Munu uses cloud AI models to think, hear and speak, so some things do leave your computer. This guide says exactly what, and where everything that stays is kept. For the legal policy, read the Munu privacy policy.
The short version
Stays on your computer
- While Munu sleeps, the microphone is checked for its name on this computer.
- The camera is watched live on this computer to track your hands. Nothing from it is recorded or saved.
- Your notes are plain Markdown files in a folder on your computer.
- Your keys and sign-in sit in the system keychain (Keychain on a Mac, Credential Manager on Windows).
- Logs never contain what you said or what Munu answered.
Leaves it, to do the job
- When it thinks it heard its name, about 1.5 seconds of audio may go through OpenRouter to double-check.
- During a conversation, your voice goes through OpenRouter to a speech model (Deepgram Nova-3 by default) to become text, and replies go to a voice model to be spoken.
- What you say or type, and the notes, files and screenshots it reads for you, go through OpenRouter to the AI models in your settings (by default from Google and Anthropic).
- When you ask Munu to look at something, one camera picture is sent the same way, for that one question.
- Web pages it looks up are fetched straight from your computer.
What leaves your computer, and why
- While it sleeps, the microphone is processed on this computer. When Munu thinks it heard its name, about 1.5 seconds of that audio may be sent through OpenRouter to double-check.
- While a conversation is open, what you say is sent through OpenRouter to a speech model (Deepgram Nova-3 unless you chose another) to become text. Munu’s replies are sent the same way to a voice model to be spoken.
- With your own Deepgram key (optional, in Settings > Voice), that audio goes straight to Deepgram instead. It hears you live, while you talk, and speaks with less delay. Audio is sent only while a conversation is open and someone is talking, plus the short name check. Remove the key and it goes back to how it was.
- Everything you say or type, and the notes, files and screenshots it reads for you, go through OpenRouter to the AI models in your settings. By default these are from Google and Anthropic. OpenRouter passes each request to the company that runs that model.
- When you ask it to look something up on the web, it searches through OpenRouter and fetches the pages it needs straight from your computer, so those websites see your internet address, as they would if you opened them yourself.
- Mail and calendar on a Mac. What it reads (senders, subjects, the start of each email, event titles and places) goes through OpenRouter to the AI models in your settings, like everything else you ask about. Email text is treated as untrusted: Munu is told not to follow instructions found inside it.
- When you ask it to look at something (“look at this”, “what am I holding”) with hand gestures on, one picture from the camera is sent through OpenRouter the same way, to answer that one question. The camera is otherwise only watched live, on this computer, to track your hands. Nothing from it is recorded, saved, or sent anywhere else.
Nothing else leaves the computer.
A safeguard after Munu reads your files
Once Munu has read your notes or files, or looked through the camera or at the screen, for a request, it stops fetching web pages and opening links or documents until your next request. That way a web page cannot trick it into sending what it read to another website. It can still search and open apps and folders. Background jobs follow the same rules and do not get the short memory summary. To combine notes and the web, ask for the web pages first, or in a separate request.
A note on hand tracking
Google’s MediaPipe library, which Munu uses for hand tracking, includes code that can send basic usage statistics to Google. We have not yet confirmed whether it does so in Munu. Munu itself has no analytics: it sends Moon Labs only what the account service needs to run your trial or plan and count your AI use.
Connected apps
Munu can use your Gmail, Google Calendar, GitHub, Slack and many other apps, on Windows and on a Mac, through Composio. Composio is a separate service (composio.dev) with its own free account. You sign in on Composio’s own page and choose which apps to connect there. Munu never sees your password.
- Reading is free. Anything that sends, deletes, creates or changes something (sending a mail, creating an event, posting in Slack) waits until Munu tells you exactly what it will do and you say “Munu confirm”.
- Composio is a third party. It sees your requests and the data of the apps you connect, for example your mail, under your own Composio account and its terms. What Munu reads from your apps then goes through OpenRouter to the AI models in your settings.
- Only the sign-in is stored. Munu keeps your Composio sign-in in the system keychain, never in the settings file or the logs. If you never connect, none of this happens.
- Disconnect any time. Settings > Account > Connected apps > Disconnect forgets the sign-in on this computer. Your apps stay connected inside your Composio account, so remove them, or delete the account, on composio.dev. Background jobs never use your connected apps.
Where your files live
| What | Mac | Windows |
|---|---|---|
| Settings, logs, state, models, workspace | ~/Library/Application Support/Munu | %LOCALAPPDATA%\Munu |
| Your keys and sign-ins | Keychain | Credential Manager |
| Your notes (the memory folder) | ~/Documents/<Assistant> Vault unless you chose another folder | The same, under Documents |
All of Munu’s keys and sign-ins sit together in one keychain item (“Munu”, account “secrets”). Munu reads it once when it starts, so a Mac that asks for your login password asks at most once per start. Keys are never written to your settings file or your logs.
Your notes
Munu keeps what it remembers in a folder of plain Markdown notes. You can open it with Obsidian or any text editor, and read or fix anything. It saves things you ask it to remember, corrections you make, decisions, open questions and the results of background jobs. It does not save every word you say as a note, and it refuses to write text that looks like a password or key. Every change is logged in Munu/Log.md.
The app only touches the Munu/ folder, plus its own notes under Knowledge/ and Decisions.md. Old claims are struck through, never silently erased. Nothing in Munu ever deletes your notes folder. To back it up, copy the folder or use whatever sync you already use.
Logs and recordings
- Logs never contain what you said or what Munu answered. Conversation history is kept only in the app’s own folder, not in your notes folder.
- Recording of your voice is off by default.
- Screenshots Munu takes to look at are kept in a temporary folder and cleaned up after a day.
- When Munu looks through the camera, the log only notes that one picture was sent, never what was in it.
Delete everything
- In Settings > Account, press Sign out. This also ends your sign-in on Munu’s server. If you connected your apps, press Disconnect under Connected apps first.
- Uninstall Munu. On a Mac, quit Munu from its menu in the menu bar, then drag it from Applications to the Trash. On Windows, open Settings > Apps > Installed apps, find Munu and choose Uninstall. This removes the program only.
- Delete Munu’s data folder:
~/Library/Application Support/Munuon a Mac, or%LOCALAPPDATA%\Munuon Windows. This removes your settings, logs, downloaded models and workspace. - Remove the saved entries named Munu from Keychain Access (Mac) or Credential Manager (Windows).
- Delete your notes folder by hand if you want it gone. It is yours, so Munu never deletes it.
Questions about your data? Read the Munu privacy policy, or write to munetic.studio@gmail.com.

