# Privacy And Permissions The product promise is local-first monitoring. Sensor reads stay on the Mac. No account is required. The helper is optional. Weather location access is opt-in. Helper diagnostics are explicit export files, not background telemetry. Privacy-sensitive areas include top-process sampling, disk process activity, battery/power information, helper diagnostics, location access, and custom command widgets. UI copy should avoid implying that Core-Monitor uploads data. If future network features are added, they must be opt-in and documented in README, Help, and this wiki.