Privacy Policy

How More AI handles your data. More AI is local-first: your conversations stay on your device by default, an account is optional, and you can bring your own API keys so your prompts never touch our servers.

Last updated July 26, 2026

This Privacy Policy explains what information More AI ("More AI", "we", "us", or "our") collects, how we use it, and the choices you have. It applies to our website at more-ai.net, the More AI desktop application, the web app at app.more-ai.net, and any paid plan or credits you buy (together, the "Service").

More AI is an independent software project, operated and published by its founder. Where you buy a paid plan, the seller is Paddle.com Market Limited, which acts as merchant of record and is identified in full on your receipt and invoice. You can reach us at the contacts in the "Contact us" section below.

The guiding principle of the Service is data minimisation. More AI is local-first: by default your conversations, code sessions, and project files stay on your own device. If you bring your own API key, your prompts go directly from your device to the AI provider and never reach us at all. We receive data only when you choose to use an optional feature — an account, cross-device sync, a paid plan that runs on our own model access, telemetry, or problem reporting.

A quick summary

We have written the full detail below, but in short:

  • You can use the More AI desktop app without an account. An account is optional and is needed only for cross-device sync, a paid plan, or the web app.
  • If you bring your own API key, your prompts and the AI responses travel directly between your device and the provider you chose (for example Anthropic, OpenAI, or Google). We do not see, store, or proxy that traffic, and your own API keys never leave your device.
  • If you use a paid plan or credits, you are using model access we provide. Those requests do pass through our servers on their way to the upstream provider. We pass them through — we do not store the prompts or the responses — but they are technically visible to our systems in transit, so treat them as you would any hosted AI service.
  • Conversations, code sessions, and project files are stored locally on your device by default. They are uploaded to us only if you turn on sync.
  • When you do sync, project files (Cowork) are end-to-end encrypted — we hold only ciphertext we cannot read. Chat messages, if you sync them, are stored on our servers in a form we can read; do not sync content you need to keep confidential from us.
  • We collect a description of the computer you run the app on (operating system, processor, graphics, memory, display, disk) so we can fix performance problems on real hardware. It describes the machine and does not identify it or you — no hostname, user name, MAC address, or serial number — and it is off entirely if you turn telemetry off.
  • Payments are handled by Paddle, which is the merchant of record and the seller you contract with. We never see or store your card details.
  • Analytics and error reporting are limited, stripped of your content, and can be turned off in Settings.
  • We do not sell your personal data, and we do not use your content to train AI models.

Who we are (data controller)

For the personal data described in this policy, More AI is the data controller. More AI is an independent project run by its founder rather than a corporate group, and it is the single point of contact for everything in this policy — every request reaches a person who can act on it. If the Service is later transferred to a company formed or acquired to operate it, that company becomes the controller, and we will name it here.

Paddle.com Market Limited acts as the merchant of record for purchases and is an independent controller of the billing data it collects from you. See "Payments and billing" below.

For privacy questions or to exercise your rights, contact us at privacy@more-ai.net.

Information we collect

We collect only what a given feature needs. If you run the desktop app without an account, with your own API key and telemetry off, you share no personal data with us at all.

The sections that follow describe each category, when it applies, and how to avoid it.

Account information

If you create an account (optional — needed for cross-device sync, paid plans, and the web app), we process your email address, which we use for passwordless sign-in. We do not store passwords. When you request a sign-in code we generate a one-time 6-digit code (and a fallback link) that expires within about 15 minutes.

If you provide them, we also store your display name and avatar. When you sign in we create a session (a signed token valid for up to 30 days, which you can revoke by signing out), a record of the device you signed in from — its name, operating-system platform, and the app version — and your time zone, so scheduled features run at the right local time. We do not store your IP address or browser user-agent against your account; an IP address is used transiently only to apply rate limits and is not retained.

Your prompts and AI content — two different paths

How your prompts travel depends on whose model access you use, and the difference matters, so we describe both.

Your own API key (bring your own key). When you connect your own key, the request — your prompts, attached files, and the provider's response — is sent directly from your device to that provider. This data does not pass through our servers, and we never receive your key, which is stored encrypted on your device using your operating system's secure key storage. The provider processes that content under its own privacy policy and terms; you choose it, and we are not a party to, and have no visibility into, that exchange.

