Using AI work memory on a company computer: a local-first privacy checklist
Screen and keyboard history can be useful and sensitive. Here is how to evaluate local storage, capture controls, model routing, and deletion before recording work.
この記事を日本語で読む →
A useful memory can contain sensitive work
A chat transcript rarely tells the whole story of a task. Screen content, browser research, app use, typed input, and agent conversations can show how a decision was reached. They can also include private messages, credentials, customer information, or unpublished work.
That tension deserves a concrete set of controls. On a company computer, check your organization's policy before enabling capture, and decide which apps, sites, and signals should stay outside the record.
Know where the history lives
Contextberg stores recorded work history and generated Memory on the computer. That includes captured screens, typed input, browser history, and agent history when their recording options are enabled. The Record view lets you inspect the source material that later feeds Remember, Memory, and Chat.
Local storage is a starting boundary, not a claim that nothing can ever leave the device. The route you choose for AI processing determines whether selected context is sent to an external provider. Account, subscription, usage-limit, and operational metadata can also remain in Contextberg's cloud systems; the privacy policy describes those categories.
Set the capture boundary before the memory is made
A sensitive window should be excluded before its content becomes Activity or a report. Contextberg provides recording controls for supported signals, including options to pause capture or turn off recording methods. Review those settings against the actual apps and websites you use at work.
| Area | Decision |
|---|---|
| Apps and sites | Which workspaces, domains, or personal apps must not be captured? |
| Signals | Do you need screenshots, typed input, browser history, and agent history for this task? |
| Timing | When should recording be paused or resumed? |
| Inspection | Where will you review what Record actually saved? |
| Deletion | How will you remove data if the capture scope was too broad? |
Reviewing the Record timeline after a short trial session is a practical way to validate the settings. A policy written on a settings screen matters only if the resulting record matches it.
Choose the processing route deliberately
| Route | Processing boundary |
|---|---|
| Local model, such as LM Studio | Model execution stays on the computer when the relevant AI features are configured to use that local route. |
| Your own supported provider credentials | The selected context goes to that provider under its terms and your configuration. |
| Contextberg Cloud | Selected context passes through Contextberg's relay to Google Cloud Vertex AI for model execution. |
For Contextberg Cloud, Contextberg does not store the prompt or response text on its own servers. That is different from promising that a provider never retains data. Google documents circumstances in which prompts or responses may be held temporarily for abuse monitoring or other features. Read the provider's current terms before using a cloud route for sensitive work.
If external model processing is not allowed for a project, choose a local model for the relevant features and verify that each enabled feature uses that route. Local model quality and speed will depend on the model and your computer.
Keep review and deletion in the workflow
Recording controls are not a one-time checklist. Inspect the Record and Memory views periodically, especially after adding a new app, changing projects, or switching model routes. If something was recorded that should not have been, use the available deletion controls and check whether a generated memory or report also needs attention.
The right question for a workplace rollout is not simply whether the app is local-first. It is whether people can tell what was captured, where selected context is processed, and how to stop and correct the flow when the scope is wrong.