MarzsAI

Privacy

Privacy Policy

Effective 26 August 2026. This is the whole policy. There is no longer version.

Changed on 26 August 2026: the website no longer has accounts, sign in, saved conversations or subscriptions. Those features were removed and the database behind them was deleted, so the three sections that described them have been rewritten to say what is there now. Nothing changed about the iOS app.

What this covers

This policy covers the MarzsAI iOS app and the MarzsAI website at marzsai.vercel.app. They are described separately below, because they do different things. The app has no accounts, no analytics and keeps your conversations on your phone. The website is three pages of text and collects nothing but page-view counts. Almost everything in this policy is about the app, because the app is where everything happens.

Memory

The app can keep a short list of things worth remembering between conversations, such as that you prefer one programming language to another or that a relative has a birthday in March. You can add to that list yourself. On some devices the app can also notice something during a conversation and add it for you.

The list is stored on your device. If you have iCloud turned on it also syncs through your own iCloud account, which means it follows you to your other devices and counts against your iCloud storage rather than against anything of ours. We cannot read it. There is no copy of it on our server.

It is sent with your messages. That is the point of it: the reply can only take account of something it has been told. So everything on that list goes to OpenRouter and to a model provider on every message, in the same way the text of your conversation does, and it is covered by everything this page says about that.

You can read the whole list, change any of it, and delete any or all of it, in Settings under Memory. Deleting something removes it from your device and from your iCloud, and stops it being sent with future messages. It does not reach back into requests that have already been answered. If the list grows longer than fits in a request, the app sends the ones you wrote first and then the most recent, and the Memory screen draws a line showing which ones are not being sent.

Health and fitness information is not stored here and the app does not read it.

What leaves your device when you send a message

The text of the conversation, and anything you have saved to memory. To answer a message, the app sends the message and enough of the preceding thread for the reply to make sense to our server, which forwards it to OpenRouter, which passes it to a model provider that generates the reply. Those are your words leaving your device and being handled by companies that are not us. It is the core of how the product works and there is no version of it that keeps your messages on the phone.

The request carries no name, no account, no email and no device identifier. It carries the messages and which of the two response styles you picked, and nothing else.

OpenRouter, and the model providers behind it

There are two companies involved and they do different things, so this page names one and not the other. Every request goes to OpenRouter. That is fixed, it happens on every message, and there is no configuration in which it does not, so we name it.

OpenRouter then routes the request to one of a small configured set of model providers, falling back to another if the first is unavailable. Which one answers a given message is a server-side detail that changes without an app update, so a name printed on this page for that layer would go out of date without anyone noticing. If you want to know which providers are currently configured, ask and we will tell you.

What does not change is the obligation. Every provider in that set is bound by its own terms to process the text only for the purpose of returning a reply, and is required to provide protection of your data equivalent to what this policy describes. We do not authorise any of them to sell your messages or to use them to build advertising profiles. Providers do retain request data for a period under their own policies, typically for abuse monitoring, and that retention is theirs rather than ours. If you want to know which providers are currently configured, ask via the support page and we will tell you.

What stays on your phone (iOS app)

  • Your conversations. Every thread and message is stored in a database on the device itself. We have no copy. There is no account to sync them to, and iCloud sync is switched off. If you delete the app, they are gone, and we cannot restore them for you.
  • Your settings. Response style, appearance and one visual preference, kept in the app's own local settings. Never sent anywhere.
  • An anonymous install identifier. A random value generated on the device and held in the iOS Keychain. It is not derived from anything about you or your hardware, and at present it is never transmitted.

What our server records

Our server does not store your conversations when you use the iOS app. It does keep two operational records, and both exist to stop one person or script from exhausting the service for everyone else:

  • Usage counts. Per request: the originating IP address, the number of tokens the request and reply consumed, and a timestamp. Not the text.
  • Rate-limit and error events. When a request is refused for exceeding a limit, or fails, we record the IP address, which endpoint was involved, and the limit or error concerned. Not the text.

An IP address is personal data in some jurisdictions, which is why it is named here rather than described as anonymous. Server request logs held by our hosting provider also contain IP addresses and are retained under that provider's own schedule.

The website, which collects nothing

The website is three pages: a page describing the app, this policy, and a support page. There is nothing to sign in to. You cannot make an account, there is no sign in form, and there is nothing to buy. The only thing recorded is:

  • Aggregate page-view analytics from our hosting provider. This measures traffic, not people, and it exists on the website only. The iOS app contains no analytics of any kind.

Until 26 August 2026 the website did have accounts, sign in, saved conversations and subscriptions. Those features were removed and the database that held them was deleted. Any account records, website conversations and subscription records that existed were deleted with it. If you had an account on the website, there is nothing left of it to ask us for and nothing left to delete.

The one thing the website can send you is a mail you started. The support page shows a mail address. If you write to it, we have your message and your address because you sent them. That is ordinary mail rather than a feature of the site, and an address used to send a TestFlight invite is used for that and nothing else.

What we do not do

We do not track you across other companies' apps or websites. We do not sell your data. We do not show advertising and we do not build advertising profiles. The iOS app contains no third-party analytics, advertising or attribution frameworks. It asks for no permissions: not contacts, not location, not the microphone, not photos.

How long things are kept, and how to have them deleted

  • Conversations in the iOS app. Kept until you delete them. Delete one thread by swiping it in the conversation list, or all of them at once from Settings. Deleting the app removes them too. This is immediate, local, and needs nothing from us.
  • Usage and rate-limit records. Retained for up to 90 days, then deleted. They are only useful inside a rolling window measured in hours.
  • Mail you send us. Kept in an ordinary mail inbox for as long as it is useful to answer you. Ask us to delete a thread and we delete it. We aim to do that within 30 days.
  • Text held by a model provider. Retained under that provider's own policy, which we do not control. We can tell you which providers are configured so you can read theirs.

To withdraw consent for the only processing the iOS app does, stop sending messages. There is nothing to switch off, because nothing is collected in the background. To request deletion of anything described above, or a copy of what we hold about you, use the support page.

Children

MarzsAI is not directed at children under 13, and we do not knowingly collect anything from them. If you believe a child has sent us data, contact us and we will delete it.

Changes

If what the product does changes, this page changes with it and the effective date at the top moves. A change that widens what leaves your device will be described here in plain terms rather than absorbed into a longer document.

Contact

Questions, deletion requests and access requests all go to the same place: marzsai.vercel.app/support.

Designed in California · MarzsAI