Skip to main content

Data, API Keys, and Prompt Transparency

What Cumbersome stores and sends, and why.

Cumbersome connects your device directly to the AI providers you choose. Folding Sky has no server between Cumbersome and those providers, and we never receive your API keys, prompts, or AI responses.

We understand why entering an API key or another authentication value into a third-party product can feel risky. This page explains how Cumbersome handles credentials, stores your conversations, and adds context or tools to AI requests.

API key safety

We recommend creating a separate API key for Cumbersome at each provider. A dedicated key is easier to monitor, limit, rotate, or revoke without disrupting anything else you use.

  • Never share an API key with another person.
  • Never paste a key into a chat, support message, screenshot, or public document.
  • Set spending limits, usage alerts, or rate limits in the provider's dashboard when available.
  • Monitor provider usage and billing for activity you don't recognize.
  • Revoke and replace a key immediately if you think it has been exposed.
  • Remove keys for providers you no longer use.

Your provider controls the key and bills its usage. Review that provider's security, privacy, logging, and retention policies before sending sensitive information.

How Cumbersome stores and uses API keys

Cumbersome stores API keys and other saved authentication values in Apple's device Keychain. If you have iCloud Keychain enabled, Apple can sync them across your devices with end-to-end encryption. This protection doesn't require Advanced Data Protection. Folding Sky can't access your Keychain or iCloud account.

When you make a request, Cumbersome reads the selected provider's key and uses it to authenticate a direct connection from your device to that provider. The request doesn't pass through a Folding Sky server.

Cumbersome sends the information needed to complete your request. Depending on what you use, that can include your message, relevant conversation history, configured system instructions, model settings, attachments, tool definitions, and earlier tool calls or results. The selected provider processes that information under its own terms and policies.

Deleting a provider's key from Cumbersome prevents new requests to that provider. You can also revoke the key in the provider's dashboard.

Multiple custom authentication headers: A custom provider can combine its primary authentication method with extra headers required by a gateway or API. Cumbersome stores every secret value separately in Keychain. Header names can sync with the rest of the provider configuration. Secret values sync only through iCloud Keychain when you enable it. Cumbersome sends those credentials only to the provider's configured model-list and inference endpoints. If you change a saved provider to a new destination, Cumbersome requires you to enter its saved credentials again.

Provider session identifiers

OpenRouter: When you use OpenRouter, requests associated with a Cumbersome conversation include a session_id. OpenRouter uses session IDs (opens in new tab) (https://openrouter.ai/docs/guides/best-practices/prompt-caching (opens in new tab)) for request grouping and routing related requests to the same provider where possible. Adding this identifier doesn't change Cumbersome's prompt caching controls or the provider's retention policy.

OpenCode, if you add it as a custom provider: OpenCode offers hosted access to AI models through services such as OpenCode Go (opens in new tab) (https://opencode.ai/docs/go/ (opens in new tab)). You can connect to these services through Cumbersome's custom provider settings. For conversation requests to opencode.ai or its subdomains, Cumbersome includes an x-opencode-session header and identifies itself through x-opencode-client and a User-Agent containing its name, version, and website. These automatic headers apply only to OpenCode endpoints. Explicitly configured custom headers take precedence over these defaults.

Both session identifiers are derived from the conversation's internal ID using SHA-256, with a separate namespace for each provider. They contain no message text or credentials. OpenRouter and OpenCode receive different values for the same conversation, and each stable value lets its recipient associate requests with that conversation.

Local servers and HTTP

Custom providers can use HTTP for supported non-public addresses and local hostnames, including localhost, .local names, private IP addresses, and Tailscale's address range. Other hostnames and public IP addresses require HTTPS. HTTP itself provides no TLS encryption: messages and any credentials sent with a request depend on the security of the network or encrypted tunnel carrying it. Storing credentials in Keychain doesn't encrypt the network connection.

Incognito chats

Choose Go Incognito in an empty chat, or New Incognito Chat from either New Chat menu. Incognito keeps the conversation in memory, outside saved history, Projects, search, and iCloud sync. The chat isn't restored after Cumbersome restarts. Automatic title generation is skipped while the chat remains Incognito.

