← marigold

Privacy

The short version: it runs on your Mac and keeps almost nothing.

Marigold watches what’s on your screen so it can offer a hand when something’s genuinely useful. That only works if you can trust where the watching goes. So the design starts from keeping as little as possible.

What stays on your Mac

Everything, by default. Reading the screen, deciding whether to speak, and writing the answer all happen on-device using Apple Intelligence. Nothing about your screen is sent anywhere as part of normal use.

What it stores

One thing: a local log of the decisions it made — that it considered a moment, and whether it spoke, stayed quiet, or you dismissed it. The log lives in a database on your Mac and never leaves it. It exists so Marigold’s sense of when to speak can improve over time.

It does not store:

Where it refuses to look

In a password manager, a banking app, or private messaging, Marigold goes completely blind — no screen capture, no reading, no model call at all. It simply isn’t watching in those places.

It also stops watching while you type, and never reads anything you can’t already see yourself.

The cloud

By default, Marigold never uses the cloud. On the rare occasion a task is too large for the on-device model, it can ask to send that one piece of context to a cloud model — but only after showing you what it wants to send and the reason, and only if you say yes that time. There is no background sync, no account, and no telemetry.

Your controls

In one line

Marigold has no servers to hold your data, because it was built not to need them.

Last updated June 2026. Marigold is open source under the MIT License.