Information kept on your device
Depending on the features you use, CuriousLM locally stores:
- conversations, branches, drafts, projects, instructions, and settings;
- memories you approve or enable;
- documents, images, extracted text, OCR results, indexes, and citations;
- downloaded model, OCR, and optional embedding artifacts; and
- generation checkpoints, verification results, and storage-health information.
The PWA encrypts private structured records and files with its local vault. Android uses encrypted native storage protected by Android Keystore and device authentication. CuriousLM cannot recover your vault or backup passphrase.
When information leaves your device
- App and model delivery. Your hosting provider, app store, or model publisher receives ordinary request metadata when you install an update or explicitly download a model. Prompt and response text is not part of those requests.
- Tavily search. A query is sent directly to Tavily only after you add your own key, review the query, and confirm that search. Tavily's terms apply.
- Response reports. The exact excerpts and optional comment you preview are sent to
reports.ai.teda.devonly after confirmation, alongside app, platform, runtime, and model versions and a random idempotency key. - Aggregate usage analytics. Google Analytics 4 (GA4) receives coarse app events automatically unless you turn usage analytics off in Settings. Events may include the app platform, broad action type, approximate duration or count bands, browser/device information, and a page path stripped of chat and project parameters.
Reports exclude stable device identifiers, API keys, complete conversations, and unrelated diagnostics. Diagnostics are off by default.
Cookieless usage analytics
CuriousLM uses GA4, not the retired Universal Analytics product sometimes called GA3, for aggregate service-improvement statistics. Analytics is enabled by default and does not require a consent banner. CuriousLM configures Google consent mode with Analytics storage denied. Advertising storage, Google signals, ad personalization, interest groups, link decoration, and enhanced measurement are disabled.
This configuration sends cookieless measurement requests and does not set GA4 _ga cookies. The only local analytics value CuriousLM stores is the preference needed to remember if you turn analytics off. GA4 may receive a stripped page path, bounded product events, ordinary browser/device information, and request metadata. Google says it uses the requester IP address transiently for routing and approximate location, then discards it before logging. Analytics data in the CuriousLM property is retained for up to 14 months. Google's privacy policy applies to its processing.
CuriousLM never includes prompts, responses, chat titles, filenames, file contents, project names, memories, search terms, API keys, model identifiers, or a CuriousLM account identifier in analytics events. This limited processing supports our legitimate interest in improving reliability and product usefulness and the statistical service-improvement exception where applicable. You can object at any time by turning Usage analytics off in Settings → Privacy. That stops future CuriousLM analytics events and removes any accessible legacy Analytics cookies. You can also clear site data or uninstall the app.
Reports and retention
Accepted reports are encrypted at rest, access restricted, excluded from content logs and email, and scheduled for server purge after 30 days. An encrypted deletion credential stays in your local vault until deletion is verified or through a seven-day post-purge grace window. Before deleting all local data, the app offers remote deletion because clearing the vault removes early-deletion access. Intake closes before its configured daily safety limit is exceeded.
Permissions
Camera and file access are requested only when you invoke those features. Android may show a privacy-neutral notification for a user-started local generation; it never contains prompt or response text. Version 1 does not request microphone access.
Your controls and data deletion
You can review, edit, export, or delete supported local data; disable memory, diagnostics, and usage analytics; remove models; clear Tavily credentials; cancel queued reports; lock the vault; and delete all local user data. Portable .curiouslmbackups are encrypted and exclude model weights.
Most CuriousLM data exists only on your device, so the fastest deletion path is in the app: open settings, choose data management, and delete local data or uninstall the app. CuriousLM cannot delete local vault contents remotely because chats, memories, documents, model files, and backups are not hosted by CuriousLM.
For optional response reports you submitted, use the deletion receipt shown in the app, or email curiouslm@ebenezerdon.com with the receipt or deletion token. Reports are scheduled for automatic deletion after 30 days even if no manual deletion request is made.
Browser or operating-system storage can be removed, devices can be lost, and forgotten passphrases cannot be recovered. Persistent storage reduces but does not eliminate this risk. Keep an encrypted backup if your data matters to you.
Age, international use, and contact
CuriousLM version 1 is intended for adults aged 18 and over. Optional third-party services may process confirmed requests in other countries under their terms. For privacy or support questions, email curiouslm@ebenezerdon.com.