Home›Features
Features

How Linda works

A private assistant for your Mac, from the inside: who does the thinking, its specialists, how it uses a browser, what it remembers, and the rules it can't break.

Version 0.3.12 · Updated 5 October 2026

Architecture at a glance

Linda is a native Swift 6 app with strict concurrency, built from a handful of small modules. The app never talks to a model directly: it talks to the Linda daemon through shared LindaCore types, and the daemon runs each task as a tool-calling loop. Every prompt is built in one place, LindaLaya. Assistants on your Mac run in Linda's own MLX engine on Apple silicon, and every action the assistant takes passes through the Gatekeeper before it touches a browser, a file or an app.

ModuleWhat it does
LindaMac · LindaUIThe app: sidebar with specialists, projects and tasks, the chat, the Computer column, command bar (⌥Space), menu bar extra, notifications with actions, Settings.
LindaDaemonTask runner (up to 3 tasks at once), the native tool-calling loop, plan checklist with proof, routines, skills, connected apps, web search, an activity log per task, gates.
LindaLayaEvery prompt and tool list: tasks, browsing, quick decisions, dictation, skills, each specialist's instructions and the tools it may use. Untrusted text and memories are fenced here.
LindaInferLinda's MLX engine (127.0.0.1, a one-time key) for its assistants, Laya for System One, plus engines for apps on your Mac and online providers.
LindaMemoryQdrant supervisor, a file-store fallback, and a client for your own Qdrant server.
LindaComputerCua Driver, the fast CDP browser engine, the Chrome bridge, the command sandbox, file and Office conversion.
LindaVoicePush to talk, dictation and voice commands on Apple's SpeechAnalyzer.
linda (CLI)linda run "…" runs one task end to end from the terminal, with --local, --online, --chrome and --json.

No third-party Swift packages: Linda is Apple frameworks, signed and notarized. The MLX engine for its assistants is installed and updated privately by Linda the first time you download an assistant (about 0.5 GB, once), apart from your own Python or Homebrew.

Who thinks: on your Mac, an app you run, or online Shipped

In onboarding and in Settings › Assistant you choose who does the thinking. Nothing runs until you choose, and you can switch at any time; the change applies to the next task.

Choose how Linda thinks: On this Mac, Online or Advanced
Onboarding: choose how Linda thinks. On this Mac keeps everything local, with the assistant that fits your Mac recommended first.

1. On this Mac: Linda runs its own assistant

Linda downloads an open model (an MLX build from Hugging Face, 4-bit) and runs it itself on MLX, Apple's machine-learning framework for Apple silicon: native tool calling and streamed replies, about 60 tokens a second for a 4B assistant on an M2 Pro. What it has already read is kept and reused, so a new task starts in about half a second instead of 14. The first time you download an assistant, Linda installs its MLX engine privately (about 0.5 GB, once) and keeps it up to date; nothing touches your own Python or Homebrew. The engine listens only on 127.0.0.1 with a one-time key, is released after 5 idle minutes like Ollama, and never outlives Linda, even after a crash. After the download, nothing leaves your Mac.

It picks for your hardware. Linda reads your chip (M1 to M5; base, Pro, Max or Ultra) and memory and lists its recommended assistants first, then More assistants: every other open assistant that can use Linda's tools, searchable. Each row says whether it runs well, “Leaves little memory for your apps”, or needs a bigger Mac, measured against the memory macOS lets the GPU use. Linda estimates writing speed from memory bandwidth and recommends the strongest one that stays quick. The conversation length is set from the memory left (4K to 64K tokens), and you can change it per assistant in Settings › Assistant › Advanced.

Settings › Assistant: the assistants Linda runs on this Mac, the recommended one first
Settings › Assistant: Linda's recommended assistants first, then More assistants, each with how it runs on this Mac.
FamilyAssistantsDownload
QwenQwen3.5 2B, 4B and 9B · Qwen3 4B Instruct (also tidies dictation) · Qwen3.8 27B · Qwen3.6 35B-A3B · Qwen3 Next 80B · Qwen3.5 122B1.7 to 69.6 GB
GraniteGranite 4.2 3B (IBM), small and steady with tools2.1 GB
gpt-ossgpt-oss 20B and 120B (MXFP4)12.1 · 63.4 GB
GemmaGemma 4 26B15.4 GB

Small assistants answer and work with files well; long multi-site tasks go better with larger ones.

