Privacy Policy
Conduck
Last Updated: 2026-09-13
What changed on 13 September 2026: we explain Apple billing and on-device subscription verification for the upcoming optional Conduck Pro subscription, and distinguish Apple’s sales and subscription reports from your private app content. This update does not announce that Pro is available to purchase. Conduck still has no backend and sends us no app content, provider keys, device identifier, or Usage records.
Data Controller: GigaDuck OÜ Tornimäe tn 5, 10145 Tallinn, Estonia Registry code: 17501858 (Estonian Business Register) Email: privacy@gigaduck.ai · General: info@gigaduck.ai
This policy covers the Conduck app itself. For the conduck.com website, email you send us, our community Discord, and participation in Conduck’s public open-source projects, see the Website & Project Participation Privacy Notice.
Overview
Conduck is a voice and text client for the AI you choose — a self-hosted agent gateway or model server, a hosted model such as one reached through OpenRouter, or an AI someone has invited you to use. It transcribes speech on your device by default, or sends audio directly to the cloud transcription provider you select, then sends your messages directly to that chosen AI service. It runs on iPhone, iPad, Mac, Apple Watch, and Apple CarPlay.
The defining fact of this app: Conduck operates no intermediary server of its own. Conduck is published by GigaDuck OÜ (“we,” “us,” “our”) — Conduck has no backend that relays your requests, runs no analytics, and never sends us your audio, your messages, your AI’s replies, your gateway address, or your access keys. Everything happens either on your device or directly between your device and services you chose.
Key points:
- No Conduck backend, no Conduck account. Conduck operates no intermediary server. It creates a random app identifier in your device Keychain and, when iCloud is available, mirrors it into your private iCloud key-value store so your Apple devices can converge on the same identifier. It is never sent to us or included in a request to your AI or voice providers.
- By default, your audio never leaves your device. Fresh installs use Apple’s on-device speech recognition; transcription happens locally.
- If you choose a cloud transcription provider, your audio goes directly from your device to that provider using your own API key. We are not in that path.
- Your messages go directly to the AI service you chose — a gateway you operate, subscribe to, or have been invited to use (including a hosted AI service such as OpenRouter) — using your own access token. We never see the address, the token, or the conversation. If the gateway is operated by someone else, that operator can receive and retain your messages and any files you send through it.
- Your conversation history is stored on your device and in your own iCloud (Apple CloudKit private database). We have no access — the same way we can’t read your Apple Notes.
- Usage is a private, content-free record for you. Conduck stores a private Usage record for each recorded request attempt. It may contain locally generated attempt, conversation, and message identifiers; start and completion times; outcome and Conduck error category; Apple surface, input method, and device class; the configured connection slot; requested and reported model names; a provider-reported response identifier and finish reason; reported token counts; and counts of inline images and text-file blocks. It contains no prompt, transcript, reply, audio, attachment, filename, file content, endpoint address, credential, provider error message, or HTTP status. Usage records are never sent to us, your AI, or a voice provider as Usage data.
- Read-aloud uses Apple’s on-device voice by default, which sends nothing off your device. If you choose a cloud read-aloud voice, the reply text is sent directly to that text-to-speech provider with your own key. We are not in that path.
- No analytics, no telemetry, no tracking. Zero outbound data to us.
1. What We Collect
Conduck sends us nothing to collect on a server. GigaDuck OÜ has no database, logs, or analytics that receive data from this app.
The table below describes where your data lives and who, if anyone, receives it.
