Security & privacy
Trusted with your code.
Local-first execution, no keys to manage, conversations stored on your machine, and every change approved by you. Here's exactly how Mel handles keys, code, and access.
How it works
Transparent by design.
Where keys live
Hosted-plan provider keys are held server-side on the Mel relay — the app ships with none. If you bring your own key, it stays on your device, in the OS keychain, and is only used in-flight.
What leaves your machine
Agent tools — read, edit, run — execute locally. Only the context a given model call needs is sent to the relay, which calls the provider.
Where your data lives
Conversations and history are stored locally under your home directory. Mel is local-first by default.
You approve changes
Writes, edits, and commands round-trip an approval card — or you opt into autonomous A⁺ mode explicitly.
Built to be open
The terminal and relay are built to be readable and auditable — we plan to open the source so you can read every line and build it yourself.
Get started
Built to be trusted with your code.
The free Mel terminal runs local-first today. The AI agent is free to start — hosted keys stay server-side, your own keys stay on your device, and every change is yours to approve.