2. Advanced: an app you already run

If you already use Ollama (port 11434), LM Studio (1234) or mlx-lm (8080), Linda talks to it over the OpenAI-compatible API, starts it when a task needs it, and uses the model you pick. Linda suggests Qwen3.5 9B for each of them. Only 127.0.0.1, localhost or ::1 are accepted, so this mode can never point at a remote server.

3. Online: a frontier model with your own key

Bring a key from OpenRouter, OpenAI, Anthropic, Google Gemini, Groq, Mistral, DeepSeek, or any OpenAI-compatible server over https. Suggested first: Claude Sonnet 5.5 (the default), then GPT-6.1 Sol, Gemini 3.1 Pro, and GPT-6 Luna or Qwen3.8 Flash when cost matters; the names are checked against each provider's live list. Keys live in the Keychain, one item per provider. With OpenRouter you also get server-side web search and fetch, the cost of each reply, up to three backup assistants when one is busy, and a live catalog to browse.

One conversation, one family. Within a task you can switch between assistants of the same family (Gemini to Gemini, Qwen to Qwen). Pick one of another family and the message bar says “New task with…”: your message starts a new task in the same folder and project, because each maker's thinking travels with the conversation in a form only its own models accept.

Where your data goes

On this MacApp you runOnline
Your request and the pages it readsStay on your MacStay on your MacGo to the provider you chose
Web searchesThe search provider you pick in Settings › Web Search (Parallel by default), from Linda itself: the query, a short line from your request and a random id per task. No cookies, no browser profile, never your memories, files or conversation. More
PasswordsNever sent anywhere: typed straight into the browser from a secure field
MemoryOn your Mac (or your own Qdrant server). Embeddings use Apple's on-device NaturalLanguage.
VoiceTranscribed on device. Audio is never sent or stored.

In the chat

A task running: the specialist in the header, steps that say what they did, a browser card with Live, and the Computer column
A task at work: Scout in the header with its status, each step in one line, the browser card with Live, Stop where Send was.
  • A header that says who and how it's going. The specialist's mascot with a status dot, the task's name and “Researcher · Checking prices on Amazon”, with Stop and Show Computer beside it.
  • Steps that say what they did. “Saved invoices.pdf · 2.1 KB”, “Ran wc -l notes.md → 41 lines”, the words of a search, the address of a page. When the browser opens, a card shows the page and site with a Live dot.
  • Approvals that stay in the chat. “Review before sending” shows where it goes, the content, Decline and the action; once you decide, the card stays as “Approved · sent” or “Declined”, so the history shows what you allowed.
  • Answers that read like a conversation. Words stream in at a steady pace, even when the provider sends them in bursts, and the finished answer stays exactly where it is: no flash, no jump. Only the answer being written redraws, so long histories stay quick.
  • Who thinks, from the message bar. Switch between the assistant on your Mac, an app you run and online assistants without opening Settings.
  • One Work with button. Who works on the task (Linda or a specialist), the project, which connected apps it may use and a skill to follow, all in one popover. Picking a skill puts /skill-name in your message; typing it works too. Without a choice, Linda matches the skill your words clearly ask for, in a millisecond.
  • Thinking when it helps. Automatic by default: a quick hello skips it, a real task gets it. Set it to off, low, medium or high per chat; the choice appears only for assistants that can think.
  • Watch it work in one line. The working line shows the current step or thought; open it to follow the thinking live. Stop replaces Send while a task runs.
  • Web search without the browser. Every assistant can search the web and read pages directly: no window opens, no cookies are sent, only public addresses are read (never your Mac or your local network). The browser stays for signing in, forms, downloads and pages that need it.
  • Long pages, only the parts that matter. A short page goes whole; a long one is split into passages and ranked against what the assistant is looking for, on your Mac, in milliseconds. It gets the opening and the best parts, sized to its conversation length, and can ask the same page again with other words without a new download. No second model, no vector database.
  • See what fills the conversation. A ring in the message bar shows how full the conversation is; click it for the breakdown in tokens: instructions, skills, Linda's tools, connected apps, memory and the conversation itself.
  • Progress you can see. While the assistant writes a file, the working line says which and how much: “Writing index.html · 1.2K tokens”, with a soft light sweeping across it. Searches and pages read in a row fold into one line, in the order they happened.
  • Web pages you can reload. A page or small site a task builds is shown live in the chat, with Reload after you or Linda change it, and Open in your browser.
  • Research that keeps the conversation short. A question that needs several searches or pages goes to a helper with a fresh conversation; only its notes and links come back. Repeated look-ups are caught and answered from what was already found, so a small assistant doesn't go in circles.
  • Text at your size. ⌘+ and ⌘− in the View menu, or Settings › Appearance › Text size, from smaller to half again as big.
Work with: Linda, Scout or Quill, then the project, apps and skill for the task
Work with: who, which project, which apps and which skill, in one popover.
The conversation ring opened: 63% full, about 10K of 16K tokens, by part
Click the ring in the message bar to see what fills the conversation, in tokens.

