Barside
Download
Barside/Privacy & data

Clear by design

Your space. Your data.

A practical guide to where your information lives in Barside 1.21.1.

At a glance

Where your information lives.

Stays on your PC

  • Notes, bookmarks, media and reminders
  • Tasks, templates, note links and the notes you import
  • Assistant memory and preferences
  • Agent jobs, the approval inbox and its history
  • Local AI: speech, assistant, agents, vision and the search index
  • Screen text, read by the text recognition built into Windows
  • Screen recordings, transcripts and saved webpages
  • Your theme and tab positions on this website, in your browser

Online only when you use it

  • Spaces: the profile, messages, files and poll votes you share, after you sign in
  • Share links: recordings you share, for 7 days
  • Voice rooms: direct connections that show your IP address to the room
  • Calendar feeds from Google or Microsoft, every 15 minutes
  • Research agent: searches on DuckDuckGo and the pages it reads
  • Leaked-password check: 5 characters of a hash, if you turn it on
  • The optional language model, downloaded once from Hugging Face
  • Cloud AI, if you add a Vercel AI Gateway key
  • MCP: the content a connected AI app asks for
  • Temporary web MCP links, through Cloudflare
  • Update checks to barside.space, which you can turn off

Kept apart

  • Passwords and two-step setup keys: encrypted by Windows, outside notes, backups, search and MCP
  • Clipboard history: off by default, encrypted, never in backups
  • Calendar addresses: encrypted on your PC
  • Saved API keys: encrypted and left out of backups
  • No analytics, advertising trackers or marketing cookies

You are in control

Settings that protect you.

Export and restore

Save your whole library to one ZIP. Restore checks the file before it changes anything.

Leave notes out of AI

Exclude a workspace or a note in Library → Sources.

Pause or revoke AI apps

Each MCP connection is read-only by default. Revoke it at any time.

Review memory

Edit or forget anything the assistant remembers, or turn memory off.

Quiet hours

Do not disturb, quiet hours and per-Space mute for Spaces notifications.

Invisible status

Appear offline to other Space members.

Wake-up is off

Barside listens for “Hey Barside” only after you turn it on.

Update settings

Turn off automatic update checks and downloads in Settings.

Approve agent actions

Nothing an agent proposes is sent or changed outside Barside until you approve it.

Clipboard history is off

Barside keeps what you copy only after you turn clipboard history on.

Remove share links

A share link works for 7 days. Remove it sooner at any time.

Erase your account

Ask support@barside.space to erase your Spaces data or export a Space.

The details

Feature by feature.

Notes live on your computer.

Barside stores notes, bookmarks, media, preferences, and assistant memory in your Windows user profile. Personal workspaces do not require an account. Barside does not automatically synchronize your personal library or add product analytics. Optional Spaces collaboration requires sign-in.

Notes and ordinary ZIP backups are not encrypted by Barside. Protect them with your computer's security controls and keep backups somewhere appropriate for their contents.

Tasks, templates and links

Tasks, templates, repeating notes, note links and the note map work from the notes on your PC. They are not uploaded.

Importing notes

When you import from Notion, Obsidian, Evernote, OneNote or other files, Barside reads the files on your PC. Nothing is uploaded. Imported notes become ordinary notes in your library, so they are included in your backups.

Screen text

Alt+Shift+S captures only the part of the screen you select. The text recognition built into Windows reads it on your PC; nothing is uploaded. A capture you add to a note becomes part of that note, and text in images inside your notes becomes searchable.

Clipboard history is off by default.

When you turn it on, Barside keeps the text and images you copy, encrypted on your PC. Clipboard history is never included in backups. It skips content that password managers mark as private, and it pauses while the screen is locked.

Delete items or turn clipboard history off at any time.

Calendar feeds come straight to your PC.

To connect Google Calendar or Outlook, you paste the calendar’s private iCal (ICS) address. Barside does not sign in to your Google or Microsoft account. The address is stored encrypted on your PC, and Barside downloads the calendar feed from Google or Microsoft every 15 minutes.