Keeping a chat: Choose Save to Timeline to keep the conversation and its attachments in normal saved history, where they follow the usual storage, search, and iCloud sync rules. Saving can also trigger automatic title generation when enabled. Before your first message, Turn Off Incognito keeps your unsent text and attachments for a normal chat.

When it ends: Ending the chat, opening another chat in the same window, starting a new chat, or closing that window discards the session immediately, without confirmation. Quitting Cumbersome or the operating system terminating it also loses the session. Opening Settings, switching away from Cumbersome, or sending it to the background keeps the session open while the process continues running. An ended session can't be recovered from Cumbersome or iCloud.

What Incognito doesn't change:

  • Provider access and retention: Requests still use your selected provider, saved credentials, instructions, and enabled tools. Providers and remote tools still receive the content needed to respond. Incognito doesn't hide your IP address or provider account, change their logging, retention, or training policies, or remove provider charges.
  • Settings and analytics: Your saved credentials and preferences remain in place. Incognito follows Share Usage Analytics; it doesn't turn collection off. When enabled, limited usage events include starting an Incognito chat and completing a reply, without chat content.
  • Copies and tool activity: Original files you attach, exports, clipboard copies, saved downloads, and changes made by tools remain after the chat ends. Browser tools keep their own storage behavior described below; Incognito doesn't clear all website cookies or retract data already sent to a service.
  • Device traces: The chat store and imported attachment contents use memory, but some workflows can create temporary files, such as a pasted image before import. Large videos can reference your original file. Incognito doesn't promise zero disk writes, secure erasure, or removal of operating system records and screenshots.

Conversation storage and iCloud encryption

Cumbersome stores saved conversations on your device and syncs them through your private iCloud account when iCloud is available. Incognito conversations are excluded. The table below describes saved conversations and other persistent data. Folding Sky can't access your personal iCloud data.

Encrypted and end-to-end encrypted describe different protections. All of the iCloud storage paths below encrypt data in transit and on Apple's servers. With standard protection, Apple holds keys that allow it to help recover data. End-to-end encryption keeps the keys needed to read the protected content from Apple. iCloud Keychain already has that protection; other eligible data gains it when you turn on Advanced Data Protection (ADP). Apple's iCloud security overview (opens in new tab) (https://support.apple.com/en-us/102651 (opens in new tab)) explains the distinction.

Compare iCloud protection with Advanced Data Protection (ADP) off and on. Scroll horizontally if needed.

Cumbersome storage and iCloud encryption
DataWhere it’s storedWithout ADPWith ADP
API keys and credentialsSaved authentication values for providers and tools.Apple KeychainSync: iCloud Keychain, when enabledEnd-to-end encryptedKeychain sync already has this protection.End-to-end encryptedNo ADP requirement.
Sensitive fields in new recordsMessage text, Project document titles and stored paths, and conversation attachment filenames.SwiftData databaseSync: Private CloudKit encrypted fieldsEncryptedField encryption is enabled; Apple retains access to service keys.End-to-end encryptedApple no longer has the keys needed to read these values.
Older records in legacy fieldsContent created before the encrypted-field rollout.SwiftData databaseSync: Ordinary private CloudKit fieldsEncryptedIn transit and on Apple’s servers.Not end-to-end encryptedADP doesn’t convert legacy fields. Cumbersome doesn’t migrate these records.
Structural sync metadataIDs, dates, relationships, provider/model IDs, and token/timing counts.SwiftData databaseSync: Ordinary private CloudKit fieldsEncryptedIn transit and on Apple’s servers.Not end-to-end encryptedThese fields remain available to CloudKit for sync and queries.
Conversation attachment paths and file URLsCan include the original filename.SwiftData databaseSync: Ordinary private CloudKit fieldsEncryptedIn transit and on Apple's servers.Not end-to-end encryptedThese filename copies don't use encrypted fields.
Preferences and configurationEligible settings and provider configuration, excluding saved credentials.Local settings storageSync: iCloud key-value storeEncryptedIn transit and on Apple’s servers.No end-to-end encryption guaranteeThis separate settings service is outside our CloudKit encryption claim.
Files stored in iCloud DriveLarge message content, attachment files, Project document originals, and presets.Saved or downloaded filesSync: iCloud DriveEncryptedIn transit and on Apple’s servers.End-to-end encryptedFile contents are protected. Some file metadata keeps standard protection.

