Loci
Privacy Policy
Loci AI, Inc., a Delaware corporation (“Loci AI,” “we,” “us,” or “our”), provides the Loci application (“Loci”). This Privacy Policy explains what information Loci handles, what remains on your device, what is transmitted, and to whom.
Summary. Loci runs AI models on your device. Your conversations are stored locally, are not sent to us in ordinary use, and are not used to train or fine-tune AI models. Some information does leave your device: diagnostics, optional advertising measurement, requests to third-party services when you use web and live-data features, model downloads, a periodic check for updates to our model catalog, and encrypted traffic between devices when you use Loci Link. Each is described below.
1. Information that remains on your device
The following are stored locally and are not transmitted to us in ordinary use of Loci:
- Your conversations, including prompts, responses, titles, and history
- Images and files you attach, and text extracted from them
- Saved memories and custom instructions
- Calendar, reminder, location, and voice information accessed through device permissions
- Installed model files
AI processing takes place on your device. We do not receive your prompts or the model’s responses in ordinary use, and we do not use your content to train or fine-tune AI models.
Content displayed outside the application. Depending on your settings, Loci may make conversation titles or response previews available to features of your operating system, including widgets, device search, notifications, and Shortcuts or voice assistants. Loci also retains local backup and recovery copies of its data to protect against data loss. These remain on your device.
Temporary chats are scheduled for automatic deletion but may remain in local storage until deletion completes.
2. Diagnostic information
When diagnostic sharing is enabled, Loci transmits operational information to our servers. This information is pseudonymous rather than anonymous: it includes persistent identifiers that link records over time and may constitute personal information under applicable law.
Diagnostics are designed to exclude your content. They do not include prompt or response text, transcripts, file or image contents, voice recordings, saved memory text, calendar or reminder contents, search queries, or precise location coordinates.
Android acquisition measurement. Android versions that support this measurement may read Google Play's install-referrer information after onboarding is complete and diagnostic sharing is enabled. The app reduces it on your device to a broad source, such as Google advertising, another paid source, Play organic discovery, another referral, or unknown, plus a recognized Loci campaign identifier and the original installation time when available. We use this information with pseudonymous usage records to compare activation and return use. Raw referrer URLs, ad-click identifiers, advertising IDs, and search terms are not stored or sent to our servers through this feature. Disabling diagnostic sharing prevents this collection and upload.
Android advertising conversion measurement. Supported Android versions also use Google Analytics for Firebase when diagnostic sharing is enabled. Measurement can begin at the first app open, before onboarding is complete, once the app has loaded the saved diagnostic-sharing setting and completed its Temporary Chat privacy checks. Google receives app-use events, including eligible app-open and session events and the first eligible successful answer saved and displayed, together with an app-instance identifier and standard app, device, session, and network information. Users upgrading from versions without this measurement may generate a first-open event when Analytics first starts; this does not necessarily mean a new installation. Google may derive approximate location from network information and process Google Play referral information to attribute an event to advertising. This measurement is separate from the reduced acquisition labels sent to our own servers.
We link these events to our Google Ads account to measure which campaigns lead to actual app use. We do not send conversation text, prompt or answer content, conversation identifiers, names, email addresses, or account identifiers through this integration. Advertising-ID collection, automatic screen reporting, and personalized advertising are disabled. Diagnostic sharing can be disabled in Settings; this stops future collection and resets the local Analytics identifier and pending Analytics data. Collection is also suspended while Temporary Chat privacy controls block diagnostics. Previously transmitted information is not recalled by changing this setting. Google processes measurement information under its privacy policy and the applicable Analytics and Ads terms.
Apple app conversion measurement. Supported App Store versions of Loci for iPhone, iPad, and Mac use Google Analytics for Firebase when diagnostic sharing is enabled. This measurement is enabled for new installations, not backfilled from existing conversations. Google receives app-open and session events and one event when the first eligible successful answer is saved and displayed in an ordinary chat. These events include an app-instance identifier and standard app, device, session, and network information; Google may derive approximate location from network information. We do not send prompt or answer content, conversation identifiers, names, email addresses, or account identifiers through this integration. Advertising identifiers, vendor-identifier collection, automatic screen reporting, and personalized advertising are disabled.