Model access included with a More AI plan or credits. When you use a model we provide rather than one of your own keys, your device sends the request to our servers, which forward it to the upstream provider under our credentials and stream the answer back. We operate that path as a pass-through: we do not write the prompts or the responses to our database, and we do not use them to train models. They are nonetheless processed by our systems in transit, and the upstream provider we route to (see "How we share information") receives them. If you would rather no prompt of yours ever reach our servers, use your own API key.

For billing and abuse prevention we do record metadata about each pooled request: the time, the model, the number of input and output tokens, the computed price, and your user ID. That record contains no prompt or response text.

If you use an optional server-side ("cloud") execution feature, you may store a provider API key with us so we can make calls on your behalf. Such keys are encrypted at rest (AES-256-GCM). Because the Service must use them to reach the provider, they are technically readable by our systems; we use them only to operate the feature you enabled.

Voice dictation and web search

Two more features route through our servers when you use the versions we provide rather than your own credentials.

  • Dictation — if you use the built-in "More AI" speech-to-text provider, the audio you record is uploaded to our servers and forwarded to a transcription provider, which returns the text. We do not store the audio or the transcript; both exist only for the duration of the request. If you configure your own transcription provider instead, the audio goes directly there.
  • Web search — if you use the in-app web search on our pooled access, your search query is sent to our servers and on to the configured search provider. We do not retain the query; we record only that a search happened, for rate limiting and billing.

Information about your device and hardware

The desktop app reports a description of the computer it runs on. Knowing what hardware people actually use is what lets us tell a real performance regression from a slow machine, decide which graphics paths are worth supporting, and reproduce a bug on something like the affected system. This report is part of diagnostics: it is governed by the same consent as all other telemetry, and if you turn telemetry off in Settings → Privacy it is never sent.

The report describes the machine. It is deliberately built so that it cannot identify the machine or you: it contains no hostname, no user or account name, no MAC or network address, no disk, board, or device serial number, no licence key, and no IP address. Values are coarse (memory is rounded to a sensible step, disk space to whole gigabytes) for the same reason. Where a device model identifier is available it is the product model — the same string every unit of that model reports — never a serial.

It is sent when it changes, not on every launch: the app keeps a fingerprint of the values and sends a fresh report only when something differs or the previous one is about 30 days old. The report contains:

  • Operating system — name and version, kernel or build number, processor architecture, the system interface language, your time zone, and whether the app is running under ARM translation (such as Rosetta).
  • Processor — model name, vendor, number of logical cores, and clock speed.
  • Memory — total installed RAM, rounded.
  • Graphics — vendor, model, driver version, how many GPUs are present, the device model identifier where the system publishes one, and whether hardware acceleration, WebGL, WebGPU, and hardware video decoding are available.
  • Display — how many screens are attached, the primary display's resolution in physical pixels, its scale factor, refresh rate and colour depth, and whether a built-in panel is present.
  • Power and storage — whether the computer is currently running on battery, and the total and free space on the volume that holds the app's data (so we can warn you before a full disk breaks something).
  • Software versions — the Electron, Chrome, and Node versions the app is built on, and whether this is a packaged release or a development build.

Diagnostics: telemetry, analytics, and error reports

To understand how the app is used and to fix crashes, we collect limited diagnostic data. In the desktop app this is on by default and can be turned off at any time in Settings → Privacy ("Send anonymous usage data"). The web app uses similar analytics. Diagnostic data never includes your prompts, messages, file contents, or API keys.

  • Anonymous install pings — a randomly generated device identifier, your platform, and the app version. This identifier is not linked to your account, even if you are signed in.
  • Product events — the names of actions taken in the app (for example "app launched" or "settings opened") and a small set of non-content properties such as which mode or model was selected. If you are signed in, these may be associated with your user ID.
  • Device and hardware description — as set out in the section above.
  • Error reports — when the app hits an error, it sends a report whose message and stack trace are redacted on your device before sending, to remove file paths, keys, email addresses, and similar identifiers.
  • We use PostHog (a product-analytics provider) to process this data, including optional session replay in the web app. Session replay masks all text you type, so prompts, keys, and other typed input are not captured.
  • AI observability — for agent runs on our own model access, we can record the prompt and response text (clipped in length) so we can debug why an agent behaved as it did. This is a separate, content-level switch from the general telemetry toggle, and turning either one off stops it. Runs that use your own API key on your own device are never sent.

