ResearchEssay
A channel is a folder
What stays on your Mac, what leaves it and where it goes — the project folder, the keychain, the providers you chose. There is no Kiju server.
- Finding
- Nothing goes to a Kiju server. There is none.
- Published
The claim
If the app disappeared tomorrow, the channel should still be there, and readable.
The short answer
A Kiju project is a folder of readable JSON records and the media they point at. The keys are encrypted with the macOS keychain and kept in Kiju’s own data folder, outside the channel’s. When you press a paid button, the prompt and its reference images go from your Mac straight to the provider you picked, using your own key, and the take comes back into the folder. Nothing goes to Kiju: there is no Kiju server, no account and no telemetry.
The instrument
Instrument
What stays, what leaves
Hover, tap or tab into the diagram; the arrow keys walk its parts. Each part says what it is and its real name on disk.
Stays on your Mac
The channel’s folder
Everything the channel is, as files you can open: readable JSON records and the media they point at. It lives where you put it. Delete Kiju and it stays.
- Wind-Up City/
File names are the same in every language.
What is in the folder
Wind-Up City/
kiju.json the channel, its defaults and its budget
bible.json approved, proposed and retired direction
characters/chr_rivet.json the cast: Rivet, Odile
productions/prod_baker.json brief, script versions, shots, notes, release
generations/gen_pixel.json every take, its cost and its job id
media/lab/gen_pixel.webp the takes themselves
journal.jsonl every agent run, reserved then settled
README.md a paragraph that says what the folder is
That is Wind-Up City, the fictional channel the tutorials are filmed on, as the desk
wrote it. journal.jsonl appears with the channel’s first agent run.
Each record is written through a temporary file and a rename, so a crash never leaves half a record. Any other tool —
or a person — can read a record, and repair one by hand. A project made before the desk was renamed has a
storykeel.json instead of a kiju.json; the desk renames it the first time it opens the folder.
What leaves, and when
- A take. Your prompt, with the Lab’s camera and look applied, and its reference images, to the provider of the model you picked. The Lab lists it under “What leaves this Mac” before you press.
- An agent run. The brief, the approved bible and the cast — and the script, when the writer revises one — to the text provider you chose. With a local model through Ollama, they stay on the Mac.
- A real person’s photos never leave. Seedance 2.5 direct receives verified portrait ids, not photos; every other model refuses, and says why.
- Browsing models. The desk reads OpenRouter’s public catalogue, which needs no key and carries nothing of yours.
Limits
- Local-first does not mean nothing leaves. A generation is a request to a provider; the provider sees what you send, under its own terms. Kiju does not control what a provider keeps.
- The keychain protects your keys at rest. A key still travels to its own provider with each request, because that is how the provider knows the request is yours.
- Sharing the folder shares the channel — its records and media — but not the keys.
What it means for Kiju
- Back the folder up like any folder. Open it in a text editor. Put it under version control if you work that way.
- Delete Kiju: the channel stays, readable.
- The tutorial Open a channel: it is a folder starts here.
Sources
- Kiju’s engine:
core/src/project.ts(the folder and how it is written),core/src/records.ts(the records),core/src/runner.ts(what leaves, and the real-person rule),core/src/providers/text.ts(Ollama). - The desk:
desktop/src/main/vault.ts(keys encrypted with the keychain, stored in the app’s own data folder).