We use this measurement to evaluate advertising and app activation. Supported iPhone and iPad versions also include Google's on-device conversion measurement for event data, which processes temporary, de-identified event information on the device. We do not provide email addresses or phone numbers for conversion matching. Mac app-use measurement does not by itself identify which advertisement led to an installation. Temporary chats do not trigger the first-answer conversion. Disabling diagnostic sharing stops future collection and resets the local Analytics identifier and pending Analytics data; it does not recall information already transmitted. Google's privacy policy and the applicable Analytics and Ads terms govern its processing.
Repeat-use measurement. Supported Android and App Store versions for iPhone, iPad, and Mac may send Google one additional event after an eligible installation receives successful answers to three distinct original prompts. Each answer must be saved and displayed in an ordinary chat. The prompts can be in the same conversation or different conversations, in one session or several, with no time limit between them. Retries, regenerated answers, imported conversations, and redisplayed history do not advance this count. This measures continued use, not whether you return on a later day. A small counter and up to three local prompt references prevent duplicate counting; these references are not sent to Google.
Return-use and review-intent measurement. Supported Android and App Store versions for iPhone, iPad, and Mac may also send Google an event when an eligible installation produces another successful, saved-and-displayed answer in a later app session, at least 24 hours after the first qualifying answer observed by this measurement. They may send a separate event when, after receiving a qualifying answer, you choose a dedicated review link and your operating system accepts the request to open the store. A review-link tap before that answer does not become a conversion later. This records review intent, not confirmation that a review editor appeared or that you submitted a review. These events do not include review text or a star rating. Small records on your device retain the original answer time, local answer and session references, and delivery state to recognize return use, retry pending events, and limit duplicate reports. These local references are not sent to Google. All answer, repeat-use, return-use, and review-intent events follow the installation-eligibility, diagnostic-sharing, and Temporary Chat controls described above; existing conversation histories are not scanned or backfilled.
Windows diagnostic sharing. Starting with Windows 1.0.31, diagnostic sharing is enabled by default when no previous choice is saved. A saved choice to turn sharing off stays off. Sharing may begin at first launch while setup is in progress. It includes feature usage, generation performance, reliability information, and a random persistent app-device identifier. Turn sharing off in Settings → Privacy → Advanced diagnostics. On Windows, turning it off stops new collection for upload, cancels pending transmission, clears pending reports, and retires the app-device identifier; the opt-out itself is recorded locally. Previously transmitted records are not recalled, and local operational diagnostics remain on your device.
Windows usage milestones. In supported Windows versions, when diagnostic sharing is enabled, Loci can record the first successful answer saved and displayed, answers to three distinct original prompts, return use in a later session at least 24 hours later, and a qualifying review-link handoff. These content-free events go to our diagnostic service, not through Google Analytics or a Google Ads conversion feed. They do not identify which advertisement, if any, led to the installation. Local progress and pending-delivery records support duplicate prevention and retries; disabling sharing stops future collection and clears pending reports. No prompt, answer, or review text is included.
Diagnostics include:
| Category | Information |
|---|---|
| Identifiers | An installation identifier that persists across reinstallation; session and conversation identifiers |
| Device and software | Device and processor class, memory, operating system version, application version, device name, locale, time zone, and network type |
| Approximate location | Country derived from IP address, and locale country |
| Usage | Model selected, feature usage, settings state, and runtime configuration |
| Message characteristics | Estimated message and token counts and mode indicators, but not message content |
| Performance | Load times, response times, throughput, and resource usage |
| Errors | Error categories and codes, sanitized error messages, and crash, memory, and storage events |
We also receive standard transport information with these requests, including IP address and user agent.
Your choice. Diagnostic sharing can be enabled or disabled in Settings. When you disable it, we record that fact, discard information pending transmission, and retire the installation identifier. Previously transmitted records are retained for the period described in Section 9.
Optional desktop advertising measurement
Supported desktop versions of Loci can optionally connect a Google ad visit to app-use milestones. This requires a separate choice on askloci.ai and confirmation in Loci. The connection is available only to eligible new installations. Declining does not affect your ability to use Loci. This connection is separate from Google Analytics and the diagnostic milestones described above, including Windows diagnostic reports.