Payments and billing

Paid plans and credits are sold through Paddle.com Market Limited, which acts as the merchant of record — the seller you contract with and the party that takes the payment. Paddle collects and processes your payment details, billing name and address, country, and any tax identifier directly, as an independent controller under its own privacy policy and buyer terms. We never receive, see, or store your card number or bank details.

What we store on our side is the record of what you are entitled to and what you have used: your plan, the subscription and transaction identifiers Paddle gives us, the status and renewal date of your subscription, the amounts and currency of your payments, your credit balance and the ledger of how it was spent, and the metered usage those charges are based on.

We keep the records that tax and accounting law requires us to keep for as long as it requires — typically several years — even if you delete your account. See "How long we keep information".

Synced data (optional)

Sync is off by default and is enabled per device in Settings. When you enable it:

  • Chat sync uploads your conversations (titles, messages, model and provider names, timestamps) to our servers so you can read them on other devices and in the web app. Synced chat content is stored in a form we can read (it is not end-to-end encrypted), so that the web app can display it. Please do not sync content you need to keep confidential from us.
  • Cowork sync uploads your project files. Cowork files are end-to-end encrypted on your device before upload; we store only the encrypted bytes and cannot read their contents. File names and paths are stored as readable metadata so the app can list them.
  • Settings sync copies your preferences (theme, language, chat options, and the configuration — not the secrets — of your connectors) so a new device starts where the last one left off.
  • Code sessions and your locally stored API keys are never synced.

Linked devices and remote control

If you pair a phone or browser with a desktop to send it commands, each device generates its own cryptographic key pair. The private key never leaves the device that made it; we store only the public keys, the device identifiers, and a label you can recognise. Commands are signed by the sending device and verified by the receiving one, so the trust is in the signature rather than in anything we hold. You can unpair a device at any time.

Problem reports and surveys (optional)

If you choose to send a problem report, the app packages information you can review and toggle first — a description you write, a summary of your settings (with secrets removed), device and version details, and, only if you opt in, recent application logs (redacted) and selected project or repository files. We store the report so we can investigate the issue.

If you respond to an in-app survey, we store your answers and, only if you choose to provide it, a contact email.

Cookies and local storage

Our website and web app use browser local storage to keep you signed in and to remember preferences such as language and theme, and our analytics provider may set cookies. Paddle sets its own cookies on its checkout, which runs on Paddle's domain. The desktop app stores its data in your operating system's application-data folder rather than in browser cookies. For full detail and your choices, see our Cookie Policy.

How we use information

We use the information above to:

  • Provide and operate the Service — sign you in, run the models and features your plan includes, sync your data across your devices, and display it in the web app.
  • Take payment and manage your plan — process purchases and renewals through our payment provider, meter your usage, apply your entitlements, and keep the accounting and tax records the law requires.
  • Maintain security and prevent abuse — apply rate limits, detect and block misuse, fraud, and payment abuse, and protect our infrastructure.
  • Diagnose problems and improve the product — understand which features are used, fix errors and crashes, and tune performance against the hardware people actually run.
  • Communicate with you — send sign-in codes and, where relevant, billing, service, or security notices.
  • Comply with legal obligations.

Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract — to provide an account, a paid plan, sync, and the web app you ask for, and to take the payment for them.
  • Legitimate interests — to keep the Service secure, prevent abuse and payment fraud, and improve the product through limited, content-free diagnostics including the hardware description. You can object to analytics by turning telemetry off.
  • Consent — where required, for non-essential cookies and analytics, for AI-observability content capture, and for optional surveys. You may withdraw consent at any time.
  • Legal obligation — to keep tax, accounting, and transaction records, and where we must otherwise process data to comply with the law.

