AnvilBack to Anvil ↗

Updated October 5, 2026

Privacy.

Chat and image generation run on your iPhone. Optional Super Mode (web search), feedback, model downloads, purchases and iCloud backup involve the services described below.

This policy covers the Anvil app for iPhone. There is no Anvil app account or sign-in. The app contains no advertising network, analytics SDK or automatic crash reporting, and it does not use the advertising identifier. Anvil does not sell your data or use it to track you across other companies' apps or websites.

What stays on your iPhone

Your chats and their photos, generated pictures, memories, notes, settings, system prompt and downloaded models are stored in the app's container on the iPhone. Tasks are stored in an App Group shared with the widget. Chats, memories, notes, settings and unsent reports use iOS complete file protection, which makes their files unavailable while the phone is locked. Tasks remain readable after the first unlock following a restart so the widget can update. These files are excluded from the iPhone's general iCloud and Finder backups; Anvil's separate iCloud backup is described below.

Chat and image generation run entirely on the phone, on the model you downloaded. With a model installed you can use Anvil in airplane mode, which is the point of the app.

What leaves your iPhone, and when

Super Mode (web search). Only while the Super Mode pill, the bolt above the chat, is switched on, and after you accept the disclosure the first time. It stays on until you turn it off, across restarts. Your message and up to four previous messages from that chat, each shortened, go to Anvil's relay at www.anvilai.com and then you.com's Answer API. A message with a photo or file attached is handled by the on-device model; if it searches, its query can include details drawn from your message. The search path does not send the raw photo, raw file, system prompt or other chats. The relay code does not log messages or queries; it holds IP addresses and request times in memory to limit abuse. Hosting providers also receive ordinary network request information. you.com's privacy policy applies to the query and context it receives.

Downloading a model. The app reads the model catalog during setup and when you open model management, including after a model is installed. Catalog requests carry no chat or account identifier. Downloads go through www.anvilai.com to the configured host: Cloudflare R2 at models.anvilai.com or a GitHub release fallback. These hosts receive your IP address and the requested model file. Pro model requests also carry a signed App Store transaction as proof of access. Your chat content is not sent for a model download.

Adding a model from Hugging Face. Only when you choose Add Model › Hugging Face in Settings › Chat or Settings › Image Generation. The app sends the model name you enter to huggingface.co's public API to list its files and licence, then downloads the files you pick directly from Hugging Face. Anvil's servers are not involved, and no chat content, account or App Store transaction is sent. Hugging Face receives your IP address, the model name and the requested files under its privacy policy. These models are published by third parties under their own licences; ones their publisher marks for adults are refused. Add Model › Files copies a model you choose on the phone and sends nothing.

Back up to iCloud. On unless you turn it off, offered during setup and in Settings › iCloud. The app can back up chats, notes, tasks, memories and settings to the private database of your own iCloud account when it goes to the background. Content fields are encrypted on the device before upload. End-to-end encryption requires Advanced Data Protection for your Apple Account; under standard iCloud protection, Apple manages the service keys. Anvil's servers do not receive this backup content. Photos in chats and downloaded models are omitted. Backup dates and CloudKit record metadata are not encrypted content fields and use iCloud's standard protections; not all metadata receives end-to-end protection even with Advanced Data Protection. See Apple's CloudKit documentation and iCloud data security overview.

Anvil Pro. Buying, restoring and checking the subscription use Apple's StoreKit, under Apple's privacy policy. The app checks verified entitlements to determine access. A signed App Store transaction is also sent to Anvil's server when requesting a Pro model. Your chats are not involved in purchases or entitlement checks.

Feedback you choose to send. Nothing is sent from Settings › Feedback or a bug report until you press Send. Feedback includes your text, an optional reply address and the build channel. Bug reports also include app, phone, model and engine diagnostics and counts of stored items. Reports opened from Settings do not attach a chat. For a report about a reply, Include this chat adds the transcript, settings, chat pictures, recent diagnostic log, memories, task text and note titles. It starts on when opened from a reply's bug button; you can turn it off before sending.

The relay can file reports and attachments in Linear and email them through Resend to the Anvil team. If the connection is unavailable, the app saves the report locally and retries; queued reports expire after 14 days. If the relay refuses a report, the app can offer a mail composer, and you decide whether to send it. A report that cannot be sent or saved remains on the sheet with an error. Submitted reports are records held by the team, not automatic crash reports.

Microphone, camera and photos

Dictation requires on-device recognition, so audio is transcribed on the phone. If on-device recognition is unavailable for your language, Anvil does not fall back to uploading audio. Apple's speech framework may first download a language asset; that download does not send microphone audio. Anvil does not save an audio recording. Camera photos go into the message and are not automatically saved to Photos. Any printed text in a photo you send is read on the iPhone with Apple's Vision framework and given to the on-device model with your message; that text is not uploaded. Saving a picture you request uses add-only Photos permission; you can separately choose a photo with iOS's picker to attach it to a chat.

How long it is kept, and how to delete it

Memories, tasks, notes and settings stay on the phone until you delete them or remove the app. Chats are kept until you delete them, or automatically after the period you set in Settings › Chat history. Settings has a delete control for chats, memories, tasks and notes. Unsent reports are removed after delivery or their 14-day expiry.

A successful iCloud backup publishes a complete snapshot after its payloads upload. When backup is on and iCloud holds a backup this installation has not yet merged, the app merges it automatically at launch or when you return to the app: its chats, notes, tasks and memories are added beside the ones on the phone and never replace them, and anything you deleted on this phone stays deleted. Settings are restored only to a new installation. Until the merge, no upload replaces that backup; the next backup includes both. Turning Back up to iCloud off stops further uploads from this phone and keeps the existing backup.

Delete iCloud backup in Settings › iCloud removes the records the app can identify, leaves a deletion marker to prevent restoring an older backup, and turns backup off on this phone. It does not remove local chats. Another device with backup enabled can create a new backup later. Build 11 and earlier use a separate legacy snapshot and cannot read the updated format. Interrupted uploads can leave unreferenced records that this release does not enumerate, so in-app deletion cannot promise to remove every byte. iOS's iCloud storage management also provides controls for Anvil's stored iCloud data.

We keep feedback and bug reports you chose to send in the team's report and email systems. Write to hello@anvilai.com to request their deletion. We answer privacy requests within 30 days.

Who else is involved

you.com receives search queries and context; Apple handles App Store purchases, iCloud backup and speech asset downloads; Cloudflare or GitHub serves model files; Hugging Face serves models you choose to add from it; Linear can store submitted reports and attachments; and Resend delivers feedback and reports to the team. Anvil uses no advertising network or data broker. Relay and website hosting providers receive ordinary network request information, including IP addresses. Each provider handles the information it receives under its own privacy policy.

Children

Anvil is not directed at children and does not knowingly collect information from them. Anvil refuses to generate any picture that pairs a child with sexual or undressed subject matter; that refusal is made on the phone, before any model is asked, and no setting, subscription or switch reaches past it.

Changes, and the long version

If this policy changes, the date at the top changes with it, and a change that affects what leaves your phone will be described in the app's release notes. The file-by-file version — every path, every protection, and how to verify each claim yourself — is the technical privacy document that ships with the app's source. Questions: hello@anvilai.com.