Your work happens here.
Your knowledge stays yours.
ArchHub is a desktop application. Your projects, your brain, and your skills live on your machine. The cloud is opt-in for collaboration and billing — and even then it holds references, never resolved secrets.
Runs on your machine
The canvas, the graph, and your files never leave your desktop unless you wire an output that says so. No silent uploads.
Bring your own key
Point ArchHub at your own model provider — or a local Ollama. We never see your prompts, your drawings, or your bill. When you ask the composer about your canvas, the labels and values of the nodes you selected go to the provider you chose, and nowhere else.
Open by license
MIT desktop client, auditable connectors. If you can't read what a node does, it doesn't belong on your canvas.
References travel. Secrets don't.
- ⌂On your machinebrain.db (skills + facts), .speckle/ commits (project state), and 1Password / Windows Credential Manager references to your API keys.
- ☁On the cloud (Fly.io), opt-inIdentity, plan tier, firm membership, billing state, and a per-user brain replica synced via CRDT — references only, no PII bodies.
- ⊘Never on the cloudResolved API keys, project drawings, and full chat transcripts (unless you opt in to telemetry).
{ "local": ["brain.db", ".speckle/", "key refs"], "cloud": ["identity", "plan", "brain replica · refs only"], "never": ["resolved keys", "drawings", "transcripts"], "delete": "Settings → Account · one button" }
Honest answers, in the repo.
The full statement lives in TRUST_CENTER.md and CAIQ_LITE.md in the source tree — copy-paste them straight into a vendor security review.
- ⌦One-button deleteGDPR delete is one operation in Settings → Account: your cloud brain replica is purged immediately and your auth tokens are invalidated.
- ◷Local-first by defaultNothing syncs to the cloud unless you sign in and opt in. The app is fully usable with no account at all.