Privacy
Policy
Last updated: 2026 | Contact: contact@llmconnect.co
1. What LLMConnect Handles
1.1. Chat and Bot Content
Stored locally on the device. If the User enables synchronization, they are stored in their private iCloud via CloudKit. The developer does not access the User's private database.
1.2. API Keys and OAuth Tokens
Provider API keys, Connected App OAuth tokens, and OAuth client registrations are stored in the device's Keychain. OAuth authorization pages are hosted by the third-party service being connected.
1.3. No App Analytics or Telemetry
The iOS app does not collect user data, analytics, telemetry, identifiers, usage events, chat content, API keys, prompts, files, bot settings, or conversation history.
1.4. Data in Transit to Providers and Connected Apps
When you select a cloud Provider, generate images, or use a remotely hosted Connected App, the content needed for that request travels over encrypted HTTPS connections to the selected AI Provider or MCP server. A custom MCP endpoint configured on the User's local network may instead use local-network transport chosen by the User. An MCP server may request model sampling, but LLMConnect shows the proposed content and provider before anything is sent; only content explicitly approved by the User is forwarded. Subsequent processing is governed by each third party's policy.
2. Purposes
- Provide the core service of chat, bots, attachments with OCR, and image generation
- Store user-created content locally and, when enabled by the User, sync it through their private iCloud
- Send only the content the User chooses to the AI Provider selected for that request
- Connect to MCP servers selected by the User and execute tools, resources, prompts, or sampling requests that the User authorizes
3. Legal Basis
- Execution of the license agreement for app features
- User direction when sending selected prompts, attachments, and context to chosen AI Providers
- User authorization for Connected App OAuth, MCP sampling, and elicitation requests
- Consent when required by law for optional features such as iCloud sync or notifications
4. Retention
- Local data: Remains on your device until you delete it
- iCloud: According to your Apple settings
5. Transfers and Recipients
AI Providers, OAuth authorization services, and MCP servers chosen by the User. Each third-party service has its own terms and data use policies. Review those policies before connecting or sending content. Custom MCP endpoints may also be operated by the User or another administrator on a local network. Examples of third-party services include OpenAI, Anthropic, OpenRouter, Replicate, Notion, Asana, Slack, and Canva.
6. User Rights
Depending on your jurisdiction, you may have rights of access, rectification, deletion, objection, limitation, portability, and withdrawal of consent. For iCloud data, you can export or delete it from the device and from your Apple account.
7. Minors
- United States: Not directed to minors under 13 and COPPA rules apply when applicable
- EU and United Kingdom: Minimum age 16 unless lower threshold permitted by law, never below 13, with parental consent when applicable
8. Security
We apply operating system security measures such as Keychain for credentials and CloudKit for private synchronization, in addition to biometric lock and blur in multitasking. Connected App authorization uses HTTPS callbacks, PKCE where supported, and validation of OAuth state and resource bindings.
9. Changes
We will publish updates in the app. Use after the effective date implies acceptance.
10. Privacy Contact
For privacy-related questions, contact us through our Contact Page.