Skip to content

Privacy ​

This page is what the nanoMuse apps — the phone, the web and desktop apps, the dsh plugin — and nanoMuse Cloud do with your data. It is short because they do little with it. Where it matters, the one thing you decide is a switch: Settings → Data controls.

Everything stays on the phone ​

The agent runs inside the app, in a Linux root file system on your phone. Conversations, memory, files the agent writes, scheduled tasks, skills and settings are stored in the app's private storage and, where you mount them, in folders you chose. There is no analytics, no crash reporting to us and no telemetry of any kind. The only nanoMuse server is the optional relay described below, and the app works fully without it.

What leaves the phone ​

  • Your model provider. Messages, attached images and tool results are sent to the model endpoint you configured (阿里云百炼, DeepSeek, OpenAI, OpenRouter, your own vLLM or Ollama, …), under that provider's terms, with the API key you entered. The key is stored on the phone only.
  • nanoMuse Cloud, if you signed in. Sign in — free on the first screen (or Settings → nanoMuse Cloud) signs you up with a phone number or an e-mail address and a code, and the app then uses our relay as a model provider — free, ¥10 of model use per account (community members: no limit; each new person who signs up with your invite code adds ¥5 to your allowance and ¥5 to theirs), paid by the developer; nanoMuse is a non-profit community project and never charges. The relay forwards your messages to the model (Alibaba Cloud Model Studio). What it keeps about the account: a salted hash of your address, the address itself encrypted so the person running the relay can see whose account it is (the database file alone shows nothing), a masked hint such as s***@example.com, the hash of the key issued to this device, the kind, model and token count of each request, your invite code with the ids of accounts that used it, and — so your devices wear the same one — the agent's name and look (which face; for one drawn in the avatar studio, its five small pictures). With each sign-in, request, timeline event and device it also records the network address the request came from and the client software (the User-Agent: the Android app and its version, the runtime on Windows, macOS or Linux, a browser), and the account keeps its first and last address and when it was last seen — the person running the relay sees these on the operator's page, per account and per address, to tell one person on two accounts from two people on one address and to see a problem's shape. What it keeps of the conversations themselves is governed by two switches, described next. It does not receive your location: the apps never send it, and the relay does not look an address up. Signing out revokes the key; deleting the account removes all of it, addresses included. The relay's source is in the repository under cloud/, and docs/cloud.md says how to run your own. Nothing about the relay applies when you use your own key.
  • The project site (nanomuse.cn), if you visit it. Its web server keeps an access log for seven days and then deletes it; a script turns it into counts per day — pages viewed, how many visitors, downloads per file, which sites linked here. A visitor is counted once a day through a hash of the address and browser string under a random salt made for that day and discarded after two; no address is stored beyond the week the raw log lives, nothing is shared with anyone, there are no cookies and no third-party analytics. The relay's own operator page shows counts of sign-ins and accounts per day, from the same records described above — nothing more is collected for it.
  • Data controls — "Help improve nanoMuse's AI models". Settings → Data controls on every app holds one switch. While it is on, the relay keeps the text of your chats with the nanoMuse Cloud models to train the community's own open model: what you wrote, what the model answered, and the tool calls it chose, together with the model, the token counts, and the app's platform and language from the request headers. It does not keep the system prompt (your memory, SOUL and instructions), what tools returned, pictures, audio or clips — those are replaced by a marker — and the turns are tied to your account id only; exports for training carry no account id, address or hint. On cloud.nanomuse.cn the switch is on for accounts created from relay 0.9 on; accounts that existed before keep whatever they had chosen. The switch says so right next to it, and a relay you run yourself chooses with IMPROVE_DEFAULT. Turn it off at any time — nothing more is kept from then on —, delete everything kept so far with one tap on the same page, and deleting the account deletes it too. Nothing about the allowance depends on this switch.
  • Synced conversations — on by default when you are signed in (relay 0.19 on). The text of your conversations is stored on nanoMuse Cloud so every device of your account shows the same chats. Files and images are not uploaded. Settings → Data controls turns it off and deletes what is stored; deleting a chat on one device deletes it on all of them. Nobody but your devices can read it; the operator sees counts, not text. (What is stored, exactly: each conversation's title and which device started it, each message's role, text, time and device, and the names and sizes of attached files — never the files, never a picture, never what a tool returned. Chats addressed to another device, or run on this one for another, are not synced. The relay keeps at most 20 000 messages per account and cuts a message at 16 KB. docs/cloud.md has the details.) Since 0.1.38 only the main conversation is synced by default: side chats stay on the device that made them, and other devices' side chats do not arrive, unless you turn on Also sync side chats on that device. While one of your devices is answering, the others are told so (kwai is working…); that note goes through the relay's memory, is never stored, and is forgotten after ten minutes.
  • The web, when the agent uses it. Web search, page fetches, the in-app browser, MCP servers and command-line tools reach the sites and services they are for. What the agent sends is what you asked it to do.
  • Update check. Settings → About (on the phone, Check for updates; the desktop app's tray; a pipx/Docker runtime once every six hours, server.update_check = false to stop it) asks the GitHub API for the latest release of nano-muse/nanoMuse. Nothing is sent besides the request itself, and nothing is downloaded on its own.
  • Backups. If you back up to a remote destination (SMB, WebDAV, SFTP, S3, FTP), the backup goes there, encrypted with the password you chose.

Permissions ​

Each permission is asked for when a feature needs it and is used for that feature only: notifications for the agent's status and reminders; accessibility for operating other apps' screens, which is off until you turn it on; storage folders you mount; the microphone for voice input; contacts, calendar and location for the tools of the same names, each callable only after you granted them. Nothing is read in the background.

What the agent may do without asking ​

Before anything it cannot take back — deleting your files, sending a message or data out, paying — the agent stops and a card asks you, in the shell, in the browser and on the phone's screen alike. What you may remember from that card comes in three tiers, and Settings → Permissions → Remembered approvals lists everything you remembered, grouped the same way, one line each, tap to revoke:

  • Runs, then tells you — installing software. Never asks; the agent says so afterwards.
  • Asks first; you may remember it — deleting and sending. Allow for this chat or Always allow for X (one folder, one recipient, one site or app).
  • Highest: asks at the moment of paying, every time — buying, ordering, booking, trading, transferring. There is no "for this chat". Remember and run next time in X exists, for one app or site only, and asks for your screen lock (fingerprint, face, PIN) before it takes; it is listed first on the permissions page, and every payment that runs on it is said out loud in the chat.

Passwords, verification codes and card numbers are never typed by the agent; those screens are handed to you. Anything alarming in a command (wiping a disk, force-pushing history, a download piped into a shell) is asked about every time and cannot be remembered. Shopping and trading are fine when you asked for exactly that; nothing unlawful or harmful is done, however it is worded — the agent refuses and says why.

Feedback ​

Bug reports go to GitHub Issues from Settings → Feedback; the report is pre-filled with the app version and the device model and nothing else. Do not paste API keys or private conversations into an issue.

Changes ​

This page changes when the app's behaviour changes; the history is in the repository.

GPL-3.0-or-later. nanoMuse is an independent community project, not affiliated with Meta.