POCKET PI

Understand what stays and what connects

Privacy, in plain language.

Phone inference is local by default. Downloads, optional connections, purchases and advertising have their own data flows. This policy explains those boundaries and the choices you control.

Last updated: 4 October 2026 · Covers Pocket Pi Local AI, including version 1.0.

Who provides Pocket Pi

Pocket Pi Local AI is developed by Richard Ziolkowski. For app support or privacy questions, email rzkowski@gmail.com. No Pocket Pi account is required to use the app.

This policy describes the app. The product and support pages are hosted at pocket-pi-local-ai.pages.dev; ordinary website requests are handled by the website's hosting provider, Cloudflare Pages. Links to other services are subject to those services' policies.

Local AI content and storage

Downloaded phone models perform inference on your device by default. Pocket Pi does not silently fall back to a developer-hosted cloud inference service. A local prompt can include the text you enter and sources you explicitly attach to the current chat.

Chats, imported sources, saved answers, generated images and project organization are stored in the app's local workspace. Private work uses iOS file protection. Downloaded model weights use protection that permits a download to continue after the device has been unlocked; those models are excluded from device backup. Your saved work may be included in device backups according to your system settings.

The developer does not receive your local workspace through the phone inference feature. You can deliberately send content out of the app through sharing, exports, a chosen native tool, optional Mac mode or support email. These actions are separate from local inference.

Connections you may use

Model downloads and discovery

When you browse, search for or download models, Pocket Pi connects to the selected model source, such as Hugging Face or a publisher's release host. Model search sends the search text to Hugging Face; repository and file requests send the requested resource. The host also receives ordinary network information, including your IP address. Public suggested downloads do not need an account.

An optional Hugging Face read token is stored in the device Keychain and authenticates requests to your Hugging Face account. This lets the provider associate those requests with that account. Pocket Pi does not send chat prompts, AI outputs, photos, document contents or contacts through the model browser.

Hugging Face records service-use information and controls its retention. Exact search-query retention is not specified publicly, so our privacy disclosure conservatively includes Search History and User ID for model discovery and account authentication, linked to the user where an account token is used. These are app-functionality disclosures, separate from advertising tracking. See Hugging Face's privacy policy, its access-token documentation, and its account and IP rate-limit documentation.

Optional paired Mac

Mac mode is off by default. When you deliberately pair and enable your own Mac, Pocket Pi can send the bounded current chat context, attached text excerpts and relevant tool results to that Mac for inference. It does not send the entire workspace. The Mac runs under your control and may have its own logging; review its configuration before sending sensitive material.

Purchases and consent

Apple handles the optional Remove ads purchase and restoration through your App Store account. Pocket Pi verifies transaction and entitlement information to apply ad removal; it does not receive your payment-card details. Google's User Messaging Platform is used for the applicable advertising consent and privacy-options flow. These services can require a network connection.

Advertising and Google SDK data

The free app can show non-personalized banner ads during eligible main-app browsing. Before advertising starts, Pocket Pi checks ad-removal status, obtains your choice to continue with ads, requires authorized Apple tracking permission, and completes applicable Google consent checks. The Google Mobile Ads SDK does not start while tracking permission is denied, restricted or not yet authorized. Every AI feature remains free if you decline; you do not need to purchase ad removal. Banners and new ad requests are suppressed in Offline only mode and during active app work. Advertising is not included in widgets or the Share extension. A verified Remove ads purchase removes banners and stops new ad requests.

Pocket Pi never includes AI prompts, AI outputs, photos, documents or contacts in advertising requests.

The bundled Google Mobile Ads SDK (13.11.0) can process IP address and coarse location, device or app identifiers, advertising data and product interactions, diagnostics and performance data. Location, identifier and interaction categories can be linked to a device. With authorized Apple tracking permission and applicable Google consent, advertising identifiers and related data may be used for advertising measurement across apps and websites. Non-personalized ad selection does not eliminate that tracking or other SDK processing. Pocket Pi requests non-personalized ads, disables publisher personalization treatment and disables the publisher first-party ID; these settings do not mean no data collection.

Pocket Pi disables the SDK's crash reporting. App Store privacy disclosures conservatively include the bundled SDK's crash, diagnostic and performance categories. This differs from the app's optional diagnostic export, which omits chat, document and audio content.

