Privacy Policy
Effective: August 19, 2026
The short version
Your Own AI runs on your device. With offline models, your conversations never leave your machine - there is no telemetry, no analytics, and no account required. And you don't have to take our word for it: the app is open source, so anyone can read the code and confirm it. The only times data moves are the ones you choose: downloading a model, using an online model, or signing a receipt. This policy lists every one of them.
On your device
Your conversations, AIs, memories, and knowledge documents are stored on your machine, written into signed, tamper-evident records built on Holochain and encrypted with a key only you hold. We never receive them and cannot read them. Deleting is in your hands: delete conversations individually, or Settings → Reset erases everything. The optional helper and memory models run on your device too, and nothing they read leaves it. Routing keeps a short log of its recent decisions and of what you did with answers, on your device only, and you can reset it in Settings.
What leaves your device, and when
- Offline models: nothing. Ever.
- Downloading models and add-ons: a standard web request to the host (Hugging Face for models, GitHub for add-ons), which sees your IP address like any download.
- Online models (optional, paid): the message you send - and attachments only after you approve sending them - is forwarded through Flowsta's relay to the model provider you chose. Flowsta strips your identity before forwarding; the provider receives the content but not who you are - no name, no email, no account details. The relay passes your messages through without storing or logging them. We record usage amounts only - model, token counts, cost - for billing. Web searches send your query to the search provider the same way. An AI set to Online and Offline sends ordinary questions to your everyday online model by default; the Routing dial decides when a model on your device answers instead, and questions about your health always stay on your device. The full picture, provider by provider, is in the next section.
- Tools and add-ons (optional): a tool your AI uses runs on your device. One that reaches the internet (a web search, a browser) sends your request there under that tool's own terms, and the model driving the tool sees the tool's results as part of the conversation.
- Checking for updates (optional): once a day the app asks this website for a small file naming the latest version, so it can tell you when an update exists. The request carries nothing about you - not even your current version - and nothing is downloaded or installed. Turn it off in Settings.
- Signing a receipt (optional): if you sign an exported conversation, its hash, your public key, and a timestamp are published to Flowsta's public signing network so anyone can verify the file. The conversation itself is never uploaded.
That's the complete list. The app contains no telemetry, analytics, or crash reporting.
Online models in detail
Online models are optional. Every AI you create picks its own model, and an AI on an offline model never sends anything anywhere. When you do use an online model, here is exactly what moves.
What the provider receives. The conversation you send (the messages the model needs to answer, including your AI's instructions and any memories it uses), any attachment you approved, and an opaque per-conversation key - a random id that lets the provider reuse its own cache across the turns of one conversation. The key carries nothing about you. The request goes out from Flowsta's servers under Flowsta's account, so the provider sees Flowsta's address, not yours.
What Flowsta keeps. For each request: which model, the token counts the provider reports (input, cached input, output including the model's thinking, and web searches made), what we charged you, and what the provider charged us. Never the content, never the key. The relay logs errors by their code, not their content.
What the provider may do with it. Once your content reaches a provider it is on their servers, under their policy, and out of our sight. We cannot verify what any provider actually does - a policy is a promise, not proof - and we have always said so. That is exactly why we send as little as we can, strip your identity before it goes, and keep the choice of model with you. What follows is what each provider publishes today, so you can weigh it; the differences are real, and we would rather you saw them before you picked a model.
- OpenAI (United States) - states that API inputs are not used to train its models; retained up to 30 days for abuse monitoring.
- xAI (United States) - states that API inputs are not used to train its models; retained 30 days, then deleted.
- Meta (United States) - states that Standard-tier API prompts and completions are not used to train its models; we use only that tier, never the cheaper Contributor tier that trains on them. No retention period is published.
- Perplexity (United States) - web-search models; states that API inputs are not used to train its models.
- Alibaba Cloud (Qwen models, served from Singapore) - states that customer inputs are not used to train its models.
- Moonshot AI (Kimi models, Singapore) - its policy allows inputs to be used to improve its models, and keeps them while its account with us is active.
- Z.ai (GLM models, Singapore) - its policy allows inputs to be used to improve its models.
- DeepSeek (Hangzhou, China; governed by Chinese law) - its policy allows inputs to be used to improve its models.
A provider appears in this list before the app can route to it: we read its policy first, and the list is kept current with the models on offer; the provider's own page is always the authority, and none of it is something we can promise on their behalf. Our part is what we control: minimal content, no identity, nothing stored on the way through. Yours is the choice - if a provider's stance is not right for a given conversation, use an offline model for it. That choice is yours per AI, per turn.
Backups go to your Vault, not to us
With a Flowsta Vault on your device, Your Own AI automatically backs up your encryption key, conversations, AIs, and memories into the Vault - encrypted, on your own machine. We never receive your backups. You can view, export, or delete them at any time from the Vault's “Your Data” page.
If you sign in with Flowsta
Signing in (needed only for online models) happens through the Flowsta Vault on your device. What Flowsta holds about your account is covered by the Flowsta Privacy Policy. Specific to Your Own AI, the servers hold: your plan and its billing records, usage amounts for online models (the per-request counts listed above - never content), and one activity marker per month - the fact that your account used the app that month, nothing about what you did. Payments are processed by Stripe; we never see your card details.
This website
This site collects nothing beyond standard hosting logs. No tracking, advertising, or analytics cookies. The account page signs in through Flowsta.
Release announcements (optional): if you subscribe in the footer, we store your email address with Mailchimp, our mailing provider, and use it only to announce new releases. Every email has an unsubscribe link, and unsubscribing removes you from the list. Mailchimp processes your address under its own privacy policy.
What we never do
- Sell your data or use it for advertising
- Read your conversations - offline ones never reach us, online ones pass through unstored
- Train AI models on your data
Children
Your Own AI is not for children under 13 (16 in the European Union).
Changes, law, contact
We'll note material changes on this page. Governing law: Victoria, Australia. Questions: privacy@flowsta.com.