Frequently Asked Questions
The product
What is Thunderbolt?
An open-source AI client you deploy yourself. It runs on the web, macOS, Windows, Linux, iOS, and Android, and connects to whichever models you choose. Each device keeps its data in a local database.
Who makes it, and how is it funded?
We are Thunderbird Technologies Corporation, the entity behind Thunderbird, funded through a dedicated investment from Mozilla.
Is it part of Thunderbird?
No. It is its own product from Thunderbird Technologies Corporation, the same entity that makes the Thunderbird email client.
Cost and licensing
What does Thunderbolt cost?
The software is free. It is licensed under the Mozilla Public License 2.0, which permits commercial and internal use. Your costs are the infrastructure you run it on and the AI inference you use.
What does inference cost?
| Path | Who pays | Notes |
|---|---|---|
| Your own provider key | You, at your provider’s rates | Key stays on the device, never synced to the server |
| A local model | Nothing beyond your own hardware | Run through Ollama or llama.cpp on the same machine as the app |
| System-managed models | Your deployment’s provider accounts | Only if you supply the backend with provider keys |
Is there a paid or hosted version?
Not currently, but there is enterprise support available.
Data
Where does my data live?
In two places: a local database on each device, and, once you sign in, your deployment’s PostgreSQL database.
Every client reads and writes its local database first, so the app keeps working against local data even when the network is down. Signing in sets up cross-device sync for that device, and synced rows are then also stored on your deployment’s server so your other devices can pick them up.
The server copy is end-to-end encrypted: the device encrypts content before sending it. The copy on the device stays readable locally so the app can search and render it.
Can the server read my chats?
Not what it stores. End-to-end encryption (E2EE) is always on, so the server holds only ciphertext for the fields listed below: the keys that would unscramble it exist on the user’s devices and nowhere on your infrastructure. It also shapes how devices join. The first device on an account creates the keys and shows a recovery phrase, and every later one must be approved from an already trusted device or with that phrase.
| Encrypted | Never encrypted |
|---|---|
| Chat titles and message content | Record ids, timestamps, ordering, deletion flags |
| Tasks, saved prompts, skills | Project icons and pin order |
| Project names, descriptions, and instructions | Device names |
| Model names, endpoints, and tuning profiles | |
| Custom agent names, URLs, and descriptions | |
| Setting values |
End-to-end encryption is in preview. It has not yet had a cryptography audit.
Does my data leave my network?
Sync and authentication stay inside your deployment, and prompts go wherever your chosen model lives. Web search reaches an external search provider, and only when the deployment sets EXA_API_KEY and the user leaves the Thunderbolt connection switched on.
| Model you picked | Where the prompt goes |
|---|---|
| Local (Ollama, llama.cpp) | Your own machine, and no further |
| A model on your own infrastructure | Your network, if you publish it on an address the app can reach over HTTPS |
| A cloud provider with your key | That provider |
| A system-managed confidential model | A hardware-isolated enclave outside your network, which neither the vendor nor you can read into |
Provider calls do not go straight from the app. They are relayed through your own backend, which forwards the bytes and hands back the response. Browsers cannot call most provider APIs directly, and the published desktop and mobile builds take the same path. The user’s key passes through untouched and is never stored, and your access logs record the destination hostname but not the request path.
Are file attachments stored on the server?
No. The file contents are held on the device. The file itself travels only in the request that answers that turn, though the text read out of it rides along in later messages in the same conversation. Nothing is written to your server or your database, so an attachment is not available on the user’s other devices and is not included in a data export.
One exception: if you connect an external coding agent that stages files on its own service, that agent receives the file under its own retention rules, not Thunderbolt’s.
Do you collect analytics?
Events from the app, only while the user has the toggle under Settings → Preferences turned on. A deployment that sets POSTHOG_API_KEY also records one event per model call it pays for, plus an error event when one fails, attributed to the user id and independent of that toggle. Calls on a user’s own key or a local model record nothing. No event carries prompts, responses, or API keys, and every one is listed in Telemetry. Leave POSTHOG_API_KEY unset to send nothing at all.
Models
Which models can I use?
Anything OpenAI-compatible, plus native support for Anthropic. In Settings → Models you can add:
| Provider | Needs a key |
|---|---|
| Anthropic | Yes |
| OpenAI | Yes |
| OpenRouter | Yes |
| Tinfoil | Yes |
| Custom, any OpenAI-compatible endpoint | Only if the endpoint requires one |
The custom option is how you reach a local Ollama or llama.cpp server on the same machine, or a model of your own published on an address the app can reach over HTTPS. A model server that is only reachable on your internal network will not work from the browser app.
Tinfoil is a confidential inference provider. Confidential means the model runs inside a hardware-isolated enclave: the request is encrypted end to end and the operator of the machine, Tinfoil included, cannot read it. The app verifies the enclave before sending anything.
Which models does a fresh install ship with?
Three system-managed models: GLM 5.3 Flash (the default on a new install), GLM 5.3, and Opus 5. The first two run in confidential enclaves; Opus 5 is routed to Anthropic.
A backend you host serves these only if you give it the matching keys.
ANTHROPIC_API_KEY=...TINFOIL_API_KEY=...Without them, the three entries still appear in the model list but every request to them fails. Add your own provider key or a local model instead.
Are there usage limits on system-managed models?
