Privacy Policy
Your conversations stay on your device. The website uses cookieless analytics and keeps limited error records and any support messages you send.
Effective 25 August 2026.
Who we are
Numen Technologies Limited makes Private LLM and is the data controller for the processing described here.
Numen Technologies Limited
Work Hub, 77 Camden Street
Dublin D02XE80
Ireland
Registered in Ireland with CRO number 677823.
For any privacy question or request, write to us at [email protected].
What this policy covers
This policy covers the privatellm.app website and the Private LLM app for iPhone, iPad, and Mac.
The app and the website are described in separate sections below, because the app collects nothing at all while the website has a contact form, analytics, and embedded posts and videos.
This policy does not cover other companies. When you download a model, follow a link from one of our articles, or load an embedded post or video, you are dealing with that company under its own privacy policy, and we are not responsible for what it does with your data.
We publish this policy in several languages. The English version is the one that controls. If a translation and the English text disagree, the English text applies.
The Private LLM app
The app collects no personal data, does not track you, and contacts no tracking domains. There is no account, no sign-up, no analytics SDK, no advertising SDK, and no crash-reporting service anywhere in it.
Everything you type and everything the model writes back stays on your device. The model runs on your device's GPU. Your prompts and the model's replies are never transmitted to us or to anyone else, because there is no server in the loop to transmit them to.
- Your conversations: chats are ordinary files in the app's own storage on your device. Private LLM has no iCloud sync and no iCloud entitlement, so your conversations do not leave the device through us or through Apple. They are also marked as excluded from device backups, so they do not travel into an iCloud or computer backup either. Deleting a conversation in the app deletes the file.
- Model downloads: the only network traffic the app generates is downloading the models you choose. Those downloads come from models.privatellm.app, a download host we operate, and from huggingface.co. On a device set to Chinese for mainland China or Hong Kong, the app uses the hf-mirror.com mirror in place of huggingface.co, because Hugging Face is not reliably reachable there. The requests carry no account, no app-level identifier, and nothing from your conversations. Like any network request, they do reach those hosts from your device's IP address, and the hosting and content-delivery entry below covers what those providers see.
- Sending us a support message from inside the app: the Help screen can assemble a diagnostic block for you: device model, operating system version, app version, build, how the app was distributed, memory figures, and any crash summary the system recorded in the last twenty-four hours. That block is built on your device. Nothing is sent anywhere until you press the button that opens a pre-filled email to us, or copy the text yourself. The crash summaries are stored in the app's cache, and are deleted after a day.
- Ratings: after you have used the app for a while, it may ask Apple to show the standard App Store rating prompt. That request goes through Apple's StoreKit and tells us nothing about you. Whether you rate the app, and what you write, is between you and Apple.
- Purchases: Private LLM is a one-time purchase on the App Store. Apple handles the payments and refunds. The app holds no payment data, and there are no in-app purchases and no subscription.
- Exporting a conversation: you can export a conversation as a PDF or as text. The file is produced on your device and saved where you tell the system to save it. Nothing is uploaded.
The app is distributed through the App Store. Apple sees an app download the way it sees any other, and gives us anonymous sales and territory reports that do not identify you. That is between you and Apple, and it is described in Apple's own privacy policy.
Models are published by others. Once a model is on your device it runs there and reports to nobody. A download from models.privatellm.app is a request to us, covered by this policy. A download from huggingface.co, or from the hf-mirror.com mirror the app uses in place of it on a device set to Chinese for mainland China or Hong Kong, is a request to a host that is not us, and that host has its own privacy policy for the requests it receives.
The privatellm.app website
The website is a different surface from the app. It is a marketing and documentation site: a home page, a model catalog, an FAQ, articles, comparison pages, and Shortcuts guides.
The website runs no AI model and has nowhere to chat. Nothing you do on this site touches the conversations in your app, because we cannot reach them.
The contact form is the only place where you intentionally submit personal data. The site also retains the limited analytics and scrubbed error records described below.
The contact form
The support form on our home page asks for your name, your email address, the kind of question you have, and your message. If you pick a technical issue, it also asks which platform you are on and which device you use, because that is what we need in order to answer.
We do not store form submissions. The message is relayed to our mailbox by our email delivery provider, and it then lives in our mail account for as long as we need it to answer you.
The form is protected by Cloudflare Turnstile and by a per-IP rate limit.
Analytics
We measure how the website is used with an analytics tool we host ourselves on our own infrastructure and serve from our own domain. There is no Google Analytics, no tag manager, and no advertising pixel anywhere on this site.
It sets no cookies and builds no cross-site profile. It records page paths, the query string an inbound link carries (including campaign tags and advertising click IDs), referrers, your browser, operating system, device type, screen size, browser language, and an approximate location down to city level, derived from your IP address. It also records named events such as a button click or an App Store link being followed. It never records anything you type.
Your IP address is processed transiently to derive that approximate location and the daily-salted hash that groups a visit. It is not stored.
