No intermediary server sits between you and your AI. Your conversations, your keys, and your voice stay on your own devices and the gateway you run. Here's exactly how it works - and where the limits are.
We run no server of our own. There's nothing in the middle to log, leak, or hand over.
Zero usage data flows to us. No analytics, no ad SDK, no crash SDK of ours.
You're a random ID kept in your own Keychain - never sent to us.
API keys and gateway tokens live in the Apple Keychain - end-to-end encrypted across your devices if you use iCloud Keychain.
Fresh installs transcribe on your device with Apple's engine. A cloud voice is opt-in, with your own key.
Stored on your device and your private iCloud database, encrypted by Apple - the way your Notes are.
From the moment you speak to the moment the reply syncs back - every hop, and who's in it.
On your iPhone, iPad, Mac, Apple Watch, or CarPlay.
On-device by default - your voice never leaves the device. Or choose a cloud transcriber and the audio goes straight there, under your own key.
On-device · or your cloud keySent directly to the AI server you run - over HTTPS, with your own token. No relay in between.
The model runs on your gateway, or the hosted provider you picked with your key, and the reply returns the same way. That server does receive your message - that's how it answers.
Apple's on-device voice by default; a cloud voice is opt-in with your key. Spoken replies are off by default everywhere except CarPlay.
On-device · or your cloud keyThe thread is stored in the app's on-device database and synced across your devices through your own private iCloud. We keep no copy.
The same private AI, reached three different ways.
| Conduck | Vendor cloud app | Self-host via a chat bridge* | |
|---|---|---|---|
| Where conversations live | Your device + your own iCloud | The vendor's servers | Your server - but messages pass through the chat platform |
| Who holds your keys | You, in your Keychain | The vendor | You, plus the bridge / bot host |
| A third party in the middle | No relay | The vendor, always | The messaging platform's servers |
| Telemetry / analytics | None | Typically yes | Varies by bridge & setup |
| Signing in | No account - nothing to sign into | An account tied to you | Your chat-app account + a bot |
| Transport | Direct HTTPS to your gateway | HTTPS to the vendor | Through the messaging platform |
| App Store privacy label | Data Not Collected | Varies by vendor | - |
| Best fit | Apple-native, direct control of your own AI | Turnkey - nothing to host | Reach your AI from chat apps you already use |
* A “chat bridge” means reaching a self-hosted AI through a chat-app bot - for example a Telegram or WhatsApp bridge. Exact behavior depends on the bridge and the services you pick; this describes common setups, not any specific product.
What “we never see your data” does - and doesn't - cover.
Your gateway, model, and any cloud voice you pick receive your messages to do their job. Their retention and use are set by their terms - choose them like any vendor.
Encryption keeps your data private on the way. What a provider does once it arrives is up to that provider.
Your conversations sync through whichever iCloud account is signed in. It's blind to us, but it's governed by Apple and your own iCloud settings.
A photo or screenshot is sent to your gateway when you hit send - so it can contain whatever was on your screen. And when your AI writes a file back, the chat may keep a small preview of it, synced through your own iCloud like the rest of the conversation.
This page explains the architecture. The privacy policy is the legal detail.