NewDesktop v0.1.7: settings grouped by area, a new first-run guide, mu-agent 0.1.8 inside
Documentation Documentation

Start here

Getting started The desktop app The command line

Using mu

Judges Permissions and safety Goal mode and finishing Context Lessons The plain-language board Sub-agents and the hive

Reference

Configuration Features and options Troubleshooting Privacy

Reference

Privacy

What stays on your machine, what the judge sees, and how to keep everything local.

On your machine

  • Keys stay local. API keys and sign-ins are kept in ~/.mu, and each Jev key is sent only to the service it belongs to. A key never goes in mu.json; custom judges name the environment variable that holds it.
  • No silent downloads. mu never downloads a model or runtime by itself. The local judge, the desktop app's updates and anything else that needs downloading ask you first.
  • Snapshots skip secrets. Checkpoints never take in .env files, private keys or certificates, and live in a folder only you can read.
  • Your other tools are read, not changed. Rules, skills and MCP servers from Claude Code, Cursor and Codex are read only.

What the judge sees

A judge only sees the fields one question needs: a message, a chunk of output, a command, a short summary of the run. Credentials are masked before anything reaches the judge or the board.

With no Jev key, these fields go to the free Jev on OpenCode Zen. OpenCode does not train on them, and mu says so once a day. With your own key, they go to the service you chose. To keep everything on your machine, use the local judge (MU_JUDGE=laya) or turn the kernel off (MU_JUDGE=off).

The ledger

Every verdict is recorded on your machine, in the session file: the outcome, the answers and their probabilities, how long it took, and whether it came from the judge or a fallback. You can read all of it with mu ledger or in the app's judgments tab. The judged state itself is kept only if you set "recordState": true.

The plain-language board

The board is written by a model you pick. What it reads is the agent's own words and steps, sent to that model's provider like any other model call. The board never enters the working model's context.

If mu is useful to you, star it on GitHub

A star helps more people find it. The code, the discussions and every release live in the repository.

Star on GitHub464