Specialists Shipped

A specialist is Linda set up for one kind of work: a name, a role, your instructions, a mascot color, the skills it reaches for first, a project to start in, and what it may use. It is the same assistant and the same approvals; only the setup changes. One specialist per task, and follow-ups stay with it.

Home with Scout chosen: What should Scout work on? Researcher, with Scout and Quill in the sidebar
Specialists in the sidebar, each with its latest task. Pick one and the home page greets you with it.
  • Six roles to start from: Researcher, Writer, Bookkeeper, Organizer, Travel planner and Builder. Each comes with short instructions (“Every fact keeps its link”, “Name files by date and supplier”) and its own skills, all yours to change.
  • May use: Browser, Files, Commands, Memory. Turning one off takes those tools away before the assistant ever sees them, and refuses them again if asked; skills that need them hide. Turning one off while a task runs stops that task. Sending, buying, deleting, posting and personal data still always ask.
  • Starts in a project you pick, or a new one made from the sheet.
  • Everywhere in the task: the chat header, the browser card, the message bar (“Tell Scout more”) and the Computer column follow the task's specialist, and the activity log says who did what.
  • Linda is always there, with everything on. New installs show only Linda until you add a specialist with + in the sidebar.
Edit Scout: name, role Researcher, color, Starts in, 6 skills, instructions and May use switches
The specialist sheet: role, color, project, skills, instructions and what it may use.

System One: quick decisions for the browser

Most browser steps are a choice among what's on the page: click this, pick that option, scroll, or stop. A decision model answers that kind of question far faster than a model that writes text, because it scores the options instead of generating an answer. Linda calls it System One; the assistant you chose is System Two.

  1. At each step, Linda's quick-browse prompt gives System One the goal, the page's actions (up to 60, labelled like CLICK 3, SELECT 2:1, SCROLL_DOWN, DONE) and the recent steps.
  2. System One returns a probability for each option in a single forward pass.
  3. System Two takes over when System One is less than 60% sure, when the step needs typing, when “done” is less than 85% sure, or when System One isn't available.
  4. Every pick goes through the same Gatekeeper: a confident “Place order” still stops for your approval.

Inside Linda. Laya, an open typed-decision model (0.85 GB), downloads by itself and runs inside Linda: about 50 ms a decision once loaded. If you run Ollama 0.35 or later with Nimble 9B, Linda can use Ollama's /v1/systemone endpoint instead (localhost only), when Laya isn't there.

Measured on an M2 Pro on sample flight pages. Laya in Linda: about 50 ms a decision once loaded. Nimble 9B through Ollama 0.35: all three steps right (0.78–0.90), 0.7–1.5 s a decision.

Computer use: Linda's own browser Shipped

Linda works in its own browser profile, in the background: your default Chrome-family browser, launched with a profile that belongs to Linda, so your cookies, history and accounts are never touched. It never takes your mouse or keyboard.

