Privacy Policy
No LeLau account, analytics or server. Answers are written on this iPhone, or on your own computer if you link one.
Effective date: October 7, 2026.
The short version
LeLau collects nothing about you. It has no account, no analytics, no telemetry, no advertising and no server of its own. All reasoning happens on your iPhone.
A few optional features send a small, specific request to an outside service, over Tor except for model downloads, which go direct unless you choose Tor. None of these services is an AI service. Each one is listed under "Who receives what" with exactly what it receives and when. Online look-up is a switch you control: during setup LeLau shows what it sends, with the switch on unless you turn it off. Downloads and pack builds send nothing until you confirm them.
No third-party AI
LeLau does not use any third-party AI service. Answers are written on this iPhone, by the model you choose in LeLau or by Apple's on-device model (also used for some answers given through Siri, Shortcuts, Control Center, Share or Safari on iOS 26 and later), or, only if you set up LeLau Link, by LM Studio or Ollama running on your own computer on your local network. No question, conversation or file is sent to an AI provider.
LeLau includes no answer model. Any model you choose (Gemma 4, Qwen 3.5, LFM 2.5, MiniCPM 5, Ministral 3, SmolLM 3, Granite 4.0, Llama 3.2 or Bonsai) is downloaded once from Hugging Face and runs on this iPhone. Without one, LeLau answers by quoting your packs. With LeLau Link, your question and the passages your packs found go over your local network to the computer you added; your packs, chats and history never do.
What LeLau itself collects
Nothing. LeLau has no account or sign-in, no analytics, no telemetry, no advertising and no server, so nothing you type, say, import or ask is sent to us, and we do not build a profile of you. There are no subscriptions, paid packs, in-app purchases or other monetization.
Diagnostics the app records stay on this iPhone unless you export them yourself.
The only way anything reaches us is an email you choose to send. "Report this response" drafts one in your mail app with the question and the answer; nothing is sent until you send it. We use what you email only to reply.
How information gets into LeLau
Everything below is stored and processed on this iPhone:
- Typing or pasting a question in chat.
- Pasting text or importing a PDF to build a pack.
- The Share extension, when you share selected text to LeLau from another app.
- The Safari extension, which fills in your selected text (or the page title) as a question you can edit before you ask.
- Siri, Shortcuts and Control Center. Siri turns your speech into text under Apple's own privacy policy; LeLau receives only the text.
- A topic name you type or say when you build a pack from Wikipedia.
How LeLau uses it
- Answers on this iPhone. Your question, the matching pack passages and the conversation are used on this iPhone to write the answer. Conversations, packs, memories and search indexes are stored on this iPhone.
- Web look-up, a switch you control. When your packs can't answer, and in chat alongside answers from topic packs and packs included with LeLau, LeLau sends a shortened copy of your question over Tor, and for a follow-up your last two questions too. Emails, links, @handles and long numbers are removed first. It goes to Wikipedia (Wikimedia Foundation) and DuckDuckGo for search, to Open-Meteo for weather (only the place name), and to CoinGecko or Frankfurter for prices (only the coin or currency pair). This also applies when you ask LeLau through Siri, Shortcuts, Control Center, Share or Safari. During setup LeLau shows you this, with the switch on unless you turn it off. You can change it any time in Settings > Privacy > Online look-up, or in any chat's pack picker.
- Building a pack from a topic. After you confirm, LeLau searches Wikipedia (Wikimedia Foundation) for the topic over Tor and downloads the matching articles. Only the topic and your phone's language are sent. The pack is built and used on this iPhone.
- Any model you choose to download, only after you tap Download. Downloaded once from Hugging Face (huggingface.co), directly by default, or over Tor if you choose Through Tor in Settings > Manage models > Download models. Only the file request is sent, never your questions. Checked against its SHA-256 fingerprint, then runs on this iPhone.
- Siri suggestions, off by default. If you turn on "Suggest my questions to Siri", LeLau gives iOS the questions you send so Siri can suggest them on the Lock Screen and in Spotlight. iOS keeps these suggestions on this iPhone.
- Spotlight. LeLau adds the names of your packs to this iPhone's Spotlight index so you can find them in search. The index stays on this iPhone.
- Home Screen widget. If you turn on "Show recent chat on widget" (off by default), your last exchange appears on the Home Screen, where anyone who sees your screen can read it. It stays on this iPhone.
- Backups. iOS device backups include LeLau's local data, including conversation history, under Apple's backup encryption.
Who receives what
This is the complete list of parties that can receive anything because of LeLau. Apart from model downloads on the Direct route, LeLau's own network access is Tor-only and fails closed: if Tor is not available, nothing is sent, and LeLau never falls back to a direct connection. Tor hides your IP address from each destination, but the destination still receives the request itself, as listed here.
