Privacy Policy

Pocketd · Last updated 11 September 2026

Pocketd collects nothing. There is no account, no analytics, no crash reporting and no telemetry, and no server belonging to this project exists to receive any. Nothing you type, and nothing the model says back, ever leaves your phone.

The rest of this page is the detail behind that sentence, including the parts that are less tidy than the sentence is.

What Pocketd collects about you

Nothing. Specifically:

This is also what the app's PrivacyInfo.xcprivacy declares to Apple: tracking off, tracking domains empty, collected data types empty.

What leaves your phone

One host: huggingface.co, and the CDN that huggingface.co redirects downloads to. Only two things ever cause a request:

WhenWhat is sent
You search for a modelThe text you typed, as a search term, and your phone's IP address
You open a repository to see its filesThe repository's name, and your phone's IP address
You download a modelWhich repository and file you are fetching, and your phone's IP address

A paired device on your network can ask the phone to run a search or start a download on its behalf, which sends the same things and nothing more.

No account, no token and no identifier of yours is attached to either. Every download address is assembled as huggingface.co, then a repository and a filename; the search API accepts a repository and a filename and never a host. The stored record for a model carries a field that could name a different address, and nothing in the app or its HTTP API ever sets it.

Nothing else is contacted. Inference does not call out — the weights are a file on your phone, and answering a question reads that file. The web pages Pocketd serves are self-contained, with no fonts, scripts or images loaded from anywhere.

Health, Calendar and Reminders

If you grant access, the assistant can answer questions about your activity, heart and sleep, your calendar and your reminders.

One thing Pocketd cannot tell you: iOS never reports to an app whether a request to read Health was allowed. That is deliberate on Apple's part — it stops an app distinguishing "you said no" from "you have no data of that kind" — and it applies to Pocketd like every other app. The app's own Data screen says so rather than guessing. Health → Data Access & Devices → Pocketd is the only place with the answer.

What is stored on your phone

Everything Pocketd keeps stays inside the app's own container:

Models and conversations are both excluded from iCloud Backup. The Data screen inside the app walks the container and accounts for every byte, names what it cannot delete and says who can, and offers to delete the rest. Deleting the app removes all of it.

The local network

When you press Start, your phone runs an HTTP server for other devices on your Wi-Fi.

The awkward parts

Worth saying plainly, because they are real and they are the kind of thing a privacy page usually leaves out:

Children

Pocketd has no account, no sign-up and no social features, and collects nothing from anyone, of any age.

Changes

This policy is versioned with the source. Its history is the file's history in the repository, so any change to it is a diff someone can read.

Contact

Questions, or something here that does not match what the code does: https://github.com/dheerajjha/pocketd/issues. The app is open source — the claims on this page are checkable against the source rather than taken on trust.