If you allow the connection, our server receives the Google ad-click identifier and creates a short-lived, random handoff link. The desktop app receives only that random link, not the Google click identifier. After you confirm in the app, Loci may report your first successful answer saved and displayed, successful answers to three distinct original prompts, and a successful answer to a new prompt submitted during a foreground session that starts at least 24 hours after the first answer. If you agree to the expanded milestone list on the website and in Loci, it may also report successful answers on three separate activity days spanning at least 48 hours from the first answer. Earlier connections keep their original milestone scope. Where a verified store-review link is available, Loci may also report that you opened it after activation. Opening a review link indicates intent; it does not confirm that you posted a review. Imported or previously saved conversations do not create these milestones.
Loci sends the milestone name, its original time, and a random delivery identifier to our server. Our server associates it with the ad-click identifier and sends the conversion to Google Ads. Google can use these records to attribute app use to the ad and improve campaign bidding. We do not send prompt, answer, conversation, or review text, names, email addresses, or account identifiers through this connection.
The website uses handoff information in the same browser tab for up to 30 minutes and honors Global Privacy Control and Do Not Track. Expired browser information is cleared when the page next checks it. Unclaimed handoff links expire after 30 minutes, or after seven days when created for a direct Mac download. Bound connections and conversion records expire 90 days after the handoff was created. Expired raw click identifiers and associated records are removed during scheduled cleanup. Click-related hashes remain during the original 90-day period to prevent duplicate connections. A separate withdrawal hash expires 90 days after withdrawal and is removed during scheduled cleanup; it prevents a delayed request from reactivating measurement. Short-lived request-rate records are removed after two days during cleanup. Your app keeps small local progress and retry records; these are not your chat history.
You can stop this measurement in Loci’s Settings. Loci then blocks new milestones, clears pending local conversion data, and requests removal of the stored click identifier and cancellation of pending server delivery. Removal requests retry when connectivity returns. Stopping measurement cannot recall events Google has already received. Applicable app-wide privacy controls can also stop collection. Google’s retention and processing of received records are governed by its privacy policy and the applicable Analytics and Ads terms.
3. Model catalog updates
Loci checks for an updated model catalog no more than once every 24 hours. This check is independent of your diagnostic and web settings. It transmits standard request information, including IP address, and no conversation content.
Because of this check, Loci is not entirely free of network activity. Model processing itself operates without an internet connection once a model has been downloaded.
4. Support and feedback
If certain failures occur while diagnostic sharing is enabled, Loci may send a diagnostic report containing application, device, model, and error information. These reports are designed to exclude conversation content.
General feedback on Windows. If you open the sidebar feedback form and choose Send feedback, Loci sends your message and a required, content-free diagnostics.json report directly to our support database, which is hosted for us by Supabase. The report contains a report identifier and timestamp; persistent installation and session identifiers; app and build versions; operating-system version; locale; device tier and memory; the selected model identifier; and a support snapshot containing app, device, model, and content-free reliability information. It does not contain your conversations, prompts, responses, or files. The form shows this disclosure before you send; nothing is sent if you cancel. The attachment is required for this form and cannot be removed. We use the submission to investigate and respond to product problems, protect the support service, and improve Loci. It is retained for the period in Section 9.
Reporting a particular response. The separate Report this response flow first lets you review the response locally. If you continue, Loci opens a draft in your email app containing a report reference and blank guidance only. Your prompt, response, conversation, and diagnostics are not attached automatically. Your email provider processes whatever you choose to send.
5. Web and live-data features
When you use web search or current-information features, online retrieval may run automatically for eligible questions according to your Use sources setting or when you request it. Depending on the request, the Loci app sends directly from your device (a) a bounded query to one or more search providers, (b) only the fields needed for a live-data request—such as a place, ticker, team, date, country, or language—to the applicable provider, and/or (c) a request for selected result pages to those page operators. A continuation, retry, regeneration, or clarification may reuse or combine earlier question or task text. Network recipients may receive ordinary connection information, such as an IP address; depending on the route, a request may also include a Loci or browser-style user-agent and language preference. Text you type—including confidential or privileged information—may be included in a manually requested or otherwise eligible online request. Beyond the reused text described above, other chat history and attached-file contents are not sent as provider request data. These direct third-party requests do not pass through a Loci server; each provider handles what it receives under its own privacy policy.
