
Littlebird is safe by every standard that can be audited, with one fact you should know before the rest: the memory it builds is encrypted and stored in the AWS cloud, not on your device. It isn't a screen recorder: no video, no screenshots, no keystroke logging. It never trains models on your data and never sells it. It's SOC 2 certified. You can pause it, exclude apps, and delete everything. Below, the eight questions people ask, each answered in its first sentence.
The app runs on your computer. The memory it builds is encrypted and stored in the AWS cloud, in the US East region. That's the accurate one-line frame, and it leads because a tool that watches your work doesn't get to be vague here. Anything you read elsewhere claiming the data never leaves your machine is wrong. In transit and at rest the encryption is AES-256, every connection uses TLS 1.3, and keys are managed with AWS KMS.
No. Littlebird is not a screen recorder: it doesn't record video of your screen, doesn't take screenshots, and doesn't log your keystrokes. What it does is read the text and elements of the active window through the macOS accessibility permissions you grant. Capture runs every few seconds on the window you're working in and builds a private, encrypted index of recent activity, which is how the assistant already knows the doc, the thread, or the ticket when you ask about it later. During a meeting, whichever app it's in, Littlebird listens along on your computer to transcribe and summarize, and no bot joins the call. The mechanism in more detail is in What does Littlebird actually see?
It's designed not to. Password fields are ignored by design, password managers such as 1Password, Bitwarden, and LastPass are auto-detected and excluded by default, and credit-card numbers and API keys are auto-redacted before anything is stored. One honest limit: designed to ignore password fields is not the same as guaranteed never to see a secret. Plain text visible elsewhere on screen can still enter context, so add the apps and sites where that matters to your exclusions. Adult content is excluded by default already.
Yes. Littlebird is SOC 2 certified, which means its security controls are independently audited by a third party. Alongside it: GDPR-aligned and CCPA-aligned data handling, and infrastructure and controls that are regularly audited and tested by third-party security firms. HIPAA is conditional. It requires accepting a Business Associate Agreement in-app (Settings > Data Controls) and enabling HIPAA, and protected health information shouldn't be entered until that's in effect. One precision note, because the difference matters legally: SOC 2 is the certification; GDPR, CCPA, and HIPAA describe how data is handled, not certificates. The formal documentation lives at trust.littlebird.ai.
No, and neither do the model providers underneath it. Neither Littlebird nor its underlying LLM providers use your data to train models. Littlebird never sells your data either, and data is used only in ways you explicitly approve. The business is the subscription you can see on the pricing page, so the customers are the users, not advertisers.
All of it, on your terms. Nothing is collected without your permission: on Mac the app needs the accessibility permissions you grant, and you decide whether it runs at startup. Pause context collection for 5, 15, 30, or 60 minutes, or until the next launch, from the status button in the app or the menu-bar icon. Exclude specific apps, specific website domains, or whole categories: Banking, Social Media, Shopping, Entertainment, and Health. Delete the last hour, the last day, or everything, and deleting your account removes the memory with it.
Yes, and the facts are public. Littlebird raised an $11M seed round in March 2026 and launched on Product Hunt the same month. Its security posture is documented at trust.littlebird.ai, its plans are on the pricing page, and the Basic plan is free, so you can test the pause, the exclusions, and the delete controls yourself before paying anything.
People who require local-only systems, honestly. For individual and consumer users the product is cloud-based, and while the team is working to bring more processing local, cloud storage may be disqualifying if your threat model or your contracts demand that data never leave the machine. Self-hosted deployments exist at the Enterprise tier. If that isn't available to you, a genuinely local tool is the right call, and we'd rather say so here than have you find out after installing.
Yes. Encrypted at rest and in transit, SOC 2 certified, GDPR-aligned and CCPA-aligned data handling, delete anytime.
Cloud, on AWS (US East), encrypted. The app runs on your computer and you control what it sees.
No. It's not a screen recorder and not a keylogger. It reads the text and elements of the active window through accessibility permissions you grant, and during meetings it listens along on your computer with no bot joining the call.
No and no. Neither Littlebird nor its LLM providers train on your data. Our customers are our users, not advertisers.
Yes. Delete the last hour, the last day, or all of it, anytime, and deleting your account removes the memory with it.
Not on individual plans yet. Self-hosting is available at the Enterprise tier. If local-only is a hard requirement, Littlebird may not be the right fit today.
The trust page you actually wanted is the honest one.
Read the full posture at the Trust Center, then try the free plan knowing exactly what you agreed to.
Product and security facts come from our maintained internal fact base, which records the capture and privacy statements as verified against Littlebird's public support documentation, and from littlebird.ai/privacy. Re-checked September 24, 2026.