Privacy Policy
Effective September 27, 2026
Lochan collects nothing. There are no accounts, no analytics, no tracking, and no advertising identifiers. Lochan runs AI models directly on your iPhone and iPad, and your conversations stay on your device by default.
What stays on your device
Your conversations, your settings, and any models you download live only on your device. We never receive them, and there is no Lochan account or server that stores them. Chat with Apple's on-device model or a downloaded open model does not send your messages to Lochan or to any third-party AI service.
The same goes for what you set up in the app: your profile and the people you add for @-mentions, saved Herdr hosts, workspace categories, key bar layouts and custom keys, and unsent drafts. Adding a person from Contacts uses the system picker, so Lochan only receives the one contact you pick, not your address book. Profile and people details are added to your prompts so the model knows who you mean. They leave the device only when the model you are chatting with does, as described below.
Permissions
- Camera. To scan a pairing QR code, or to take a photo you choose to send.
- Photos. Only the photos you pick to attach.
- Microphone and Speech Recognition. Only while you dictate. Lochan uses Apple's speech recognition, which may send the audio to Apple to transcribe it, under Apple's privacy policy. Lochan does not keep or receive the audio.
- Local Network. To reach a Herdr host or model server on your own network or tailnet.
What touches the network, and only when you act
- Sharing a conversation. If you choose Share as link, Lochan shows what will be included (message text, timestamps, model names, and any images or files in the share), names the recipient service (
share.lochan.app), and only uploads after you tap Create link. Content is encrypted on your device before it leaves. The share service stores only encrypted data that we cannot read. The decryption key travels in the link fragment and never reaches our server. Links expire automatically (within about an hour). Nothing is shared unless you initiate it and confirm. - Web Search. Optional. If you enter your own Brave Search API key and allow web search when Lochan first asks, the assistant may send search queries derived from your message to Brave Search (
api.search.brave.com) using your key when it needs current information. Remove the key in Settings to stop web search. Your conversation otherwise stays on device. Lochan does not receive those queries. - Finding and downloading models or voice assets. Browsing or searching for open models sends your search text to Hugging Face (
huggingface.co). Downloading an open model or the read-aloud voice pack fetches it from the model's host or our CDN. These are normal requests and file downloads. They involve no Lochan account and no upload of your chat content. - Cloud models with your own key. Optional. If you enter an OpenAI, Anthropic, Google, or xAI API key, or a RunPod key and endpoint, Lochan talks to that provider directly using your key. Messages in those chats, including any attachments and the profile and people details in the prompt, go to that provider, not to Lochan. With an OpenAI key set, asking for an image sends that request to OpenAI.
- Herdr. Optional. Herdr is a separate product, the runtime coding agents run on. If you pair a Mac or Linux computer that is running Herdr, Lochan opens an SSH session from your iPhone to that machine so you can see and type into those agent terminals. The phone's private SSH key and any passwords live in the iOS Keychain and never leave the device. Traffic goes only to the host you configure, not to Lochan and not to herdr.dev. The one-line setup script at
lochan.app/herdr-setuponly configures the computer you run it on.- What you type, dictate, or attach in a pane goes to that host. Photos and files you attach are copied to
/tmp/lochan-herd/on the host so the agent can read them. - The first message you send to an agent includes a short note that you are on a phone, so it keeps answers brief.
- If you start the Shepherd, Lochan installs its files in
~/.lochan/shepherd/on the host and runs the coding agent you pick there. Like every agent on that machine, it uses its own provider under your account on the host. Lochan does not see what it sends. - Categories, key bars, and custom keys stay on the phone. Nothing about them is written to the host.
- What you type, dictate, or attach in a pane goes to that host. Photos and files you attach are copied to
No analytics or tracking
Lochan contains no third-party analytics, advertising SDKs, tracking pixels, or usage telemetry. We do not build a profile of you because we do not receive any data about you.
Third parties
When you use an optional network feature above, data goes only to the party named in the app at the moment you grant permission (your chosen cloud provider for chats with your own API key; Brave Search for web search queries; Hugging Face for model search and downloads; Apple for dictation; share.lochan.app for encrypted share payloads; a computer you own that is running Herdr). Those parties process the data under their own terms for the purpose of providing the service you requested. Lochan does not sell personal data and does not use third-party AI services for default on-device chat.
Children's privacy
Lochan does not collect personal information from anyone, including children. Because there is no account and no data collection by Lochan, there is nothing for us to gather regardless of a user's age.
Changes to this policy
If this policy changes, we will update this page and revise the effective date above.
Contact
Questions about privacy? Email [email protected].