What stays on your machine
What Salidium keeps, where it keeps it, and what it runs in your repository.
The daemon, the event store, the report and the interface never leave your machine. There is no account, no telemetry and no hosted service.
- State lives in
~/.salidium, or whereverSALIDIUM_HOMEpoints. Environment lists the rest. - The daemon listens only on
127.0.0.1, by default on port47822. - Every request for your data carries a token, regenerated each time it starts.
- The directories it creates are readable only by you, and it repairs their permissions on every start.
- Optional saved personalization terms live separately in
personalization.json; Delete saved terms removes the file.
Local operations
Ingest & Storage and salidium status read the same versioned local operations state. Queue and store values are exact when safely observable and explicitly unavailable when a bounded scan cannot establish a total. Queue velocity, drain rate, storage growth, and time to empty are labelled estimates and appear only after enough exact samples exist.
- Local policy records whether each value came from a shipped default, the stored file, or an environment override.
- Alerts cover queue age and growth, storage size, collection gaps, daemon health, maintenance failure, and hook-trust changes. Acknowledgement lasts until recovery.
- Native notifications are separately opt-in because previews may appear on a lock screen. They contain minimized alert metadata, no session content or filesystem paths, and delivery depends on the operating system.
salidium doctor --bundle --dry-runpreviews a diagnostic manifest. Writing the bundle is a CLI-only action; it excludes raw events, transcripts, prompts, commands and output, tokens, secrets, and identifying paths.
Your repository
When a turn ends, when a session starts, and after the agent commits, for a live session inside a git repository, Salidium runs four read-only commands to record where the work sat.
git rev-parse --show-toplevelgit rev-parse HEADgit rev-parse --abbrev-ref HEADgit status --porcelain=v2 --untracked-files=normal
Nothing is written, and SALIDIUM_NO_GIT=1 switches it off.
Redaction
Credential-shaped strings are redacted, and files on paths that hold credentials have their contents withheld. Both happen when an event is ingested rather than when it is shown. So what Salidium suppresses is suppressed everywhere: in what it shows you, and in the packet an explanation is written from.
How much was redacted is counted without exposing the matched value.