VIRGIL
Privacy Policy
Effective July 28, 2026
Virgil is a web browser for the Mac, made by Introspective Labs. It is built local-first: your browsing belongs to you and stays on your machine. This policy explains what data Virgil handles, where it goes, and the few cases in which anything leaves your computer.
What we collect
Nothing. Virgil has no accounts, no analytics, and no tracking. We do not collect, receive, sell, or share your browsing history, your mindmaps, or any other personal data. Everything Virgil records about your browsing — history, mindmaps, pins, page summaries, thumbnails, saved passwords for autofill, and search indexes — is stored locally on your Mac and never sent to us.
Network connections Virgil makes
Like any browser, Virgil connects to the websites you choose to visit; those connections are governed by each site's own privacy policy. Beyond ordinary browsing, the app itself makes only these connections:
- Software updates (direct-download version only). Virgil periodically checks our server for a newer version. This is a standard web request; our server sees the usual connection metadata (such as IP address) in transient server logs. The App Store version is updated by the App Store instead and makes no update checks of its own.
- Translation models. Page translation runs entirely on your device. The first time you translate into a given language, Virgil downloads the model files for that language from our server. The text being translated is never sent to us or anyone else.
- Sharing and publishing — only when you ask. If you explicitly share a topic or publish a page, that content is uploaded to our sharing service and becomes accessible to anyone who has the link, until you unshare or unpublish it from within the app.
Optional AI features
Virgil's assistant features (chat, topic organisation, suggestions) are optional and powered by an AI provider you choose. Where the data goes depends entirely on that choice:
- A cloud provider you connect (such as Anthropic or OpenAI, using your own API key): the relevant content is sent directly from your Mac to that provider and handled under that provider's terms. Introspective Labs is not in the middle — we do not proxy, see, or store any of it. Your API key is stored in the macOS Keychain on your device.
- Apple Intelligence (where available): processing happens on your device using Apple's models, under Apple's terms. Nothing is sent to Introspective Labs or to any third-party AI provider.
Either way, nothing is sent anywhere unless you use these features, and you can see and change the configured provider in Settings at any time.
Before any page content is handed to an AI — whether Virgil's own assistant or a connected agent — Virgil strips sensitive form data from it: password fields, credit-card fields, and fields marked sensitive are removed.
AI agents — granular, permissioned access
Virgil can act as a workspace for AI agents — both its own built-in assistant and any external tool you connect (such as Claude Desktop). The built-in assistant goes through the same controlled interface as external agents and holds its own separate set of permissions. What any agent can see and do is governed by a layered permission system:
- Off by default. The connection for external agents is disabled until you switch it on in Settings, and it only ever listens on your own Mac — agents on other machines cannot reach it. Each connection is authenticated with a secret token that you can rotate at any time.
- Reading vs. changing. Agents you connect can read your mindmap — topics, pages, page content, and browsing history — to help you; anything that changes your map (creating, renaming, moving, sharing) is permissioned per agent and per action type: the first time an agent attempts a given kind of change, Virgil asks you, and your choice (allow once, always allow, or always deny) is remembered for that agent and that action only — never granted wholesale.
- Destructive actions always confirm. Deleting or merging topics prompts every time by default, and larger reorganisations are always shown to you as a before/after preview that you explicitly approve or reject. You can also raise the prompt level so every agent action asks first.
- Acting on a page confirms too. If an agent operates a web page on your behalf, any action that would submit something (a form, a button that commits) asks you each time, without exception.
- Reviewable and revocable. All granted permissions are listed in Settings, where you can change or revoke any of them at any time.
None of this changes where your data lives: agent access happens on your Mac, and the only data that leaves it is what the agent's own AI provider (which you configured) receives under that provider's terms.
Site permissions
Websites can request access to your location, camera, microphone, or notifications. Virgil asks you before granting any of these, remembers your choice per site, and lets you review and revoke permissions in Settings. Location requests use macOS Location Services and are additionally governed by the system-level permission you give Virgil.
Your data, your control
Because your data lives on your Mac, you can delete any of it at any time from within the app, or remove all of it by deleting the app and its data folder. Content you have shared or published can be withdrawn from within the app, which removes it from our servers.
Children
Virgil is a general-purpose web browser and is not directed at children. We collect no personal data from anyone, including children.
Changes to this policy
If we change this policy, we will post the updated version at this address with a new effective date.
Contact
Questions about privacy in Virgil: mail@benp.net