Privacy

Privacy Policy

Last updated: 16 September 2026

A field journalist writes notes while holding a phone inside a subtle privacy boundary.

Scope: five separate things

People often read one privacy claim and assume it covers everything a project touches. It does not. LlamaBox involves several distinct systems with genuinely different data behaviour, and this policy treats them separately:

  1. The Android application — on-device inference
  2. Model downloads — third-party repositories
  3. This marketing website
  4. Historical access-request records
  5. Email communication and hosting logs

The important distinction: the Android app keeps chat inference on your device. Website visits and support emails involve separate providers. The former access-request form is retired; no signup is needed to install LlamaBox.

1. The Android application

What is stored, and where

  • Prompts and conversations — stored in a local SQLite database inside the app’s private storage on your device.
  • Images you attach — copied into the app’s private storage so the local model can read them, and referenced from the conversation record.
  • Settings — stored locally via Android’s app-preferences storage.
  • Model files — GGUF weights you download or import are stored in the app’s documents directory on the device.

Does any of it leave the device? The app does not upload your chats, prompts, attached images or generated responses. Inference runs through the bundled llama.cpp build on your device, with CPU as the default and experimental acceleration on supported devices; there is no LlamaBox inference server for it to contact.

How to delete your data

  • Delete an individual conversation from within the app.
  • Clear the app’s data from Android Settings → Apps → LlamaBox → Storage.
  • Uninstall the app, which removes its private storage including models and history.

Permissions and hardware access

  • Internet — used for model downloads that you explicitly start, and for the local-network API described below. Not used for chat inference.
  • Storage — to import and manage GGUF model files you choose.
  • Camera and photo selection — only when you explicitly take or select an image for on-device analysis. Images are processed locally by the model on your device.
  • Voice input — not included in the current public capability set.
  • Notifications — used to show model-download progress.
  • Vibration — haptic feedback in the interface.

Analytics, crash reporting and update checks

Verified against the application’s dependency manifest and source tree:

  • Analytics SDK — none. The app contains no analytics or product-telemetry library.
  • Crash-reporting SDK — none. No Crashlytics, Sentry, Bugsnag, App Center or equivalent is present.
  • Behavioural telemetry — none. Prompts and responses are not transmitted for measurement.
  • Update checking — the app does not implement its own update-check network call. Application updates are delivered by Google Play, and Google Play’s own data handling applies to that channel, independently of LlamaBox.

Note that when the app is distributed through Google Play, Google receives installation and delivery information as part of operating that store. That is Google’s processing, not LlamaBox’s, and it is outside our control.

Local-network API

The app includes a local-network HTTP API for compatible clients:

  • It is enabled by default in the current build and can be stopped from the app.
  • When active, it serves compatible clients on your local network while inference remains on-device.
  • It serves requests from clients you point at it. Anything you send through it travels across your own network.
  • It does not forward your conversations to LlamaBox or any third party.

Text-to-speech

Voice output uses the Android system text-to-speech engine that you have selected on your device. Some Android TTS engines process text on-device and some use their vendor’s cloud service. That behaviour belongs to the engine you have chosen, not to LlamaBox. Check your device’s TTS settings if this matters to you.

2. Model downloads

When you choose to discover or download a model, the app contacts Hugging Face.

  • These downloads require a network connection.
  • The hosting provider receives the ordinary technical metadata that accompanies any HTTP request, such as your IP address, the requested file and your user agent. That is inherent to downloading a file from the internet.
  • LlamaBox does not intentionally attach your chats, prompts or generated responses to model-download requests.
  • Each model carries its own license and its publisher’s own terms.

If you do not want to make any network request, import a model file manually instead of downloading it in-app.

3. This website

  • Analytics — no analytics or tag-management script is deliberately installed on this site.
  • Cookies — no tracking cookies are set by this site.
  • Local storage — a single key, lb-theme, remembers your light/dark theme preference in your own browser. It is not transmitted anywhere.
  • Fonts — pages load webfonts from Google Fonts. Your browser therefore makes a request to Google’s servers, and Google receives the technical metadata of that request. If you would rather avoid this, a content blocker will prevent it; the site remains readable with system fonts.
  • Hosting logs — this site is served by a static hosting provider. We do not claim the provider sees nothing: like any web host, it processes standard request and network information (including IP addresses) in order to serve pages and protect the service. We do not add our own visitor-tracking layer on top of that.

4. Historical access-request records

The access-request form is retired. LlamaBox is publicly available on Google Play without a tester invitation. This section covers any information submitted through the former form.

The former form requested an email address and optional device, Android version, RAM, intended use and business information. It used FormSubmit, a third-party relay, to send submissions to the project mailbox. Those providers could process the submitted contents; the form was separate from the Android app.

Retention: any received requests remain subject to the previously stated limit of up to 12 months after testing ends. This release does not extend that period.

For a deletion request, email work.aalhad@gmail.com with the address used. Requests will not be added to an unrelated marketing list.

5. Email communication and hosting

  • If you email us directly, that message is stored in the project’s Gmail mailbox and processed by Google as the mail provider.
  • We use your address to reply and to send information you asked for.
  • Ask us to delete a thread at any time using the contact address below.

Future optional services

No optional cloud services, accounts, sync or benchmark-upload features currently exist. If any are added later, they will be opt-in, disclosed in the app before use, and documented here. We will not silently begin collecting data while keeping the claims on this page unchanged.

What we have and have not verified

Honesty about the basis for the statements above:

  • Verified from the application source and dependency manifest: absence of analytics and crash-reporting SDKs, absence of a LlamaBox inference endpoint, the set of outbound download hosts, local SQLite storage of conversations, the declared Android permissions, and the documented local inference and network boundaries.
  • Not independently verifiable by you today: the Android app source is not yet public, so you cannot currently audit a build against these statements yourself. Treat them as declared product behaviour by the project, testable behaviourally — see network behavior for how to check the offline claim on your own device with airplane mode.

Children’s privacy

LlamaBox is not intended for children under 13, and we do not knowingly collect data from children. Note that language models can produce inaccurate or inappropriate output regardless of the app presenting them.

Changes to this policy

This policy may be updated. Material changes will be reflected in the “last updated” date above and, where they affect app behaviour, surfaced in the app.

Contact

Privacy questions and deletion requests: work.aalhad@gmail.com

Related reading: network behavior · product facts · architecture