ComfyUI Continues Differentiating Between Local and Cloud
Worth Knowing
When ComfyUI's commercial Terms landed in May, our read was that the pixels are yours but the recipe isn't: the no-training pledge protected your Input and Output, while a carve-out reserved "workflow structures, and node configurations" as metadata Comfy could use.
This week we discovered a new Desktop Privacy Policy, effective June 3, which is the other half of that line, and it is genuinely protective. On your own machine, even with telemetry on, your workflows, prompts, outputs, and model weights never leave the device, which is what makes the Cloud boundary stark: the recipe stays yours right up until you sign in and run it on the Comfy Products, where workflow structure is the metadata the Terms reserve.
In human terms: A VFX freelancer spent two years on her workstation building texture-synthesis workflows for ad clients: the node sequence she refined by trial and error, the sampler choices, the ControlNet chained to her in-painting pass. That craft lives in JSON files on her drive, and the Desktop policy keeps it there, since even with telemetry on the workflow content is not transmitted. Then a brief requires the job to run on hosted infrastructure, so she clicks "Launch Cloud." The workflows transfer cleanly, and her workflow structure, the thing she actually got paid for understanding, is now metadata Comfy is permitted to use to improve its products. The pixels she generates are protected. The recipe that produced them is not.
Why this matters: ComfyUI sits underneath a large share of professional VFX, ad-studio, and game-studio pipelines, which is why the boundary is worth tracing exactly. Outputs commoditize and prompts are noisy, while a workflow encodes expertise: which nodes chain to which, which sampler an artist preferred, an order of operations worked out over months. The Desktop policy confirms that expertise stays local on your own machine. The Cloud carve-out is where it becomes product-improvement input, with no cap, no anonymization requirement, and no time window, while the no-training pledge covers only Input and Output. The contract never says Comfy is building a workflow-savvy agent on user behavior. It does reserve the ability to do so… Below for more…
The mechanics • Desktop keeps the work local. With telemetry on, Comfy Desktop does not transmit "Workflow content (the graph, the nodes you connect, their parameters)," "Prompts you write," "Generated images, video, or audio," or "Model weights." Those "remain on your device... not transmitted to Comfy Org, and... not accessible to us." • The hinge is the identifier. "Before you sign in to Comfy Cloud it is not linked to your name, email address, or hardware. When you sign in, it is associated with your Comfy account." • Cloud is the other side. The commercial Terms pledge that Comfy "will not use Input or Output to train generative AI or diffusion models," then add it "may, however, collect and use limited metadata... such as prompt classifications, workflow structures, and node configurations." "Limited" qualifies the categories, not the volume. • Prompt classifications are the labels a classifier assigns to your prompt: an intent tag, an embedding, a category. Those can be retained even when the prompt text itself never enters a training set. • Per last issue's commercial Terms, work run on the Comfy Products generates "limited metadata... such as prompt classifications, workflow structures, and node configurations" used to improve those products, with a separate pledge not to train models on Input or Output. Desktop files are out of scope; cloud runs are not.