aiity

Privacy Policy

For the aiity iOS app and the aiity.de website · 1 August 2026

In short: aiity has no server of its own. There is no account and no sign-up. Your conversations, mini-apps and access keys stay on your device. We do not collect, store or process any personal data about you. Once you enter an AI provider, however, what you type goes directly from your device to that provider, and their privacy policy applies there. That is the only point at which data leaves your device, and it is your decision.

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR):

Xianjie Zhan
Kölner Str. 205
41468 Neuss
Germany
Email: getaiityapp@gmail.com

aiity is a private, non-commercial project run by an individual.

2. The app collects nothing

aiity runs no backend service. There is no registration, no login and no user account. The app sends us no usage statistics, no telemetry and no crash reports. There is no tracking, and no advertising or analytics SDKs are used.

The following exists only locally on your device and is never seen by us:

3. Access keys

API keys and OAuth tokens you enter for an AI provider are stored in your device’s keychain — not in a settings file, and not in a backup file you export. They leave your device only as part of a request to the exact provider you entered them for.

4. AI providers you choose yourself

aiity is a client with no model of its own. For the app to answer anything you have to configure a provider. From that point on, the contents of your conversation — text, images where applicable, and the system context you selected — are transmitted directly from your device to that provider. There is no intermediate server of ours.

What that provider stores, for how long, and whether they use it for training is governed solely by their terms. Please read the privacy policy of the provider you use. Depending on the provider, processing may take place outside the EU.

If you instead run a model on the device itself (Apple MLX), nothing leaves your iPhone in order to generate an answer. The model itself is downloaded once from the source you choose.

The legal basis for this transmission is Art. 6(1)(b) GDPR — performing the function you requested.

5. Web search and page fetching

When you use the web tools, or an agent does, your query is sent to the search service you selected in settings and the page is loaded directly by your device. Again, there is no intermediate server of ours. For local models the web tools are off by default.

6. iCloud sync (optional)

You can turn on syncing of your saved mini-apps via iCloud. The data then lives in your own private iCloud database at Apple and is synced between your devices. We have no access to it. Apple’s privacy terms apply. The feature can be switched off at any time; locally stored data is kept.

7. Diagnostics

The app keeps a small local record of how the last program run ended (app version, iOS version, device model, memory use, the name of the configured provider, and a list of technical events). It contains no message content and no access keys. This record stays on the device. It is transmitted only if you export it yourself via “Share” and actively send it. You can delete it in the app at any time.

Separately, Apple may collect crash reports if you have allowed that in iOS settings. That is an operating system feature.

8. Reporting content

AI answers are not filtered by us in advance. A message's context menu (“Inhalt melden”) lets you report one. The app shows you the complete text of the report first, and you send it yourself by email to getaiityapp@gmail.com — there is no aiity server that receives reports automatically. What is transmitted is only the reported message, the reason you chose, an optional note, and the model, app and iOS versions. The rest of the conversation, your access keys and diagnostic data are not included.

9. Mini-apps

Mini-apps generated by the AI run in a sandbox (a WKWebView with a strict Content Security Policy). A mini-app has no access to your conversations, your access keys, or the data of other mini-apps; storage is separated per mini-app. A mini-app reaches the network only if you explicitly allow it, and opening an external link is presented to you for confirmation first.

10. The aiity.de website

This site is static, sets no cookies, and embeds no external resources, fonts or analytics services. When you visit it, the server processes technically necessary connection data (IP address, time, requested file, user agent) in order to deliver and secure the site. The legal basis is Art. 6(1)(f) GDPR. This data is not combined into profiles.

11. Your rights

Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to lodge a complaint with a supervisory authority (Art. 77).

In practice: because we store no personal data about you, we can neither give you access to your content nor delete it — we simply do not have it. Your data is on your device and with the providers you entered yourself. You can delete it by removing the app’s data or the app; for the provider’s side, please contact that provider directly.

12. Children

The app is not directed at children. Using it requires your own access to an AI service, whose age limits apply in addition.

13. Changes

If how the app works changes, this policy will be updated. The version published here, with the date given above, is the one that applies.

← Back to the home page