# LLM Studio Privacy Policy

Effective date: September 8, 2026 (free Google Play release 1.0)

LLM Studio runs language models on your Android device without a LLM Studio account. The first Google Play release, version 1.0, is free and contains no advertising or in-app purchases. It does not include AppLovin MAX, Google Mobile Ads, Google UMP, an advertising-identifier SDK or Google Play Billing. There is no separate Firebase analytics or crash-reporting SDK.

## Data that stays on your device

Prompts, model responses, attached images, downloaded model files, chat history,
generation settings, and local API credentials are processed and stored on the
device. Android cloud backup and device-to-device transfer are disabled for the
app's private data. Deleting a conversation removes its stored messages. Model
files managed by the app can be deleted from the model library; removing a linked
model only removes its library entry and leaves the original file untouched.
Uninstalling the app removes its private app data;
model files saved in a user-selected shared folder remain under the user's
control.

Attachments are copied into private app storage for local use. Temporary and
unreferenced files may remain until cleanup or uninstall. Deleting data from
the app does not delete copies you exported or shared with another app.

## Network activity

The app contacts Hugging Face (`huggingface.co`) and, when needed, the community
mirror (`hf-mirror.com`) only when the user browses or downloads a model. Those
services receive normal network metadata such as an IP address. Prompts, chat
history, and attached images are not sent as part of model downloads.

Expert mode can expose an OpenAI-compatible endpoint to the user's local
network. The feature is off by default and every request requires a randomly
generated access key. Traffic on that local endpoint is HTTP and should be used
only on a network the user trusts; it is not sent to the LLM Studio publisher.

Code execution and web-app previews use a separate, offline sandbox with external
network access, file selection, camera, microphone and location access blocked.
Opening an external link or explicitly sharing content uses another app, whose
privacy rules apply. No chat content is attached to the privacy section's links.

## AI response reports

Users can report an AI response from inside the chat. A report sends the chosen
reason and any optional note to the feedback service configured by the official
build. The response text is excluded by default and is sent only when the user
explicitly enables “Include this response.” Hidden model thinking is never sent.
Reports contain the app version and Android API level, but no account, advertising
identifier, device identifier, or conversation identifier. Reports are used only
for safety review, abuse prevention, and improving model recommendations.
The service is operated by Eugene Svistunov for LLM Studio at vans.wtf and hosted
on Railway in the Netherlands. HTTPS traffic also passes through Cloudflare.
These infrastructure providers can process connection metadata such as IP
addresses under their own security and operational policies. The report database
does not store raw IP addresses; short-lived keyed hashes are used for rate
limiting and removed after their hourly window. Report content is encrypted at
rest and is available only through the operator's authenticated Railway access.
It is not sent to advertising services or used to train models.

Reports expire after 29 days and are automatically deleted every 15 minutes,
providing a margin within the 30-day retention period. Expired reports cannot be
viewed. Cleanup also runs before the service starts accepting reports after a
restart; if hosting is unavailable, physical cleanup resumes when it recovers.
No separate report backups are configured. A random report receipt and retry
identifier are not linked to your account, device or conversation. Save the
receipt shown after submission if you may want to request access or deletion.
Contact evhenii.svistunov@gmail.com with that receipt; do not resend your chat.
If the service is unavailable, the app reports a failure rather than claiming
that your report was received.

## Advertising and privacy choices

Version 1.0 on Google Play has no ads, advertising SDKs, ad requests or advertising identifiers. Prompts, responses, chat history, images, model files and local API credentials are not sent to advertising services. No advertising consent form is needed for this release.

Any future release with advertising will require updated disclosures and applicable privacy choices before advertising is enabled. Earlier development builds included Google AdMob or experimental AppLovin MAX integration. Removing or updating the app does not erase information those providers previously received; their policies apply to that historical processing: https://policies.google.com/privacy and https://legal.applovin.com/privacy/.

## Optional ad-removal purchase

Version 1.0 on Google Play has no purchases, subscriptions, paywalls or paid ad-removal option. It does not contain the Google Play Billing SDK or request purchase records. LLM Studio does not collect payment-card details, bank credentials or purchase receipts in this release.

Any future monetization will be described in its release information and privacy policy before it is offered. Installation and updates through Google Play remain subject to Google's own account and store privacy practices.

## Sharing and sale

The publisher does not sell your chats, model files or reports and does not share them for advertising. Model downloads and optional local-API use are initiated and controlled by you. Report content is processed by the publisher and infrastructure providers only for the purposes described in the report section; it is not used for advertising or model training. External services may process connection metadata under their own privacy and security policies.

## Children

LLM Studio is a general-purpose developer and productivity tool and is not
directed to children.

## Contact

For privacy questions and requests about your data, contact the LLM Studio
developer at evhenii.svistunov@gmail.com. The app opens your email application only when
you choose to contact us; no chat, image, access key or purchase receipt is
attached automatically. Your email provider processes the message under its own
privacy policy. Your address and information you choose to send are used to
respond to your request, not for advertising. Correspondence is retained for
as long as needed to handle the request or meet applicable legal obligations.
You can request access or deletion at the same address.

Do not include chat content, images, access keys or payment details unless
necessary for your request. Never send passwords or full payment credentials.
The full policy is bundled in English, Russian and Ukrainian; other app languages
show a translated summary and clearly identify the English full text.

Changes to this policy will be published in the same repository with a new
effective date.
