Skip to content

ResearchEssay

A channel is a folder

What stays on your Mac, what leaves it and where it goes — the project folder, the keychain, the providers you chose. There is no Kiju server.

Finding
Nothing goes to a Kiju server. There is none.
Published

The claim

If the app disappeared tomorrow, the channel should still be there, and readable.

The short answer

A Kiju project is a folder of readable JSON records and the media they point at. The keys are encrypted with the macOS keychain and kept in Kiju’s own data folder, outside the channel’s. When you press a paid button, the prompt and its reference images go from your Mac straight to the provider you picked, using your own key, and the take comes back into the folder. Nothing goes to Kiju: there is no Kiju server, no account and no telemetry.

The instrument

Instrument

What stays, what leaves

Hover, tap or tab into the diagram; the arrow keys walk its parts. Each part says what it is and its real name on disk.

Your MacWind-Up City/kiju.jsonthe channel and its budgetbible.jsonthe directioncharacters/the castproductions/briefs, scripts, notesgenerations/every take, with its costmedia/pictures, clips, voicesjournal.jsonlevery agent runREADME.mdthe folder explains itselfmacOS keychainyour provider keys,encryptedvault.jsonKijureads and writes the foldersays what leaves, firstno estimate, no spendingOllama · optionaltext, on this MacDelete Kiju:the folder stays.prompt andreferences →← the takeand its costProviders you choseBytePlus ModelArkSeedance 2.5, Seedream 5.0 ProOpenRoutervideo, image and text modelsElevenLabsvoicesAnthropic · OpenAItext, for the agentsKiju serverThere is none.No account, no sync, no telemetry.Your MacWind-Up City/kiju.jsonthe channel and its budgetbible.jsonthe directioncharacters/the castproductions/briefs, scripts, notesgenerations/every take, with its costmedia/pictures, clips, voicesjournal.jsonlevery agent runREADME.mdthe folder explains itselfKijureads and writes the foldersays what leaves, firstno estimate, no spendingKeychainyour provider keys,encryptedvault.jsonOllamatext, on this Macoptionalprompt andreferences →← the takeand its costProviders you choseBytePlus ModelArkSeedance 2.5, Seedream 5.0 ProOpenRoutervideo, image and text modelsElevenLabsvoicesAnthropic · OpenAItext, for the agentsKiju serverThere is none.No account, no sync, no telemetry.

Stays on your Mac

The channel’s folder

Everything the channel is, as files you can open: readable JSON records and the media they point at. It lives where you put it. Delete Kiju and it stays.

  • Wind-Up City/

File names are the same in every language.

From Kiju’s engine: the project folder (core/src/project.ts), its records (records.ts), what leaves (runner.ts), the keys (desktop/src/main/vault.ts). The channel is Wind-Up City, the fictional sample of the tutorials.

What is in the folder

Wind-Up City/
  kiju.json                      the channel, its defaults and its budget
  bible.json                     approved, proposed and retired direction
  characters/chr_rivet.json      the cast: Rivet, Odile
  productions/prod_baker.json    brief, script versions, shots, notes, release
  generations/gen_pixel.json     every take, its cost and its job id
  media/lab/gen_pixel.webp       the takes themselves
  journal.jsonl                  every agent run, reserved then settled
  README.md                      a paragraph that says what the folder is

That is Wind-Up City, the fictional channel the tutorials are filmed on, as the desk wrote it. journal.jsonl appears with the channel’s first agent run.

Each record is written through a temporary file and a rename, so a crash never leaves half a record. Any other tool — or a person — can read a record, and repair one by hand. A project made before the desk was renamed has a storykeel.json instead of a kiju.json; the desk renames it the first time it opens the folder.

What leaves, and when

  • A take. Your prompt, with the Lab’s camera and look applied, and its reference images, to the provider of the model you picked. The Lab lists it under “What leaves this Mac” before you press.
  • An agent run. The brief, the approved bible and the cast — and the script, when the writer revises one — to the text provider you chose. With a local model through Ollama, they stay on the Mac.
  • A real person’s photos never leave. Seedance 2.5 direct receives verified portrait ids, not photos; every other model refuses, and says why.
  • Browsing models. The desk reads OpenRouter’s public catalogue, which needs no key and carries nothing of yours.

Limits

  • Local-first does not mean nothing leaves. A generation is a request to a provider; the provider sees what you send, under its own terms. Kiju does not control what a provider keeps.
  • The keychain protects your keys at rest. A key still travels to its own provider with each request, because that is how the provider knows the request is yours.
  • Sharing the folder shares the channel — its records and media — but not the keys.

What it means for Kiju

  • Back the folder up like any folder. Open it in a text editor. Put it under version control if you work that way.
  • Delete Kiju: the channel stays, readable.
  • The tutorial Open a channel: it is a folder starts here.

Sources

  • Kiju’s engine: core/src/project.ts (the folder and how it is written), core/src/records.ts (the records), core/src/runner.ts (what leaves, and the real-person rule), core/src/providers/text.ts (Ollama).
  • The desk: desktop/src/main/vault.ts (keys encrypted with the keychain, stored in the app’s own data folder).