How we share information (sub-processors)

We do not sell your personal data and we do not share it for advertising. We use a small number of service providers ("sub-processors") to operate the Service, each acting on our instructions:

  • Cloudflare — hosting and infrastructure (compute, database, key-value and object storage, content delivery, and sending sign-in emails). Our data is stored on Cloudflare's global network.
  • Paddle.com Market Limited — merchant of record, payment processing, tax calculation and remittance, invoicing, and refunds. Paddle acts as an independent controller for the billing data it collects from you.
  • PostHog — product analytics, error tracking, and AI observability. Processed in the United States.
  • Model and infrastructure providers behind our own model access — when you use a plan or credits rather than your own key, we route the request to an upstream provider (currently OpenRouter, and Groq for dictation), which processes it under its own terms in order to return the answer.
  • Web-search providers — if you use the in-app web search, your query is sent to the configured search provider.
  • AI providers you choose (for example Anthropic, OpenAI, Google, or a compatible endpoint you configure) — they receive the prompts you send them directly, under your own key and their terms. They are not our sub-processors; you select and control them.

International data transfers

Our infrastructure and payment providers operate globally, including in the United States and the United Kingdom. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent mechanism offered by the provider. If you are outside the country where our providers store data, your information may be processed there.

How long we keep information

We keep personal data only as long as needed for the purpose it was collected:

  • Account data — until you delete your account or ask us to delete it.
  • Synced chats — until you delete them or your account; you control them from the app.
  • Cowork files — kept while your account is active; on free use, files expire about 7 days after they were last touched.
  • Billing and tax records — for the period required by applicable tax and accounting law (typically 6 to 10 years, depending on the jurisdiction), even after you delete your account. This is a legal obligation and is not affected by a deletion request.
  • Usage and metering records — while they are needed to operate and reconcile your plan, then aggregated.
  • Sign-in codes — about 15 minutes; device pairing requests — about 10 minutes.
  • Prompts and responses on our own model access — not retained; they exist only for the duration of the request. Dictation audio and search queries likewise.
  • Diagnostic events, error reports, and problem reports — retained for as long as they remain useful for security and product improvement, then deleted or aggregated.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent. You can update your name and avatar in the app, and turn diagnostics off in Settings. To make any other request, email privacy@more-ai.net; we will respond within the time the law requires. You also have the right to complain to your local data-protection authority.

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not use your personal data for profiling of that kind.

Where a request concerns data held by Paddle as merchant of record — for example your billing address or payment method — we will point you to Paddle, since we do not hold it.

Regional disclosures

Some jurisdictions require specific statements. Those that apply to us are set out here.

  • EEA and UK — you have the rights described above under the GDPR and UK GDPR, including the right to lodge a complaint with your supervisory authority. Requests and complaints reach us fastest at privacy@more-ai.net, which is our contact point for all data-protection matters. Where we are required to appoint a representative under Article 27 of the GDPR, we will do so and name it here.
  • California — under the CCPA/CPRA you have the right to know what we collect, to delete it, to correct it, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined, and we do not process it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights.
  • Switzerland and Brazil — the rights described above are available to you on an equivalent basis under the Swiss FADP and the Brazilian LGPD respectively.
  • Mainland China — the Service is not directed to users in mainland China. We have not appointed a local representative and we do not carry out the cross-border transfer formalities that the Personal Information Protection Law requires of an operator targeting that market. Our Chinese-language documents are provided for Chinese speakers generally, not as an offer of service in mainland China.
  • Russia — the Service is not directed to users in the Russian Federation. We do not store or process personal data on servers located in Russia and therefore do not meet the localization requirements of Federal Law No. 152-FZ. Our Russian-language documents are provided for Russian speakers generally, not as an offer of service in Russia.
  • If you access the Service from a jurisdiction we do not target, you do so on your own initiative and are responsible for compliance with local law.

Security

We protect data with encryption in transit (HTTPS/TLS) and with the security features of our infrastructure provider, including DDoS protection and a web application firewall. API keys are encrypted on your device, Cowork project files are end-to-end encrypted, stored cloud-execution keys are encrypted at rest, and the credentials behind our own model access never leave our servers.

No system is perfectly secure. As noted above, chat content you choose to sync is stored in a form we can read, and requests on our own model access pass through our infrastructure — so apply your own judgement about what you send and what you sync.

Children

The Service is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country, if higher) to create an account or buy a plan. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date at the top and, where appropriate, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

Contact us

For privacy questions or to exercise your rights, email privacy@more-ai.net. For billing and refunds, email billing@more-ai.net. For other legal matters, email legal@more-ai.net.

Back to home