🛡️
Privacy commitment — transparency, not just promises

Privacy isn't a feature.
It's the foundation.

Every design decision starts with one question: can this stay on your device? If the answer is yes, it stays there. No exceptions.

What privacy-first actually means

These aren't marketing claims. They're hard constraints baked into how Buddy is built.

🏠
On-device first

All sensitive requests — your files, calendar, health, contacts — are handled entirely by local AI models. They never touch the internet.

🎙️
Voice stays local

Audio recording starts only after your wake word fires and stops the moment you finish speaking. Your raw audio is never uploaded anywhere.

🔐
Encrypted at rest

Your voice profile, conversation history, and personal context are stored locally with military-grade encryption. Only you hold the key.

🚫
Zero telemetry

Buddy collects no usage analytics, no crash reports, no behavioral data. There is no "home base" Buddy phones home to.

✂️
PII stripped before cloud

When a request genuinely needs cloud AI, Buddy automatically strips names, locations, and identifying details before it leaves your machine.

👤
No account required

Buddy runs without sign-up, login, or any identity tied to you. There is no profile of you on any Buddy server — because there are no Buddy servers.

Two tiers — your data decides

Every request Buddy receives is automatically classified by an on-device model. Sensitive data never leaves. General questions go to cloud only after PII removal.

🧠 Buddy's local AI brain classifies every request in a fraction of a second before any processing begins
🟢 Tier 1 — Local
Stays on your device

Handled entirely by on-device AI models. No network connection. No exceptions. These are requests where your personal context matters most.

Anything about your files or documents
Calendar, reminders, to-do items
Health data and personal metrics
Contacts and communication history
Home location and daily routines
Anything you've marked as private
🔵 Tier 2 — Cloud (PII removed)
Cloud as a last resort

Only used when local models genuinely can't handle the complexity. All identifying information is stripped before the request leaves your device.

Complex multi-step reasoning tasks
General knowledge questions
Code generation and debugging
Creative writing and brainstorming
Language translation
Web search and current events

Exactly what Buddy stores and where

No guessing. Here's every piece of data Buddy touches and precisely where it lives.

Data type What it is Where stored Encrypted
Voice profile A mathematical embedding of your voice (not a recording) 🏠 Your device Military-grade
Conversation history Past questions and answers, used to build context over time 🏠 Your device Military-grade
Personal memory Facts you've told Buddy (preferences, routines, names) 🏠 Your device Military-grade
App context What app is open, screen region for context-aware answers 🏠 RAM only Not persisted
Audio recordings Raw voice audio after wake word trigger ✕ Never saved
Usage analytics How often you use Buddy, what features you use ✕ Not collected
Cloud query content Text sent to cloud AI (Tier 2 only, PII removed) ↗ Cloud, PII-free TLS in transit

Things Buddy will never do

These are architectural constraints, not policy promises. The system is built so these things are technically impossible.

Train on your data Your conversations and personal context are never used to improve any AI model — not ours, not our cloud partners'.
Record without trigger Buddy's microphone access activates only after the wake word fires. Continuous background recording is architecturally impossible.
Share data with third parties No analytics SDKs, no advertising networks, no data brokers. Buddy has no revenue model that involves your data.
Send raw audio to the cloud Transcription happens entirely on your device. Only text ever has the potential to leave — and only after classification.
Build a profile on you There is no Buddy account, no user ID, no cross-device sync to a server. You are not identifiable to us.
Require an internet connection Core Buddy functionality — wake word, transcription, local reasoning, memory — works fully offline. Cloud is opt-in.

Under the hood

Privacy by architecture, not by policy. Here's how it's enforced technically.

Encryption standard
Military-grade encryption

All locally stored data — voice profiles, memory, conversation history — is encrypted using the strongest standard available, with a key that only your device holds.

Local database
Private local database

Personal memory and conversation history live in a private encrypted database stored entirely on your device. The file is unreadable without your device key.

Wake word model
Buddy's always-on listener

A tiny program running entirely on your device. Listens for one phrase only. Uses almost no CPU. No audio is streamed or stored until you say "Hey Buddy".

Transcription
Buddy's voice engine

Your voice is converted to text entirely on your device. Your audio never leaves your machine — only the resulting text can move forward, and only after classification.

Privacy classifier
Buddy's local AI brain

Every request is classified in a fraction of a second by Buddy's local AI brain before any routing decision. Sensitive requests are blocked from the cloud regardless of content.

PII removal
Buddy's privacy filter

Before any cloud request, Buddy's privacy filter strips your name, location, organisation, and any other personal identifiers from the text before it leaves your device.