On Windows, an open-web lookup may send the same bounded query concurrently to one or more of Bing, DuckDuckGo, and Wikipedia, subject to temporary provider cooldowns. It may request a bounded set of selected public HTTPS pages and admits readable page text from at most two. Availability and cooldowns mean not every lookup contacts every provider.
Location-based requests on Windows. After you choose Use My Location, the Loci app handles the Windows location on your device only for that request. It rounds the coordinates to two decimal places (approximately one kilometre) and sends them directly to BigDataCloud, an independent reverse-geocoding provider, to obtain a city or area name. No coordinates are sent to or stored by Loci AI, Inc., and they are not included in diagnostics. BigDataCloud may receive ordinary connection information, such as an IP address, and handles the request under its own privacy policy. The resulting place name may then be included in a request to the weather, live-data, mapping, or search provider needed for your request, just as if you had typed the place name.
Providers include search services (Microsoft Bing, DuckDuckGo, Mojeek, Google, Wikimedia), reverse-geocoding services (BigDataCloud), weather and mapping services (Open-Meteo, Apple), financial, sports, entertainment and reference data services, publisher news feeds, the operators of any web page retrieved or opened, and the hosts from which models are downloaded (including our model host, Hugging Face, ModelScope, and GitHub).
If you configure Loci to use separately installed model software on your own device, that connection does not leave your device.
6. Loci Link and paired devices
Loci Link is an optional feature that lets a phone use models running on a paired Mac or PC. Linking starts when you scan or enter a short-lived pairing credential shown by the computer. The devices then retain a cryptographic pairing record and the other device’s name or identifier until you remove that device.
When you use Loci Link, the paired devices exchange the phone’s model request, prompt, selected conversation history and settings, the computer’s model availability and status, and the generated response. This information goes to the paired device you chose. If conversation mirroring is offered and you consent during pairing, the phone may also send read-only copies of its conversations to that paired computer. Those copies are stored on the computer and can be removed by removing the linked device.
On the same local network, the devices connect directly over an encrypted and authenticated connection. Away from that network, or when the direct connection is unavailable, they may use our rendezvous and relay service at link.askloci.ai, which is hosted by Cloudflare. The relay receives ordinary network information such as IP address and connection timing, plus a derived pair handle, a public verification key, presence and last-seen state, and encrypted traffic. Conversation text, model responses, and long-term pairing secrets are end-to-end encrypted and are not available to the relay in plaintext.
The relay forwards encrypted traffic in real time rather than storing conversation content. Its derived pair registration and last-seen state remain while the computer is present and for up to 24 hours after it disconnects. Cloudflare may retain operational and security logs under its own policies. You can stop future Loci Link access by removing a linked device in Settings; this revokes that device’s pairing key and removes its mirrored conversations from the computer.
7. Device permissions
Loci requests your permission before accessing your calendar, reminders, microphone, camera, photo library, files, and location. This information is processed on your device. Granting permission does not cause the content to be transmitted to us.
Except for Windows voice typing described below, speech recognition is configured to operate on your device; we do not receive audio or transcripts. On Windows, the voice button invokes Windows voice typing; Windows may use Microsoft’s online speech-recognition service under your Windows privacy settings. Loci AI does not receive or store that audio or transcript. Approximate location is disclosed only as described in Section 5. Changes you make to your calendar or reminders may sync through your own accounts according to your device settings.
8. Pre-release and internal test versions
Development and internal test versions of Loci may capture full conversation content, including prompts and responses, and transmit it to us for evaluation. This capability is not present in the version distributed through the Apple App Store or in a Microsoft Store build, including an initial private-audience submission or a later package flight. If you participate in a separate internal test program in which it is enabled, we will disclose this to you separately.
9. Retention
We retain diagnostic information for 12 months from collection and support and feedback reports for 90 days, after which they are deleted.
Information you delete within Loci is removed from its primary storage. Copies may persist temporarily in local backups, in your device’s search index, in notifications already delivered, and in exports you have created.
Uninstalling on Windows. An ordinary Windows uninstall removes Loci’s program files but may intentionally preserve local conversations, preferences, linked-device records, and downloaded models so that an update, repair, or reinstall does not destroy your data. Before uninstalling, you can delete conversations in Loci and remove models in the model manager. To remove all remaining Loci data after uninstalling, delete the Loci folder under Windows Local AppData and, if it exists, the Loci folder under Windows Roaming AppData. These are typically %LOCALAPPDATA%\Loci and %APPDATA%\Loci. Other operating systems may remove app-managed local data with the application, subject to that system’s backup and retention behavior.
