Privacy Policy

Last Updated: Aug 31, 2026
🛡️

Privacy by Design

When using local servers, chats stay on your hardware. We never see your prompts.

🔐

Zero Accounts

No login required. Your identity remains anonymous to us.

📂

Total Control

Export or delete your JSON vault at any time.

At TechMitten LLC, we care deeply about your privacy and respect your right to keep your conversations private. TechMitten LLC does not see or collect your local server chat data, nor can we see your data if you optionally use cloud APIs like OpenRouter. We will never share your chats with advertisers, and other apps on your device cannot access your stored chat data. LMSA is engineered from the ground up for complete data sovereignty, meaning you remain in full control of your information when using local servers.

This Privacy Policy explains exactly how we protect your data across the LMSA Android app and our website (lmsa.app). We are fully committed to complying with GDPR, CCPA, COPPA, and modern privacy standards. By using our services, you agree to these practices. Your use is also subject to our Terms of Service.


We believe in data sovereignty: we don't own your chats

LMSA Android App

When you use our Android app, we stick to a simple rule: minimal collection, maximum privacy.

  • Your chats stay in a local vault: All your custom characters and chat histories are saved inside a local JSON file right on your Android device.
  • The app talks directly to your computer: When you connect to LM Studio or Ollama, the app establishes a direct handshake with your machine. Your data never touches TechMitten servers.
  • Using cloud backends: If you choose to use a cloud service like OpenRouter, your chats are sent directly to OpenRouter's servers and follow their Privacy Policy.

Zero Data Retention (ZDR) – How LMSA respects your privacy when using OpenRouter

LMSA enforces Zero Data Retention (ZDR) when you chat with any OpenRouter model that qualifies for this feature. This gives you the highest level of privacy available from cloud‑based AI providers.

What ZDR means (as defined by OpenRouter)

"Zero Data Retention (ZDR) means that a provider will not store your data for any period of time. Providers that do not retain your data are also unable to train on it. (Some providers may retain data temporarily for abuse detection or legal compliance without training on it – OpenRouter gives you separate controls for training policies.)"

ZDR is an OpenRouter feature, not an LMSA feature

Zero Data Retention is a privacy feature provided by OpenRouter. LMSA does not have its own ZDR mechanism. Instead, for every chat request sent to OpenRouter, LMSA automatically adds the zdr: true parameter and only allows models that OpenRouter lists as ZDR‑compatible.

Models that support ZDR are marked with a green shield icon in the model picker. Models that do not support ZDR will not have this icon.

You cannot turn ZDR off within LMSA – this protection is always active for qualifying models. However, this does not override your own OpenRouter account settings: any ZDR-related preferences you have configured directly with OpenRouter always take precedence over the zdr: true parameter that LMSA sends with each request.

How OpenRouter handles ZDR requests

Per OpenRouter: OpenRouter routes your requests only to endpoints that have a verified Zero Data Retention policy. OpenRouter tracks the specific retention and training policy for each individual endpoint, works with providers to keep these policies up to date, and in some cases negotiates special agreements with providers to secure data retention or training terms that are more privacy-focused than that provider's default policy. If a clear policy cannot be established, OpenRouter assumes the endpoint both retains and trains on data and will not send ZDR‑enforced requests to it. You can also enforce ZDR globally in your OpenRouter account settings, per model group, or per request. OpenRouter itself has a ZDR policy; your prompts are not retained unless you explicitly opt in to prompt logging.

LMSA's role and limitation of liability

TechMitten LLC and LMSA act only as a conduit – we send the zdr: true flag and respect OpenRouter's model compatibility list. We are not responsible for any failure on OpenRouter's part to properly handle ZDR. If, for any reason, Zero Data Retention is not actually applied by OpenRouter or a downstream provider – whether due to OpenRouter bugs, misconfigurations, provider policy changes, API errors, or any other circumstance – LMSA cannot be held liable. The ZDR feature is provided "as is", and your use of it is at your sole risk. LMSA and TechMitten LLC have no involvement in, oversight of, or control over how OpenRouter or its providers manage data retention – it is managed entirely by OpenRouter and the underlying providers.