The ADP columns cover iCloud copies. Local files, SwiftData, and the Project search cache rely on device protection. Its extracted text doesn't sync or back up and has no separate encryption.

Keychain stores credentials and cryptographic keys. Cumbersome's general settings and conversation history use the separate storage systems above. CloudKit sync is asynchronous, so a conversation being available on one device doesn't mean its latest changes have reached iCloud or another device.

Starting with Cumbersome 1.58, released July 18, 2026, newly created records store many sensitive values in CloudKit encrypted fields. Later features use the same protection for their sensitive fields. When you enable Advanced Data Protection for iCloud, those fields are end-to-end encrypted. Cumbersome can't determine whether Advanced Data Protection is enabled on your account.

The protected fields used for new records include:

  • Message text, reasoning, pre-edit originals, and raw provider responses.
  • Conversation titles and per-conversation system prompts.
  • Face/Off and Mind/Meld candidate and judgment data.
  • Local-tool arguments, content-bearing diagnostics, and human-readable error details.
  • Project names, preset names and previews, and annotation contents.

Technically, these SwiftData attributes opt into CloudKit encryption with @Attribute(.allowsCloudEncryption). CloudKit encrypts their values on the device before uploading them. ADP determines whether Apple also has access to the service keys. CloudKit's encrypted-field documentation (opens in new tab) (https://developer.apple.com/documentation/cloudkit/ckrecord/encryptedvalues (opens in new tab)) describes this behavior. SwiftData's .externalStorage option alone doesn't establish CloudKit encrypted-field or asset protection.

Project documents: Titles and stored paths use encrypted CloudKit fields, including those in saved version history. A title can come from an imported filename or a name you or AI choose. The stored file uses a generated filename that contains no original name.

Conversation attachments: New records have an encrypted filename field, but synced iCloud Drive paths and saved file URLs can contain the original filename. Those path and URL fields use ordinary CloudKit fields, protected in transit and on Apple's servers but not end-to-end encrypted with ADP.

Large message content, attachments, Project document originals, and preset bodies can use iCloud Drive. With Advanced Data Protection, those files are end-to-end encrypted.

This rollout is forward-only. Cumbersome doesn't rewrite records created before version 1.58, so older data remains under Apple's standard CloudKit protection. New messages use encrypted fields even inside an older conversation, which means one conversation can contain both storage types. Structural sync data, including IDs, dates, relationships, provider and model identifiers, token counts, and timing data, remains in ordinary CloudKit fields.

Settings synchronized through Apple's key-value store are outside this CloudKit encrypted-field claim. This includes custom-provider configurations, custom API parameters, and most preferences. A global system message can use either the key-value store or iCloud Drive depending on its size.

iCloud Keychain resets

Resetting iCloud Keychain isn't a reliable way to delete your conversation history. Cumbersome stores conversations locally as well as syncing them through iCloud, so copies already on your devices can remain visible after a reset.

Apple also keeps key material used for CloudKit encrypted fields and private-database assets in iCloud Keychain. Those Apple-managed encryption keys are separate from the API keys you enter in Cumbersome. Deleting a provider's API key removes its saved credential; it doesn't erase the conversation database.

If a Keychain reset discards the encryption keys CloudKit needs, affected cloud data can become permanently unreadable. Apple's recovery guidance (opens in new tab) (https://developer.apple.com/documentation/cloudkit/encrypting-user-data (opens in new tab)) describes uploading surviving local copies with new encryption keys. Seeing conversations on one device doesn't confirm that iCloud sync has recovered.

To remove conversation history, delete the conversations in Cumbersome.

Conversation copies, exports, and imports

You can copy a conversation or export it as Markdown or JSON. On Mac, you can also export or import all conversations in one JSON file, including their project organization. JSON exports contain conversation text, settings, and metadata, so treat them as sensitive files. Cumbersome doesn't add file encryption to these exports; their protection depends on where you save or share them.

Exporting can download message content stored in iCloud Drive. Importing reads the chosen file into the local conversation database, after which imported conversations can sync through iCloud. Importing alone doesn't send the conversations to an AI provider. Continuing an imported conversation can send its history under the same rules as any other conversation. Deleting a conversation in Cumbersome doesn't remove copies you've exported or shared elsewhere.