The legal basis is our legitimate interest in understanding how our own site performs. We weighed that against your interests and concluded it is proportionate: the measurement is first-party, cookieless, content-free, confined to this one site, and never shared with an advertising network.
The app does none of this. It carries no analytics at all.
Embedded posts and videos
Some articles and FAQ answers quote a post from X or a video from YouTube. Those embeds do not load when the page loads. What you get first is a plain placeholder we serve ourselves, with a button.
Nothing reaches X or YouTube until you press that button, unless you have already chosen to load embeds from that service. When you press it, your browser fetches the post or the video from them directly, and at that moment they can see your address and set their own cookies, under their own privacy policies rather than this one. One press also loads every other embed from the same service on that page. YouTube videos are requested from youtube-nocookie.com, Google's reduced-tracking host, but it is still Google receiving the request.
Your choice is stored in your own browser, separately for each of the two providers. On a later page or a later visit, embeds from a service you have already chosen to load start loading as soon as the page does, without another press. Clearing your browser storage withdraws the choice, and if your browser blocks that storage in the first place (private browsing, for instance) the choice never persists and you are asked again each visit; either way, nothing loads without a press. The legal basis for loading an embed is your consent, and the press is how you give it.
Error reports
When something on the website breaks, your browser can send an error report to an error tracker we also host ourselves. The report describes the failure so we can fix it.
Before a browser error report is stored, query strings are stripped from URLs and identifiers are removed. The legal basis is our legitimate interest in keeping the site working.
The same error tracker also receives performance measurements: a sampled share of ordinary page loads and requests is timed and sent there even when nothing breaks, scrubbed the same way. We use those measurements only to keep the site fast and working, on the same legal basis and with the same handling as the error reports.
The app sends us no crash reports and no error reports of any kind. If you want us to see a crash, you send it to us yourself from the Help screen.
Cookies and browser storage
There is very little here, and none of it is an advertising cookie. The table below is the complete list.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| NEXT_LOCALE | First-party cookie | Records the language the site serves you — the one you pick in the language switcher, negotiated from your browser's language settings when you open the site at its root, or set to English when you follow the English link on a legal page — so later visits land in the same one. Strictly necessary for delivering the site in that language. | Until you close the browser |
| Theme preference | First-party local storage | Remembers whether you chose the light or the dark theme. | Until you clear it |
| Embed consent - X | First-party local storage | Remembers that you agreed to load embedded posts from X, so the placeholder stops asking on every page. | Until you clear it |
| Embed consent - YouTube | First-party local storage | Remembers that you agreed to load embedded videos from YouTube, so the placeholder stops asking on every page. | Until you clear it |
| Cloudflare Turnstile | Third-party security challenge | Tells a person from a bot on the contact form. | Per challenge, set by Cloudflare |
| cf_clearance | Cookie, set by Cloudflare | Appears only if Cloudflare has to challenge suspicious traffic, so that a visitor who passes the challenge is not asked again. It protects the site; it does not track you. On an ordinary visit it is never set. | Short-lived, set by Cloudflare |
There is no consent banner on this site because there is nothing here that needs consent taken in advance: the locale cookie only remembers which language to serve you, the analytics are cookieless and first-party, Turnstile and Cloudflare's cf_clearance challenge cookie are security measures that protect the site rather than track you, and the only genuine third-party embed does not load until you click it.
Why we process data, and on what legal basis
Every purpose we process data for needs a legal basis under the GDPR. The table below is the complete list.
| What we do | Data involved | Legal basis (GDPR) |
|---|---|---|
| Answer a message you sent us | Name, email address, question type, message, and for a technical report the platform and device model | Article 6(1)(b) and Article 6(1)(f), answering your request |
| Block bots and keep the contact form available | Connection data processed by Cloudflare Turnstile, and a per-IP rate limit | Article 6(1)(f), our legitimate interest in a form that survives abuse |
| Serve a model file you asked the app to download | The file requested and the connection data any download carries | Article 6(1)(b), taking steps at your request |
| Measure how the site is used | Cookieless, content-free page and event data | Article 6(1)(f), our legitimate interest in improving our own site |
| Load an embedded post or video after you click it | The request your browser makes to X or to YouTube, including your address | Article 6(1)(a), your consent, given by the click |
| Diagnose errors | Error reports and performance measurements with query strings stripped from URLs and identifiers removed | Article 6(1)(f), our legitimate interest in a working service |
| Meet legal obligations, including accounting and tax | Records Apple and our accountants require | Article 6(1)(c), legal obligation |
Who else is involved
We keep as much as possible in our own hands. Our analytics, our error tracking, and our databases are all operated by us, not bought as a service, so they are not third parties receiving your data.
These providers process data on our behalf:
- Our hosting provider - runs our servers.
- Cloudflare - DNS, TLS, content delivery, Turnstile, and encrypted off-site backup storage (R2).