| Data | Who receives it | Stored by us? |
|---|---|---|
| Voice recordings | (a) No one when Apple on-device transcription is active — processed locally, then discarded; (b) the cloud transcription provider you selected, sent directly with your key, if you opt into one | No |
| Transcribed text, your messages, and any attachments you send (photos, screenshots, files) | The AI service you configured — a gateway you operate, subscribe to, or have been invited to use, including a hosted service such as OpenRouter — sent directly with your token. Where that gateway is operated by someone else, its operator may receive and retain what you send. If a file-server is set up for your gateway, your files are also uploaded there using a credential in your Apple Keychain. | No |
| AI replies (returned to you) | Returned from that service to your device | No |
| Reply text read aloud (only if you choose a cloud read-aloud voice) | The text-to-speech provider you selected — OpenAI, Mistral, ElevenLabs, Gemini, OpenRouter, or a custom endpoint you point to — sent directly with your key, to be turned into spoken audio. The default is Apple’s on-device voice, which sends nothing. | No |
| Conversation history, including inline image and text-file attachment copies and stored previews of files your AI produces | Your device + your iCloud (Apple CloudKit private database) | No |
| Private Usage records | Your devices + your iCloud private database. A record may contain locally generated attempt, conversation, and message identifiers; start and completion times; outcome and Conduck error category; Apple surface, input method, and device class; the configured connection slot; requested and reported model names; a provider-reported response identifier and finish reason; reported token counts; and counts of inline images and text-file blocks. It contains no prompt, transcript, reply, audio, attachment, filename, file content, endpoint address, credential, provider error message, or HTTP status. | No — never sent to us, your AI, or a voice provider as Usage data |
| Random app identifier | Your device Keychain and, when iCloud is available, your private iCloud key-value store, so your Apple devices can converge on the same identifier. It is not included in requests to your AI or voice providers. | No — never sent to us |
| Access keys / tokens (transcription or read-aloud provider, gateway, file-server) | Your Apple Keychain. On iPhone, iPad, and Mac, synchronizable items can move between your devices when iCloud Keychain is enabled; an Apple Watch holds a local copy sent by its paired iPhone. A key is also sent to the provider, gateway, or file-server you configured when needed to authenticate your request. | No — never sent to us, never logged |
| Pro purchase and subscription status, when available | Apple handles the purchase. Conduck processes Apple’s verified transaction and subscription information on your device to determine Pro access, including expiry, revocation, and any applicable billing grace period. | No — the app does not send transaction or entitlement records to us |
| Apple sales and subscription reports | Apple makes reports available to us as the app’s developer. They may include purchases, renewals, refunds, prices, storefront country, and a pseudonymous subscriber identifier. They do not contain your app content or payment-card details. | Reports may be accessed or retained for the limited business purposes and periods described in Sections 3 and 5 |
Data We Do NOT Collect
- No audio, transcripts, messages, or replies on any Conduck-operated intermediary server (we have none)
- No Conduck account, email, name, or contact information collected by the app. Information you choose to send in correspondence is covered by the separate Website & Project Participation Privacy Notice.
- No analytics events, Usage records, or telemetry are sent to us. Conduck does keep the private, content-free Usage ledger described above for you on your devices and in your private iCloud; we cannot access it. Separately, Apple gives every developer aggregate totals about their own app, and we do read them: App Store download counts, anonymized crash diagnostics through App Store Connect (unless you opt out in iOS Settings), and — through Apple’s CloudKit console — the number of iCloud accounts that sync with Conduck, along with request and error counts for that sync. These are totals with no identifier attached: we cannot link any of them to you or your device, and none of them originates in anything the app reports to us. We may publish such figures in aggregate.
- No advertising identifiers, no fingerprinting, no tracking
- No device location. Apple’s purchase reports may show your App Store country or region; this is separate from device-location tracking.
2. How Your Data Flows
Conduck performs up to three independent, device-direct hops, depending on your settings. We are in none of them.
Hop 1 — Speech to text.
- Apple on-device (default): audio is transcribed by Apple’s Speech framework entirely on your device. It is never uploaded anywhere. The recording is deleted as soon as the transcription completes — see “How long a recording exists” in Section 4 for the two cases where a copy is kept briefly so it is not lost.
- Cloud provider (optional): if you switch to a cloud transcription provider in Settings, your audio is sent directly from your device to that provider using the API key you entered. If that provider is a hosted AI service or aggregator (such as OpenRouter), it may in turn route your audio to a downstream model provider. That provider processes the audio under its own privacy policy. You chose the provider; you hold the key; you are responsible for that relationship. We are not in that path.