Project files and search

Cumbersome Pro lets you create and edit text files manually or ask AI to work with files in the current Project. New AI files save automatically, as do refinements during the response that creates them. Later AI edits, replacements, and deletion require your review before changing saved files.

Saved files and version history sync through your private iCloud storage. Unfinished edits stay in local recovery drafts that survive restarts but don't sync through iCloud. Discarding a draft leaves any saved file intact.

Cumbersome Pro lets AI search and cite saved documents in the current Project. It can search other conversations in that Project only when Let AI search Project conversations is on. New Projects start with that setting on; older Projects without a saved choice keep it off. Documents stay searchable while Pro is active even when conversation search is off.

Search and read results enter the current chat as tool results and can go to its AI provider. They can contain document text or passages from conversations that used another provider. Provider usage is billed separately from Pro. Deleting a file after confirmation removes it and its saved versions from the Project library and stops future access. Failed file cleanup is retried. Turning off conversation search stops future access to other chats; losing Pro stops AI file access and Project search. Already sent passages can't be retracted, and tool results remain in saved chat history until you delete that chat. Deletion doesn't remove copies you've exported or shared elsewhere.

Settings across conversations, projects, and models

System message presets can differ by conversation or project. Most other AI controls apply across chats:

  • Provider and model: For ordinary chats, Cumbersome uses the current selection in the model picker. Returning to an older conversation doesn't restore the model used for its earlier messages. You can change models between turns in the same conversation.
  • Reasoning: The AI Reasoning toggle and Reasoning Effort selection apply across chats. Their effect depends on what the selected provider and model support.
  • Tools: Your choices about which tools to enable apply across chats. Available tools depend on the provider, model, operating system, and any required setup.
  • Face/Off and Mind/Meld: These modes and their settings apply across chats. Mind/Meld uses the models configured within that mode.
  • Custom API Parameters: Enabled parameters apply across chats and can override Cumbersome's built-in request settings. Examples include temperature, output token limits, and sampling options such as top_p. Supported parameter names and values depend on the provider and model. Cumbersome doesn't provide a separate temperature control for each conversation or project.

These shared controls aren't saved as independent settings profiles for each conversation, project, or model. In Advanced Features, the groups Applies to All Chats and Applies to This Chat Only distinguish shared controls from the conversation's system message preset.

OpenRouter presets are separate. An OpenRouter preset selected in the model picker can supply models, system prompts, routing, and parameters saved with OpenRouter. Cumbersome leaves its reasoning configuration to the preset by default. Explicit Custom API Parameters can still override preset values. OpenRouter's preset guide (opens in new tab) (https://openrouter.ai/docs/guides/features/presets (opens in new tab)) explains how those settings combine with request parameters.

System prompts and current-date context

Cumbersome doesn't apply a default persona to ordinary chats. Your base system instructions come from what you configure globally, through a project or preset, or for the conversation. Features such as Face/Off add instructions for their specific tasks, as described below.

Which system message applies?

For a regular chat, Cumbersome chooses the system message in this order:

  1. The conversation's selected system message preset, if it has one.
  2. The project's selected system message preset, if the conversation has no preset of its own.
  3. Your global default system message, if neither has a preset.

These are alternatives: selecting a conversation preset replaces the inherited project or global message. Cumbersome doesn't combine all three. A saved preset contains system instructions; it doesn't bundle a model, temperature, or tool selection.

Manage the global message and saved presets under Settings > AI > Instructions. Choose a project's preset when creating or editing the project. Choose a conversation's preset in Advanced Features under System Message. Selecting Project default or Default (global) returns that conversation to its inherited instructions.

Inheritance applies when you send a request, including in existing conversations. Changing a project's preset affects subsequent requests from chats that inherit it. Editing a saved preset affects subsequent requests wherever that preset is used. Earlier responses aren't rewritten.

Current date

By default, the Include Current Date setting appends this one line to supported AI requests:

The user's current local date is YYYY-MM-DD.

Cumbersome creates the date on your device at request time. It doesn't include your time, time zone identifier, language, locale, or location, and it isn't saved as part of your system message. The date applies to regular chats, Ghost/Write, Quick Prompt, and Cumbersome shortcuts. You can turn it off under Settings > AI > Instructions.

