Field notes / 05 · Privacy in practice
Local AI Privacy: Trace Text, Voice and Image Routes
A chat window running on your computer does not tell you where its model runs. Map each feature’s destination before deciding whether the configuration fits your privacy needs.

Trace one request from start to finish
For each step, write the component name, where it runs, what it receives and where it stores results. Mark an unknown destination as unknown. A local text model with a cloud voice feature is a mixed configuration, so assess the voice route separately.
SillyTavern’s API connections documentation lists local and cloud backends. That makes the selected connection important: the name of the interface alone is not a privacy guarantee. This guide does not certify any particular installation.
A configuration worksheet that catches side routes
| Component | Record |
|---|---|
| Text generation | Endpoint host; local process or remote operator; request contents |
| Speech recognition | Where microphone audio goes; whether recordings are saved |
| Voice output | Which service receives the text to speak |
| Image features | Upload destination; prompt destination; saved outputs |
| Extensions / memory | Enabled components; search or embedding destinations; retained records |
| Storage / backup | Chat directory; exported files; device or cloud backup copies |
A limited offline check
- Record the current configuration and save your work. Use a fictional test conversation.
- Disconnect networking temporarily and start a new request. Test text, voice and images individually.
- Record which features respond and which fail. Restore networking when finished.
- Compare those observations with the configured endpoints and documentation.
A feature working offline shows that this observed operation could complete without a live connection at that moment. It does not prove that the application never contacts a server, that it cannot queue data for later, or that its backups stay local. A failed feature is also not proof of data collection: licensing, downloads or other dependencies can require connectivity. Treat the check as a clue to investigate, not a security audit.
Local control creates local responsibilities
Decide who can use the computer and who can read its files. Review device access, backups and any remote-access configuration. A locally saved chat may still be copied by a sync folder. Keep API keys out of screenshots and public configuration files.
Choose a setup you can maintain. A fully local workflow may require hardware, model downloads and troubleshooting; a remote service shifts processing to an operator whose rules you must inspect. Neither label resolves every risk. The useful outcome is a documented route that matches what you are willing to send.
Revisit the worksheet after changing a model connection or enabling voice, image or memory extensions. If your next concern is removing existing records, use the deletion plan for both local copies and external providers.
Make it practical
Keep your own record
Download the blank worksheet and fill it in privately. No account or upload is needed; nothing you write in the downloaded file is sent to this site.
Download worksheet · CSVScope: editorial guidance and official documentation checked on September 18, 2026. No in-app deletion tests or infrastructure audit were performed. Illustrative scenarios are fictional. Evidence method · Website privacy