the site.

Helpers can only do less

When Palmer delegates to a subagent, the helper inherits at most the parent's tools and folders, never more, and its shell runs inside the operating system's sandbox.

The server relays, it does not hoard

Palmer's API relays model requests and records usage metadata (model, tokens, credits). Prompt and response content is not retained unless a bounded diagnostic audit is switched on, which expires after 30 days.

Payments never touch our servers

Checkout, cards, invoices, and refunds run on Stripe. Palmer stores your Stripe customer and subscription ids, not card numbers.

What data goes where

Palmer is local-first. The list below is everything the service handles on your behalf.

On your device
Tasks, conversations, activity logs, mini-apps, and the files they touch live on your Mac or PC in Palmer's local database and your working folders.
Account
Email, name, and photo from Google sign-in or the one-time email code; your organization, its members and roles. Authentication is handled by Firebase Auth.
Model relay
The context a task sends to a model passes through Palmer's API to the model provider. Palmer records model, token counts, and credits charged; content is not stored by default.
Web search
Search queries a task issues are sent to the search provider and returned as cited sources.
Product analytics
Named product actions (a screen viewed, a task created) from the signed-in desktop, without message content or file contents, in Palmer's own pipeline. No third-party analytics vendor.
Crash reports
Crash and error diagnostics from the desktop app so we can fix defects. Bug reports you send include only what the report screen shows you.
Billing
Plan, seats, credit balances, and a ledger of grants, debits, purchases, and refunds. Card details stay with Stripe.

Controls you have

Revoke, per scope

Folder grants, mini-app permissions, paired remote browsers, and trusted tasks are each listed in Settings and revocable individually.

Owners decide for the org

Owners and admins manage members, roles, model access groups, API keys, and billing. Members see only their own balance.

An activity log for every task

Each run shows the files read, sites visited, commands run, and approvals given, so you can audit what happened after the fact.

Cancel any time

Stop a run from the desktop or the web. Cancel a plan from Manage billing; access continues to the end of the paid period.

Reporting a security issue

Found a vulnerability or something that looks wrong? Email support@askpalmer.app with the steps to reproduce. We read every report and will tell you what we did about it.