Cloister AI
Privacy Policy
Every model runs on your device. Nothing is transmitted unless you turn on an optional feature, and each one is named below.
- Last updated
- Applies to
- Cloister AI for iOS
This policy covers Cloister AI. It sits alongside our general Privacy Policy. Where the two differ for this app, this policy applies.
Who is responsible
The data controller for Cloister AI is the developer behind Leap Studio, named on the entity details page.
Contact: contact@leapstudio.dev. We respond within 30 days.
Summary
Every model runs on your device. Nothing is transmitted unless you turn on an optional feature, and each one is named below.
There is no account, no sign-up and no login. What does leave your device is listed below.
What leaves your device
This is the complete list. Anything not in this table is not transmitted.
| What | Who receives it | Where | Why | Trigger |
|---|---|---|---|---|
| The name of a model you chose to download | Hugging Face | United States | Fetching open-weights model files you explicitly requested | You choose |
| A search query you typed, when web search is enabled | DuckDuckGo | United States | Answering with current information and citations | You choose |
| A request for the voice pack and pronunciation dictionary | Hugging Face and GitHub | United States | One-time download of text-to-speech assets | You choose |
| A web address you paste or open | The website you chose | Wherever that site is hosted | Reading a page you asked the app to read | You choose |
Notes
- Web search is switched off by default. Turning it on is the only way a question you type reaches a third party, and the app tells you so at the moment you enable it.
- The app declares background audio so a meeting keeps transcribing when your screen locks. It does not record in the background at any other time.
- Subscriptions are handled by StoreKit on the device. There is no analytics SDK and no subscription service — nothing about your purchase reaches us.
What stays on your device
Everything — chats, vaults, documents, meeting notes, memory — is stored only on your device. There is no account and no server-side copy. Subscriptions are verified on the device by the App Store, so no purchase record is sent to us. Deleting the app deletes the data.
This content does not reach us and we hold no copy of it. Uninstalling the app or erasing your device destroys your content permanently. Use your own device backup if you want it kept.
All model inference happens on your device. Prompts and documents are not transmitted.
Permissions this app asks for
Each can be refused or revoked in Settings. Refusing a permission disables only the feature that requires it.
- Microphone
- Meeting transcription and voice conversation. Audio is processed live and never saved.
- Speech recognition
- Turning speech into text on the device.
- Camera
- Photographing a document to add it to a vault.
- Health (read only)
- Optional health insights. Read on the device, never transmitted, never written back.
- Reminders
- Pushing action items from a meeting into your reminders.
- Calendar (write only)
- Creating follow-up events. The app cannot read your calendar.
Analytics, advertising and tracking
None. This app collects no usage statistics, no crash reports and no telemetry of any kind.
There is no advertising, no advertising identifier, no data broker, no cross-app or cross-site tracking, and no App Tracking Transparency prompt. We do not sell or share personal information, including as those terms are defined by California and other US state privacy laws.
Children
This app is not directed to children and we do not knowingly collect personal information from children. See our Children's Privacy notice.
Legal bases (EU and UK)
- Contract — processing a purchase or subscription.
- Consent — optional features you switch on that send data off the device. Withdraw by switching the feature off.
- Legitimate interests — keeping the app working and secure. You may object at any time.
- Legal obligation — tax and consumer-law records.
Sensitive and confidential material
This app is built for confidential material — legal files, clinical notes, financial records, personal information about other people. That material is not transmitted to us. Where you use the app for another person's information, you are the controller of it and we are not a processor of it.
If you connect Apple Health, those readings are read on your device and are never transmitted or written back.
Organisations requiring contractual terms should refer to our Data Processing Addendum.
International transfers
We are in Australia. The service providers named above are in the United States. Transfers of personal data from the EEA are made under the European Commission's Standard Contractual Clauses, and from the UK under the International Data Transfer Addendum. Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles. The full list is on our Subprocessors page.
Retention
Content you create in the app is held on your device until you delete it or remove the app. We do not hold it. Purchase records are retained for seven years as required by Australian tax law. Analytics events, where collected, are retained by the provider on a rolling basis and are not linked to an account.
Your rights
You may have some or all of the following rights depending on where you live. We honour them for everyone.
- Access
- Ask what personal information we hold about you and get a copy of it.
- Correction
- Ask us to fix anything inaccurate, out of date or incomplete.
- Erasure
- Ask us to delete personal information we hold. In this app, uninstalling it deletes your content directly, because we never had a copy.
- Restriction and objection
- Ask us to stop or limit a particular use, including any use based on our legitimate interests.
- Portability
- Receive the personal information you gave us in a structured, machine-readable format.
- Withdraw consent
- Where we rely on consent, withdraw it at any time. This does not affect anything done before you withdrew it.
- Complain
- Take the matter to a privacy regulator without going through us first.
Requests are free of charge and we will not discriminate against you for making one. Write to contact@leapstudio.dev.
We hold no directly identifying information about app users and are often unable to locate records relating to a specific individual.
Data breaches
Where a breach is likely to result in serious harm we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where the GDPR applies we will notify the relevant supervisory authority within 72 hours of becoming aware.
Report a security problem to contact@leapstudio.dev. See our Security overview.
Complaints
Contact us at contact@leapstudio.dev. We respond within 30 days. You may also complain to a regulator at any time:
- Australia — Office of the Australian Information Commissioner (OAIC)
- European Union — Your national data protection authority
- United Kingdom — Information Commissioner's Office (ICO)
Changes to this policy
Updates are published here with a new date. Material changes are notified in the app before they take effect.