# Privacy and safety Normal diagnostics are local. Agent Assistance is enabled by default but creates a short-lived redacted packet only after the user requests preparation; the user then explicitly launches the configured Omarchy agent and a remote provider may be used. The evidence JSON never includes process names, full command lines, environments, paths, host/network identity, PCI addresses, or serials. The foreground handoff necessarily names the local session instructions path, which may reveal the XDG state location to the selected agent/provider. Responses are digest-bound and advisory-only; no LLM output can authorize actions. Powercap filesystem paths, helper PIDs, usernames, and the completion-marker path are not copied into the evidence packet. The foreground prompt does contain the absolute local XDG session path because the selected agent needs a concrete file to open; this is disclosed before launch and is not claimed to be redacted. The marker is a local notification only; changing it does not make an assistant response trusted. The response still passes session, inode, expiry, digest, size, schema, and allowlist validation. The backend never accepts arbitrary shell fragments, paths, PCI addresses, sysfs writes, process controls, privilege escalation, package installation, reboot, or driver/boot changes. The only backend action currently eligible for guarded automation is an advertised `powerprofilesctl` profile, and it is typed, re-discovered, verified, audited, and rollback-capable. Bluetooth is manual/recommend-only.