// privacy
Nothing to hide, nothing to share.
Privacy by architecture.
Not by policy.
A privacy policy is a promise. An architecture is a fact. grAIm is built so that your data can't be collected โ there's no server for it to land on. grAIm's developers are opposed to surveillance business models and data collection.
Where your data actually goes
One arrow. That's the entire data flow. Your conversation goes from your phone directly to the LLM provider you chose โ and nowhere else.
Four guarantees, built into the code
Memory lives on your device
Everything your assistant learns โ projects, contacts, preferences, skills โ is stored in a local database on your phone โ encrypted at rest, or plain text, your choice. Back it up, export it, wipe it. It's a file you own, not a profile we hold.
Your keys, your provider, no middleman
Conversations travel straight from your phone to the LLM provider you chose, using your own API key. grAIm never proxies, logs, or even sees a single message. Keys are stored in your device's secure storage. The assistant itself never has access to your raw keys โ it can use them to call your provider but can't read or repeat them, so even if malicious instructions slipped past prompt-injection defences, your API keys couldn't be leaked.
Permissions you can actually read
Every piece of device context โ time, locale, battery, network โ is a separate toggle with a plain-English description and a sensitivity rating. Off by default where it counts. No bundled "accept all."
Voice can work fully offline
Speech-to-text and text-to-speech can run entirely on-device, so voice keeps working with no signal at all. Cloud voice providers are available too, and which one runs is always your choice โ nothing is sent off your device unless you pick one.
CONTROL PANEL
"6 of 9 permissions enabled" โ and you chose all six.
The permissions screen isn't buried three menus deep. It's a first-class part of the app, showing exactly what your assistant can see right now, with colour-coded sensitivity so you can make the call at a glance.
Data is only included in a conversation when the toggle is on โ and because context is assembled on your phone, turning something off means it's genuinely gone from the pipeline, not just hidden from the UI.
FULL TRANSPARENCY
What we do collect during beta
During beta only, grAIm collects anonymised diagnostic and usage data โ so we can find and fix bugs, and focus on the features people actually use. It never includes your conversations, memories, or keys.
Crash reports, performance metrics and usage patterns โ so we know which features people actually use and where to focus improvements. We never see what you're doing, only that you're using a feature.
Diagnostic and usage data is deleted when beta ends. After beta, collecting it becomes opt-in. If that trade-off isn't right for you, we'd genuinely rather you wait for the release version than feel uneasy in the beta.