iOS app (App Store name): Privacy Policy — Offline AI Studio

Privacy Policy

OfflineGPT · Android

In short

  • For normal on-device use, CodeAlp does not receive, store, sell, or analyze your chats, prompts, images, or voice on our servers. We cannot open your private conversations remotely.
  • Your content stays on your phone or tablet unless you turn on optional features that use the internet (for example your own API keys, web search, or OfflineGPT hosted models). Requests with your own API keys and web-search requests go from your device to the provider you chose. Hosted models are different: if you explicitly select one, the request is sent over HTTPS to the OfflineGPT Gateway. Depending on the model you choose, the Gateway forwards it to Infomaniak AI Services in Switzerland (Gemma 4), to OpenAI (GPT-6 Luna and GPT-4o mini), or to DeepSeek (DeepSeek Flash). Prompt and response bodies are processed by OfflineGPT transiently in memory for forwarding and are not stored by OfflineGPT as a cloud chat archive.
  • We do not sell your personal data. We do not use your chats for advertising profiles.

1. Introduction

This Privacy Policy describes how OfflineGPT (“the App”) handles information when you use the App on Android, and how we handle information when you visit this policy on codealp.ch/privacy-offlinegpt (“Website”).

The related iOS app is listed on the App Store as Offline AI Studio; it has a separate privacy policy. Principles match; details follow each platform.

OfflineGPT is built offline-first: the default path is local AI on your device. The App also offers optional online features (such as connecting to external AI providers with your API keys, web search, downloading models, or OfflineGPT hosted models). You decide whether to use them. Hosted models are used only when you select them.

2. Responsible Entity / Contact

Controller / responsible entity: CodeAlp Responsible person: F. B. (natural person) Contact (privacy): info@codealp.ch

3. Scope of This Policy

This policy covers the OfflineGPT app for Android (Google Play) and this Website. It does not replace the privacy policies of third-party services you choose to use (for example OpenAI, Google, or a search engine when you enable those features in the App).

4. What CodeAlp actually receives

Core on-device use: Chats, generated text and images, imports, OCR results, transcriptions, and tool outputs are processed and stored on your device. CodeAlp does not collect copies of that content on our own servers for that mode of operation. We are not “syncing” your private threads to ourselves.

Why privacy policies still mention “personal data”: If you type your name or personal notes into the App, that content is personal to you—but it remains on your device unless you use an optional online feature that sends it somewhere else. We describe this so we are honest with regulators; it does not mean CodeAlp secretly accesses it.

We may receive limited information in these situations:

  • You email us (e.g. support)—we receive what you put in that message.
  • In-app purchases—Google Play Billing handles payment on Android; we may receive non-payment-card signals from the store needed to confirm a hosted-models subscription (see Section 9).
  • OfflineGPT hosted models—if you explicitly select it, the OfflineGPT Gateway receives the request in order to verify the subscription and allowed model, then forwards it to the inference provider for the selected model: Infomaniak AI Services for Gemma 4, OpenAI for GPT-6 Luna and GPT-4o mini, or DeepSeek for DeepSeek Flash. Prompt and response bodies are processed by OfflineGPT transiently in memory and are not retained by OfflineGPT as chat content (see Section 6).
  • This Website—like any website, hosting can create basic technical logs when you load a page (see Section 12).

5. On-device processing (default)

When you use local models and local tools, processing happens on your device. That includes, depending on your settings: chat history, on-device text and image generation, OCR, speech-to-text where implemented on-device, safety checks where implemented on-device, settings, and downloaded model files.

CodeAlp has no remote access to that local data. Uninstalling the App or clearing app data removes it from your device according to Android’s rules—we cannot remotely wipe or read your chats.

6. Optional internet use (your choice)

Some features need a network connection. Examples: downloading or updating models, optional web search, using an external AI provider with your own keys, or OfflineGPT hosted models. You choose whether to use these; they are not required for core offline-style use after models are installed.

OfflineGPT hosted models: If you explicitly select a hosted model, the App sends the request over HTTPS to the OfflineGPT Gateway operated by CodeAlp. The Gateway verifies the active subscription and the allowed model, then forwards the request for inference. Gemma 4 is processed by Infomaniak AI Services in Swiss data centers. GPT-6 Luna and GPT-4o mini are processed by OpenAI. DeepSeek Flash is processed by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. DeepSeek states that it collects, processes and stores personal data in the People's Republic of China, so Chinese data protection law applies to that inference path. The generated response is streamed back to the App. The Gateway necessarily processes prompt and response data transiently in memory while forwarding. OfflineGPT does not persist prompt bodies, response bodies, cloud conversation histories, or uploaded content as a personal cloud library, including when you use hosted models. OfflineGPT does not train on your requests.

