DocsReference
Privacy & data
Where data lives, how sessions and API keys are encrypted (AES-GCM, DPAPI / Secret Service), and what goes online.
| Windows | Linux | macOS | |
|---|---|---|---|
| Data folder | %APPDATA%\Hover | ~/.local/share/Hover | ~/Library/Application Support/Hover |
| Sessions | agents/, encrypted with AES-GCM | ||
| API keys | secrets.dat, sealed with the same key, never in plain text | ||
| The key | Protected by DPAPI | The Secret Service (GNOME Keyring, KWallet, KeePassXC), else a file only you can read | The login Keychain |
If the key isn’t available, a key you type in is kept only until Hover quits.
What goes online
There is no account, server or analytics. Hover itself goes online only for the things you switch on:
- the Cursor and Claude Code quotas, once every five minutes each;
- the Phonon download, if you choose local speech;
- Groq, if you choose cloud speech;
- the cleanup service, if you add one;
- Kiro Web, if you send a Kiro task there: the task runs in Kiro’s cloud and clones the GitHub repository you pick;
- the list of your Kiro Web sessions in history, fetched from Kiro each time history opens.
The Kiro quota runs kiro-cli /usage on your PC, and the Codex quota reads Codex’s own logs. Neither needs Hover to go online.
Voice data
Cloud speech sends the audio to Groq. Local speech keeps recognition on your computer. Cleanup only ever gets the text, never the audio. The recording is deleted once it has been turned into text. A screenshot you ask for by voice is sent with the task to the agent you picked.
The agents
Agents run as hidden child processes in the folder you choose, in a job tied to Hover, so a quit or crash leaves none behind. OpenCode’s server listens on 127.0.0.1 only, with a password made for each start. Each agent stops after 5 or 15 idle minutes and starts again when you reply.
Checkpoints
Checkpoints are copies of the files in your project folder (what its .gitignore leaves out is not copied), kept in a Git store in the data folder. Unlike sessions they are not encrypted, just as your files aren’t. Deleting a session deletes its checkpoints.
Other tools you switch on
On a Mac and on Linux the sandbox keeps agents to their folders. Computer use gives agents the right to see and operate your apps. On a Mac the agent browser talks to each agent over a Unix socket only you can use, with a token made for each start. GitHub CLI setup and Create pull request run gh and git on your computer and push to the remote you pick.