Hop 2 — Message to your AI service. Your transcribed (or typed) message, any attachments or screenshots you add, and the prior turns of the current conversation are sent directly from your device to the AI service selected for that conversation, authenticated with the access token you entered. For a self-hosted gateway, that destination is the server you operate — or, where you set the gateway up from a pairing code someone else gave you, the server that person operates. In that case the gateway’s operator, not you, controls it: they may receive and retain your messages, your attachments, and the conversation context sent with them, under their own practices rather than ours. Connect only to a gateway whose operator you trust. For a hosted AI service such as OpenRouter, that destination is the hosted service and — depending on the model you select — the downstream model provider it routes your request to. The reply is returned to your device. We never see the address, the token, the message, the attachment, the reply, or the conversation.
If a file-server for your gateway has been set up (an optional, advanced feature so the AI’s tools can act on real files — it may run on the gateway machine or on a separate one), your attachments and files are also uploaded directly to that configured file server, using its saved credential. That connection uses HTTPS unless you explicitly configured a local-network plain-HTTP address under Section 4. Where the gateway is operated by someone else, its file-server is theirs too, and they may receive and retain the files you send to it. For photos, the file-server receives the original image with its camera and location metadata intact, whereas the copy sent inline to the AI is downsized with that metadata removed. Files the AI produces can be downloaded back to your device. In addition, when your AI names a file it has produced, Conduck may automatically copy a small, size-limited preview of it — up to roughly 128 KB of text, or a reduced image thumbnail — from your file-server into the conversation record, so the chat can show the file without a fresh download each time. That conversation record lives on your device and in your private iCloud (see Section 4); neither end of this copy is ours, and we see neither. The preview is a snapshot kept and deleted with the conversation; opening a file always downloads its current full version from that file-server. The file-server belongs to whoever operates the gateway; we operate nothing here and never see the credential or the files.
Hop 3 — Reply to speech (optional).
- Apple on-device (default): replies are read aloud by Apple’s built-in voice entirely on your device. The reply text never leaves your device; the synthesized audio is held in memory only during playback, then discarded.
- Cloud provider (optional): if you select a cloud read-aloud voice in Settings, the text of the reply being read aloud is sent directly from your device to that text-to-speech provider, using the API key you entered (the same key as that vendor’s transcription), and the provider returns synthesized audio. If that provider is a hosted service or aggregator (such as OpenRouter), it may in turn route the text to a downstream model provider. You chose the provider; you hold the key; that provider processes the text under its own privacy policy. We are not in that path. Read-aloud uses Apple’s on-device voice by default; a cloud voice runs only when you have selected one and you tap Speak on a reply, enable a Spoken Replies option in Settings, or use the app in CarPlay (which always speaks).
Private Usage — no additional network hop. Conduck stores a private Usage record for each recorded request attempt. It may contain locally generated attempt, conversation, and message identifiers; start and completion times; outcome and Conduck error category; Apple surface, input method, and device class; the configured connection slot; requested and reported model names; a provider-reported response identifier and finish reason; reported token counts; and counts of inline images and text-file blocks. It contains no prompt, transcript, reply, audio, attachment, filename, file content, endpoint address, credential, provider error message, or HTTP status. Usage records sync through your CloudKit private database so Settings → Usage can show the same view on your Apple devices. They are never sent to us, your AI, or a voice provider as Usage data.
Because you bring your own keys and connect to services you chose — whether a gateway you operate, subscribe to, or have been invited to use — the privacy and data-retention terms that apply to these hops are those of the providers, gateway, and read-aloud voice you selected, not ours. We recommend reviewing the privacy policy of any cloud transcription provider you enable, of any cloud read-aloud (text-to-speech) provider you enable, of the AI gateway you operate, subscribe to, or have been invited to use, and — for a hosted gateway — of the downstream model providers it may route to. For a gateway operated by someone else, the practices that govern what you send are that operator’s; ask them if you do not know what they are.
3. Third-Party Services
GigaDuck OÜ does not contract any sub-processors for this app. The third parties below are involved only because of your own configuration or Apple’s platform:
Apple Inc.
- App distribution and purchases via the App Store. The app is free to download. When the optional Conduck Pro subscription becomes available, Apple will handle its payment and renewal. We do not receive your payment-card details. Conduck uses Apple’s StoreKit transaction and subscription information on your device to verify access; it does not send that information to a Conduck server or link it to your private app identifier.