- Our email delivery provider - delivery of messages sent through the contact form.
- Apple - the App Store, and the standard rating prompt.
Hugging Face, X, and YouTube are not on that list, because they do not process anything on our behalf. When you download a model from Hugging Face or click an embed, you are dealing with those companies directly, and they answer for that processing themselves.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models. We disclose data to a public authority only where the law requires it.
How long we keep things
We keep little:
- Your conversations: never held by us at all. They are files on your device, and we have no copy and no way to get one.
- Model downloads: we do not build a download history tied to you. Our hosting and content-delivery providers process the ordinary connection data any file transfer needs in order to happen.
- Support messages: kept in our mailbox for as long as we need them to deal with your request.
- Analytics: kept indefinitely as event records. Our analytics groups a visit using a hash that is re-salted every day, so there is no identifier that follows you from one day to the next, and the IP address the hash is derived from is not stored. Where an inbound link carried an advertising click ID, that ID stays part of the recorded URL.
- Error reports and performance measurements: kept while they are still useful for fixing the fault or keeping the site fast, with query strings stripped from URLs and identifiers removed before they are stored.
Our servers are backed up nightly to encrypted off-site storage, and those backups are kept for up to about six months. They can contain the analytics and the scrubbed error and performance records described above. Contact-form submissions are not saved in our database, but the messages remain in our mailbox and follow that mail system's retention and backup process.
International transfers
We are an Irish company. The cloud servers that run this site and its APIs are hosted in the European Union. Some of the providers listed above are established in the United States and may process data there or in other countries.
The safeguard for each transfer depends on that provider's arrangement: either an adequacy decision or the European Commission's standard contractual clauses, as required by Chapter V of the GDPR. Contact us if you need the current details for a particular provider.
A model download you start goes wherever that host is, and the fallback mirror is a different host again. Nothing about your conversations travels with the request; it is a file transfer, and the file is the same one for everybody who asks for it.
Security
Traffic to the site is encrypted in transit. Backups are encrypted. Access to production systems is limited to the people who need it.
If we ever suffer a breach that puts your rights at risk, we will notify the Irish Data Protection Commission and, where the law requires it, you.
Children
Private LLM is a general-audience tool for adults, and some of the models it can run are uncensored. It is not directed at children, and we do not knowingly collect personal data from children. If you think a child has sent us personal data through the contact form, write to [email protected] and we will delete it.
Changes to this policy
We update this policy when what we do changes. The effective date at the top always tells you which version you are reading. We keep a full revision history of this page, and we will share the relevant changes on request.
We do not ask you to click a box accepting it.
Your rights
Which rights you have depends on where you live. To exercise any of them, write to [email protected]. We answer within the time the applicable law allows, and there is no charge. We may ask you for enough information to be sure the request is really yours, and no more.
One limitation: we hold no app conversations and cannot reach the files on your device. We may hold support messages, cookieless analytics records, and scrubbed website error reports. If we cannot find data that identifies you, we will tell you so rather than invent a match.
European Union and European Economic Area (GDPR)
You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing that already happened.
Where we rely on legitimate interests, you can object on grounds relating to your particular situation, and we will stop unless we have compelling grounds that override yours.
Our lead supervisory authority is the Irish Data Protection Commission. You can complain to it, or to the authority in the country where you live. The list of national authorities is published by the European Data Protection Board.
United Kingdom (UK GDPR and Data Protection Act 2018)
You have the same set of rights described above. You can complain to the Information Commissioner's Office at ico.org.uk.
United States state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to know what personal information we collect, to get a copy of it, to have it deleted, to correct it, and not to be treated worse for exercising those rights. Not every right exists in every state.
We do not sell personal information and we do not share it for cross-context behavioral advertising, in any state, for any price. Because there is no sale or sharing to stop, a Global Privacy Control signal has nothing here to opt you out of. We do not use sensitive personal information to infer characteristics about you.
To exercise a state right, write to [email protected]. If we cannot verify a request, we will say so and explain why.
Canada (PIPEDA)
You can ask what personal information we hold about you, how we use it, and who we disclose it to, and you can ask us to correct it. You can complain to the Office of the Privacy Commissioner of Canada.
If you are in Quebec, Law 25 gives you further rights, including rights around automated decisions and data portability. We do not make automated decisions that produce legal effects about you.
Brazil (LGPD)
You have the right to confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about with whom we share data, and revocation of consent. You can complain to the Autoridade Nacional de Proteção de Dados.
India (Digital Personal Data Protection Act 2023)
You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance route. Send grievances to [email protected], which is our contact point for this purpose.
Australia (Privacy Act 1988 and the APPs)
You can ask for access to the personal information we hold about you and ask us to correct it. If you are unhappy with how we handled a privacy matter, complain to us first at [email protected]. If our answer does not satisfy you, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au.
Contact us
Privacy questions, requests, and complaints all go to the same address: [email protected]
The terms that govern your use of this site are in our Terms of Use.