What leaves this Mac, and when
This page is the complete list of what Vixlo sends anywhere, and when: what goes automatically, and what goes only if you turn something on. Read it before you sign in, save an API key or flip a switch that mentions a network.
The sign-in card says it first
Use the email and password of your Vixlo account. Your photographs never leave this Mac; the account only licenses the app, and Vixlo checks it once a day. That sentence sits under the card's title, and it is the whole rule for the account.
What the account sends
The account talks to Vixlo's own site, and only at these moments. Every request, whichever row, also names the app's version and macOS's.
| When | What goes |
|---|---|
| Signing in, once per Mac | Your email and password, the Mac's name, an id made from the Mac's hardware (a scrambled form, never the hardware number itself). The password is sent once, over an encrypted connection, and never stored here. |
| The licence check, when one is due — a day after the last, or when the last answer has run out. The app looks at launch, on wake and daily while running; Refresh in Settings checks at once. | The sign-in token this Mac was given and this Mac's id. The answer says what your account allows and until when. |
| Your answers, once, right after a sign-in | The same token and Mac id, to fetch the three things you answered in the browser when you signed up. Three short strings come back. |
| Sign out | The token, so the site can end this Mac's session. |
No photograph, file name, library contents, decision or edit ever leaves the Mac through the account. If the site cannot be reached, nothing changes: the last answer stands, and Settings ends its status line with Last check: and the reason. Your account in the app covers the account's states and working offline.
What the account keeps between launches lives in this Mac's own Keychain, marked never to travel to another Mac.
What stays on this Mac, always
- Faces, places and search. People are found with Apple's on-device Vision framework and grouped on this Mac. GPS is read off the original files and clustered here, with place names from a table inside the app unless you turn on the switch below. What each frame is of, and the search index, are computed here and kept in the library folder.
- Measurements, proposals and what Vixlo learns. Everything proposals rest on is numbers in the library folder (A library is a folder), and what Vixlo learns from your decisions is a log of numbers in Vixlo's own folder, never handed to any provider (What stays on your Mac).
- Models. Vixlo ▸ Models… opens a sheet headed Models on this Mac, which begins Vixlo ships no model weights. and promises nothing about your photographs has left this Mac, then or since. Every model it lists runs on this Mac.
- Export and hand off. Each writes to a folder you choose on this Mac, and refuses a folder on a card or any drive you can eject, an external SSD included.
The Models sheet lists and removes models but cannot add one. Face models explains.
Two things that send something only when you set them up
Both stay off until you act, and neither ever sends a photograph.
Precise place names
On the Library rules sheet, and in an open library's places section under Change…, is a switch: Name places precisely, using Apple's service. Its sentence: Sends the centre of each place — a coordinate, nothing else — to Apple's geocoder over the network. Off, names come from the table inside the app and nothing leaves this Mac.
On, Vixlo sends one coordinate per place and per journey's destination, never one per frame, once, and keeps the answer in the library folder. The switch is per library and starts off.
The assistant on the edit page
Ask for an adjustment… on the edit page can send your request to a model. Settings is where that is set up, under the heading Where Vixlo looks for AI, and what it is allowed to send off this Mac.
- Ollama, a model you run yourself, is used first whenever it answers with a model that can do the job. At its usual address,
http://localhost:11434, it runs on this Mac. The address is a field in Settings: point it at another computer and what the assistant sends goes there. - Anthropic is the one cloud route in this build, used only with a key you saved, Ollama not answering, and Local only off. Keys for OpenAI and Google can be saved, but nothing in this build sends anything to either.
- Local only turns the cloud routes off: with it on, a saved key is ignored, and the page says Cloud providers are disabled app-wide. Nothing leaves this Mac. It does not govern Ollama, and it has no hold on Precise place names or the licence check.
That sentence is not true when the Ollama address points at another computer: Local only does not touch the Ollama route, so what the assistant sends goes to that computer with the switch on or off. The field's header still reads via Ollama · and the model's name in quiet ink, and its hover text says Sentences on this page are answered by Ollama on this Mac. Keep the address at localhost to keep your sentences here.
Whichever route answers, the request is the same: your sentence; the frame's file name; the name of its look or film simulation, if it has one; the current values of its exposure, contrast, highlights, shadows, temperature, tint, saturation and vibrance sliders, and whether they apply to the whole frame, the subject or the background; and the list of adjustments Vixlo is willing to make. No other slider, and never the photograph — no pixels, no file, no thumbnail.
The field's header names the route the next sentence will take: via Ollama · qwen2.5:14b, or via Anthropic · claude-sonnet-5 in warning ink, because that one leaves your Mac.
Every key you save goes into the macOS Keychain, never into a file or a library folder. Settings shows only its last four characters, as Stored key ends in •••• 9f2a. Where keys and sign-in details are kept covers it.
Doors that open your browser
Some buttons open a page in your browser — Account page, Create an account, the darktable install link under Max quality. They hand your browser a web address and nothing about a library.