The short version: your conversations never leave your device.
CappedAI runs AI models locally on your own hardware. We don't operate a server that processes your chats, we don't have user accounts, we don't use analytics or tracking, and we don't sell data to anyone. The sections below explain the few times the app does touch the network, and exactly what happens when it does.
CappedAI LLC, based in Austin, Texas. You can reach us at hello@cappedai.com. This policy covers the CappedAI apps and this website.
All AI processing happens locally, on your device's own processor. Specifically, these never leave your device and are never transmitted to us:
We have no ability to read any of it. There is no CappedAI server that receives it, because we don't operate a backend at all.
The app is usable entirely offline. It connects to the internet only for the following, and never to process your conversations.
The app can download open-weight AI models so it has something to run. It first fetches a
small public list of available models we publish on GitHub, then downloads the model file
itself directly from Hugging Face (huggingface.co), the standard
public host for open models. We link to models published there; the download is between your
device and Hugging Face.
Knowledge packs — topic-specific reference material and personas — are downloaded from our public releases on GitHub.
As with any download, the provider serving the file (Hugging Face or GitHub) will see the network request in the ordinary course of delivering it, including your IP address, under their own privacy policies. We don't receive that information. You can also skip downloads entirely and load your own model and pack files from local storage.
Some knowledge packs may offer to connect an account you already have elsewhere, so the assistant can answer questions using your own data from that service — for example, a trading-focused pack reading your own brokerage balances and positions.
Not active in the current release. No knowledge pack we currently publish uses this, so nothing in the app today can start an account connection.
When a pack does offer it, this is how it works:
Keeping data on your device only helps if what's on the device is actually protected. Concretely:
What this doesn't do. Files on the drive itself — your conversation history, documents, and saved notes — are not encrypted at rest today. Anyone with physical access to an unlocked drive, or software running on your computer under your own user account, can read them. If that's part of your threat model, keep the drive somewhere physically secure and use your operating system's own disk encryption on the computer you plug it into.
If you enter your email address to join the early-access list, that address is sent to us through Web3Forms, a third-party form service, and we use it only to contact you about CappedAI. We don't sell or share it. Ask us at any time to remove you from the list and we will.
This site runs no analytics, no advertising trackers, and sets no tracking cookies. Our hosting provider keeps standard server logs, as essentially all web hosts do.
CappedAI isn't directed at children under 13, and we don't knowingly collect personal information from them. Since the app has no accounts and collects no personal information, there's generally nothing for us to collect in the first place.
Your app data lives on your device and is under your control — you can delete conversations, packs, models, and memory at any time from within the app, and deleting the app removes what remains. Because we hold no account data, there is typically nothing on our side to request or delete. The exception is your email address if you joined the early-access list; write to us and we'll remove it.
If we change this policy, we'll update the date at the top of this page. Material changes to how the app handles your data will also be described in the app's release notes.
Questions about privacy, or about anything above: hello@cappedai.com.