MarzsAI

Privacy

Privacy Policy

Effective 30 August 2026. This is the whole policy. There is no longer version.

Changed on 8 September 2026, and it is the same correction as the one below dated 30 August, made a second time in a sentence that sweep missed. The photos section ended with a claim that a message's words were the sole thing the app ever transmits. That is narrower than the truth, and this page already said so three sections earlier, where it lists what a request carries: the messages, anything you have saved to memory, a short description of what the app can do, which response style you picked, and a number that stands for your copy of the app. The page disagreed with itself. The photos section now points at that list instead of restating it. Nothing about the product changed and nothing new leaves your phone.

Changed on 1 September 2026, under what our server records. The server now adds up how much processing it did each day, across everyone, and stops for the rest of the day if that total reaches a ceiling. It is one number per day with no address in it and nothing about who sent anything. It exists so that a runaway cost stops by itself instead of running until someone notices. Nothing changed in the app, and nothing new leaves your phone.

Changed on 30 August 2026, and it is a correction rather than a new feature. Four sentences on this site and one inside the app said that nothing but your messages leaves your phone. That was written before memory existed and it was never updated. Memory does leave: it is sent with every message, and it is carried through your own iCloud account if you have iCloud on. The memory section below has said so since the feature shipped, so the page disagreed with itself; the sentences that were too strong now say what actually goes out. Nothing about the product changed. What changed is that the description of it is no longer narrower than the truth.

Changed on 28 August 2026, in two places, both under what our server records. The server now keeps a count of how many requests it answered each day, which carries no address and nothing about who sent them. And the retention figure for usage counts was wrong: it said 90 days, the service has only ever kept them for about an hour, and it was corrected that day to 60 minutes. The figure moved again later, and the current one is in the retention list below. Nothing changed in the app, and nothing new leaves your phone.

Changed on 26 August 2026: the website no longer has accounts, sign in, saved conversations or subscriptions. Those features were removed and the database behind them was deleted, so the three sections that described them have been rewritten to say what is there now. Nothing changed about the iOS app.

What this covers

This policy covers the MarzsAI iOS app and the MarzsAI website at marzsai.app. They are described separately below, because they do different things. The app has no accounts and keeps your conversations on your phone. The website is three pages of text and collects nothing but page-view counts. Almost everything in this policy is about the app, because the app is where everything happens.

Memory

The app can keep a short list of things worth remembering between conversations, such as that you prefer one programming language to another or that a relative has a birthday in March. You can add to that list yourself. On some devices the app can also notice something during a conversation and add it for you.

The list is stored on your device. If you have iCloud turned on it also syncs through your own iCloud account, which means it follows you to your other devices and counts against your iCloud storage rather than against anything of ours. We cannot read it. There is no copy of it on our server.

It is sent with your messages. That is the point of it: the reply can only take account of something it has been told. So everything on that list goes to OpenRouter and to a model provider on every message, in the same way the text of your conversation does, and it is covered by everything this page says about that.

You can read the whole list, change any of it, and delete any or all of it, in Settings under Memory. Deleting something removes it from your device and from your iCloud, and stops it being sent with future messages. It does not reach back into requests that have already been answered. If the list grows longer than fits in a request, the app sends the ones you wrote first and then the most recent, and the Memory screen draws a line showing which ones are not being sent.

Health and fitness information is not stored here and the app does not read it.

What leaves your device when you send a message

The text of the conversation, anything you have saved to memory, and any photo you attach to a message. To answer a message, the app sends the message and enough of the preceding thread for the reply to make sense to our server, which forwards it to OpenRouter, which passes it to a model provider that generates the reply. Those are your words leaving your device and being handled by companies that are not us. It is the core of how the product works and there is no version of it that keeps your messages on the phone.

The request carries no name, no account and no email. What it does carry is the messages, any photos you attached to them, anything you have saved to memory, a short description of what this app can do so the reply does not invent features that are not there, which of the two response styles you picked, and a number that stands for your copy of the app. Nothing else.

That number is how the messages are counted. It is a random value the app makes on first launch and keeps on the phone; it is not your name, not your Apple Account and not an identifier for the device. Our server uses it to add up how many messages your copy of the app has sent this calendar month, and it is not passed on to OpenRouter or to any model provider. If you delete the app and install it again, a new number is made and the count starts from zero. If you have a subscription, the request also carries the signed receipt Apple issues for it, so the higher monthly limit can be applied.