The Computer column on Activity: progress, what Linda did and when, this Mac, and Can use Browser, Files and Memory
The Computer column: Browser, Files, Commands and Activity, with Running, Take Over and what the task can use.
  • The Computer column. Browser shows Linda's browser live with Take Over; Files the folders the task can see and what it made; Commands what it ran and what came back; Activity who did what, where and when. A “Can use Browser, Files and Memory” menu shows the task's permissions and opens them.
  • An activity log per task: who acted (you or the specialist), what, where and the outcome. Typed text is never kept: it says “typed in Destination”, not what was typed.
  • Numbers tied to the page they came from. Each look at a page has an id that every click, fill and download must name. If the page changed since, the step is refused with “Look again” instead of clicking whatever now sits under that number.
  • Fast engine over the DevTools protocol. A Swift port of browser-use's compact page snapshot turns the page into a short numbered list of actions; the assistant picks one; Linda acts and waits for the page. Password and file inputs never appear in snapshots.
  • Cua Driver 0.30.1 (pinned, bounded mode) drives the browser app itself, with background input only.
  • Guard rails: at most 40 actions a run, three steps with no change ends the run, and any gated step stops and asks.
  • Your Chrome, if you want: the Linda extension in the Chrome Web Store (Manifest V3) lets Linda work in your own Chrome, only in its own tabs inside a “Linda” tab group, with Chrome's debugging bar visible, and only on sites you approve one by one. A never-visit list always wins.
  • Several tasks at once: up to three run together; Linda's browser is lent to one task at a time.
  • Take Over: brings the task's tab forward so you can do a tricky step yourself. Linda's next action waits, the fast engine pauses (“Paused: you took over”), and Hand Back makes Linda look at the page again before it goes on. Linda's browser profile and files stay as they are.
  • Dropdowns, keys and page dialogs: it picks options, presses Escape, arrows, Space or Page Down, and reads alerts and confirms. Space on a checkout page asks first, like Return.

Measured: Google Flights, Milan to another Italian city, answered in 18 s in your Chrome and 33 s in Linda's Chrome (9 decisions). The extension reads a page in about half a second.

Files, projects and commands Shipped

A project: its tasks share one folder
Each task sees only its own folder, and the folder of the project you work in.
  • Each task on its own. File actions are Swift code confined to the task's own folder and downloads and its project's folder; nothing carries over between tasks. Overwriting moves the old file to the Trash; deleting always asks.
  • Projects: tasks that share one folder (Documents › Linda Projects, or one you pick), so what one task makes is there for the next. ⇧⌘N starts one.
  • Documents: reads and makes PDF, Word, Excel, PowerPoint and OpenDocument; merges and splits PDFs; previews web pages it builds, live.
  • Command sandbox: when a task needs code (a chart, a QR code, a spreadsheet crunch), it runs under macOS sandbox-exec with deny-by-default rules: an empty environment, the task's own workspace as the only writable place, shared folders read-only, ~/.ssh and Keychains denied, no network until you approve it, and a 120-second limit. A Python toolkit (pandas, openpyxl, matplotlib, reportlab, python-docx, python-pptx…) works offline.
  • Routines: any task can repeat daily, weekly or monthly, with Run Now.
Computer › Files: the task's folders and the files it made
Computer › Files: the folders a task can see, and what it made, one click from a preview.

Memory with Qdrant Shipped

Memory: facts Linda keeps, searchable and editable
Everything Linda remembers is visible, editable and forgettable.

Memory lives in Settings › Memory. Linda remembers what you tell it (“invoices go in Accounting, named by month”) and short summaries of past tasks, and recalls them when relevant.

  • Qdrant 1.19.1 ships inside the app and runs on 127.0.0.1 only. Without it, a small file store takes over.
  • Or your own Qdrant server (self-hosted or Qdrant Cloud): https only, API key in the Keychain, collections named linda_memories and linda_episodes, with a connection check in Settings › Memory.
  • Every search is scoped, to you or to one task, by design of the storage API.
  • Per specialist: turn Memory off for a specialist and nothing is recalled or saved in its tasks.
  • Recalled as data: memories reach the assistant fenced as notes, never as instructions.
  • Only your words become facts. Text from web pages, emails or files is never stored as a fact about you; a red-team test checks it. Remember opens your memory with the request as an editable draft.
  • Embeddings come from Apple's on-device NaturalLanguage framework: no text leaves the Mac to be embedded.

Safety: approvals that can't be skipped Shipped

Five kinds of action always stop for your approval: send, buy, delete, post, and submitting personal data. The rules are code in the Gatekeeper, not instructions to the model, so no setting, web page, skill or prompt can turn them off.

