AI & privacy

How to choose a private AI workspace

Private AI is not a badge. It is a set of choices about where your working data lives, what you intentionally send, which provider receives it, and who decides whether a suggestion becomes work.

Most AI note-taking promises start with what the model can do. A better starting point is the data boundary: what happens before you ask for help, what gets sent after you ask, and whether output has the power to alter your work without review.

Keep ordinary work separate from AI requests

A privacy-conscious workspace remains useful when AI is off. Opening a page, searching notes, arranging a board, or writing a daily entry should not create a provider request. When you choose an action such as summarize, continue writing, or organize an inbox item, that is the moment to show what will leave the device and to which configured provider.

Know the processing path

Cloud subscriptions and API keys send requested context to their providers under those providers’ terms. A local model keeps processing on the machine but asks more of the computer and its operator. A third option is to use no AI for sensitive material. A responsible tool lets you choose instead of making a hidden default.

Mind Marshal works without an AI provider. When you choose to configure one, it supports existing ChatGPT, Claude, or Kimi subscriptions, supported API keys, and local Ollama. Choosing Ollama keeps configured AI processing on your own computer, Mac or PC. Read the detailed privacy policy before connecting a service.

Require review before changes become real

Suggestions are useful. Silent edits are risky. A good AI workflow gives you the source context, proposed result, and a clear approve, reject, or undo path. This matters for writing, task organization, and any automated project workflow where a plausible response can still be wrong.

Mind Marshal’s configured workflows can run manually, on an interval, or when a card enters a stage. Their output lands as a proposal until you approve or reject it, and the activity view makes the workflow inspectable. A daily agent-call ceiling helps put a practical boundary around provider use and cost.

Approval gates matter for security as well as accuracy: text an AI reads can carry instructions aimed at the model rather than at you. The prompt injection field guide explains that attack class, the verified incidents, and how to judge any AI app’s defenses.

Use a pre-flight checklist

  1. Is this note safe to send to the selected provider?
  2. Which provider or local model will process it?
  3. What exact action am I asking for?
  4. Can I review the result before it changes a page, card, or plan?
  5. How can I undo or correct a bad result?

Private does not mean isolated

Privacy-aware AI can still be useful for summaries, a first draft, project planning, and focused organization. The goal is not to avoid assistance. It is to retain the human decision point around it.

Choose deliberately

Try AI only after the workspace is useful without it.

Mind Marshal keeps the core workspace local and makes AI an optional, configured choice.