Privacy Policy

lili AI Router for iPhone, iPad and Mac · Effective 14 July 2026 · Last updated 21 September 2026

In short: there is no account, and we operate no server of our own. Your conversations stay on your device and your API keys stay in the system Keychain. What leaves your device goes only to the AI provider you configured, to Hugging Face when you choose to browse or download a model, and — on iPhone and iPad only — to Google's ad network, which pays for the app being free. The app contains no analytics; this website, which is a separate thing, counts visits with Google Analytics (section 5).

1. Who this covers

This policy applies to the lili AI Router app on iPhone, iPad and Mac, published by trading as DevZHR (“we”, “our”, “us”). Our other apps — Lili Call Blocker, Lili Widget and Lili Keyboard — are covered by the same family policy and are not described here. By using the app you agree to what follows; if you do not agree, please do not use it.

2. What we never do

  • We do not require an account, an email address or a sign-in of any kind.
  • We operate no backend server, so your conversations are never uploaded to infrastructure we control. There is nothing of yours for us to read, hand over or lose.
  • We do not put analytics or crash reporting in the app — no Firebase, no third-party SDK watching what you do. (The website is different: see section 5.)
  • We do not sell, rent or trade personal information.
  • We never receive your API keys.

3. What stays on your device

DataWhere it lives
Conversations, messages, attachments and titlesThe app's local database on your device. Deleting the app deletes them.
API keysThe system Keychain, marked accessible only when the device is unlocked and only on that device.
Provider settings (base URLs, deployment names, custom headers)The app's local database. Not secret, and never sent anywhere but to the provider they belong to.
Downloaded model filesThe app's Application Support folder, excluded from iCloud backup because of their size.
Reasoning traces from “thinking” modelsShown while they stream, then discarded. They are never written to disk.

4. What leaves your device, and where it goes

To the AI provider you configured

When you send a message to a cloud provider, its text — and any photo or file you attached — goes over HTTPS directly from your device to that provider's endpoint, using your key. We are not in the path and have no copy. What that provider does with it is governed by its privacy policy, which is worth reading for whichever ones you use. This includes OpenAI, Anthropic, Google Gemini, Azure OpenAI, Mistral, Groq, Cerebras, xAI, DeepSeek, Alibaba Qwen, Moonshot, Zhipu, OpenRouter, Together AI, Fireworks, Perplexity, Cohere, Hugging Face Inference, and any custom endpoint you add yourself.

To Hugging Face

When you search for or download an on-device model, the app talks to the Hugging Face Hub to list repositories, read file sizes and fetch the file. No account is needed and none of your conversation content is involved.

To a server on your own network

If you connect to Ollama, LM Studio or a llama.cpp server on your own Wi-Fi, the traffic stays between your device and that machine. Plain HTTP is permitted for these local addresses only; anything on the public internet must use HTTPS, which the app enforces when you enter the address.

To Google, for advertising — iPhone and iPad only

The iPhone and iPad app is free and shows ads through Google Mobile Ads (AdMob). It asks for App Tracking Transparency permission so ads can use the advertising identifier (IDFA); if you decline, you still see ads, just less relevant ones. Google's handling of that data is described in its privacy policy. The Mac app contains no advertising code at all, and ads never have access to your conversations on any platform.

Nothing else

Nowhere. Nothing goes to us, because there is no “us” on the network.

5. This website

Everything above is about the app. The website you are reading, liliairouter.app, is separate, and it does use analytics: Firebase Analytics, Google's analytics service (Google Analytics 4), to count visits and see which pages are read. It runs only on this website's pages; the iPhone, iPad and Mac apps are unaffected.

When you open a page, your browser loads Google's analytics scripts, and Google may set or read cookies or similar identifiers in your browser. It receives technical information such as the page you viewed, how you reached it, your browser and device type, language, screen size, an approximate location derived from your network address, and interactions like clicks on a download button. We use this only in aggregate — to learn what visitors read and whether the site is doing its job. There are no accounts on this site, so we have no way to tie any of it to who you are, and we do not try to.

  • Who processes it: Google, under its Firebase privacy terms and privacy policy. Data is kept for the retention period set in our Firebase project (Google offers up to 14 months).
  • Opting out: the site works fully without it. Block it with your browser's tracking protection or a content blocker, or use Google's Analytics opt-out add-on.
  • Not on the apps: nothing in this section applies to the app itself.

6. Nothing runs offline more literally

On-device models and Apple Intelligence run entirely on your hardware. With those selected, you can put the device in airplane mode and keep working; not a byte of the conversation goes anywhere.

7. The Mac API server

The Mac app can expose your configured providers to other programs on your own machine through a local HTTP server, which is off until you turn it on. It refuses to start without an access key you generate; only the SHA-256 digest of that key is stored, in the Keychain. It listens on loopback only unless you explicitly enable sharing on your local network, and even then it accepts connections only from private network addresses. Nothing about this server reaches the internet or us.

8. Permissions the app asks for

PermissionWhy
CameraOnly to take a photo you choose to attach to a message.
PhotosOnly to attach an image you pick.
Local networkTo reach Ollama, LM Studio or llama.cpp on your Wi-Fi, and on Mac to let devices on your network use the API server if you enable it.
Tracking (iPhone / iPad)Asked by Google's ad SDK. Declining is fine and costs you nothing in the app.

9. Retention

  • On your device: everything stays until you delete it, or until you delete the app.
  • At your providers: governed by each one's own retention policy.
  • At Google (ads, iOS only): governed by Google's policy.
  • With us: nothing, because we store nothing.

10. Security

Credentials are kept in the Keychain, Apple's dedicated secure store, rather than in any file the app writes. Network requests use HTTPS/TLS, with the narrow local-network exception described above. On-device data benefits from the platform's standard file protection. No system is perfectly secure, but there is very little here to attack: the valuable material never leaves your hardware.

11. Your rights

Because your content lives on your device rather than our servers, you already hold it directly. You can view, edit and delete anything inside the app, export every session as JSON, or delete the app to remove all of it at once. For questions about data processed by Google for advertising, write to us and we will help, including forwarding deletion requests where they apply.

European Union / EEA (GDPR)

  • Controller for advertising data: DevZHR, [email protected]. For content you send to a provider you configured, that provider is the controller.
  • Lawful bases: consent (ad personalisation, via the ATT prompt you may decline) and legitimate interest (showing non-personalised ads so the app can be free).
  • You have rights of access, rectification, erasure, restriction and objection, and the right to complain to your local Data Protection Authority.

California (CCPA / CPRA)

  • We hold no server-side personal information at all. Google processes advertising data as described in its own policy.
  • We do not sell personal information. You can limit ad personalisation by declining the tracking prompt.
  • We will not treat you differently for exercising any of these rights.

12. Children

The app is not directed at children under 13 and we do not knowingly collect personal information from them. It carries a 13+ age rating because it can show AI-generated content that is not moderated by us. If you believe a child has provided personal information through the app, write to us and we will address it.

13. Changes

We may update this policy — for instance when a platform or a service provider changes. Significant changes update the “Last updated” date above and, where it matters, are surfaced in the app. Continuing to use the app after a change means accepting it.

14. Contact

Email [email protected]. We reply within 30 days.