> For the complete documentation index, see [llms.txt](https://docs.gotempest.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gotempest.app/accounts-vaults-and-privacy/how-tempest-protect-your-privacy.md).

# How Tempest Protects Your Privacy

Tempest's current privacy boundaries: encrypted vault contents, protected local account storage, server-visible metadata, Web Mode and AI data paths.

Tempest protects synced vault content with **end-to-end encryption**, and protects local account secrets with a host master key kept in the operating system's credential store where available. These layers protect different things: encrypted sync content from the sync service, and local secrets from someone who obtains application files without the necessary keys.

## What is encrypted

Vault document bodies contain your saved hosts, connection credentials, SSH key material and Tempest Drive content. They are encrypted before sync. Current v3 vaults use independent vault keys, wrapped for authorized account public keys; the account private key is encrypted under a key derived from your **Master Password** with Argon2id.

The sync service stores ciphertext and encrypted key envelopes. It does not receive the plaintext Master Password or vault key through this encryption flow. An authorized shared-vault member, however, is a recipient of the data and can decrypt it.

See [End-to-End Encryption](/accounts-vaults-and-privacy/end-to-end-encryption.md) for the algorithms and key-chain diagram.

## What the service can see

Encryption does not hide all metadata. Account identity/email, device/service metadata, vault and team membership, permissions, public keys, document IDs, revisions, payload sizes and timestamps can be visible to the services handling them. Current document creation/update timestamps are outside the encrypted document body.

The content guarantee applies to encrypted vault payloads, not every API field, support message, telemetry event or data you choose to send to another service. The sync service can also delete data or clean up old revisions. [Vault History](/accounts-vaults-and-privacy/vault-history.md) has no guaranteed retention on Tempest Cloud.

## Protection against local intrusion

It is too broad to say that Tempest offers no protection from any local intrusion. Copying encrypted vault files or sealed account files does **not** automatically reveal their contents when the keys remain inaccessible in the OS credential store.

It is equally too broad to call the app “malware-proof.” An attacker able to read an unlocked process, retrieve the credential-store key or control your user environment may access decrypted data. On a host without a usable keyring, the persistent `master.key` fallback is protected by file permissions; an attacker who can read that key and the encrypted files can unseal cached secrets.

Use OS disk encryption, keep the OS user secure, and protect backups. The [local threat scenarios](/accounts-vaults-and-privacy/end-to-end-encryption.md#protection-on-the-local-machine) explain exactly where protection can help and where it stops.

## Native apps versus Web Mode

Desktop, mobile, CLI and MCP use the local native vault host. Current **Web Mode** runs that vault host on the standalone backend machine. That backend is a trusted decryption endpoint: browser-session account isolation does not protect your data from the backend's administrator or a compromise of the host.

Do not confuse the web-mode session backend with a sync database that stores only encrypted payloads. See [Where Tempest Stores Your Credentials](/accounts-vaults-and-privacy/where-tempest-stores-credentials.md).

## AI and other destinations

When you give terminal output, documents or attachments to AI, the selected provider processes that information. A custom provider uses its configured endpoint; built-in hosted AI has its service data path. **Apple Intelligence On device** processes model requests locally, while **Cloud (PCC)** sends them to Apple's Private Cloud Compute. See [Storm AI](/ai-and-automation/tempest-ai-assistant.md).

Similarly, webhooks, email and other notification destinations receive data you configure Tempest to send. Vault encryption does not hide information from a destination that must process it. Review the provider/channel before sending sensitive content.

## Accounts and device cleanup

Accounts have separate endpoints, tokens, keys and vault files, but native accounts on one machine share its host master key. Multiple accounts are not separate OS security sandboxes.

**Sign out retains personal data locally**; it is not a device wipe. To discard an account's local data, use **Remove from this device**, and separately handle exports and backups. See [Accounts & Multiple Accounts](/accounts-vaults-and-privacy/accounts-and-vaults.md).

## See also

* [End-to-End Encryption](/accounts-vaults-and-privacy/end-to-end-encryption.md)
* [Local Credential Storage](/accounts-vaults-and-privacy/where-tempest-stores-credentials.md)
* [Passwords & Recovery](/accounts-vaults-and-privacy/resetting-password.md)
* [Vault History](/accounts-vaults-and-privacy/vault-history.md)