LMSA does not control OpenRouter's internal systems, we encourage you to:

  • Check your OpenRouter activity logs to confirm that requests show ZDR enforcement.
  • Review OpenRouter's current list of provider endpoints and how each one handles data retention and logging.
  • Contact OpenRouter support if you believe a request was improperly retained.

Learn more

For the complete, authoritative explanation of Zero Data Retention (including which providers support it, how to configure it at the account level, and OpenRouter's own retention practices), please read OpenRouter's official documentation: https://openrouter.ai/docs/features/zdr

Our Web Search feature is optional and privacy-focused

LMSA offers an optional “Web Search” feature powered by Brave Search to fetch live information from the web. When enabled, the app on your device sends queries directly to Brave Search. Here is how your privacy is handled:

  • It is strictly opt-in: Web Search is turned off by default. You must explicitly enable it in your app settings, and you can turn it off at any time.
  • Direct connection to Brave: LMSA only transmits the specific search query generated by the AI to get real-time web context. We never attach your name, email, or other personal identifiers. However, because your device connects directly to Brave Search, your queries are processed under the Brave Search Privacy Policy. By enabling this feature, you agree to their policy.
  • All connections are secure: All queries sent to Brave Search are transmitted over secure, encrypted HTTPS channels.
  • Accuracy and safety: Brave Search is highly accurate, but we cannot guarantee that the information it returns from the live web is completely correct or safe.

How we handle Voice Mode (Local Transcription & TTS)

LMSA includes an optional Voice Mode feature that allows you to have real-time conversations using your voice. To protect your privacy, this feature is built with a local-first design:

  • Voice Transcription via Native Android Services: Your voice input is transcribed using your device's native speech recognition service. TechMitten LLC does not collect, store, or receive your raw vocals or voice recordings. Please note that the native Android transcription service may connect to Google/Android servers to process the audio, and is governed by the Google Privacy Policy you accepted when setting up your device.
  • Automated Text-to-Speech (TTS): The app automates text-to-speech playback using your device's native text-to-speech engine. While many native voice models are processed entirely on-device, some voice options are processed over the network by the device's native TTS service (these are marked with a "network" tag in the voice settings and are pre-existing native options on your device). TechMitten LLC does not host or process these voices, and any network-based synthesis is governed by your device manufacturer's or OS provider's privacy terms.
  • Standard Text Prompts to Backend Models: Because the voice transcription and text-to-speech synthesis are managed via native services on your device (either locally or via native network-based TTS), LMSA only sends the resulting text prompts to your selected AI backend (such as local servers or OpenRouter). The backend models never receive your voice or audio recordings, allowing you to use standard text-only models without needing specialized multimodal audio or voice recognition capabilities.

How we handle biometric locking

If you upgrade to LMSA Premium, the app offers enhanced security features that run entirely on your own device:

  • We have no access to your biometrics: If you turn on Fingerprint or FaceID locking, we do not collect, store, or see your biometric data. The app simply requests authentication through Android’s BiometricPrompt API, and your device's secure hardware handles the rest.

Any information processed is kept to an absolute minimum

We aim to keep your experience entirely anonymous, but our third-party partners require a few basic details to keep our services running. Here is exactly what is processed and why:

We use privacy-first analytics and optional tracking pixels on our website

For our website (lmsa.app), we prioritize your privacy by defaulting to Umami Analytics, which is a cookieless, privacy-first analytics system hosted in the USA that does not collect any personal data.

We only load third-party tracking scripts—specifically Google Analytics and the Facebook Meta Pixel—if you explicitly grant permission through our cookie consent banner.

Facebook Meta Pixel (Website only)

If you opt in to third-party tracking, we use the Facebook Meta Pixel (provided by Meta Platforms, Inc.) on our website. The Pixel collects information about your interactions with our site (such as pages visited and links clicked) to help us measure and optimize the effectiveness of our marketing campaigns, build retargeting audiences, and deliver relevant advertisements on Facebook.

