An internal report may be well suited to a summary. At the same time it holds details the recipient has no business seeing. Before an AI processes it, someone has to decide: which part may go where? That decision belongs to the people responsible for the information. A product has to show them what is at stake beforehand.
More than a location
A company’s registered office tells you little about what happens to data in its software. Even a locally developed product can send information to external services. Respect for privacy has to show up in the product: clear permissions, understandable settings and processes people can follow. An address is no substitute for that work.
When we talk about data sovereignty, we mean practical questions. Which data is needed at all? Where is it stored and processed? Who may see it? How long does it stay? Can it be corrected, exported or deleted? The answers differ by application. What matters is that people can find them.
For one person that might mean seeing which passage is selected before sending. For a company, responsibilities and approvals matter more. Between two programs it takes clearly limited access. We want to offer these decisions where they come up in the workflow. A setting helps little when nobody understands what it does.
Clarity is part of control. “Allow access” becomes a real decision only when it is clear who gets access, to which information and for what purpose. One short sentence with a concrete scope helps more than a long list of technical terms. Nobody should have to study a whole architecture first.
Trust grows when you can see what happens to your data.
Start locally, think about the onward path
LeanCTX describes local default operation and safeguards for file access and sensitive content. Its documentation separates two things: limiting access, and detecting and masking secrets. Those are different jobs with their own configuration. Any real deployment still has to check which safeguards are active and what they cover. [1]
Information prepared locally can still go to an external AI service afterwards. That depends on the connected tool, the chosen model provider and any other active connections. So “local-first” describes the starting point of the architecture. It does not automatically describe the whole data path. We say that clearly, so nobody mistakes a local component for a fully local system.
Take a report with credentials in an appendix. A summary of its content does not need them. Deliberate selection and protective checks lower the risk that they travel along. They are not a promise to catch every sensitive detail. Good design combines sensible limits with a way to look, and with clear responsibility.
Derived data belongs in the picture too. A summary, a stored decision or a search index can hold confidential material even after the original has been moved. So we think about retention and permissions across the whole workflow. Data sovereignty does not end at the upload and does not begin when someone deletes an account.
The freedom to continue elsewhere
Self-determination shows up when you switch. Anyone moving to another tool or model should not have to explain important work again. Understandable formats and visible relationships help. Knowledge should travel without losing its origin. An exported file only helps when the next system can make sense of it.
LeanCTX documents context packages as a way to bundle selected material and pass it on. For us that is a practical start for portability. It does not replace checking the recipient. Before sharing, it has to be clear what is inside and who may receive it. Easy transfer and careful release belong together. [2]
Open documentation helps people judge such limits. It shows which settings exist, what an export contains and how a local workflow is put together. An organisation still needs its own decisions about operation, contracts and responsibility. Our stance is not a certificate and does not replace that review. It is the standard we hold our products to.
Whether the claim holds shows in concrete options. Can I see which data is affected before a transfer? Can I end an access? Can I take my work with me in a usable form? That is what we want to be measured on. Self-determination is part of good technology. It needs understandable controls and an implementation that enforces the choice.
From the Thinkery workshop
Our view of the work behind our products. Examples help explain the ideas. Links show which features already exist. Where we describe a goal, work is still ahead of us.
Edition of 9 September 2026