Privacy Policy
Last updated: August 13, 2026
Offeline ("we," "us," or "our") provides a privacy-first AI chat application that runs language models locally on your device. This Privacy Policy explains how we handle information when you use the Offeline mobile apps for iOS (App Store) and Android (Google Play, package name com.offeline.android), and when you visit offeline.site (the "Website").
Summary
Offeline does not send your prompts, conversations, or other personal content to any third-party AI service. All AI processing for the mobile apps happens on your device. There is no Offeline backend server for chat, and the apps have no endpoint that sends your messages anywhere. The only network activity related to AI is when you choose to download model files from Hugging Face. We do not operate cloud accounts for chat, we do not transmit your messages to our servers for AI processing, and we do not use in-app analytics or advertising SDKs. The only bundled native library used for AI is the local inference engine.
After you download a model, chat works without an internet connection. Offeline does not require an account or a subscription for local AI chat, and the apps do not include ads.
The only data that ever leaves your device for AI is a standard file-download request to Hugging Face (your IP address and a user agent string) when you choose to download a model. Offeline receives nothing from that request. Nothing else is transmitted for chat: not your prompts, not your messages, and not any other personal content. Optional Rate or Feedback links open external web pages in your browser and leave the app.
Offeline's Google Play Data safety declaration for the Android app is that no data is collected and no data is shared. The Hugging Face IP exposure described in this policy is an inherent property of downloading a file from a third party; it is not data Offeline collects or shares.
No Personal Data Shared With Third-Party AI Services
Offeline does not share personal data with any third-party AI provider for inference, training, ranking, or any other AI processing. In particular:
- Chat prompts and messages never leave your device
- AI responses are generated entirely on your device
- Conversation history never leaves your device
- Images, documents, audio, or other attachments you use in chat never leave your device
- Display names, assistant settings, preferences, and local device identifiers never leave your device
- No usage telemetry, prompt logs, or conversation content is sent to Offeline or any AI company
Because no personal data is transmitted to a third-party AI service, Offeline does not request permission to share personal data with an external AI provider. There is nothing to share for AI processing.
What Leaves the Device
When you use the Offeline mobile apps, this is what leaves the device and what does not:
- Chat prompts, replies, and conversation history: Do not leave the device. Processed and stored only on device. Recipient: none.
- Images, documents, audio, or other chat content: Do not leave the device. Recipient: none.
- Account information: Does not leave the device. Offeline does not require an account. Recipient: none.
- App preferences and local device identifier: Do not leave the device. Recipient: none.
- AI model file downloads you initiate: Leave the device as a download request only. Recipient: Hugging Face, Inc. (model host). No prompts or chat content are included.
- Optional links you open (for example, Rate or Feedback): Leave the device only if you choose to open them. Recipient: the App Store or Google Play listing, offeline.site, or the destination you select.
Information Stored on Your Device
When you use the Offeline app, the following data is stored locally on your device:
- Chat messages and conversation history
- Custom assistant names, instructions, and configuration
- A display name you provide during onboarding or in settings
- A locally generated device identifier used only on your device
- App preferences such as active model, temperature, context window, and reasoning settings
- Downloaded AI model files cached for offline use
This information is collected and stored only on your device. It is not synced to Offeline servers and is not used to create an online account. On Android, conversations and custom assistants are stored in the app's private storage, and settings are stored in Android SharedPreferences. On both platforms, local data is protected by the operating system's application sandbox. Offeline does not add its own encryption layer on top of that sandbox.
The local device identifier is a random value generated on first launch and stored only on the device. It is shown in Settings > Account so you can quote it for support. It is never transmitted anywhere. Erasing app data regenerates it.
You can delete conversation history, clear cached models, or erase all user data from within the app at any time.
Backup and Device Transfer
On Android, Offeline disables Android Auto Backup and excludes all app data from both Google Drive cloud backup and device-to-device transfer. Conversations cannot be copied off the device by Google backup, and they do not follow you to a new phone during device setup.
On iOS, local app data remains subject to iOS system behavior for backups and device transfers you control through Apple settings.
How Information Is Collected and Used
App data is created by your use of Offeline and remains under your control on the device. We use that on-device data only to provide local chat, remember your settings, and run the model you selected. We do not collect, sell, rent, or share this data with advertisers, analytics companies, or third-party AI services.
Information We Do Not Collect
In the Offeline apps, we do not:
- Require sign-in, registration, or account creation
- Send your chat prompts, AI responses, or conversation history to Offeline servers
- Send any personal data to a third-party AI service for processing
- Collect analytics, crash reporting, or advertising identifiers through third-party SDKs
- Access your camera, microphone, photo library, contacts, or location
- Track you across apps or websites
Permissions
The apps request only the permissions needed for model downloads and optional local reminders. They do not request location, camera, microphone, contacts, storage, or phone permissions.