Tools and external services

When a tool is available and enabled, Cumbersome can send its name, description, and input schema to the selected AI provider. The model decides whether to call it unless you explicitly request a feature. Tool definitions consume input tokens even when the model doesn't call them. When Cumbersome executes a local or MCP tool, its call and result are shown in the conversation, and the result can be sent back to the provider so it can continue the response.

Some optional tools may be enabled by default, and the model may invoke an enabled tool during a chat. Other tools require you to configure or enable them. Review and change available tools under Settings > Tools. You choose which remote MCP servers and tools to add or enable. Defaults, saved choices, and feature availability can vary by operating system and product version.

  • Local Web Search and Local Web Browser: On iOS 26, iPadOS 26, and macOS 26 or later, Local Web Search sends an AI-generated query from your device to a selected search engine and returns result links and snippets. Local Web Browser loads one page through your device, can run AI-generated JavaScript once, extracts readable content, and then discards that page. These tools can run without displaying a browser window. Each call uses a fresh page and doesn't keep an open page or navigation sequence for the next call. WebKit may still retain ordinary website data, such as cookies or cached resources, outside that page's lifetime. Stateless browsing doesn't mean anonymous or private browsing.
  • Web Agent (beta): This visible browser stays with the active chat for multi-step navigation, page inspection, JavaScript execution, and sites you choose to sign into. You can interact with the page at any time. If a site presents a CAPTCHA during access you are authorized to make, you can complete the challenge yourself and then let the AI continue from that state. Web Agent doesn't solve, bypass, or automate the challenge. It uses a nonpersistent browser data store and closes when you close it, disable the feature, or leave the chat. Its tool instructions tell the AI not to inspect password, payment, passkey, or authentication fields. This is an instruction to the model, not a technical guarantee that sensitive information cannot be read or transmitted.
  • Question Cards: The model can call this tool once per user turn when it needs clarification. It supplies up to three questions and chooses a control for each one: choices, ranking, slider, date, or confirmation. Cumbersome returns your answers to the provider as the tool result. If you skip the cards, the result tells the model to continue with reasonable assumptions. The tool instructions say not to request secrets or use the cards to confirm an external action. Review every question anyway, and never enter a credential or other secret.
  • Local Data Analysis: When enabled and available, this tool can work with supported attachments. The selected AI provider may receive information about those attachments and the tool's results as part of the conversation. Results can include text, tables, charts, or errors.
  • MCP servers: For servers you configure and enable, Cumbersome sends their tool definitions to the provider. A tool call sends its arguments to the remote MCP server. Those arguments can contain information from your prompts, conversations, or attachments. The server's response is added to the conversation and returned to the provider. Review each server's privacy and retention practices before enabling its tools.
  • Provider-hosted tools: Depending on your provider and settings, Cumbersome can attach native web-search or image-generation tools. The selected AI provider, not your device, executes those tools under its own terms and policies.

Cumbersome's Settings govern only tool features Cumbersome exposes or requests. A provider or gateway may also run its own search, page retrieval, code execution, or other tools on its servers and may contact websites or other services. Turning off a Cumbersome tool does not guarantee that a provider will not use a similar capability independently. Its tool behavior, data practices, and terms can change without a Cumbersome update. Review the provider's current terms and privacy policy before sending content you would not want it or its downstream services to process.

Search engines, websites, and MCP servers receive direct requests from your device when their tools run. Folding Sky doesn't proxy those requests.

Browser tool data flow and untrusted pages

Websites can receive information normally included in a browser request, such as your IP address, browser request data, cookies or temporary session state, search terms, URLs, and content submitted to the page. The selected AI provider can receive extracted page text or HTML, interactive-element details, metadata, and JavaScript results when those outputs are returned as tool results.

The selected model generates browser tool arguments. It can create a search, URL, JavaScript action, page interaction, or navigation using information already present in your prompt or conversation. If Web Agent is signed into a site, inspection or JavaScript can also access information available within that browser session. In unusual or unintended cases, a model-generated action could include conversation or page information in a request to another website or service.

Webpage content is untrusted. A page can contain visible or hidden instructions intended to change the model's behavior, sometimes called indirect prompt injection. Such content could influence later tool calls, redirect the browser, or encourage disclosure to another site. Cumbersome's tool instructions and the selected provider's safeguards reduce this risk but cannot eliminate it. The product does not have a deterministic data-loss prevention system that can prove every AI-generated URL, script, or page interaction is safe.