This tracking is strictly opt-in. You can manage or revoke your consent at any time by clicking "Manage Cookies" in our website footer. Revoking consent will instantly stop Meta Pixel tracking and delete its tracking cookies (specifically `_fbp` and `_fbc`) from your browser. You can also opt out of interest-based ads directly in your Meta account settings or via the Digital Advertising Alliance at optout.aboutads.info.

Google Play Store handles licensing checks

To deliver premium features and verify your purchase status, the app interacts locally on your device with the Google Play Store APIs. TechMitten LLC does not host a database or collect your purchase history.

Google AdMob serves advertisements in the free tier

To fund ongoing development, the free version of LMSA displays advertisements served by Google AdMob. Your interaction with these advertisements is subject to the Google Privacy Policy. If you live in the European Economic Area (EEA) or the UK, we use Google’s User Messaging Platform (UMP) so you can choose whether to allow personalized or non-personalized ads.

Our commitment to regional privacy rights

TechMitten LLC highlights the regional privacy disclosures below for the sole purpose of confirming that we are aware of these rights and will fully respect and honor them.

European Union & United Kingdom (GDPR)

TechMitten LLC acts as the “Data Controller” for the minimal personal details we process. We follow GDPR principles of privacy-by-design, which means we make sure we handle your data in a transparent and lawful way.

Who controls and holds your data?

Because LMSA is designed to be a local-first application, your chat history, characters, and local settings are stored directly on your own device. When you connect LMSA to local server providers (like LM Studio or Ollama) running on your own hardware, you keep physical custody and control of that data. However, your use of those local servers, or any external API providers (like OpenRouter or Brave Search), is subject to their respective Terms of Service and Privacy Policies.

TechMitten LLC only acts as a controller for the minimal information we actually receive (such as website analytics, support requests, or Google Play purchase validations). We do not—and cannot—access, edit, or delete any data stored in your local app vault, nor do we control or store queries sent to local or cloud server integrations. If you wish to exercise your rights regarding data processed by those local or cloud providers, you must contact them directly. Their rules govern their services and do not reflect on us or represent us in any way.

Your Rights as an EU/UK Resident

If you reside in the European Union, United Kingdom, or a jurisdiction with similar data protection laws, you have the following standard rights under the General Data Protection Regulation (GDPR):

  • Right to access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can request that we correct inaccurate or incomplete personal data.
  • Right to erasure (Right to be forgotten): You can request the deletion of your personal data under certain conditions.
  • Right to restrict processing: You can request that we limit how we process your personal data under certain conditions.
  • Right to data portability: You can request the transfer of your personal data to another organization or directly to you in a structured, machine-readable format.
  • Right to object: You can object to the processing of your personal data, including for marketing purposes or where we rely on legitimate interests.
  • Rights in automated decision-making and profiling: You have the right to object to decisions based solely on automated processing. TechMitten LLC does not use automated profiling or make automated decisions about you.
  • Right to withdraw consent: If you gave us consent to process your data, you have the right to withdraw that consent at any time.

How to contact us to exercise your GDPR rights

To exercise any of these rights, just send us a message:

We will get back to you within 30 days. If your request is particularly complex, it might take us up to 90 days, but we will let you know. We will also ask for info to verify who you are before we share or change any data.

Our legal reasons for processing your data

Under GDPR rules, we only process your personal data when we have a valid legal reason:

  • Our legitimate interests: We analyze basic website performance and app operations to improve our services, making sure we have strong safeguards in place to protect your privacy.
  • Your consent: For optional cookies, personalized ads via AdMob, and marketing updates, we only use your data if you give us permission. You can withdraw this consent at any time.
  • Fulfilling a contract: We process the basic data required to provide the LMSA app and website features you want to use.
  • Our legal duties: We keep and share data when the law demands it, such as for tax, financial, or regulatory purposes.

