A note can stay as a local file even when you use part of it with a cloud AI model.
The useful question is not “local or cloud?” It is “which part stays local, which part is sent, who chose it, and what happens when the answer comes back?”
The short answer
Keep the durable record local. Send only the context the current task needs. Treat the model's answer as a draft until you review it.
Local storage and cloud inference are different decisions. Your notes folder can remain the primary copy on your Mac while one selected note, section, or excerpt is sent to a remote model for one request.
Once that text is sent, that part of the workflow is not local. The provider's current product, account, settings, retention rules, and terms now matter.
| Job | Local model may fit | Cloud model may fit |
|---|---|---|
| Search or classify private notes | The work should stay on the device | A connected service is acceptable and its terms are understood |
| Summarize a short project note | The local model handles the format well | You want a different model and can send that note |
| Analyze a complex brief | The material is sensitive or offline use matters | The task benefits from the chosen model and the context can leave the device |
| Draft from selected sources | You want a fully local path | You want remote inference but can keep the source record local |
| Update the note | Review and edit the file locally | Let the cloud model propose; apply the change only after review |
This is not a contest between two kinds of model. It is a way to keep the boundary understandable.
Five boundaries matter
People often talk about “AI notes” as if storage and intelligence happen in one place.
They do not have to.
1. The source record
The source is the note you intend to keep.
It may be a project brief, meeting note, decision log, or research file. In a local-first system, that primary copy lives on your device and remains usable without a model answering a request.
Ink & Switch's local-first work makes this distinction explicit: local-first gives the local copy priority, but it does not require pretending that servers never exist. Read the local-first paper
2. Discovery
Before a model can help, something has to find the useful context.
That may be you opening one note. It may be local search. It may be a retrieval system choosing several passages.
Discovery can happen locally even when the next step uses a cloud model. But you should be able to tell whether discovery is based on your explicit selection, automatic retrieval, or both.
3. The context packet
The context packet is what the model actually receives.
It might contain:
- your question;
- one full note;
- two selected sections;
- retrieved excerpts;
- titles and source paths;
- instructions about the expected output.
This is the boundary worth making visible.
A model does not need the whole vault merely because the vault is available to the app. The application can prepare a smaller packet for the task. Smaller is not automatically safe or correct, but it is easier to inspect and less likely to include unrelated material.
4. Inference
Inference is where the model processes that packet.
If the model runs on your Mac, the request can remain local. If the model is hosted elsewhere, the packet crosses the network and is handled under that service's current rules.
The provider name alone is not enough to answer a data-handling question.
OpenAI currently documents different controls for consumer ChatGPT, Temporary Chats, business products, and API accounts. Anthropic separates consumer settings, commercial/API retention, connector content, feedback, and some covered-model rules. These policies can change. Check the exact product and account you are using, not a general claim about “OpenAI” or “Claude.” OpenAI data controls · OpenAI business data · Anthropic training controls · Anthropic commercial retention
5. Write-back
The returned answer is not the source record.
It may summarize the note incorrectly, miss a conflict, or turn an open question into a false decision. Keep it as a draft. Compare it with the sources. Apply only the part you accept.
This keeps the local file authoritative even when a remote model helped produce the next version.
Choose the context before you choose the model
People often begin with model selection.
Start one step earlier.
Ask what the model needs to see.
For a launch-risk review, it may need the current project brief and the latest decision note. It probably does not need old brainstorms, personal journals, unrelated client work, or every meeting transcript in the folder.
Use a small pre-send check:
- Task: What exactly should the model do?
- Sources: Which notes or sections answer that question?
- Exclusions: What sensitive or irrelevant material should stay out?
- Destination: Which model, product, account, and settings will receive the packet?
- Return: Will the answer stay a draft, create a new note, or propose an edit?
If you cannot answer the destination question, stop before sending.
Bring-your-own-key does not remove the boundary. It may change billing and which account terms apply, but the provider still receives the request.
Local search does not remove the boundary either. It can keep discovery on the Mac, but the retrieved passages still leave the Mac if they are inserted into a cloud request.
A concrete workflow
Imagine a fictional project called Atlas.
Its local folder contains:
Atlas project brief.mdAtlas launch decisions.mdDesign partner calls.mdCustomer contacts.md- several older brainstorms
You want an AI model to answer:
What are the three largest launch risks, and which one needs a decision this week?
Step 1: keep the durable record local
Open the project brief and launch decisions.
Confirm that they show the current state, not an abandoned plan. Leave the customer-contact file and unrelated brainstorms outside the request.