Web Agent uses a nonpersistent WebKit data store, so its cookies, cache, and other browser state stay in memory rather than being written to the persistent browser store. That state is destroyed when you close Web Agent, disable it, or leave the chat. This limits persistence after the session. It does not prevent a website or the selected AI provider from receiving information while the browser session is open, and it cannot retract information already sent.

You can see and interact with Web Agent at any time. Review the current domain and browser actions, enter credentials yourself, avoid highly sensitive accounts or pages, and close the browser session when you are done. Do not expose information you would not want the selected AI provider or the visited website to process.

Authorized and responsible use

Cumbersome's browser, code, data, and remote tools can take actions with real effects. Use them only with websites, accounts, systems, and data you own or are authorized to access. Security testing requires prior express authorization from someone authorized to grant it. A published vulnerability disclosure or bug bounty policy provides authorization only within its stated scope.

Do not use Cumbersome to bypass access controls or anti-bot challenges, gain unauthorized access, probe or exploit systems without permission, obtain credentials or protected data, deploy malicious code, conduct phishing or fraud, or disrupt a service. Review generated code and proposed browser or tool actions before using them. The complete restrictions are in our Terms of Service (https://folding-sky.com/terms (opens in new tab)).

Usage analytics and your choice

Cumbersome uses Google's Firebase Analytics to measure limited product usage and feature outcomes. It doesn't send prompts, responses, API keys, attachments, website content, or screenshots to Firebase. The Privacy Policy (https://folding-sky.com/privacy (opens in new tab)) lists the data Firebase may receive and how long it is retained.

Share Usage Analytics is on by default. Turn it off in Settings to stop new Cumbersome Firebase Analytics collection and reset the SDK's local analytics data on that device. The preference syncs through iCloud when available, but another device may keep its previous choice until sync arrives. Turning the setting off does not remove events already sent to Google or from existing reports. The setting controls Cumbersome's analytics, not analytics in another Folding Sky product or on our website.

When Cumbersome loads a third-party page, its scripts, pixels, or cookies may track that visit or your interaction with the page. Search engines, AI providers, remote MCP servers, provider-hosted tools, and other external services can also collect information from requests you make through the product. Cumbersome's analytics setting does not control any of them. Web Agent's nonpersistent browser storage limits what remains on your device after a session; it does not block tracking or data sent while the page is open. Review each service's privacy terms before using it.

Other built-in requests and framing

Some features append instructions to your system message or make separate requests with a dedicated task prompt. These instructions reach the selected AI provider even when they aren't shown as chat messages. They don't rewrite your saved system message or preset.

Face/Off: three approaches, then a judge

Face/Off sends the same conversation to the selected provider and model three times. Each candidate gets your configured system instructions followed by a different instruction:

  • Cautious: Prefer established answers over novel or speculative ones.
  • Balanced: Weigh established and novel approaches.
  • Creative: Prefer novel, imaginative answers over conventional ones.

Each candidate is also instructed to reply in the language of your messages. These additions guide the approach to the answer; they don't change the words of your request.

Earlier versions also varied temperature between candidates. The current implementation leaves temperature unset for all three candidates and the judge, so the provider's default applies unless you explicitly override it through Custom API Parameters. The different instructions provide the intended variation.

A separate judging request includes your latest query and all three candidate answers. It asks the model to select the best answer for accuracy, helpfulness, clarity, and completeness, then return a selection and short rationale. The judging prompt asks it to evaluate the supplied answers without browsing or adding sources. This is a model's assessment, not independent fact checking.

Mind/Meld: decide whether to combine perspectives

Mind/Meld first asks its configured assessor model whether multiple perspectives would improve the answer. For a simple request, it follows that assessment with a direct answer. Otherwise, it asks three configured models to answer independently, with different instructions: focus on facts and constraints, explore alternatives and tradeoffs, or produce a practical solution.

A synthesis request receives your original request and the candidate answers. Its instructions ask the model to combine useful material, address conflicts, retain valuable minority insights, and remove repetition. They explicitly caution that agreement between models isn't proof of correctness. These task instructions are appended to your configured system instructions. The assessor, candidate, and synthesis requests can use different providers and models according to your Mind/Meld settings.