Events appear in your agenda, your daily briefing and meeting reminders. A meeting note is created only when you choose one. Anyone who has a private calendar address can read that calendar, so treat it like a password. Remove the calendar in Barside to stop the updates.

Provider policies: Google and Microsoft.

Spaces shares only what you choose.

In Barside 1.10 and later, Spaces uses Supabase to store account identifiers, verified email, your profile, Space membership, invitations, messages, shared notes, bookmarks, files, reactions, and moderation reports. Public Spaces are discoverable to signed-in Barside users; private Spaces require membership. Personal workspaces are not uploaded when you sign in.

Email sign-in codes are delivered through Resend. Google sign-in requests basic identity and email; it does not request access to Gmail, Drive, or Calendar. Session credentials are protected using Windows encryption and excluded from library backups. Signing out removes the local session and its online presence. Spaces also stores your chosen availability and per-session heartbeat timestamps to show member status. Invisible appears as Offline to other members; Do not disturb pauses Spaces notifications. These controls do not change access to shared content. Notification preferences are stored with your account and sync between computers; Windows quiet hours use each computer's local time; email quiet hours use the time zone saved by the last computer to save preferences. Profile photo selection creates a small square PNG and removes source metadata before upload. Your saved photo is available to you and unblocked members of an active Space you share. Removing it stops new requests from retrieving it, but cannot retract a copy someone already saved.

Email invitations can be sent to people who have not joined Barside. The address, sender, Space, expiry, and delivery status are stored privately. Only the verified recipient can accept. Resend delivers invitations and optional unread-activity emails; notification emails contain Space/sender information, not message bodies. Delivery records are retained for up to 30 days. Unsubscribe links retain a random token and hashed address so they continue working afterward. Email preferences, per-Space mute, quiet hours, and Do not disturb control delivery.

GIPHY is optional and disabled by default in each Space. When enabled, GIF search terms and normal connection information are sent directly to GIPHY; displayed GIFs load from GIPHY. Barside stores the selected GIF ID and dimensions, not a media copy. Removing a GIF at the provider can make it unavailable in chat. Emoji artwork is bundled locally and does not call a third-party service. GIPHY privacy policy.

Files attached to chat are uploaded when you press Send. Other members can download them. Image previews are generated locally. Sharing a note or bookmark creates a separate copy after a preview. Password-vault entries, saved API keys, assistant memory, and bookmark account labels are excluded. Sensitive information written directly in a note can still be shared, so review the preview. Members can download copies; removing a post or member cannot retract those copies.

Space data is protected by HTTPS and server membership controls, but is not end-to-end encrypted. Hosting administrators can access it. Shared content is not automatically sent to AI or exposed through MCP. Copies you explicitly save into your personal library follow that library's AI and MCP settings.

Removing a post clears its text and blocks future file access, but stored upload bytes remain until operator cleanup. Archiving retains a Space while preventing member access. Online Spaces are not included in your ordinary library ZIP. To request account erasure or a Space data export, contact support@barside.space.

Polls and member numbers

Polls and votes are stored in Spaces with the rest of the Space. Members can see who voted for each option. Owners and moderators see member numbers for their Space: members, new and active members, messages per day, and top contributors by name.

Space helper

The Space helper runs on the owner’s PC and uses the owner’s local AI. When a member asks a question, the owner’s Barside answers using only what the Space has shared, plus one of the owner’s workspaces if the owner adds it. Anything in that workspace can then appear in replies that members read, so choose it with care.

Replies are marked Auto-reply. In Ask me first mode, each draft waits in the owner’s approval inbox. Questions it cannot answer go to the owner. The helper runs only while the owner’s Barside is running.

Provider policies: Supabase, Resend, and Google.

Voice rooms connect people directly.

A voice room connects up to 6 people directly, peer to peer, so the audio goes between the people in the room. Barside does not record voice rooms.

