On your device
Prompts, documents, results, history and memory stay on the device. Local inference has no token meter.
- No Software Tailor cloud required
- Can work offline after model download
- Performance depends on model and hardware
“Private AI” should describe an architecture, not an aspiration. Here is what stays local, what can be on-premises, and where an optional provider may enter the path.
Prompts, documents, results, history and memory stay on the device. Local inference has no token meter.
AI Server hosts models and inference within the environment your organisation chooses and operates.
Some supported apps offer optional cloud models. The app identifies that path before use; the provider's terms then apply.
Local-model inference content stays on the device. On-premises inference content stays within the customer's configured infrastructure path.
Product telemetry is separate from prompts and results and can be disabled. It requires opt-in in specified privacy regions and Apple builds, but may start enabled elsewhere.
Install and machine identifiers are pseudonymous, not anonymous, and can be joined to registration, entitlement or support records in restricted operator tools.
Privacy boundaries do not remove the need for endpoint security, access control, backups, model governance or user policy.
Require an answer for each supported model path—not a single general statement for the whole product.
Separate content, identity, entitlement, diagnostic and optional telemetry flows.
Test the real workflow, including model acquisition, updates, licence checks and recovery.
Define audit requirements without collecting prompt content by default.