Review before sending: the reply to Marco Rossi, where it goes, Don't send and Send
Review before sending: where it goes, exactly what will be sent, and the choice stays in the chat.
  • Deterministic checks with word lists in English, Italian, German, French and Spanish, plus personal-field and checkout detection. Pressing Enter in a message box counts as sending.
  • Secure sign-in: a login card types your password straight into the browser. It never reaches the assistant, the chat, logs or memory.
  • Secrets in the Keychain (the data protection keychain in released builds).
  • Prompt-injection defenses: fixed core rules, untrusted text fenced, page reports and results from apps marked untrusted with their labels made inert, memories fenced as data, and app tools that write always ask.
  • Specialists can't loosen anything: their switches only take tools away, and their instructions are your words, never text from a page, email or file.
  • No stale clicks: a step aimed at a page that changed since Linda looked is refused, and Take Over pauses every action until you hand back.
  • Red-team suite: fake approvals, hidden sends, “buy now” traps, data exfiltration and a planted IBAN. All six pass with scripted plans.
  • Voice can confirm only while an approval card is on screen.
  • Signed updates: a new version installs only if it's signed by Linda's developer team and its SHA-256 matches the published latest.json.

How approvals work, in detail →

Voice and dictation, on device

  • Push to talk Shipped: hold Right Option (or Right Command, or Fn) and speak; the words appear live. Built on Apple's SpeechAnalyzer; about 50–90 ms from key release to final text on an M2 Pro.
  • Dictation in every message bar: a mic button, then Linda tidies the words (rules first, then the local assistant) on your Mac. Tested in English, Italian, Spanish and French.
  • Short spoken replies, off by default. Audio is never sent or stored.

Apps and skills Shipped

Plugins: apps and skills
  • Search providers under Plugins › Apps › Search: Parallel in use by default, Brave, Tavily and Exa with Add Key…, DuckDuckGo with Use.
  • Apps over MCP: Calendar and Reminders built in; Notion and Todoist with OAuth 2.1 sign-in (PKCE); Linear, GitHub and Stripe with a key from the Keychain; or any app that speaks MCP, added by command, by https address, or imported from Claude, Cursor or VS Code. Read-only tools run; anything that writes asks first.
  • Mac Apps: Linda uses the apps on your Mac through accessibility, in the background: Outlook, Teams, Word, Excel, Numbers, Pages, Keynote, Notes, TextEdit. It reads the window as buttons and fields, then clicks, types, presses keys or picks menu items. Sending, buying, deleting and posting always ask; in mail and chat apps so do Return, line breaks and unnamed buttons. It never types into password fields and never uses Terminal, System Settings, password managers, the Finder or Messages. Text read from an app is treated like a web page: never followed as instructions.
  • Skills in the open SKILL.md format: 26 built in (invoices from a portal, compare prices, fill a form from a file, tidy a folder, build a web page, reconcile payments, slides from a document…), your own in a built-in editor, or skills from Claude, OpenClaw and Hermes. Save as Skill turns a finished task into one. Each built-in skill says which tools it needs and hides when a specialist can't use them. Skills are text: they can't change the gates.

Measured, not promised

WhatResult
Direct answer (Claude Sonnet 5)4 s
Google Flights, Milan to another Italian city18 s in your Chrome · 33 s in Linda's
Invoices sorted into month folders, with a summary sheet67 s
System One decision, M2 Proabout 50 ms (Laya, inside Linda) · 0.7–1.5 s (Nimble 9B via Ollama)
Assistant on your Mac, M2 Pro (Qwen3.5 4B)about 60 tokens a second · a new task starts in about 0.5 s
Push to talk, release to text44–86 ms
Core task suite · documents · red team11/12 · 5/5 · 6/6

The task suites run on local demo sites with scripted plans, to test Linda's hands and gates; they are not a measure of how well a given assistant plans. Evals with the assistant planning are next.

Requirements, updates and languages

  • macOS 26 on Apple silicon (M1 to M5). Linda recommends the local assistants that fit your Mac; online assistants work on any of them.
  • Notarized DMG from download.getlinda.app, not the Mac App Store: the App Store's sandbox doesn't allow an assistant to work in a browser for you.
  • Updates: Linda checks once a day; when a new version is out, the sidebar offers Update and Restart.
  • Languages: English, Italian, Spanish and French.
  • Permissions: Microphone and Accessibility; Calendar and Reminders only if you connect them.

What's next

  • Planned Routines while the Mac sleeps, and “tell me only if it changed”.
  • Planned Gmail, Google Calendar, Drive and Slack apps.
  • Planned Linux tools in Apple's container, for tasks that need them.
  • Planned Evals with the assistant planning, published with the method.

See it on your own Mac

Free, no account. Pick who thinks and type your first task.

Download for Mac