OpenRouter, and the model providers behind it

There are two companies involved and they do different things, so this page names one and not the other. Every request goes to OpenRouter. That is fixed, it happens on every message, and there is no configuration in which it does not, so we name it.

OpenRouter then routes the request to one of a small configured set of model providers, falling back to another if the first is unavailable. Which one answers a given message is a server-side detail that changes without an app update, so a name printed on this page for that layer would go out of date without anyone noticing. If you want to know which providers are currently configured, ask and we will tell you.

What does not change is the obligation. Every provider in that set is bound by its own terms to process the text only for the purpose of returning a reply, and is required to provide protection of your data equivalent to what this policy describes. We do not authorise any of them to sell your messages or to use them to build advertising profiles. Providers do retain request data for a period under their own policies, typically for abuse monitoring, and that retention is theirs rather than ours. If you want to know which providers are currently configured, ask via the support page and we will tell you.

What stays on your phone (iOS app)

  • Your conversations. Every thread and message is stored in a database on the device itself. We have no copy. There is no account to sync them to, and they are not carried through iCloud either. Memory is the one thing in the app that is, and it has its own section above. If you delete the app, your conversations are gone, and we cannot restore them for you.
  • Your settings. Response style, appearance and one visual preference, kept in the app's own local settings. Never sent anywhere.
  • An anonymous install identifier. A random value generated on the device and held in the iOS Keychain. It is not derived from anything about you or your hardware. It is sent with your messages so they can be counted, which is described under what leaves your device. Until 6 September 2026 it was never transmitted, and this entry said so.

What our server records

Our server does not store your conversations when you use the iOS app. It keeps a few operational records. Two of them exist to stop one person or script from exhausting the service for everyone else. The other two are daily totals for the whole service, carrying no address and nothing about who sent anything: one counts how many requests arrived, so we can tell whether anyone is using the app at all, and one adds up how much work the service did, so it can stop itself before a runaway cost.

  • Usage counts. Per request: the originating IP address, the number of tokens the request and reply consumed, and a timestamp. Not the text.
  • Rate-limit and error events. When a request is refused for exceeding a limit, or fails, we record the IP address, which endpoint was involved, and the limit or error concerned. Not the text.
  • A daily request count. One number for each day: how many requests arrived at the chat endpoint. No address, no identifier, nothing about who sent them and nothing about what they said. It cannot be broken down by person, because there is nothing in it to break down by.
  • A daily total of work done. One number for each day: how much processing the whole service used, added up across everyone. There is a ceiling on it, and when the day's total reaches that ceiling the service pauses until the next day rather than running up a bill. We also record the time it paused, if it ever does. No address, no identifier, nothing about who sent anything and nothing about what they said. Like the count above, it cannot be broken down by person, because there is nothing in it to break down by.

An IP address is personal data in some jurisdictions, which is why it is named here rather than described as anonymous. Server request logs held by our hosting provider also contain IP addresses and are retained under that provider's own schedule.

The website, which collects nothing

The website is three pages: a page describing the app, this policy, and a support page. There is nothing to sign in to. You cannot make an account, there is no sign in form, and there is nothing to buy. The only thing recorded is:

  • Aggregate page-view analytics from our hosting provider. This measures traffic, not people, and it exists on the website only. The iOS app records no page views and nothing about what you do inside it: not what you tap, not which screens you open, and no session or foreground timer of any kind. It is not, however, blind to when you send a message: as the section on what leaves your device says, each request is counted against the address it came from with a timestamp, for 61 minutes. That is the whole of it, and this paragraph used to end “and not how long you spend in it” — which read as a broader promise than the one above it could keep.

Until 26 August 2026 the website did have accounts, sign in, saved conversations and subscriptions. Those features were removed and the database that held them was deleted. Any account records, website conversations and subscription records that existed were deleted with it. If you had an account on the website, there is nothing left of it to ask us for and nothing left to delete.

The one thing the website can send you is a mail you started. The support page shows a mail address. If you write to it, we have your message and your address because you sent them. That is ordinary mail rather than a feature of the site, and an address you write from is used to reply to you and nothing else.