Yes. Two rolling spend windows apply per user, with these defaults.
| Window | Anonymous session | Signed-in account |
|---|---|---|
| 5 hours | 10 cents ($0.10) | 1500 cents ($15) |
| 7 days | 60 cents ($0.60) | 7500 cents ($75) |
Override them with INFERENCE_QUOTA_ANONYMOUS_5H_CENTS, INFERENCE_QUOTA_ANONYMOUS_7D_CENTS, INFERENCE_QUOTA_REGISTERED_5H_CENTS, and INFERENCE_QUOTA_REGISTERED_7D_CENTS. Usage against your own provider key is not metered or capped by Thunderbolt.
Are user API keys visible to the server?
Not stored, no. A provider key, an agent credential, or a connected account’s token is written to a part of the device’s storage that is excluded from sync, so no central copy exists and a user who signs in on a second device has to enter it again there, or bring it across in a data export. The key does pass through your server on each request, because the browser cannot call most provider APIs directly: it is forwarded and discarded, never written down, and access logs record only the destination hostname. A user’s own Tinfoil key is the exception, going straight to the enclave.
Running it
Where can I deploy it?
| Target | Best for |
|---|---|
| Docker Compose | Demos, evaluations, a single host |
| Kubernetes | Production, existing clusters |
| Pulumi on AWS | Green-field AWS, infrastructure as code |
We recommend starting with Docker Compose whatever you plan to run in the end. All three read the same core settings, though some of the optional ones are wired up on only one or two of them.
All three deploy the application frontend, the backend API, a PostgreSQL server (holding two databases), the sync service that replicates data between devices, and Keycloak for single sign-on. Kubernetes and AWS add a sixth piece, the marketing and docs site. All three ship set up for OIDC; the backend also speaks SAML, but no target exposes it, so that needs an edit to the deployment files.
With single sign-on, nothing in the deployment has to call out. Emailed sign-in codes are the exception: they go through Resend, which is the only supported way to send them.
Does it work offline?
Partly. Changes are written to the device immediately and uploaded when the connection returns. If the same record was changed on two devices while one was offline, the most recent change wins.
Sign-in, web search, and inference against any model that is not running on your own hardware still need the network.
Can I run it air-gapped?
Every server component runs inside your network, and with a local model and no web search there is no required outbound call at runtime. Two things to plan for:
- Official desktop builds check a hosted update service for new versions. Build your own or distribute installers internally if that is unacceptable.
- Web search needs a search provider key on the backend (
EXA_API_KEY). Leave it unset and no search call is possible. A user can also switch the Thunderbolt connection off under Settings → Connections. - Location search, the weather widget and map tiles reach out to Open-Meteo and a map tile host. Turning off the Weather and Map skills under Settings → Skills stops those two. Location search in Settings has no switch, so block it at the network edge if you need to.
We don’t test air-gapped operation today, so treat it as a pilot.
How many devices can one account use?
Ten active devices. Devices awaiting approval do not count against the limit.
What happens if a device is lost or stolen?
Revoke it from Settings → Devices on another device. It can no longer ask for a new sync token, so an online device is cut off within 5 minutes and an offline one when it reconnects. Its sign-in sessions end at once, and the account’s keys are replaced so it cannot read anything written afterwards. That enrolment can never rejoin; re-admitting the same machine means setting it up again as a new device.
Revocation is not a remote wipe. The next time the revoked device runs, it shows a message the user cannot dismiss, offering to keep or delete its local copy of the data. Whatever was already on that device stays readable until its holder chooses to delete it, or until you wipe the device through whatever endpoint management you already use.
What if all devices are lost?
The 24-word recovery phrase shown once at setup is the only way back. Without that phrase, the encrypted data cannot be recovered by the user, by you, or by anyone with access to the server, unless you run organizational key escrow. We recommend making the phrase part of your onboarding.
What happens when a user deletes their account?
Deletion is permanent. The account and everything synced under it are removed from your database outright, and there is no undo inside the app. Every other device that is online notices within seconds, erases its local copy, and signs out. A device that is offline keeps its copy until it reconnects, and after a long gap it is more likely to land on a sign-in prompt with its data intact. Anything sitting in your own database backups is yours to manage under your own retention policy.
Platforms
| Platform | How you get it today |
|---|---|
| Web | You host it |
| macOS (Apple silicon and Intel), Windows (x64 and ARM64), Linux x64 | Installers attached to GitHub releases |
| iOS | TestFlight |
| Android | Play Store internal track |
Mobile builds are not publicly listed in the app stores yet. Every platform runs the same application, so the storage, sync, and encryption answers above apply everywhere.
Comparison
How does this differ from a hosted assistant?
| Thunderbolt | Typical hosted assistant | |
|---|---|---|
| Where conversations are stored | Your device, and your database if sync is on | The vendor’s servers |
| Who chooses the model | You, per chat, across providers and local models | The vendor |
| Server access to content | None for encrypted fields | Full |
| Where it runs | Your infrastructure, including on-prem | The vendor’s cloud |
| Cost model | Software free, you pay for inference | Per seat, per month |
Getting help
Found a bug, or want a feature? Open an issue.
Found a security vulnerability? Use the private reporting form rather than a public issue.
For more depth on the topics above:
- Security and privacy: what is stored, where, and who can see it
- Users and access: sign-in, identity providers, and user access
- Devices: device approval, limits, and revocation
- Configuration: every setting and environment variable