Privacy Policy
Last updated: August 15, 2026
Overview
LocalRAG! is designed with privacy at its core. Your documents are processed entirely on your device. We do not collect, store, or have access to the content of your documents.
On-Device Processing
All document processing — including text extraction, chunking, and search index building — happens locally on your device. Your original files never leave your phone or tablet.
What Is Sent to External Services
When you ask a question, only your question text and relevant text snippets from the matched sections of your documents are sent to the AI service (Anthropic Claude API) to generate an answer. The full content of your documents is never transmitted. If you use the on-device AI, not even that leaves your device — though the usage analytics below are still sent.
The app also sends usage analytics to our own server. That is the only other data that leaves your device — “Data Collection” below lists exactly what it contains.
Third-Party Services
- Anthropic (Claude API) — Processes your questions and relevant document excerpts to generate answers. Subject to Anthropic’s Privacy Policy.
- Apple / Google — Handles subscription payments and app store transactions. Subject to Apple’s Privacy Policy and Google’s Privacy Policy.
Under Anthropic’s standard commercial API policy, API inputs and outputs are deleted from its backend within 30 days, except where longer retention is needed for usage-policy enforcement or required by law. Zero data retention is a separate arrangement and is not enabled for LocalRAG!.
Data Collection
LocalRAG! collects usage analytics from the app. We do this to see where people get stuck, so we can fix it. The data is pseudonymous: it is tied to a random per-install identifier, never to you, and none of it touches your documents.
Here is everything we collect:
- A pseudonymous per-install identifier — a random value generated and stored on this installation. It is sent to our analytics service so events from the same installation can be counted together. It is not IDFV, an advertising ID, or an account identifier; it is not shared with advertising networks; and records keyed by it expire after 90 days. It is not linked to you as a person, but because it groups events from one installation we call it pseudonymous rather than anonymous.
- App version, build, and platform (iOS or Android), and how many days ago the app was installed.
- Subscription tier and access mode — whether you use our proxy, your own API key, or on-device AI, and whether an answer was generated in the cloud or on your device.
- How many documents you have added, as a coarse range (0, 1, 2–3, 4–10, 11–30, 31+) — never file names, never contents.
- Product-interaction events — how far you got through onboarding; whether a document import started, succeeded, or failed (with a generic failure reason); whether you asked a first question and got an answer; when you reach the free usage limit; and subscription interactions (paywall shown, purchase started, purchase outcome).
Here is what we never collect:
- Document contents, file names, or any text extracted from your documents.
- The text of your questions or of the answers you receive.
- Names, email addresses, or any other personal identifiers.
- Location, contacts, photo metadata, or advertising identifiers.
When it is sent: a launch ping goes out each time the app is launched, at most once per app session. The product-interaction events are sent as the corresponding action happens — finishing onboarding, importing a document, asking a first question, hitting the free limit, interacting with the paywall, and so on. If a transmission fails, for example because the device is offline, the event waits on your device and is sent later; nothing extra is collected in that case.
This happens even when on-device AI is selected. Choosing on-device AI means your documents, your questions, and the answers never leave the device. The usage statistics described above are still sent.
This data goes to our own server, hosted on Deno Deploy. Records tied to the per-install identifier are deleted automatically after 90 days. What remains after that is aggregate counts only — totals such as how many installs reached their first answer on a given day — which contain no identifier and cannot be traced back to any install.
We use this only to improve the app. It is not used for advertising, it is not sold, and it is not shared with third-party analytics providers.
This website uses no cookies. It uses Cloudflare Web Analytics for aggregate page-view and performance metrics, and a first-party redirect to count aggregate clicks to the App Store and Google Play by page and language. Cloudflare states that its beacon does not collect personal data or store data in cookies or browser storage. Our redirect stores only the date, platform, campaign label, and count — never an IP address, user agent, referrer, or persistent identifier.
API Keys
If you choose to use your own Anthropic API key, it is stored securely in your device’s Keychain and is never transmitted to our servers.
Payments
All subscription payments are processed by Apple (App Store) or Google (Google Play). We do not have access to your payment information.
Children’s Privacy
LocalRAG! does not knowingly collect personal information from children under 13. The usage analytics described above contain no personal information. The app is not directed at children.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date.
Operator
Contact
If you have questions about this privacy policy, please contact us at [email protected].