Privacy: self-hosted openWakeWord mode sends ambient PCM only to authenticated JARVIS wake detector on your own VPS; never Deepgram. Deepgram receives command audio only after “Jarvis” detection or push-to-talk. Grok requests leave VPS through xAI. Route always shown.
API MANAGEMENTENCRYPTED VAULT
Runs from VPS while Mac is off. Desktop Codex app is not used. Only approved bounded jobs dispatch; arbitrary shell and unscoped prompts remain blocked.
WAKE DETECTOR · JARVISOFF
Official openWakeWord runtime is Python/server-side. Browser-native ONNX/WASM chain was not shipped because full preprocessing + embedding + classifier path lacks validated official browser integration. This opt-in adapter sends audio only over same-origin WSS to your self-hosted detector—not Deepgram or another vendor. Exact “Jarvis” requires user-supplied trained model; bundled upstream model detects “Hey Jarvis,” so it is not substituted.