Information transmitted to third-party providers through the features described in Section 5 is retained by those providers under their own policies and cannot be recalled by us.
10. Data location
Diagnostic and support information is stored on servers located in the United States. If you use Loci from outside the United States, this information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
Loci Link relay connections and their limited registration, presence, and security metadata are processed on Cloudflare infrastructure and may be processed in countries where Cloudflare operates.
11. What we do not do
- We do not use your content to train or fine-tune AI models
- We do not sell your personal information
- We do not display advertising in Loci
- We do not require an account or login
These statements describe our own practices. They do not extend to independent third-party providers you reach through the features described in Section 5.
12. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal information, to opt out of certain processing, or to appeal a decision regarding a request. To make a request, contact us at michael@lociai.app.
13. Children
Loci is not directed to children under 16, and we do not knowingly collect personal information from them. If you are under 16, please do not use Loci.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email to the address associated with your use of Loci, where available, or through the application.
15. Contact
Questions about this Privacy Policy may be directed to michael@lociai.app.
Website
Our website at askloci.ai uses Vercel Web Analytics and Speed Insights to understand aggregate traffic and site performance. These services do not use cookies or persistent identifiers and do not follow visitors across websites or days. We do not use session replay or heatmaps.
Website analytics may include the requested page, limited campaign parameters, referring site, timestamp, coarse location, browser, operating system, device type, and performance measurements such as page-load responsiveness and layout stability. We also measure button and link clicks, download destinations, demo topics, FAQ openings, sections viewed, and whether a visit includes an interaction or 30 seconds with the page visible. Typed demo questions are not collected. Vercel reports this information in aggregate. We do not send names, email addresses, form contents, or anything from the Loci application to website analytics.
Windows installer download requests. Our download service records a random request identifier, request time, platform, architecture, and the installer’s version, checksum, and source revision. These records contain no persistent visitor identifier, referral details, or URL query parameters. Recording respects Global Privacy Control and Do Not Track. A request record does not confirm a completed download, installation, or generated answer.
Google Ads measurement. When a visitor arrives through a Google ad, askloci.ai loads a Google Ads conversion tag for that browser session. Google receives the ad-click identifier, requested website page, ordinary browser, device, and network information, and an event if the visitor selects an official Loci download link. Google may use cookies or similar storage to attribute that event to the ad. We do not send names, email addresses, form contents, conversation content, or information from the Loci application through this tag. The tag is not loaded for other website visits.
Links shared on websites, newsletters, and other placements may contain a short source or campaign label. We carry these labels in website links and pass them to Apple App Store or Google Play download links so their aggregate reports can show which placements lead to downloads. These referral links do not add cookies, browser storage, personal identifiers, or advertising scripts. We honor Global Privacy Control and Do Not Track when adding these labels.
For Google-ad visits, Android download links may pass a fixed source label, a recognized Loci campaign label, and the original Google click information (gclid or gbraid) to the official Loci listing on Google Play. This helps Google connect a website ad click with a later app installation and eligible app-use event. The site keeps only these click fields in the browser tab's session storage and uses them for up to 30 minutes. Expired values are removed on the next check; values are also cleared when a browser privacy signal is detected or a different referral source is visited. If that storage is unavailable, the handoff works only from the current landing page. We do not add these fields to Vercel analytics, Loci's diagnostic reports, Apple or Windows download links, or unrelated website links. Search terms and other landing-page query fields are not included in this handoff. In-app measurement remains subject to the diagnostic-sharing and Temporary Chat controls described above.
askloci.ai honors Global Privacy Control and browser Do Not Track signals. When either signal is enabled, the site does not send analytics, performance, or Google Ads conversion events. Our hosting provider may still process basic server logs, such as IP address, browser type, requested page, and time of request, to deliver and secure the site.
Vercel discards the temporary identifier used for aggregate website visitor counts after 24 hours. Aggregate website metrics and hosting logs may be retained as needed to operate, secure, and improve the website or comply with law.
Get Loci
Private AI that keeps working.
Download Loci once, then chat without an account, chat upload, or signal.