Native Soil
Soil Desktop

Account & privacy

Sign in once, then Soil Desktop launches offline. Your handovers live on this device, sensitive content is excluded from every handover, and signing out clears the local session.

Soil Desktop is gated by your Soil account · the same account as the web and Soil Cloud. Sign in once, and after that the app runs offline on this device.

Sign in once, then offline

  • The first sign-in needs the internet · Continue with Google, or email and password.
  • After that, Soil Desktop caches a verified session on this device and launches offline · no network, no token needed to open the app.
  • Signing out clears that cached session (you'll need the internet to sign back in). Your local handovers stay on disk either way.

One account, keyed on your verified email

Whatever you sign in with · Google or email · resolves to the same Soil account as long as the email is the same and verified. Connect a different client with the same email and you see the same handovers.

What's stored on this device

  • Your handovers and projects, in a local store on your machine.
  • A small session record (your verified email + a locally-derived account id) so the app can open offline. That's it · no provider API keys, no passwords.

What's excluded from every handover

Before anything is written · locally or, if you opt in, to the cloud · Soil runs its safety scan. Raw prompts, provider payloads, source files, and private paths are excluded from every handover by design.

Cloud & billing

  • Cloud backup is off by default · see Cloud backup to opt in, and to delete the cloud copies and go local-only again.
  • Soil Desktop is free while in beta. Billing arrives with Soil Cloud; there's nothing to manage in the app yet.

On this page