Settings & local data

Manage appearance, notifications, usage, exports, onboarding, provider data, and complete local deletion.

Open Settings from the chat screen. The current source groups controls into Provider, Generation, Appearance & data, and Token usage.

Settings directory

EntryWhat you can change
Provider & API keySelect/enable a provider, save or delete its key, select/search/refresh models, and add or delete a custom endpoint. See Providers & models.
GenerationSet Temperature, Max output tokens, and response-completion notifications. Reasoning level is beside the model in the model picker. See Generation controls.
AppearanceOpen the Appearance & data page for theme, accent, onboarding, and complete local erase.
Token usageOpen the usage page and refresh local token/cost summaries.

Settings are global preferences. The active conversation retains its provider identity; model and generation-setting behavior is described in the linked guides.

Appearance

Under Appearance & data:

  • Theme: System (default), Light, or Dark.
  • Brand accent: Malachite (default), Clay, or Amber.
  • Show onboarding: reopen the first-run privacy and setup walkthrough.

Theme and accent update immediately and persist as local preferences. Reduced-motion handling follows the platform setting; it is not a separate Cordy toggle.

Response notifications

Under Generation, Response notifications is off by default. When enabled, Cordy may post a system notification when a background reply completes or fails. Android 13+ requests notification permission when you opt in. Denying it does not stop generation; replies finish without a notification.

Token usage

Open Settings → Token usage, then tap Refresh when you need a current local calculation. The page shows Estimated cost, Input, Output, Generations, a Daily trend, and By model rows. A leading means token counts were estimated locally because the provider did not return usage. Cost uses pricing captured when the run completes; unknown prices show . Reconcile with the provider bill.

Export and delete one conversation

  • Export creates Markdown and opens the system share surface, with clipboard fallback.
  • Delete from a library row removes that conversation, its messages, generation runs, and referenced attachments.

Neither action changes provider keys or other conversations.

Remove a provider key or custom provider

In Provider settings, saving a blank key deletes that provider's secure-storage entry. Deleting a user-defined provider also removes its key, cached catalog, and active selection if it was selected. Built-in provider presets cannot be deleted; they can be disabled under Availability.

Erase all local data

Open Settings → Appearance & data → Erase all local data and confirm. Cordy first stops active generation and pending settings writes, then attempts every owned boundary:

  1. conversations, messages, generation runs, user-defined providers, and model catalog;
  2. the complete preferences store, including onboarding and voice disclosure;
  3. all provider keys;
  4. attachment files;
  5. image memory/disk caches;
  6. capture temporary files.

The operation continues across boundaries if one fails and reports the failed boundary. A success resets the app to a blank first-run state. It cannot delete the app binary, provider-side data, OS backups, or data already sent to a provider.

See Privacy & security for storage details and platform evidence limits.