Privacy Policy
LocalML Privacy Policy
LocalML is a privacy-first Apple-native workspace. This policy describes how the released LocalML app handles information.
Effective date: August 14, 2026
Provider and summary
LocalML is provided by Ashkan Zanjani. Core workspace data stays on your device unless you explicitly export or share it or enable optional iCloud chat sync. LocalML does not use advertising SDKs, tracking SDKs, third-party analytics SDKs, or third-party AI model providers.
On-device Apple model processing
When Apple Intelligence and Apple Foundation Models are available, LocalML text generation runs on device through Apple's Foundation Models framework. The app does not send prompts, documents, chat history, attachments, or voice transcripts to OpenAI, Anthropic, Google, Hugging Face, or another third-party AI provider. If Apple Intelligence is unavailable, LocalML explains the applicable device, language, region, operating-system, or model-readiness requirement instead of routing the request to another model provider.
Information stored locally
Depending on the features you use, chats, prompts, projects, imported-document text, local search chunks, OCR text, citations, generated artifacts and images, optional memory, settings, local diagnostics, and temporary voice files may be stored on your device. This information remains local unless you explicitly share or export it or enable the optional iCloud chat-sync path described below.
You can review and delete local categories in Settings > Data & Privacy. Exports and feedback reports use Apple's system share sheet; LocalML does not choose a destination or upload them automatically.
Optional iCloud chat sync
iCloud chat sync is off by default. If you enable it, LocalML stores supported conversation fields in the private CloudKit database of your Apple Account so conversations can continue across your Apple devices. The developer does not operate a separate sync server and does not access users' private CloudKit records through a support or administrative service.
Synced chat payloads can include conversation and message identifiers, titles, previews, message text, sent voice transcripts, saved requests and responses, timestamps, message status, routing and display metadata, and structured answers or artifacts stored in a chat. Attachment files, raw imported documents, raw OCR sources, source-citation records, generated-image files, projects, the document index, memory, settings, local diagnostics, composer drafts, and raw voice audio do not sync as separate fields.
Schema version 3 stores inline chat payloads and sensitive preview and deletion fields with CloudKit encrypted values. Larger encoded chat payloads use assets in the private CloudKit database. Integrity and ordering metadata such as schema version, revision, checksum, and update time remains ordinary record metadata and contains no chat text.
Web Source Access
Web Source Access is off by default. If you enable it, LocalML can contact a public HTTPS address you provide or a page selected through General Web Research to retrieve readable source text. The destination website receives ordinary connection information such as your IP address and may apply its own logging, terms, retention, and privacy policy. LocalML uses an ephemeral connection without stored cookies, credentials, cache, or a referrer and does not copy fetched pages to a developer-operated server.
General Web Research and Brave Search
General Web Research is off by default and requires Web Source Access plus a Brave Search API key that you save in the device Keychain. When you request public-web research, an on-device Apple model may create one bounded query. LocalML sends Brave Search the query, basic language or region parameters, and your API credential. It does not send Brave your chat history, attachments, documents, memory, fetched page text, voice transcript, model answer, or precise location.
Brave can associate the request with your Brave Search API account and may retain or process the query under its terms and privacy policy. For App Store privacy reporting, the bounded query is treated as linked Search History used only for App Functionality and not for tracking. Brave returns public result locators; LocalML contacts a bounded number of selected websites separately and performs final synthesis on device with Apple Foundation Models. Cited URLs and excerpts may remain in your local conversation.
Apple Online Research and Apple Maps
Apple Online Research is enabled by default and can be turned off in Settings > Data & Privacy. For recognized place, address, landmark, or point-of-interest requests, LocalML sends a bounded version of the request to Apple Maps. It does not include your chat history, documents, memory, voice transcript, or precise device location. Apple Maps results are supplied as sources to the on-device Apple Foundation Models response. Apple handles Apple Maps according to Apple's terms and privacy practices.
Optional Spotlight indexing
Spotlight integration is off by default. If enabled, LocalML indexes only approved document and generated-image metadata. It does not index raw chat transcripts, raw document contents, screenshot OCR, voice transcripts, memory, or internal prompts. The named Spotlight index uses Apple Data Protection.
Camera, photos, microphone, and speech
Camera access is requested only when you choose to capture an image for visual analysis or OCR. The system photo picker is used when you choose an existing image. Selected pixels are analyzed on device with Apple Vision; LocalML does not use face regions for identity or emotion inference and does not automatically open barcode content.
Microphone and Speech access are requested only when you start dictation or a voice conversation. Transcription requires an on-device Apple Speech path and does not fall back to a third-party transcription service. Spoken replies use installed Apple system voices. Temporary voice files are protected on device and included in LocalML cleanup controls.
Feedback, diagnostics, analytics, and tracking
LocalML can prepare a response-feedback report, but nothing is uploaded automatically. If you explicitly include an Apple Foundation diagnostic, the protected report may contain the in-memory Foundation Models session transcript and is shared only after you choose a destination in the system share sheet.
The app contains no developer-operated telemetry endpoint, advertising SDK, third-party analytics SDK, or cross-app tracking mechanism. Apple may provide system crash or App Store analytics according to your Apple settings and Apple's policies.
Price and purchases
LocalML is offered free of charge and contains no subscriptions or in-app purchases. It contains no advertising.
Retention and deletion
Local information is retained until you delete it, remove the app, or iOS removes the app's data. LocalML provides category-specific and broad deletion controls. Turning iCloud chat sync off stops future sync but does not automatically delete existing iCloud records. When sync is enabled, LocalML records deletion intent locally and retries transient CloudKit failures until Apple confirms the operation. A CloudKit deletion record becomes eligible for cleanup after 365 days when no live conversation record remains, but it may remain longer until a later sync performs cleanup.
Apple may retain iCloud, system diagnostic, Siri, Speech, Spotlight, Image Playground, or Apple Maps information according to Apple's own terms, account settings, legal requirements, and retention practices. To request deletion of information contained in a support email, contact support from the address used for that request.
Children
LocalML is a general-purpose productivity app and is not designed or marketed for the Kids Category. Do not provide information about a child unless you have the authority and legal basis to do so.
Changes and contact
This policy may be updated when LocalML data practices change. Material changes will be reflected by updating the effective date.
For privacy questions or deletion requests, contact azanjani@me.com. For troubleshooting, use the LocalML Support page.