Y Combinator

Backed by Y Combinator

Draft — do not publish

Privacy Policy — RunAnywhere for Android

Publication status: Operational and publisher review pending

On-device by design

RunAnywhere performs ordinary language, vision, speech, embedding, and document inference on your device. The app automatically sends device, usage, performance, authentication, and error diagnostics. Structured modality metrics use counts instead of content, but raw error text is also transmitted and may contain user or generated content. A network feature sends the data needed for that feature when you choose or configure it.

1. Who we are and what this policy covers

RunAnywhere, Inc. ("RunAnywhere," "we," "us," or "our") publishes the RunAnywhere Android app. This policy explains how the app handles information when you use local inference, download models, enable tools such as web search, configure optional cloud speech-to-text, or contact an external website.

2. Content processed on your device

Unless you deliberately use one of the network features described below, the following content is processed or stored in the app's private storage on your device:

  • Prompts, generated answers, and conversation history
  • Documents, copied attachments, embeddings, and retrieval results
  • Selected images, camera frames, and vision-model results
  • Microphone recordings, local transcripts, and generated speech
  • Downloaded model files and benchmark results
  • Hugging Face and cloud-provider credentials, which are stored using Android encrypted preferences
  • Production SDK access and refresh tokens plus backend-assigned device, user, or organization identifiers

Ordinary structured diagnostics are designed to send measurements and counts rather than prompt, response, document, image, audio, or transcript bodies. The current app also transmits raw SDK error text without a universal proven redaction boundary. An error message may contain user or generated content, a URL, a local path, a transcript fragment, or a provider response.

3. Diagnostics sent automatically

The production app automatically authenticates, creates or updates an SDK installation registration, fetches model assignments, and sends diagnostics during initialization and while features run. The information may include:

  • A randomly generated, persistent app-installation or device identifier
  • App package identifier, app name/version/build, locale, timezone, device model, operating system, and SDK version
  • Backend-assigned device, user, or organization identifiers
  • CPU architecture and chip name, form factor, memory, acceleration availability, CPU/GPU/NPU details, and battery or power information
  • Model and inference-framework identifiers
  • Feature lifecycle events, latency, throughput, token or character counts, audio duration and size, and image count or resolution
  • Raw error text and network diagnostics

We use this information to register and operate SDK installations, provide app functionality, understand performance and feature reliability, prevent abuse, and diagnose errors. We do not use it for third-party advertising, and we do not sell it. The app does not currently provide a separate switch for these production diagnostics.

4. Network features you choose to use

Model downloads

Downloads may contact Hugging Face, GitHub, or another model host. The host receives the requested repository or file and ordinary network metadata. If you provide a Hugging Face token, it is sent only to Hugging Face to authorize the requested download.

Web search tool

Tool calling is disabled by default. If you enable it and the model invokes web search, the generated query and ordinary network metadata are sent directly to DuckDuckGo when no proxy is configured, or to a RunAnywhere-operated proxy and its search provider when configured. The query may be derived from your prompt. The tested signed APK uses direct DuckDuckGo; a store AAB is blocked until the production proxy and provider are configured and disclosed.

Cloud speech-to-text (Beta)

If you configure and select Hybrid (Beta), its router may choose the online provider based on network, battery, confidence, and ranking. Microphone audio, language or model settings, request metadata, and the provider credential are then sent to Sarvam, OpenAI, OpenRouter, or your configured HTTPS host under that provider's privacy terms. Local transcription does not use this cloud flow.

External links

Opening documentation, this policy, a social link, or another external service sends your browser or the selected app to that service. Copying or sharing a benchmark sends the selected report to the system clipboard or your chosen app. The receiving service, app, and operating system apply their own privacy terms.

5. Permissions

PermissionPurpose
Microphone
Voice input, transcription, voice-activity detection, and voice-agent features
Camera
Taking a photo or providing live camera frames to a vision model
Internet
Diagnostics, SDK registration, model downloads, and network features you use

Microphone and camera access are optional and can be revoked in Android Settings.

6. Storage, retention, and deletion

  • Conversations and copied attachments remain in app-private storage until you delete the conversation or uninstall the app.
  • Downloaded models and caches remain until you remove them in the app, clear app storage, Android evicts them, or you uninstall the app. Some PDF, benchmark, and other temporary files are deleted automatically.
  • Saved credentials remain until you clear them, clear app storage, or uninstall the app.
  • The production backend retention schedule, deletion scope, and anonymization process have not yet been verified for this release candidate and must be finalized before this policy becomes effective.

The backend deletion-request process is not yet operationally verified, and the current app does not display the installation ID needed to locate a record. Before publication, RunAnywhere must implement and test the lookup, requester verification, deletion scope, and response timeline. The proposed privacy contact is founders@runanywhere.ai.

7. Service providers and security

We share information only with service providers needed to operate the diagnostics and network features described above, when you direct the app to a provider, or when law requires it. Network endpoints configured for the production app use encrypted HTTPS connections, and Android encrypted preferences protect stored credentials. No method of storage or transmission is completely secure.

Depending on your location and the service you choose, information may be processed in a different country. Each third-party model host, search provider, cloud speech provider, website, or app handles information under its own terms and privacy policy.

8. Prominent disclosure and consent review

Production authentication, registration, assignment sync, and diagnostics begin before the user can reach the Settings privacy link. The current app intentionally has no separate privacy or diagnostics-consent screen. Before Play submission, the publisher must determine whether this automatic collection is within users' reasonable expectations. If Google Play's prominent-disclosure rule applies, a website policy and Settings link are not sufficient; an in-flow disclosure and affirmative consent must precede collection.

9. Children's privacy

The intended Play target audience and any Families-policy obligations have not yet been confirmed for this release candidate. The final policy must match the exact age groups selected in Play Console.

10. Changes to this policy

We may update this policy as the app or its services change. We will post the revised policy on this page, update the effective date, and provide any additional notice required by law.

11. Contact us

RunAnywhere, Inc.

founders@runanywhere.ai
RunAnywhere

RunAnywhere Labs

A research-first inference lab. We hand-write the kernels that make consumer silicon fast — and open-source the SDKs and infrastructure that run them on every platform.

© 2026 RunAnywhere, Inc.