Step 2: make a small packet
Prepare:
- the question;
- the current-state section from the project brief;
- the approved decisions;
- two relevant call excerpts;
- the date each source was last checked.
Remove customer names if the analysis does not need them.
Do not summarize away a disagreement. Include the conflicting lines and ask the model to name the conflict.
Step 3: inspect the destination
Choose a model for the task.
If the material should not leave the Mac, use a suitable local model or do the review yourself. If a cloud model is acceptable, check the actual account and provider settings before sending.
Do not rely on a privacy slogan written for a different product tier.
Step 4: ask for a bounded answer
Use a prompt like this:
Use only the attached project brief, launch decisions, and call excerpts. List three launch risks. For each risk, cite the source and date, state what is known, and name the missing decision. Do not invent an owner. If the sources conflict, show both versions.
The prompt tells the model which evidence can govern the answer.
Step 5: review before write-back
Compare each risk with the local sources.
If the model finds a real gap, add it to a new draft note called Atlas launch risk review.md. Do not silently rewrite the project brief.
After the team makes a decision, update the durable project record yourself or approve a clearly shown change.
The source remains local and understandable. The model helped with one selected task. Those two facts can coexist.
Where Cue fits
Cue Notes keeps notes as ordinary local Markdown. Its current public workflow shows selected notes and meeting context informing a conversation while other notes stay outside it.
Cue Agent is designed to answer from notes and meetings with visible sources and to prepare a note change for review. The current page is also clear about the cloud boundary: when a supported provider is selected, Cue sends the context needed for the request under that provider's terms.
Cue MCP is a separate, user-initiated way to let compatible agents work with Cue context. A connected agent still has its own permissions, model route, and data-handling terms.
Do not assume that clicking one note means it is the only context a request can use. Check the selected sources and whether the current mode can retrieve additional context. Provider choice and context selection are separate controls.
The practical rule is simple: keep the context narrow and visible. If you cannot see what a cloud request will use, do not use sensitive notes with that path.
Limits and when cloud is not the right choice
A local source file does not make every later use local.
The note may be copied by a sync service, included in a backup, exposed through broad file permissions, or sent to a model. “Stored locally” describes one part of the system.
Narrow context is not a guarantee either. A short excerpt can still contain a name, trade secret, credential, health detail, or confidential decision. Redaction can remove needed meaning. Automated retrieval can choose the wrong passage.
Use a fully local path, a formally approved business service, or no model when the consequence requires it.
Examples include work governed by client contracts, regulated records, legal privilege, unpublished financial information, secrets, credentials, and any material you are not authorized to send.
Local models have limits too. They may require storage, memory, setup, and model downloads. They may be a poor fit for the task. Cloud models can have cost, latency, availability, policy, and data-handling tradeoffs.
Available models, context controls, and tool permissions can vary by app version and setup. Check the active provider and context in your current app before using sensitive material.
Frequently asked questions
Do local notes stay local when I use a cloud model?
The source files can stay local, but the text included in the request leaves the device. Keep those two facts separate.
Does the model need my whole notes folder?
Usually not for a focused task. One note, a section, or a few retrieved excerpts may be enough. Confirm what the application actually sends.
Is local retrieval the same as local inference?
No. Retrieval finds context. Inference generates the answer. Retrieval can happen locally and then pass its selected text to a cloud model.
Does BYOK keep the request on my Mac?
No. A bring-your-own key can send the request directly to the chosen provider under your account, but the request is still remote unless the endpoint itself is local.
Are cloud requests used to train models?
It depends on the provider, product, account type, settings, and current terms. Consumer chat, business products, and APIs can follow different rules. Check the exact route before sending the note.
Should I use a local model for every private note?
Use a local model when the work should stay on the device and the model fits the task. For high-consequence work, also consider whether any model is appropriate.
Can a cloud model update the local note directly?
A tool can be designed to propose or apply an edit. Prefer a visible proposal and review step. The model's output should not become the durable record merely because it was generated.
For practical checks, read your notes should be files you can keep and what an AI agent should confirm before acting.
Sources
Sources checked October 4, 2026.
- Ink & Switch: Local-first software
- OpenAI: Data controls in ChatGPT
- OpenAI: Business data privacy
- Anthropic: Is my data used for model training?
- Anthropic: Commercial data retention
- Cue Notes
- Cue Agent
- Cue MCP
Try one bounded request
Download Cue for Mac and start with one non-sensitive project note.
Keep the source as a local file. Select the smallest context that answers one question. Check where the request will go. Keep the result as a draft until you have compared it with the note.
