← Onda

Privacy Policy

Effective August 15, 2026

Onda ("Onda", "the app", "we", "us") is designed around a single principle: your data stays on your device. This policy explains, in plain language, exactly what data the app handles, what never leaves your device, the network activity you initiate, and the choices and rights you have. It applies to the Onda apps for iPhone, iPad, and Mac.

1. The short version

Onda has no user accounts. Core model inference, saved conversations, personalization, attachments, device information, and settings stay on your device. The optional Cortex bridge is off by default and uses a same-device Apple app group: after you enable sharing in Cortex and approve a retrieval in Onda, Cortex answers a live request with bounded excerpts while Cortex is running — it does not copy your notes into the shared container, and Onda never opens the Cortex vault. If you explicitly enable Web Search and approve a search, only the exact approved query, device locale, app version, and a random installation identifier used for abuse prevention are sent over HTTPS to Onda's narrow Railway-hosted search broker. The broker sends the query and locale-derived language and region to Brave Search, then returns public search-result metadata to the app. Your selected model still generates the answer locally. Your chat history, other prompts, model output, Memory.md, files, images, location, and device profile are not sent with a search. Voice dictation uses Apple's Speech Recognition framework: when iOS can transcribe on-device it may do so, and otherwise Apple may process speech to provide dictation. We run no analytics, no advertising, and no cross-app tracking.

2. Who we are and how to reach us

Onda is published by JTR Labs. For any privacy question or request, email [email protected]. Because we hold no data about you, most requests are things you can satisfy yourself directly on your device (see "Your controls and rights" below).

3. Information we do NOT collect

We do not retain your chats or build user profiles. The optional Web Search broker processes an approved query only long enough to return search results and does not store it in an Onda database. Specifically, there is:

4. Information that stays on your device

The following is created and stored locally, under your control, and is not uploaded to us:

On iOS this data lives in the app's private container; goal-loop checkpoints that may include Cortex excerpts are stored with complete file protection so they are inaccessible while the device is locked. On macOS it lives in the app's Application Support directory and the system preferences store for that app. It is removed when you delete the relevant data in-app or uninstall the app.

5. Network activity you initiate

To run a model locally, Onda downloads that model's files from the model host you choose — for example, Hugging Face — over an encrypted HTTPS connection directly from your device to that host. As with any download, the host necessarily receives your device's IP address and the name of the file requested, and the host's own privacy policy governs that interaction. Onda does not attach any identifier of you to these requests, and no prompt, conversation, attachment, or personal content is ever included in a model download.

If you use Link a Mac, the iPhone/iPad app connects directly to the Onda app running on your Mac over your local network or Tailscale. Your prompt and the model response do not route through Onda servers and are not retained by the Mac API after the request. A random pairing key is stored in Apple Keychain on each device and authenticates an encrypted TLS connection. Onda has no plaintext network fallback for paired-device traffic. Tailscale can provide an additional encrypted network layer.

If you enable Web Search for a question, a tool-permission sheet shows the exact query before it leaves your device. If you approve it, Onda sends that query, your device locale, app version, a random installation identifier, and ordinary network information such as your IP address over HTTPS to Onda's Railway-hosted search broker. The identifier is stored in Keychain and is used only to rate-limit abuse. The broker sends the query and locale-derived language and region to Brave Search, then returns public result titles, snippets, dates, and HTTPS URLs to the app. Brave Search does not receive the installation identifier, app version, or your direct app connection. Neither provider receives your conversation history, model response, Memory.md, files, images, location, or device profile. The selected model uses the results locally. Search is off by default, requires Onda Pro, and can be denied once or for the session. Railway and Brave process requests under their applicable privacy terms. Onda's broker code does not log request bodies and does not persist search queries or results in a server-side database; infrastructure providers may retain operational data under their own policies.

6. Permissions you control

Each permission below is optional, requested only in context, and used only for the feature you invoke:

7. Files, folders, and images you attach

On the desktop you can drop documents or folders into a chat, and on all platforms you can attach images. This content is read and processed locally to build context for the model. It is never uploaded to us and is held only for your session and your saved conversation on your device.

8. Third parties

9. Optional iCloud preference sync

Off by default on iPhone, iPad, and Mac. If you enable it, Onda synchronizes only small app preferences through your own private iCloud account, such as recommendation goal, appearance, haptic feedback where supported, response-finished notification preference, thermal-risk preference, and whether iCloud preference sync is enabled. It never synchronizes prompts, conversations, model responses, Memory.md/personalization, attached files or images, downloaded model files, run history, or benchmark history.

10. Device backups

If you back up your device to iCloud or to a computer, your on-device Onda data (such as conversations and settings) is included in that backup, which is yours and encrypted by Apple. Downloaded model files are excluded from backups where possible because they can be re-downloaded on demand.

11. Security

Model downloads and approved web searches use HTTPS. Web Search accepts only a bounded query, returns only HTTPS source links, strips unsafe source metadata before model use, rate-limits requests, uses an ephemeral no-cookie client session, and does not store queries in an Onda database. Cortex excerpts are size-limited, treated as untrusted reference text rather than model instructions, and transferred on Mac through authenticated XPC with code-signature checks rather than unsigned app-group files. On-device data is protected by your operating system's app sandbox and device encryption; iOS also stores goal-loop checkpoints with complete file protection. Link a Mac pairing keys are stored in Apple Keychain. Link a Mac uses pairing-key authenticated TLS for direct connections, including ordinary local Wi-Fi, and Tailscale can add another encrypted layer. No method of storage or transmission is perfectly secure.

12. Children

Onda is intended for users 17 and older and is not directed to children. We do not knowingly collect children's personal information. Optional Web Search processes only the limited data described in Sections 5 and 8 after the user approves the displayed query.

13. Your controls and rights

You can view, edit, export, or delete your conversations and notes in-app. You can delete individual goal loops, including their saved Cortex excerpts, or use "Delete Cortex excerpts from goals" to remove Cortex queries, excerpts, and stored Cortex-backed model replies from checkpoints without deleting the goal. "Clear history" erases conversations, and "Reset app" erases Onda's local data, including goal loops and the Web Search rate-limit identifier in Keychain. Turning Onda access off in Cortex stops live retrieve answers and deletes pending bridge requests. Onda does not keep a server-side search-history database or sell personal information. For privacy questions or rights requests under laws such as the GDPR or CCPA/CPRA, contact us at the address below.

14. International users

Most Onda processing occurs on your device wherever you are. Model downloads connect to the host you choose, and an optional approved Web Search connects to Railway and Brave Search infrastructure, any of which may process the request in another country.

15. Changes to this policy

If this policy changes, we will update the effective date above and the in-app copy. Material changes will be reflected in the app's release notes.

16. Contact

Questions or requests? Email [email protected].

Onda is published by JTR Labs. This page mirrors the copy shown inside the app.