When you opt in, Datum sends only the fields named in that tool's consent notice to a managed AI API. Passwords, encryption keys, and unrelated vault files never leave your device.
Every AI turn in Datum shows a compact Receipt: what left the device, what stayed local, and that you decide before anything is saved as proof.
Choose what AI may remember
One reply remembers nothing. This conversation keeps context until the tab closes. Remembered notes stay on your device until you erase them. Every tool asks before data leaves your device.
Guidance modes (Off / Minimal / On) live in Account and the shell. Off hides Coach AI invites and the Coach thread.
What each tool may send
- Skill review: Text excerpts from locally decrypted vault files you choose to analyze · only after consent.
- Coach: Text you enter, plus optional role and company fields. Each result names the fields it received.
- Money guidance: Numbers from your calculator (cash, burn, severance, unemployment) · only after consent.
- Practice mentor: The active exercise, your question, help mode, and up to 5,000 characters of the current practice draft · only after explicit consent for that response. Vault files are never included.
What never leaves
- Master password or derived vault encryption keys
- Full vault ciphertext blobs (unless you explicitly export them yourself)
- Baseline contents as plaintext without your consent action
- Practice drafts when you do not consent to a mentor response
Resume stays human-written
Proof helps you choose evidence from your vault. You write every bullet. Datum does not rewrite your whole resume into generic AI copy.
When AI is unavailable
Coach calls a managed model API only after consent. If AI is unavailable or you decline, deterministic guidance and saved local data remain usable. Datum identifies built-in guidance when it is not an AI response.