Security

Built so every app can only do what you say it can.

Ion is early software, provided without warranty, and self-hosting means you are the administrator. Apps are isolated from each other, you grant every permission yourself, and you can audit what happened. Anything connected to the internet carries some risk, including this.

Where your data lives

Stored on your computer. It goes to your AI provider only when you ask, or when an app you’ve allowed uses your AI in the background.

Every app in its own container

Every app runs in its own container with only the access you grant it. An app can’t reach your other apps’ data unless you allow the connection.

Permissions and the read log

Apps ask for exactly what they want to read, like phone permissions. You approve each one at install, can revoke any time, and every read is logged.

Your AI and your credentials

You sign in on Anthropic’s or OpenAI’s own page. Ion runs their own unmodified agents and never sees, stores or reuses your credentials.

Background AI is visible per app and can be switched off per app.

What guests can see

Guests sign in with a one-time code and see only the app you shared. The invite tells them the app runs on your computer and that you can see what they store in it.

How your devices reach your computer

Private mode connects just you and your devices over Tailscale, encrypted end to end between your devices and your computer.

Shareable mode adds a private, access-controlled link for the people you invite. That traffic passes through Cloudflare on its way to your computer, so Cloudflare’s network handles it in between.

Compare the two ways to connect →

Read the code

The apps are open source (MIT). The Hub is source-available: you can read and run it, but not host and resell it.

Backups

At launch, Ion takes nightly local snapshots and every app can export its data. Keep a copy somewhere else; off-site backup isn’t built yet.

Report a security issue

Found something? Email security@useion.ai.

Security questions

Does Ion include AI?

No. Ion runs Claude Code or Codex on your own machine, signed in with your own plan or API key. Your usage comes from your own plan and is subject to its limits. That includes background use by apps you’ve allowed.

Does my AI run in the background?

Only for apps you allow. Some apps, like Pipeline, can use your AI in the background. You can see which ones do and switch it off for any app. Background use counts toward your plan’s limits.

Where is my data stored?

On your own computer. It goes to your AI provider only when you ask, or when an app you’ve allowed uses your AI in the background.

Is this against Anthropic’s or OpenAI’s terms?

Ion runs their own unmodified agents on your machine, and you sign in with your own plan on their own page. Ion never handles your AI credentials.

All questions about your AI and your data →

Get early access.

Invite-only, released in small waves. Free during early access.

Get early access.

Invite-only, released in small waves. Free during early access.