Data handling
What leaves the browser
Aperture is not pure browser-only after you sign in. Two copies can leave this tab: the project is saved to your account as you edit, and each send uploads a snapshot through Aperture's server before the provider you picked is called. Checks and the in-tab test sandbox stay in the browser. Threat model and disclosure are on the security page.
What stays in the tab
- Signed out, the project stays in this browser. It is not uploaded.
- Parse, import, and type checks, and the page preview, run in the tab. They do not call a model.
- npm run test in the built-in runner is a Worker with no network access. That code cannot reach Aperture or anything else.
- Design mode stays in the tab until you send the capture to Composer.
- .env, private keys, and credential files stay on this device. They are not saved and they are not sent.
What is saved when you sign in
The rest of the project is saved on the account as you edit. It does not expire. Delete the account in Settings to remove it, with your keys and your GitHub token. That also removes the copy in this browser, so the next sign-in does not save it again. If a secret file was saved earlier, the next save removes it and does not load it back.
What a send includes
Composer, Chat, Inline, and Tab each take a server hop. The browser uploads a snapshot for that turn to Aperture's server. That snapshot is your instruction, recent chat, the file tree, a symbol map, the open file, the selection, a short note of the cursor line and anything you just typed or dismissed, files you attach with @, and files the agent reads with its tools. The server uses that snapshot to run the tools, then forwards the prompt to the provider you picked. The saved project is the other copy. A model on this computer (Ollama / LM Studio on localhost) is the exception: that turn does not pass through Aperture's server.
Secret-looking files are dropped before the send: .env (not .env.example), private keys, and credential files. Lines that look like API keys, tokens, or passwords are replaced with [redacted]. Your provider key is not put in the prompt.
Where keys are stored
- A provider key, a custom-endpoint key, a GitHub token, and an MCP token are encrypted with AES-256-GCM before they are saved on the account.
- The browser is only sent the last four characters. The full key is not returned.
- On a send, the server decrypts the key you chose and calls that provider. There is no shared Grok key. If the key is missing, the send stops.
What each model can see
Every real model gets the same prompt for that turn. The difference is who receives it. They do not receive your key.
| You pick | Who sees the prompt |
|---|---|
| Your Grok key | xAIapi.x.ai |
| Your GPT key | OpenAIapi.openai.com |
| Your Claude key | Anthropicapi.anthropic.com |
| Your Gemini key | Googleaistudio.google.com |
| Your DeepSeek key | DeepSeekapi.deepseek.com |
| A custom endpoint | The host you typedOllama, LM Studio, OpenRouter, or another OpenAI-compatible URL |
| A model on this computer | Only your machineYour browser tab calls Ollama or LM Studio on localhost. The turn does not pass through Aperture's server. |
| Replay, including the public demo | NobodyA recorded answer. No provider is called. |
GitHub
Connecting GitHub stores an encrypted token on the account and uses it to list, read, push, and review the repos you granted. Opening a repo downloads the files into the tab. A later send can include those files, the same as a folder you dropped. The token itself is not sent to the model.
The public demo
On aperturesais.grok.me, and wherever the server is started with APERTURE_MODEL=replay, a send is a recording. It does not call a provider, even if you added your own key. The key is still saved on the account. On any other host, the key you pick is the one that is called.
Keys are added under Settings → Models. Sandbox limits and how to report a vulnerability are on the security page.