Privacy policy

What stays on your phone, and what you choose to share.

Pre-release draft · Updated 2026-09-30

About this policy

This policy describes the current Anan iOS app and the anan.sh website. Anan is in development; this is a pre-release draft. It will be reviewed against the release build, with the operator’s identity and contact information added before release.

Data stored on your device

Anan stores conversations, model responses, tool calls and results, memories, task records, submitted attachments, and settings in the app’s local storage. This supports conversation history, personal context, and the features you choose to use.

Anan does not require an Anan account or use an Anan-operated server to relay model conversations. Local storage does not mean cloud model processing is offline. Device backups may include app files according to your Apple and device settings; Anan does not change the system’s default backup behavior.

API keys and model providers

API keys are stored in the iOS Keychain, with Keychain synchronization disabled for these credentials. Anan uses the appropriate key to authenticate requests directly to the provider address you configure, including compatible third-party endpoints or proxies you choose.

Model requests can contain your messages, relevant conversation history, memories, attachments, and tool results. The provider also receives the network information needed to serve the request. Its privacy policy, retention rules, and any model-training settings apply to data it receives. Review those terms before connecting a provider; Anan cannot delete data held by that provider on your behalf.

Phone tools and sensitive data

When you use supported capabilities, Anan can access data such as calendar events, reminders, contacts, Health data, or location, subject to the relevant system permissions. Tool results can be saved in your local conversation and included in later model requests. System permission to read information does not mean the information stays only on your phone.

If you do not want sensitive information sent to a model provider, do not use the corresponding tools or include that information in a conversation. You can revoke access in system settings; Health permissions are managed in the Health app. External services used by a tool, such as Apple’s weather service or a shortcut you run, may process data under their own policies.

Attachments and voice

Images and text files you submit are stored with the conversation and may be sent to your selected model. Camera access is requested when you choose to take a photo. Unsubmitted attachment drafts are not saved as conversation files.

The current voice-input implementation uses on-device speech recognition and does not save or upload recorded audio. Speech resources may need to be downloaded by the system. The recognized text, once submitted, is processed like any other message and can be sent to the model provider.

Retention, deletion, and your choices

Local data is retained until you delete it using the app’s controls, reset Anan, or remove the app’s storage. Different controls affect different data: clearing conversations does not automatically clear memories, tasks, or model settings. The current development version provides these controls under Settings → Debug; full reset includes local files, preferences, and model credentials.

Keychain credentials can survive uninstalling an app. Remove them using Anan’s controls before uninstalling, or revoke the keys with the provider. Revoking permissions stops future access but does not erase previously saved tool results. Device backups and provider-held copies must be managed separately.

Security and diagnostics

Anan uses iOS app storage protections and the system Keychain for credentials. No storage or transmission method can guarantee absolute security. Choose providers and service addresses you trust, and protect your device and API keys.

The current app does not include advertising, cross-app tracking, or a third-party analytics SDK. Diagnostic records can exist locally. If you voluntarily share logs, screenshots, or other material for support, we use what you send to investigate and respond; remove secrets and unrelated personal data first.

The website

anan.sh uses a first-party cookie named anan-language to remember your language selection for up to one year. The website currently has no advertising or analytics integration. Hosting infrastructure may process IP addresses, request details, and technical logs to deliver the site and maintain security; this is separate from the app’s local conversation storage.

Changes and contact

We will update this page when data practices change and show the revision date. For questions, requests concerning support correspondence, or privacy concerns, use the contact details on the Support page once published. Operator and contact details are still being prepared for release.

An open beginning.

The repository is not public yet, and the license is still being decided. The GitHub link will appear here when it’s ready.