Other assisted tasks

  • Automatic titles: When enabled, Cumbersome makes a separate request after you start a saved conversation or choose Save to Timeline for an Incognito chat. It sends a bounded text excerpt, normally from your first message; a saved Incognito chat can include recent user and assistant messages. Instructions ask for only a short title in the excerpt's language. Title generation can use a different model from your chat. Incognito skips this request until you save it. You can change this setting under Settings > Tools.
  • Ghost/Write: This runs only when you request it. A dedicated prompt asks the selected model to draft your next message from the conversation, with a grounded observation and a question that advances the discussion. It instructs the model not to invent personal facts, consent, or commitments. Cumbersome sends the generated message as your next turn, marks it as written by AI, and requests an AI reply.
  • Annotations: When you send an annotation, Cumbersome adds the selected passage, your optional note, and bounded surrounding context to the next request. Sent annotations remain associated with that request in the conversation.
  • Conversation compaction: Choose Compact in the conversation title menu after the latest AI reply finishes. Cumbersome sends the current conversation context to the selected provider with instructions to preserve goals, constraints, key facts, decisions, and unresolved tasks in a short summary in the conversation's language. Later requests use the most recent summary and messages after it. Compacting again summarizes that latest summary together with newer messages. Original messages and older summaries remain visible in Cumbersome but are excluded from later request history. Compaction doesn't erase content already sent to a provider.
  • Tool guidance: Enabled tool descriptions explain when and how the model should use each tool. For example, search guidance can suggest opening a result when snippets are insufficient, and browser guidance distinguishes reading one page from navigating several steps. Question Cards and data analysis include instructions about suitable questions, available inputs, and output formats. These descriptions can influence the model's behavior even before it calls a tool.
  • Attachments, PDF extraction, and tool results: Cumbersome can add labels or formatting so the model can understand attached content and tool output. When on-device PDF text extraction is used, the extracted text and filename are inserted into the provider request instead of uploading the original PDF through that path. A photo captured inside Cumbersome stays in the attachment draft until you send the message. Cumbersome then sends it to the provider and can sync it with the saved conversation, just like another image attachment.

Ghost/Write drafting and compaction omit the regular chat system message to focus on their dedicated tasks. The normal instruction hierarchy applies again when Cumbersome requests an ordinary reply.

These prompts, conversation context, and any additional requests count toward your provider's token usage and charges. Wording and behavior can change between versions; this describes the main uses of added instructions rather than every internal prompt.

Our approach to future features

Future features may also require built-in prompts, system instructions, tool definitions, or small amounts of request framing. We will add them only when they are needed to perform the feature's stated purpose, keep them as focused as practical, and provide a setting or explicit action when appropriate.

Our goal is straightforward: don't surprise you. We will use built-in instructions judiciously and aim to document significant patterns that can affect model behavior or token usage. This page is an explanation of our approach, not a guaranteed complete or continuously updated feature ledger.

Inspecting provider requests

Cumbersome keeps a sanitized copy of the effective parameters used for each AI response. To inspect it:

  1. Open the ellipsis menu on an AI response. You can also long-press the response on iPhone or iPad, or right-click it on Mac.
  2. Choose Message Details.
  3. Expand Request Parameters.

The parameters reflect provider defaults and your custom values after Cumbersome merges them. If a response required several provider requests, Message Details lists each one in order. This view excludes message content, system messages, tool definitions, and attachments. It also redacts credential values.

Message Details shows the effective request parameters Cumbersome recorded, along with provider-reported usage and timing. Select the image to enlarge it.

This is Cumbersome's copy of the outgoing parameters, not a receipt or billing log from the provider. Provider dashboards remain the authoritative source for usage and charges. They can also show what the provider received. For example, OpenRouter offers optional Input & Output Logging (opens in new tab) (https://openrouter.ai/docs/guides/features/input-output-logging (opens in new tab)) in its Observability settings. Review OpenRouter's privacy and retention details before enabling it. Logging applies only to subsequent requests.

For more information, read our Privacy Policy (https://folding-sky.com/privacy (opens in new tab)) and Terms of Service (https://folding-sky.com/terms (opens in new tab)).