Skip to content

Data & Privacy

Qirabot is a vision service: the model needs to see the screen, and nothing else. This page states exactly what crosses the wire.

What is uploaded

Each AI step sends to the Qirabot server:

  • a screenshot of the bound target (JPEG quality 80 by default — screenshot_format / screenshot_quality in Configuration),
  • your instruction text (the natural-language description or task),
  • step metadata (action type, parameters, timing).

What never leaves your machine

  • Your code. The server returns coordinates and decisions; actions execute locally through your framework or adapter.
  • Cookies, credentials, session state. Qirabot drives your browser or device; it doesn't read or transmit their storage.
  • Custom tools. Functions passed via custom_tools run locally — your endpoints, tokens, and databases are never seen by the server, only the tool's string return value is fed back to the model. See AI Tasks & Custom Tools.

What the server stores

Each run is a server-side task: name, status, steps, and the step screenshots — that's what the dashboard shows and what qirabot task <id> / qirabot screenshot <id> retrieve. Steps executed without AI are uploaded to the same timeline for completeness; turn that off with Qirabot(sync_local_steps=False).

What stays local

The HTML report (report.html, full-resolution screenshots/, recording.mp4) is written to ./qira_runs/ on your machine, is fully self-contained, and makes no network calls. Disable it with report=False.

Transport

All traffic is HTTPS to app.qirabot.com (or your own base_url). Certificate verification is on by default; verify_ssl=False exists for self-hosted / self-signed setups only.

Released under the MIT License.