Google processes advertising and consent data under its own policies. See Google's privacy policy, Google's iOS SDK data-disclosure guidance, and its explanation of non-personalized ads. The App Store privacy label discloses applicable advertising tracking, linked identifiers, coarse location and interactions, and the conservative SDK diagnostic categories. “Non-personalized” is not a claim of no tracking or no SDK data collection.

Permissions and Apple integrations

Pocket Pi asks for access when you choose a feature that needs it. Examples include camera capture, microphone and on-device speech, adding a chosen image to Photos, selected location or contact tools, and reviewed Calendar or Reminders actions. Choosing a photo through Apple's picker gives the app that selection; it does not grant unrestricted photo-library access.

Voice capture lets you review the transcription before sending it. Recordings are deleted after transcription or cancellation. On-device speech and translation may need supported language assets to be installed. Apple's interfaces and device capabilities determine availability.

Calendar, Reminders, Photos, file providers, sharing destinations and other system accounts may synchronize through your settings. Exported or native copies are separate from the app workspace. Review the content and destination before confirming an action.

Spotlight indexing is optional and includes only chosen titles and type labels, not document text or image descriptions. Project names become available to widget, Shortcut and Share configuration only when you enable that separate option. These titles can appear outside the app lock. Live Activities use generic progress stages without prompts, project names or images.

Choices you control

  • Apple tracking permission: choose whether to allow it when Apple asks. Denied or restricted permission prevents Google Mobile Ads initialization and new ad requests; all AI features remain free. You can change permission in iOS Settings → Privacy & Security → Tracking, where available. Revoking permission after SDK activation removes banners and stops new requests; an already in-flight SDK request may still complete.
  • Offline only: pauses model browsing and downloads, disables optional paired Mac connections, and pauses new ad requests. An advertising SDK request already in progress may still complete. It does not turn off the device network or control independent Apple services and file providers.
  • Remove ads: an optional one-time purchase, intended US price US$0.99 or the local App Store price. All AI features are free whether or not you buy it. Open Settings → Ads & purchases → Remove ads to buy or restore the purchase.
  • Google advertising privacy choices: available in Settings → Ads & purchases when the consent service provides a required privacy-options form. Applicable options depend on region and consent status. Google consent, Apple tracking permission and ad removal are separate controls.
  • App lock and temporary chats: optional device authentication and temporary chat controls help limit access and retained conversation history. Saved files, images and confirmed native actions remain separate.
  • System visibility: choose whether to publish project names and which titles are indexed in Spotlight. Turning off project-name sharing removes the app's snapshot; existing widget or Shortcut configurations may retain a saved label until you edit or remove them.
  • Attachments and actions: select current-chat sources, inspect proposed edits and review native actions before confirming them.

Removing ads stops new ad requests from Pocket Pi; it does not delete information that a third-party service has already received. Google and Apple provide their own account and privacy controls.

Retention, deletion and exported copies

Saved work remains on the device until you delete it or remove the app's data. Deleted chats stay in Recently Deleted for 30 days unless you permanently remove them sooner. Document deletion removes its local original, index and versions; information already included in another saved answer or chat remains in that item.

Temporary chat history is discarded on relaunch. Separately saved files, created images and confirmed native actions remain. Shared items stay in the intake area until you import or delete them. Failed model downloads can be discarded from the model or image-download interface.

Deleting a project folder does not itself delete its chats or Library sources. Copies exported to Files, Photos, another app, a paired Mac, or a system account are controlled separately. Device backups can contain saved work and may require their own deletion controls.

Google controls retention of the SDK data it receives under its own policy. Model providers, including Hugging Face, control their request and service-usage records; use their privacy controls for provider-held information. Apple controls purchase records and system-account data. If you email support, the developer receives the information you choose to send and keeps it as needed to handle the request and related support. Do not send credentials or private AI content unless you intend the developer to receive it.

Questions and policy changes

Richard Ziolkowski · Pocket Pi developer

rzkowski@gmail.com

Contact for app privacy questions, support, or questions about information you deliberately sent to support.

This page will be updated if the app's data flows change. The date above identifies the current policy. For help with local deletion controls, model downloads or restoring purchases, visit Pocket Pi support.