Infomaniak states that submitted AI requests are not stored and that prompts are not used to train models or improve its services. See Infomaniak AI Services. OpenAI publishes its practices in the OpenAI Privacy Policy. DeepSeek publishes its own practices in the DeepSeek Privacy Policy. Optional web search, external APIs, or networked Python operations may send relevant data to those services under their own terms when you enable or invoke them.

7. External AI providers (your API keys)

If you enable optional cloud providers and enter your own API keys (for example OpenAI, DeepSeek, Gemini, Groq, Mistral, xAI, OpenRouter, or a custom compatible endpoint), requests go from your device directly to that provider (or the URL you configured). For that path, CodeAlp does not sit in the middle as a data processor of those chats—we do not run the inference backend for those providers. This is separate from OfflineGPT hosted models, which uses the OfflineGPT Gateway when you select it.

Your keys are stored on your device as part of the App configuration. What you send (prompts, attachments, etc.) is then handled under that provider’s terms and privacy policy. You are responsible for choosing providers you trust and for complying with their rules.

We do not control how a third party logs, stores, or trains on data sent to them—check their documentation.

8. Web search and websites

If you use optional web search, your query may go to a search engine (such as DuckDuckGo or another engine as implemented). The App may fetch public web pages to summarize or extract content. That traffic is between your device and those services—not a hidden pipeline to CodeAlp for your chat history.

9. In-app purchases

On Android, the current paid offer is the OfflineGPT hosted models subscription through Google Play Billing. Payment card data is handled by Google, not by us. We do not receive your full card number. We may receive limited store signals to confirm the subscription, plus technically necessary billing, access, and operational metadata (for example an anonymous entitlement identifier, access state, validity period, and aggregate usage or abuse-prevention information). That metadata is not your chat and does not contain persistently stored prompt or response bodies. There is no one-time Pro purchase as the current sales model.

See Google’s Privacy Policy.

10. Permissions

The App may ask for microphone (voice input), camera (capture), and photos/files (import)—for the features those permissions serve. For local features, processing stays on the device. Content only goes to a third party if you use an optional online provider or web feature that sends it.

11. Storage on your device

The App keeps data locally: chats, outputs, settings, models, API configuration, keys, and purchase state as shown in the App. Third-party model files have their own licenses (see in-app or separate license information).

You can delete data via system settings or by uninstalling.

12. Third parties and this Website

Google Play: provides the store and purchase flows for this Android app.

Infomaniak AI Services: When you select Gemma 4 in OfflineGPT hosted models, inference is provided by Infomaniak in Swiss data centers after the OfflineGPT Gateway forwards the request.

OpenAI: When you select GPT-6 Luna or GPT-4o mini in OfflineGPT hosted models, inference is provided by OpenAI after the OfflineGPT Gateway forwards the request. See the OpenAI Privacy Policy.

DeepSeek: When you select DeepSeek Flash in OfflineGPT hosted models, inference is provided by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. after the OfflineGPT Gateway forwards the request. DeepSeek states that personal data is processed and stored in the People's Republic of China. Chinese data protection law applies to that path. OfflineGPT still does not keep a cloud chat archive. See the DeepSeek Privacy Policy.

Providers you turn on: Only when you use optional cloud or web features do those companies receive what you send, as explained above.

Website hosting: Visiting codealp.ch may generate standard technical logs (e.g. IP address, time, page) at the hosting layer. We do not use those logs to reconstruct your App chats—we do not have your App chats on the server in the first place for local use.

13. Legal bases (EEA / UK)

Where EU/UK law applies, we rely on appropriate grounds—for example contract and legitimate interests for providing the App, the Website, and support, and for purchase validation through Google Play. Optional online features you activate may involve consent or contract with third parties under their terms.

14. Your rights

For information held only on your device, you manage it yourself (delete app data, uninstall). We generally cannot export or erase that from afar because we do not hold a copy.

For personal data we do hold (such as support emails or purchase-related records available to us), you may have rights under applicable law (access, correction, deletion, objection, complaint to a supervisory authority). Contact us at info@codealp.ch—we aim to reply within two business days when reasonable.

15. Children’s privacy

The App is not aimed at young children. We do not knowingly collect children’s information beyond what is unavoidable in ordinary support or store processes. If you believe there is a problem, contact us.

16. Security

Local data is protected by your device (passcode, OS sandbox). You choose whether to store API keys in the App. No system is perfect; use device security and trusted networks when you enable online features.

17. Changes

We may update this policy. The current text is always at codealp.ch/privacy-offlinegpt. Material changes may be announced in the App or on the site where appropriate.

18. Contact

info@codealp.ch

Last updated: September 14, 2026