Skip to content

Security: fabiospalla9-tech/Limitless

Security

SECURITY.md

Security and privacy

Reporting a vulnerability

Do not publish API keys or private session data in a public issue. Report a security concern through the repository's private security reporting feature when available, or contact the maintainer before sharing sensitive details.

Data flow

Limitless sends learner prompts and current learning context only to the AI provider selected by the user. Provider accounts, subscriptions, retention, and authentication are governed by that provider.

The current beta stores session history and provider settings locally through the desktop application's browser storage. Users should treat locally entered API keys as sensitive data and should never commit them to Git.

The project does not include hidden executables, bundled AI models, advertising SDKs, cryptocurrency miners, or intentional analytics telemetry. The Windows application is an Electron package built from the source in this repository.

CLI execution

When a CLI provider is selected, the Electron main process launches the locally installed codex, gemini, or claude command. The application verifies that the command is executable before activating it. Keep CLIs updated and install them only from their official package sources.

There aren't any published security advisories