We have a Data Protection Officer to help

We have appointed a Data Protection Officer (DPO) to oversee how we follow data protection laws. You can reach out to them directly:

We will notify you in the rare event of a data breach

If there is ever a data breach that could put your rights and privacy at risk, we will notify both you and the proper authorities without delay. Our update will explain what happened, the potential impact, what we are doing to fix it, and whether we have notified the relevant supervisory authority.

We do not make decisions about you using algorithms

We never use automated algorithms or profiling to make major decisions about you that have legal effects.

You can file a complaint with a supervisory authority

You always have the right to file a complaint with a data protection authority if you feel we have handled your data incorrectly. For example:

  • European Union: Find your national Data Protection Authority via the EDPB
  • United Kingdom: Contact the Information Commissioner's Office (ICO)
  • Other jurisdictions: Check with your local data protection authority

State of California (CCPA/CPRA)

The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) give California residents control over their personal information. TechMitten LLC does not directly collect, store, process, or sell your personal information. Any data processed in connection with our app or website is handled by our third-party partners (such as Google Play, Google AdMob, or Umami Analytics) according to their own policies.

You still have the following rights under California law regarding any data processed by third parties in connection with our services:

  • The right to know: You can ask what categories of personal information are processed, shared, or sold by businesses.
  • The right to delete: You can request the deletion of personal information processed about you.
  • The right to correct: You can request that inaccurate personal information be corrected.
  • The right to opt out of selling or sharing: You can direct businesses not to sell or share your data. We do not sell your data, but you can opt out of third-party cookies on our site at any time.
  • The right to non-discrimination: You will never be treated differently or charged different prices for exercising your privacy rights.

How to exercise your California rights

To submit a request regarding your California rights, you can contact us:

If you make a request, we will verify your identity and respond within 45 days (or up to 90 days for complex requests). Because we do not directly collect or store your personal information, please note that we do not have access to or custody of any raw data collected by Google Play, Google AdMob, or other third-party services. To exercise rights for data held by those companies, please contact them directly.

We do not share your info for third-party marketing

Under California's "Shine the Light" law, we confirm that we never share any personal information with third parties for their own direct marketing purposes without your consent.

You can opt out of selling or sharing

You have the right to opt out of data sharing at any time:

  • On our website: You can adjust your preferences via our Cookie Settings.
  • In the app: You can contact us to request restrictions on optional data sharing.
  • Via email: Just send an opt-out request to privacy@lmsa.app.

We will only disclose your information if we are legally forced to

If law enforcement, a court, or a government agency sends us a valid legal request to share data, we will comply. But we will make sure to protect your privacy as much as possible:

  • We will comply with valid legal requests only as required by law.
  • Where legally permitted, we will give you notice of such requests.
  • We will limit what we disclose to the absolute minimum required by law.
  • We will challenge any requests that are too broad or invalid.

We review and validate every government request to make sure it is legally required before we share anything.

We respect your inbox and your marketing preferences

If you give us your email, we may send you messages about app updates, new features, or support requests. We will never use your email to send marketing messages unless you explicitly sign up for them.

You can opt out of emails at any time

You can unsubscribe from non-essential emails by:
• Clicking the unsubscribe link at the bottom of any email we send
• Contacting us at privacy@lmsa.app to request removal from our mailing list
Please give us up to 10 business days to update our list.

We are not responsible for websites we link to

Our website and app contain links to other services, like OpenRouter, the Google Play Store, and external websites. This Privacy Policy only covers our own site and app. We don't control and aren't responsible for the privacy practices of other companies, so we encourage you to read their privacy policies before giving them any information.

We will notify you when we update this policy

We might update this privacy policy from time to time. When we do, we will let you know by:

  • Posting the new policy on this page
  • Updating the "Last Updated" date
  • Displaying a notice on our website for any significant changes

How to get in touch with us

Company

TechMitten LLC

Plymouth, Michigan USA