Privacy Policy

Deploy — On-Device AI Agents

Last updated: May 5, 2026

The Short Version: Deploy runs AI models entirely on your iPhone. There are no accounts, no analytics, no telemetry, no advertising, and no tracking of any kind. Your conversations, documents, images, and agents stay on your device. The only times the app makes a network connection are when you choose to download a model or use the Web Search tool.

1. Information We Do Not Collect

Deploy does not collect any information from you. Specifically:

  • No personal information. Deploy does not require an account, email address, name, or any form of registration.
  • No usage analytics. We do not track how you use the app, which agents you talk to, which models you download, which features you access, or how often you open it. There is no anonymized telemetry of any kind.
  • No conversation data. Your chats with agents, including any text, images, or document contents, are processed entirely on your device. They are never transmitted to us or to any third party.
  • No advertising. Deploy contains no ads and integrates no advertising SDKs or trackers.
  • No device identifiers. We do not collect your device ID, advertising identifier, IP address, or any other fingerprinting information.
  • No crash reports. We do not use third-party crash-reporting services. No diagnostic data is sent from the app.
  • No cloud sync. Deploy does not use iCloud, CloudKit, or any other cloud storage layer. Your data does not sync across devices because it never leaves the device it's on.

2. Data Stored on Your Device

Deploy stores the following data locally on your device, within the app's private sandbox. This data is only accessible to Deploy and is never transmitted to us.

  • Conversations. The full text of your chats with each agent, including any thinking content, tool results, and attached images.
  • Agents. The built-in agents (Scout, Lens, Ghost, Vault, Spark) and any custom agents you create, including their names, system prompts, model assignments, tool settings, and accent colors.
  • Knowledge base documents. PDFs, text files, and Markdown files you import into a Documents-enabled agent are copied to the app's private storage and indexed for local search.
  • Attached images. Photos you take or pick from your photo library are stored alongside the message they are attached to.
  • Downloaded model weights. The 4-bit quantized language model files you download are stored in the app's Documents directory so the app can run inference offline.
  • Settings. Your preferences such as default model, appearance (light/dark/system), and per-agent settings.

You can delete any of this data at any time from inside the app, or remove it all by uninstalling Deploy from your device.

3. Network Connections

Deploy is designed to run AI inference offline. The app does not contact our servers, and we do not operate any backend that receives data from the app.

There are exactly two situations in which Deploy makes outbound network connections, and both are initiated by an explicit action you take:

  • Model downloads (Hugging Face). When you tap “Download” on a model in the Model Manager, Deploy fetches the model weights from the public mlx-community organization on Hugging Face. The request includes only what is required to download the file (such as the file path and a standard User-Agent). It does not include any account information, conversation data, or unique identifier created by Deploy. Hugging Face's own privacy practices apply to that connection.
  • Web search (DuckDuckGo). When an agent with the Web Search tool enabled runs a search, Deploy queries DuckDuckGo's HTML Lite endpoint with your search terms and an iPhone User-Agent. No account information or unique identifier from Deploy is sent. DuckDuckGo's own privacy practices apply to that connection. You can disable Web Search for any agent in its settings.

Apart from these two cases, Deploy makes no network requests. Your conversations, documents, and images are never sent over the network.

4. Device Permissions

Deploy requests the following permissions only when you choose to use the feature that needs them. All processing happens on-device.

  • Photo Library. Used when you pick an image to attach to a message. The selected image is stored locally with the message and processed on-device by the vision-capable model. Deploy does not browse or read your library beyond the photo you explicitly select.
  • Camera. Used when you take a new photo to attach to a message. The captured image is stored locally with the message and processed on-device.
  • Files. Used when you import a PDF, text file, or Markdown file into an agent's knowledge base. The file is copied into Deploy's private storage and indexed on-device.

You can revoke these permissions at any time in your device's Settings. Revoking a permission disables the relevant feature but does not affect anything else in the app.

5. Third-Party Services

Deploy does not integrate any third-party analytics, advertising, crash-reporting, or tracking SDKs. No Firebase, Sentry, Mixpanel, AdMob, or similar service is present in the app.

The two third-party services Deploy can connect to, only when you act, are:

  • Hugging Face — used to download model weights when you tap Download. See their privacy policy at huggingface.co for details on how they handle inbound requests.
  • DuckDuckGo — used by the optional Web Search tool to fetch search results. See their privacy policy at duckduckgo.com for details. DuckDuckGo is a privacy-focused search engine that does not build user profiles.

Neither service receives an account identifier from Deploy, because Deploy does not have user accounts.

6. Children's Privacy

Deploy does not collect personal information from anyone, including children. Because no data is collected by us, the app complies with the Children's Online Privacy Protection Act (COPPA) and similar regulations by design.

The AI models that ship with Deploy are general-purpose language models. As with any open-ended AI tool, parents may wish to supervise younger users.

7. Data Deletion

Since all data is stored locally on your device, you control it completely:

  • You can delete individual conversations from any agent's chat history, or delete all conversations from Settings.
  • You can delete custom agents, or reset built-in agents to their defaults.
  • You can delete individual knowledge-base documents from an agent's Knowledge Base tab.
  • You can delete downloaded models from the Model Manager.
  • You can delete all app data by uninstalling Deploy from your device.

There is no server-side data to request deletion of, because no data is ever sent to a server we operate.

8. International Users

Deploy does not transfer any of your conversation data, documents, or images across borders, because it does not transfer that data at all. All AI processing and storage occurs on your local device, which makes the app compliant with data-residency requirements by design.

The two optional outbound connections (Hugging Face for model downloads and DuckDuckGo for web search) are direct connections between your device and those services. No provisions of the GDPR, UK GDPR, or similar laws regarding data transfers by us apply, because we do not collect or transfer any personal data.

9. Changes to This Policy

If we update this privacy policy, we will post the revised version at this URL and update the “Last updated” date. Because Deploy does not collect contact information, we cannot notify you directly. We recommend reviewing this page periodically.

Any future version of Deploy that changes the app's data practices (such as introducing analytics, accounts, or cloud features) will clearly disclose those changes in the App Store release notes and in an updated version of this policy before they take effect.

10. Contact

If you have any questions about this privacy policy or Deploy's data practices, you can contact us at deploy@pixel.management.