Privacy Policy
Last updated: August 26, 2026
Pisper is a local-first AI workspace. It does not require a Pisper account and does not send analytics, advertising identifiers, crash telemetry, prompts, files, contacts, photos, or location data to the Pisper developer.
Information stored on your device
Pisper may store the following information in the app's private storage:
- conversations, prompts, model responses, session metadata, and app settings;
- files and images that you choose to open, create, attach, or generate;
- model and search provider configuration, including credentials that you enter;
- pairing records and access tokens for a Pisper Desktop Runtime that you control;
- optional skill, workspace, and memory data supported by the selected Runtime.
Removing the app may remove locally stored information, subject to platform backup behavior.
Connections you choose
AI and search providers
When you configure and use a third-party AI model or search provider, Pisper sends the content required for your request directly to that provider. This can include prompts, conversation context, selected files or images, tool results, and technical request metadata. The provider processes that information under its own privacy policy and account settings. Pisper does not proxy these requests through a developer-operated server.
Your Pisper Desktop Runtime
You may pair the app with a Pisper Desktop Runtime that you control. On a local network, the app can discover Desktop advertisements and send a connection request; the Desktop user must approve it before a device access token is issued. QR-code and manual pairing remain available when discovery is unavailable. After pairing, the app can exchange conversations, files, settings, and Runtime results with that computer over a local-network or encrypted peer-to-peer connection. The Pisper developer does not receive this traffic.
Optional device permissions
- Camera: scan a pairing code or capture a photo after your action.
- Contacts: search contacts for an operation that you approve.
- Location: read one foreground location for an approved operation.
- Notifications: show local app or task notifications.
- Local network: discover and connect to a Desktop Runtime that you choose.
Permission results and returned content are used for the requested operation. They are not sent to the Pisper developer. You can revoke permissions in system settings and disable device capabilities in Pisper.
Updates and executable content
App Store and Google Play builds are updated only through the applicable store. Their code, user interface, and embedded Runtime are included in the signed app package. Store builds do not download and execute plugins, scripts, Runtime replacements, or other code that changes the app's functionality.
The separately distributed GitHub build uses the same embedded Node Runtime and signed in-app user interface, but may check and open an external update channel. It does not include a rooted Runtime, rootfs, su, or chroot assets.
Security and retention
Pisper uses operating-system app isolation, loopback-only services for its embedded Runtime, authenticated pairing, and certificate fingerprint validation for direct remote connections. Local information remains until you delete it, clear app storage, or uninstall Pisper. Information sent to a provider or stored by your Desktop Runtime is retained under that service's settings and policy.
Children and policy changes
Pisper is not directed to children under 13, and the developer does not knowingly collect children's personal information. Provider age requirements may be higher. Material changes to this policy will be published here with a revised date.
Contact
Email the developer or open an issue in the Pisper issue tracker.