A direct connection needs IP addresses. The people in the room and a public connection helper (Google’s STUN server) can see your IP address. If you do not want that, do not join voice rooms.

You choose when to use AI.

Local AI features use models on your computer after setup. If you select a cloud API provider, relevant requests, tool results, memories, and requested screenshots may be sent to that provider. Its data policies apply.

Memory is optional and can be reviewed or removed. It learns from assistant interactions; it does not passively read all your apps, messages, or browsing history.

Agents ask before they act.

Scheduled agents, the meeting agent, the research agent and saved workflows run in Barside on your PC. Every action they propose waits in the approval inbox; nothing is sent or changed outside Barside until you approve it. Agent jobs, the approval inbox and its history are stored on your PC and are not included in backups.

Agents use the AI you chose: the local model on your PC by default. If you choose your AI Gateway model, an agent’s instructions and the notes, transcripts or pages it works with go through Vercel to that model.

The meeting agent works from a call transcript. Approving its recap email opens a draft in your email app; Barside never sends it. The research agent sends your search terms to DuckDuckGo, reads up to 5 of the pages it finds, and saves copies of them with its summary note. DuckDuckGo and those websites receive normal connection information, such as your IP address.

Provider policy: DuckDuckGo.

MCP connections have boundaries.

Each connection can access only the workspaces you select, subject to individual note exclusions. New notes in selected workspaces are included unless excluded. Connections are read-only by default, with optional write permissions.

MCP tools do not expose the password vault, saved API credentials, media attachments, assistant memory, or desktop controls. Note text, transcripts, bookmark URLs, and optional account labels can still be sensitive.

Temporary web connections route through Cloudflare. The selected AI provider processes the content it requests. Revocation stops future access; it cannot withdraw copies already received by a provider.

Passwords are stored separately.

The native login vault uses Windows encryption for your Windows account and stays outside your note library and normal ZIP exports. This does not protect against malicious software already running as that same Windows user.

Moving passwords to another computer requires the vault's separate encrypted export and a backup password. Login filling is available for supported browser forms and does not automatically submit them.

Two-step login codes are made on your PC from the setup key you add, by scanning a QR code on screen or pasting the key. Setup keys are kept in the same encrypted vault as your passwords.

The leaked-password check is optional. When it is on, Barside sends only the first 5 characters of a hash of each password to Have I Been Pwned and compares the reply on your PC. Your passwords never leave the PC. Reused-password warnings are worked out on your PC too. Have I Been Pwned privacy policy.

Recording and screen context are explicit features.

Call transcription can capture microphone and computer audio. Saved recordings and transcripts become note attachments and content. Computer audio can include other apps, so tell participants before recording and check what is playing.

Transcripts label lines You (your microphone) and Others (computer audio). Transcripts in languages other than English use an optional 141 MB speech model, downloaded once from Hugging Face. Speech is still transcribed on your PC. If you turn on the webcam bubble, your camera image becomes part of the recording.

Screen context captures the requested window or monitor. Voice wake-up is optional; it is not speaker identification and cannot guarantee zero false activations.

This website and downloads.

barside.space is hosted on Vercel. Installer files are delivered by Vercel Blob. These services process connection information needed to deliver the website and downloads, such as IP addresses and request details.

Shared recording pages on barside.space play the video from Barside’s Spaces storage (Supabase).

This site does not add advertising trackers, analytics scripts, signup forms, or marketing cookies. Fonts, icons and the 3D background are served from barside.space itself. Your theme choice and tab positions are stored only in your browser.

Infrastructure providers have their own policies: Vercel privacy policy and Cloudflare privacy policy.

Export, remove, or disconnect.

Manage notes and workspaces in Barside. Export your library in Settings. Manage memories in Assistant settings, logins in Passwords, and MCP access in Connect Barside to AI. Remove share links, calendars and clipboard items in Barside where you added them. Old backups retain the content they contained when created.

This page describes the current product's behavior. Last updated September 24, 2026.