Privacy
Local first. Cloud when you choose it.
Last updated 2026-07-13
What Neroli sees
Neroli reads repositories, Git history, agent conversations, settings, and browser state on your Mac so it can run the workspace you see. It does not upload a local worktree unless you explicitly move that session to the cloud. A session created directly in cloud starts from the repository and branch configured for that workspace instead. Local browser profiles do not move to Neroli Cloud.
Local agent traffic
When you dispatch Claude, Codex, or OpenCode locally, it talks to its own provider over the network using your credentials. Neroli coordinates the pane and worktree. It is not a proxy for local provider requests.
Neroli Cloud
Saving or testing a cloud environment sends its setup command, network policy, and environment variables to Neroli Cloud. Values marked as secret are encrypted at rest and masked when returned to the app.
Moving a session uploads the state needed to continue on a hosted cloud machine. This includes repository changes, allowed untracked files, supported pane layout, provider conversations, and the required provider configuration and resume state.
Cloud sessions do not use or transfer the provider login from your Mac. You connect a separate subscription login or API key for cloud use. Neroli encrypts that credential at rest and provides it to the selected provider when a cloud session starts. A personal credential belongs to your account. A team credential is available to people using that workspace's cloud sessions.
The provider then receives agent requests directly from the cloud session. Neroli does not proxy those requests. Disconnecting a cloud credential deletes Neroli's stored copy but does not revoke it at the provider.
Git-ignored files and local browser profiles do not move. Cloud browser state is separate from local browser state and stays inside the cloud environment where it was created.
Product analytics
Neroli sends allow-listed product events through the Neroli backend to Mixpanel. These events use a random installation ID and, when you are signed in, your Neroli account ID. They can include app version, provider and model, session location, product actions, and aggregated token counts.
Product analytics do not include prompts, source files, repository or branch names, file paths, transcripts, or command output.
Diagnostics and crashes
Production builds use Sentry for crash reports, error diagnostics, performance traces, and sampled profiling. Sentry is configured not to send default personally identifiable information. Reports can include stack traces, app and OS metadata, timing information, and cloud session error details.
Neroli does not currently provide an in-app switch to disable product analytics or production diagnostics.
This website
The marketing site does not set analytics cookies or load a client-side analytics tracker. Its hosting provider may process ordinary request information, such as IP address and user agent, to deliver and protect the site.
Questions
Email privacy@neroli.app with any privacy question.