The front page has a box for asking for a feature. What you type in it is stored on our own server, in the same store that holds the rate-limit counts, and it is read by a person. The email field is optional, an address you leave is used only to write back to you, and nothing else about the request is recorded: no address, no identifier, and nothing about the browser you sent it from. It goes to no third party, because there is no form service involved. Ask us to delete a request and we delete it.

Photos, and the two permissions the app asks for

The app asks for two permissions and no others: your photo library, for Trips, and a rough location, for finding somewhere nearby. Neither is asked for until you use the feature that needs it.

The app has a Trips feature. If you use it, it asks to read your photo library so it can pull in the photos you took on a set of days you choose, along with the place and time the camera recorded for each one. Nothing else in the app needs it. Until you start a trip and choose to import, you are never asked.

What it does with them: it keeps its own smaller copies on your phone, works out a place name for each location once, and stores that too, so a trip still knows where it went when you look at it with no signal. It does not write anything back to your photo library and nothing in your camera roll changes. No photograph, and no location taken from one, is sent to us or to anyone else by Trips. Photos have exactly one route off this phone: a photo you attach to a chat message yourself, which travels with that message the way the section above describes. Trips is not that route and never uses it. What else the app sends is set out above, under what leaves your device when you send a message.

iOS lets you grant access to selected photos rather than all of them. If you do, the app sees only the ones you picked, and it says so rather than telling you a range of days held no photographs.

What we do not do

We do not track you across other companies' apps or websites. We do not sell your data. We do not show advertising and we do not build advertising profiles. The iOS app contains no advertising or attribution frameworks and no usage analytics. It contains one third-party framework, which records subscription purchases and is described above; it receives no screens, no events and none of your messages. It does not ask for your contacts or the microphone. The permissions it does ask for are photos, only for Trips, and a rough location, only when you ask for somewhere nearby.

This section used to say the app asked for no permissions at all, and it named photos as one of the things it did not ask for. That was true until Trips shipped. It is corrected here rather than quietly dropped, because it was specific enough to have been relied on. Everybody already using the app is shown the changed disclosure once, inside the app, and asked to agree to it again.

How long things are kept, and how to have them deleted

  • Conversations in the iOS app. Kept until you delete them. Delete one thread by swiping it in the conversation list, or all of them at once from Settings. Deleting the app removes them too. This is immediate, local, and needs nothing from us.
  • Usage counts. Kept for 61 minutes, then deleted automatically. The rate limit works on a rolling window of one hour, and the key is given one extra minute so that it outlives the window it serves instead of expiring inside it. This used to say 90 days, which was longer than the service has ever kept them, and then 60 minutes, which was a minute shorter than the code.
  • Rate-limit and error events. Lines in our hosting provider's request logs, kept under that provider's own schedule. We keep no separate copy of them.
  • Daily request counts. Kept for 400 days, then deleted. They are counts with nothing in them about a person, and a year of them is what makes it possible to see whether use is growing.
  • Daily totals of work done. Kept for 35 days, then deleted. A month is enough to see whether the ceiling is set sensibly, which is the only thing they are for.
  • Mail you send us. Kept in an ordinary mail inbox for as long as it is useful to answer you. Ask us to delete a thread and we delete it. We aim to do that within 30 days.
  • Text held by a model provider. Retained under that provider's own policy, which we do not control. We can tell you which providers are configured so you can read theirs.

To withdraw consent for the processing that reaches us, stop sending messages. Nothing is collected in the background by us. The one thing that moves without you sending a message is memory, which is carried through your own iCloud account rather than ours, and turning iCloud off for MarzsAI in your iOS settings stops that. To request deletion of anything described above, or a copy of what we hold about you, use the support page.

Children

MarzsAI is not directed at children under 13, and we do not knowingly collect anything from them. If you believe a child has sent us data, contact us and we will delete it.

Changes

If what the product does changes, this page changes with it and the effective date at the top moves. A change that widens what leaves your device will be described here in plain terms rather than absorbed into a longer document.

Contact

Questions, deletion requests and access requests all go to the same place: marzsai.app/support.

Designed in California · MarzsAI