Terms of Service
Privacy Policy
Our privacy commitment, in plain language
Complice is built so that your conversations, prompts, and documents stay on your device by default. There is no Complice account, no sign-up, and no server where your content is stored — we (the developer) have no way to see, read, or access what you write or generate in the app when you use local, on-device models.
Specifically:
- Chat runs on-device by default, using open-source local models (via Apple's MLX framework) that you download once from Hugging Face. Nothing you type is sent anywhere for this.
- If you use a cloud AI model (Claude, GPT, or Gemini), your prompt — and only your prompt/attachments for that specific request, never your full local chat history — is sent, over an encrypted connection, to that provider. Unless you've supplied your own API key (see below), this request is routed through a relay service (AIProxy) that does not log or store the content of successful requests or responses, and never exposes full provider API keys inside the app.
- On Mac, you can supply your own API key for Anthropic, OpenAI, or Google in Settings. When you do, your requests go directly from your Mac to that provider, using your own account and key — Complice and its relay are not involved at all in that path, and your key never leaves your device's Keychain.
- We do not run any analytics SDK, tracking pixel, or advertising SDK in Complice. The only usage data that may exist is the fully anonymized, aggregated data Apple collects if you've opted in to "Share [App] Analytics" in your device Settings.
- On iOS, some cloud AI models require a paid Subscription (handled entirely through the App Store and RevenueCat, which only sees anonymized purchase events). On Mac, you can unlock cloud models either the same way, or by using your own API key instead.