Security

Security

Halo's security model is simple: there's no server to breach, no account to compromise, and your data never leaves your control.

Last updated June 26, 2026

Local-first by design

Halo is a local app. It runs entirely on your iPhone — there is no backend that stores, processes, or proxies your data. The most secure data is data we never have, so we built Halo to never have it.

No accounts, no signups

There is nothing to sign up for and no password to create. Without accounts, there are no central credentials to leak, phish, or breach. You simply download the app and start using it.

Everything executes on device

When Halo reads your data, talks to a connected service, or sends a request to an AI provider, it does so directly from your device using your own keys. Nothing is routed through us. Because all processing happens locally, there is no shared infrastructure that could expose one user’s data to another.

Where your data is stored

Your data — including sensitive items such as API keys and the cookies Halo uses for browser-based actions — is stored on your device and, by default, in your own private iCloud account so it can sync across your devices.

  • This iCloud sync is between you and Apple. Halo has no access to it, and we cannot read your synced data.
  • iCloud data is protected by Apple’s encryption and tied to your Apple Account.

Your device is the security boundary

Because everything is performed from your device, your data’s security is implicitly the security of your device and your Apple Account. There is no separate Halo account to harden — protecting your device protects your data.

Recommendations

To keep your Halo data secure, we recommend:

  • Use a strong device passcode and enable Face ID or Touch ID.
  • Keep iOS up to date so you have the latest security protections.
  • Secure your Apple Account with a strong password and two-factor authentication, and consider enabling Advanced Data Protection for iCloud.
  • Treat your AI provider API keys like passwords and revoke any you believe have been exposed.

Reporting a security issue

If you believe you’ve found a security vulnerability, please let us know at [email protected]. We appreciate responsible disclosure and will investigate every report.