Your data
BOARDROOM is a local application. It reads only what you explicitly authorize and writes new files instead of changing your originals.
Where data lives
Section titled “Where data lives”| Platform | Default data directory |
|---|---|
| Windows | %LOCALAPPDATA%\Boardroom |
| macOS | ~/Library/Application Support/Boardroom |
| Linux | $XDG_DATA_HOME/boardroom, or ~/.local/share/boardroom |
Data stays outside the application directory. Every command accepts --data-dir to choose another location.
What the current build does
Section titled “What the current build does”- Sources need your consent. A document is read only after you authorize that file with
--allow-source. - Citations point to exact revisions. Each saved citation references a SHA-256 identified snapshot. Editing the original does not change it; inspection warns when the original has changed or disappeared.
- Exports never overwrite. Each export creates a new directory with a plan and a decision memo, and records receipts with the hashes of the files it wrote.
- History is inspectable.
historylists saved events and export outcomes; use--projectfor your live project and--jsonfor structured output. - Recorded playback stays local. It makes no model or cloud calls. The application sends no telemetry.
- Live calls are explicit. Authorized phases send selected text and phase inputs to configured OpenAI and Anthropic APIs. Later phases also send the relevant saved analyses, proposals and objections. The providers process and bill those requests.
- Keys stay separate. Credentials use the host vault or explicit process-local injection. Shareable configuration omits credential references; live exports omit original source paths and redact known keys and token patterns.
Limits worth knowing
Section titled “Limits worth knowing”Local files and SQLite databases are readable by the machine owner. Hashes identify revisions; they do not protect against a malicious machine owner. Saved source paths may reveal local directory names.
Read exports before sharing: filtering known credentials does not remove every unrelated secret that might occur in source text. See the credential guide and live exports.
Was this page helpful? Tell us on GitHub