What leaves my Mac, and when?
A model on this Mac processes selected frames here. A configured endpoint on another computer receives those frames and enabled context. Your API and Rush send the selected inputs to their respective services. Connected-storage sharing, updates, model downloads and account features have separate network activity. Review Settings → AI and Sharing & Privacy for your setup.
Is the JuiceMount sharing really on by default?
Yes. Sharing with a detected JuiceMount server is on by default. In Settings → Sharing & Privacy, you can turn off sending ratings, pick/reject decisions, color labels, the selected logging profile, face-group names and searches against that volume. Other metadata can travel through enabled sidecar files, which have separate settings. This is separate from Local, Your API and Rush reasoning.
If I use a local model, can frames still leak to the cloud?
For a run pinned to the local family, a cloud provider should not be silently substituted as its reasoning route. That does not turn off unrelated sharing or account features. Check where your endpoint actually runs: localhost is this Mac, while a LAN address is another machine. Review the recorded route and the sharing settings when validating a local-only workflow.
What exactly does Rush upload?
Rush sends selected frames that help explain the clip, together with your logging fields and enabled text or project context. It can also receive audio for transcription. The complete camera original stays in your storage. Images may show people and context may contain names, so check the submission disclosure before starting.
How do I know which engine produced a value?
Every reasoning result stores its provenance (local, remote server, cloud with your key, or ClipLogger Rush), recorded at the moment it ran, not inferred later. The clip's provenance badge shows it, with an honest tooltip ("frames stayed on this Mac or your own network" vs "frames were sent to your API provider" vs Rush). A value from before provenance tracking says "provenance unrecorded" rather than guessing.
Where are my API keys kept?
Configured provider keys are stored in the macOS Keychain. Your API requests use the selected provider and are subject to its billing and your account entitlement. A Rush account and a local endpoint are separate configurations. Review the recorded route before assuming which service handled a result.