Privacy
The short version: it runs on your Mac and keeps almost nothing.
Marigold watches what’s on your screen so it can offer a hand when something’s genuinely useful. That only works if you can trust where the watching goes. So the design starts from keeping as little as possible.
What stays on your Mac
Everything, by default. Reading the screen, deciding whether to speak, and writing the answer all happen on-device using Apple Intelligence. Nothing about your screen is sent anywhere as part of normal use.
What it stores
One thing: a local log of the decisions it made — that it considered a moment, and whether it spoke, stayed quiet, or you dismissed it. The log lives in a database on your Mac and never leaves it. It exists so Marigold’s sense of when to speak can improve over time.
It does not store:
- Screenshots or recordings of your screen.
- The text it read from your screen.
- Your keystrokes, clipboard, or browsing history.
Where it refuses to look
In a password manager, a banking app, or private messaging, Marigold goes completely blind — no screen capture, no reading, no model call at all. It simply isn’t watching in those places.
It also stops watching while you type, and never reads anything you can’t already see yourself.
The cloud
By default, Marigold never uses the cloud. On the rare occasion a task is too large for the on-device model, it can ask to send that one piece of context to a cloud model — but only after showing you what it wants to send and the reason, and only if you say yes that time. There is no background sync, no account, and no telemetry.
Your controls
- Pause or quit anytime from the menu bar. When paused, it watches nothing.
- Inspect the log. Reveal the decision database on disk whenever you like.
- Delete it. The log is a file. Remove it and the history is gone.
In one line
Marigold has no servers to hold your data, because it was built not to need them.
Last updated June 2026. Marigold is open source under the MIT License.