| Recipient | What it receives | When | Your choice | Privacy policy |
|---|---|---|---|---|
| Wikimedia Foundation (Wikipedia) | During web look-up: the shortened, redacted question, and for a follow-up the last two questions too. When you build a pack from a topic: the topic and your phone's language. | If look-up is on and your packs can't answer, or in chat alongside a topic pack's answer, or after you confirm a pack build. | Look-up is a switch you control, and each build asks you to confirm first. | https://foundation.wikimedia.org/wiki/Policy:Privacy_policy |
| DuckDuckGo | The shortened, redacted question, and for a follow-up the last two questions too. | During web look-up, when Wikipedia has little or nothing. | Only while look-up is on. | https://duckduckgo.com/privacy |
| Open-Meteo | A place name taken from a weather question, then that place's coordinates. Your device location is never used. | During web look-up, for a weather question. | Only while look-up is on. | https://open-meteo.com/en/terms |
| CoinGecko | A coin identifier, such as bitcoin. The request passes through Cloudflare, which serves CoinGecko's API. | During web look-up, for a crypto price question. | Only while look-up is on. | https://www.coingecko.com/en/privacy |
| Frankfurter | A currency pair, such as EUR and USD. The request passes through Cloudflare, which serves Frankfurter's API. | During web look-up, for an exchange-rate question. | Only while look-up is on. | https://frankfurter.dev |
| Hugging Face | A request for one model file, which Hugging Face may serve from its download network. On the Direct route it also sees your IP address. No questions and no other user data. | Once per model, when you tap Download for that model. | Yes. Only after you tap Download. | https://huggingface.co/privacy |
| Tor network relays | Your IP address reaches the first relay, never the content. No single relay sees both you and what you asked. | Only when look-up is on, a pack build runs, or a model download uses Through Tor. Once started, Tor stays connected until LeLau closes. | Follows the features above. | https://community.torproject.org/relay/types-of-relays/ |
| Apple | Your speech, when you ask LeLau through Siri. Apple turns it into text under its own privacy policy; LeLau receives only the text. | Each time you use Siri with LeLau. | Your choice to use Siri. | https://www.apple.com/legal/privacy/data/en/ask-siri-dictation/ |
How these services treat what they receive
Each service receives only the item listed above, over Tor (Hugging Face directly unless you choose Through Tor), with no account, cookie, advertising ID or device identifier from LeLau. Where a request names the app, it names it the same way for every user. The words of a look-up question can still say something about you, which is why they are shortened and cleaned first and why look-up is a switch you control. This is what each service's own privacy policy says, as checked in September 2026:
- Wikimedia Foundation keeps readers' IP addresses and request logs for up to 90 days (up to 180 days when investigating automated traffic, and longer when needed to investigate abuse or security issues), then deletes, aggregates or de-identifies them. It does not sell personal information or share it for marketing. For what LeLau sends, this protects you as well as LeLau's own policy does.
- DuckDuckGo says it does not store IP addresses with searches and does not build profiles. It keeps search text without identifiers, for a period it does not state. LeLau reaches it through its onion service, so no Tor exit relay is involved. For what LeLau sends, this protects you as well as LeLau's own policy does.
- Open-Meteo deletes its logs after 90 days, does not link IP addresses to identities, and does not share data or advertise. For what LeLau sends, this protects you as well as LeLau's own policy does.
- Frankfurter says its API does not collect or log personal data, IP addresses or request URLs. It runs behind Cloudflare, which Frankfurter says gives it only aggregate traffic stats; Cloudflare's own handling falls under Cloudflare's policy. For what LeLau sends, Frankfurter's own service protects you as well as LeLau's own policy does.
- CoinGecko receives only a public coin name, such as bitcoin, over Tor with no account, cookie or identifier, so no personal data is shared with it or with Cloudflare, which serves its API. Its own privacy policy, linked above, covers how it handles requests.
- Hugging Face receives no questions or other content from LeLau: only a request for a public model file that is the same for every LeLau user, with no account, token or cookie. On the Direct route it also sees your IP address, as any website you open does; choose Through Tor to hide it. Its own privacy policy, linked above, covers how it handles requests.
- Tor relays are the encrypted transport that carries each request, run by independent volunteers. They see no content: the first relay sees your IP address but not the destination, and the last relay sees the destination but not your IP address. Tor is not a guarantee of anonymity: someone who can watch both ends could link a request to you by its timing and size.
- Apple handles Siri speech under its own privacy policy, linked in the table above.
How to turn each thing off
- Web look-up: turn off Online look-up in Settings > Privacy, or in Chat tap the pack name at the top and turn off "Look things up online". Nothing is sent while it is off.
- Building from a topic: nothing is sent unless you tap Build on the confirmation. You can delete any pack you built.
- Downloaded models: nothing is requested from Hugging Face unless you tap Download. Delete a model in Settings > Manage models, and choose Through Tor under Download models to hide your IP address from Hugging Face.
- LeLau Link: nothing goes to a computer unless you add one and pick one of its models. Settings > LeLau Link > Forget this computer removes it.
- Siri suggestions: turn off "Suggest my questions to Siri" in Settings > Siri and Shortcuts. This also removes the suggestions already given to iOS, as do Wipe local data and clearing your chat history.
- Widget: turn off "Show recent chat on widget" in Settings > Siri and Shortcuts.
- Siri and Spotlight: Siri's own settings, and whether LeLau appears in search, are in the iOS Settings app. Deleting a pack removes it from Spotlight.
- Backups: turn off LeLau in iCloud Backup to leave it out of backups.
- Everything: Settings > Storage > Wipe local data removes conversations, memories and settings (packs and models stay). Deleting the app removes all of it, including models and packs. Copies you exported or shared yourself are outside the app. A request a service has already received cannot be erased by LeLau; how long each service keeps it is described above.
Children
LeLau is not directed at children under 13. It includes always-on on-device content filtering that blocks slurs and hate terms before a query is processed.
Changes to this policy
If LeLau's data flows change, we will update this bundled policy and its effective date before describing the new behavior as available.
Contact
Questions about privacy: support@lelau.org.