- Developer reporting. Apple makes sales and subscription reports available to us, including purchase and renewal details, refunds, prices, storefront country, and potentially a randomly generated subscriber identifier specific to the customer and developer. This is pseudonymous reporting, not solely aggregate totals; see Apple’s Subscriber Report description. These reports do not give us access to your conversations, Usage records, provider keys, or device identifier. We use relevant records to reconcile proceeds and refunds, keep accounts, and respond to subscription-support requests. Where those records are personal data, the bases are performance of our contract for necessary subscription support (GDPR Article 6(1)(b)), compliance with applicable accounting and tax duties (Article 6(1)(c)), and our legitimate interest in reconciling the proceeds and refunds for our app (Article 6(1)(f)). They are not used to track your activity inside Conduck. Support correspondence is handled as described in the Website & Project Participation Privacy Notice.
- iCloud / CloudKit stores conversation history and private Usage records in your CloudKit private database. Conduck separately uses your private iCloud key-value store to sync app settings, the random app identifier, and the Usage clear-before cutoff. We have no access to either store.
- Watch Connectivity and CarPlay frameworks support the watch and in-car surfaces.
- Apple Privacy Policy
Transcription provider you selected (optional)
If you enable a cloud transcription provider, your audio is sent to that provider under your own account and key. We have no contract with them on your behalf, and their handling of your audio is governed by their policy. (The default — Apple on-device transcription — involves no third party.)
AI gateway you configured
The AI assistant you connect to is a service you chose — a gateway you operate, subscribe to, or have been invited to use: a server of your own, a custom OpenAI-compatible endpoint you point to, a hosted AI service, or a server operated by someone who gave you a pairing code for it. Your messages, attachments, and conversation context go there under your own token; where the gateway is operated by someone else, that operator may receive and retain them. We have no relationship with it.
Hosted AI gateway or hosted voice provider, such as OpenRouter
If you configure a hosted service like OpenRouter (as your AI gateway, your cloud transcription provider, and/or your cloud read-aloud voice), Conduck sends your requests directly from your device to that service using your own API key. That hosted service may forward your audio, your messages, attachments, screenshots, conversation context, and — if you chose it as a read-aloud voice — the text of any reply you have it read aloud, to the downstream model provider selected or routed for the request. Their terms, privacy policy, retention rules, and data-transfer safeguards — not ours — govern that processing. See OpenRouter’s Privacy Policy and Terms.
4. Storage and Security
| Data | Location |
|---|---|
| Voice recordings | Never part of your conversation history, and never synced to iCloud. Kept on your device only for as long as the recording is being processed, plus the two bounded cases described below. With a cloud provider, any retention on their side is governed by that provider. |
| Synthesized read-aloud audio | Not stored. Held in memory only during playback, then discarded; never written to disk. With a cloud read-aloud voice, any retention of the reply text you send is governed by that provider. |
| Files uploaded to your gateway’s file-server (optional) | Not stored by us. Held on the file-server your gateway uses — yours, or its operator’s — under a credential in your Apple Keychain. Inline photos and text/code files sent in chat are also stored with the conversation, and small previews of files your AI produces may be stored there too (see Section 2). |
| Transcribed text / messages / replies | Not stored by us. Persisted as conversation history on your device + your iCloud. |
| Conversation history | Your devices + your iCloud private database (Apple CloudKit), including inline image and text-file attachment copies and stored previews of files your AI produces. Encrypted by Apple. We have no access. |
| Private Usage records | Your devices + your iCloud private database (Apple CloudKit), separate from conversation history. They contain the Usage fields described in Section 1, but no prompt, transcript, reply, audio, attachment, filename, file content, endpoint address, credential, provider error message, or HTTP status. We have no access. |
| Random app identifier | Your device Keychain and, when iCloud is available, your private iCloud key-value store. Never sent to us or included in an AI or voice-provider request. |
| Access keys / tokens | Your Apple Keychain. Synchronizable items can move between your iPhone, iPad, and Mac when iCloud Keychain is enabled; the Watch holds a local copy sent by its paired iPhone. Sent to the provider, gateway, or file-server you configured only when needed to authenticate a request; never sent to us. |
How long a recording exists. A recording is written to your device’s own protected storage while it is being processed — transcription and upload both need it as a file — and is deleted when that finishes, on success and on failure alike. It is never added to your conversation history and never synced to iCloud. Two cases keep a copy slightly longer, both on your device only, and both deleted automatically:
- A transcription that failed. The recording is kept so you can tap Retry rather than say it again. It is deleted when you retry, when you dismiss it, or automatically after about ten minutes — whichever comes first.