- Internet / network access: Used only to download a model you chose from Hugging Face, after you grant consent. On Android this corresponds to the INTERNET and ACCESS_NETWORK_STATE permissions.
- Notifications: Used only for the local reminders described below. On Android 13 and later, this is the POST_NOTIFICATIONS runtime permission.
Hugging Face Model Downloads
AI inference runs entirely on your device after a model is installed. The only third party involved in the AI feature path is Hugging Face, Inc., and only as a host for model files you choose to download.
- What is sent: A standard HTTPS download request for the model files you select. Like any web download, this request exposes your IP address and a user agent string (which identifies the app and operating system making the request) to Hugging Face's servers. Your prompts, chats, display name, and personal content are never included in these requests. Offeline does not receive this request data.
- Who receives it: Hugging Face, Inc., a US company that hosts open-source model files (for example GGUF models such as Qwen, SmolLM, Phi, and Gemma). No Hugging Face account is required, and Offeline does not send any account credentials or identifiers of yours to Hugging Face.
- What Hugging Face does with it: According to Hugging Face's own privacy policy and documentation, it automatically records standard request information, including IP address, request date, approximate location derived from the IP, and device and user agent details, for security, operations, and download counting. Download counts are computed on Hugging Face's servers from these requests; no additional information is sent from your device for counting. Where Hugging Face shares download analytics with model publishers, IP addresses are provided only as non-reversible hashes alongside country or region and user agent, not as raw identities.
- When it happens: Only when you initiate a model download. After the model is stored on your device, chat works offline and does not contact Hugging Face.
- Permission: Model downloads are user-initiated. You choose which model to download. Before any model is downloaded, the app asks for your explicit permission on-device and does not contact Hugging Face until you grant it. You can review or withdraw this permission at any time in Settings (on Android, in Settings > Model downloads). Offeline does not download models or contact Hugging Face in the background for AI chat.
- Third-party protection: Hugging Face states that it follows industry-standard administrative, physical, and technical safeguards, processes personal data in accordance with the GDPR under the supervision of the French data protection authority (CNIL), retains request logs only as long as necessary, and does not sell, rent, or lease personal information. We have reviewed Hugging Face's privacy practices and confirm they provide protection for this download-request data equal to that described in this policy. Because Offeline never transmits your chat content to Hugging Face, your conversations cannot be affected by Hugging Face's data practices. Review Hugging Face's privacy policy at huggingface.co/privacy.
Offeline is built with the open-source Quaynor inference library for on-device model execution. Optional local notifications and store review prompts (App Store on iOS, Google Play on Android) use platform services according to Apple's and Google's policies and only when permitted by your device settings.
Other Network Activity
If you tap Rate, Feedback, or another external link, your browser may open the App Store or Google Play listing, offeline.site/support, or another destination you select. Those visits leave the app, are separate from AI chat, and do not include your conversation content unless you paste or type it yourself.
Notifications
Notifications are local only. There is no push notification service and no Offeline server involved; nothing is sent or received for notifications.
If you grant notification permission, Offeline may schedule local reminders on your device, such as inactivity nudges 1, 3, and 5 days after you last leave the app. These reminders are rescheduled each time you use the app. They are generated locally and are not used to deliver ads or collect usage analytics.
On Android 13 and later, the app requests the POST_NOTIFICATIONS runtime permission. Reminders are only scheduled while that permission is granted. Revoking it cancels all scheduled reminders.
Clipboard
You may copy chat messages or your local device identifier to the clipboard using in-app controls. Clipboard access is initiated by you and is not used for background data collection.
Website Visitors
When you visit offeline.site, standard web server logs and privacy-respecting analytics may be collected to understand site traffic and improve the Website. This Website analytics does not include the content of your Offeline app conversations.
Data Retention and Deletion
App data remains on your device until you delete it or uninstall the app. You can withdraw consent to continued local storage by deleting data in the app or uninstalling Offeline.
- Delete individual conversations or clear chat history in the app
- Clear the model cache in Settings to remove downloaded model files
- Erase all user data in Settings > Account to remove conversation history, reset assistants to defaults, clear your display name, and regenerate the local device identifier
- Uninstall the app to remove remaining local app data from your device. On Android, because backup and device-to-device transfer are disabled, uninstalling removes everything and conversations do not follow you to another device. On iOS, removal is subject to iOS system behavior for local app data.
Downloaded model files are not removed by erase-all-data unless you separately clear the model cache. Because chat content never leaves your device, there is no remote copy for Offeline to delete on a server.
Children's Privacy
Offeline is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided personal information through the Website, contact us and we will take appropriate steps.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Continued use of Offeline after changes become effective means you accept the updated policy.
Contact
Questions about this Privacy Policy can be sent through the Contact page at offeline.site/support, or through the Feedback option in the Offeline app.