- A recording made on your Apple Watch. The Watch saves the clip before handing it to your iPhone, so that a dropped connection or an app restart cannot lose what you just said. It is deleted the moment the iPhone takes it. If delivery never succeeds, it is discarded within a day, and only a small number of undelivered clips are ever held.
Security measures:
- Access keys and gateway tokens are stored in the Apple Keychain and are never logged or shown in error messages. Synchronizable items can move between your iPhone, iPad, and Mac when iCloud Keychain is enabled; a Watch receives its local copy from the paired iPhone.
- Connections to a configured gateway, file server, or custom voice endpoint use HTTPS except when you explicitly save a plain
http://address that is limited by its address to your own network: a loopback address, a private IPv4 or IPv6 literal, or a Bonjour name ending in.local. Conduck warns that this traffic is not encrypted. Public and otherwise routable plain-HTTP addresses are rejected. You may optionally pin your gateway’s certificate fingerprint as an added restriction on top of a certificate your device already trusts — it cannot be used to accept a certificate your device would otherwise reject.
5. Data Retention
- On Conduck-operated intermediary servers: none — Conduck operates no intermediary server.
- Audio and read-aloud: not retained by us. On-device transcription and on-device read-aloud discard immediately; a cloud transcription or read-aloud provider’s retention of the audio or reply text you send it is governed by that provider (review their policy).
- Conversation history: kept on your devices and in your private iCloud until you delete the conversation in Conduck. Deleting a conversation on one device propagates to the others through CloudKit. Deleting the app removes that device’s local copy, and signing out makes the iCloud copy unavailable on that device, but neither action by itself necessarily deletes the copy still held in your private CloudKit database.
- Private Usage records: kept separately from conversation history on your devices and in your CloudKit private database. Deleting a conversation does not delete its related Usage record. Settings → Usage → Clear Usage History writes a clear-before cutoff to your private iCloud key-value store; as each device receives that cutoff, it removes records at or before it and will not restore an older local copy. Records created after the cutoff remain. Deleting the app or signing out removes or hides that device’s local view but does not by itself necessarily delete records still held in the CloudKit private database.
- Random app identifier: kept in your device Keychain and, when iCloud is available, your private iCloud key-value store. It can persist across an app reinstall and can sync back to your devices.
- Keys / tokens: kept in the Apple Keychain. Synchronizable items can persist in iCloud Keychain, move between your iPhone, iPad, and Mac, and return after a reinstall; the Watch keeps its own local copy. Forgetting a connection removes its synced settings and synchronizable key from devices that receive the change, but does not revoke the credential at the server or provider. A paired iPhone can also tell its Watch to remove the Watch’s local copy; a forget performed only on iPad or Mac cannot reach the Watch. Rotate the credential at the server or provider whenever you need to revoke every copy that may still exist.
- Subscription verification: Conduck reads Apple’s verified purchase and subscription information on your device and keeps the current access decision in memory. Apple retains purchase records under its own policy; deleting Conduck neither erases Apple’s records nor cancels a subscription.
- Apple reports and subscription correspondence: any copies we retain are limited to what is needed to reconcile proceeds or refunds, resolve the request or dispute concerned, or meet applicable accounting and tax retention duties. Records are reviewed and deleted when those purposes and any legally required retention period end. Apple’s own report availability and retention remain under its control. Correspondence follows the retention criteria in the Website & Project Participation Privacy Notice; this does not establish a separate app-content database.
6. International Data Transfers
GigaDuck OÜ receives none of your app content, provider keys, device identifier, or Usage records and therefore does not transfer those data internationally. Their transfer is between your device and a service you chose (a cloud transcription provider, a cloud read-aloud voice provider, your AI gateway, or a hosted AI service and the downstream model providers it routes to), or is Apple’s iCloud handling under Apple’s own published safeguards. A hosted service and its downstream providers may process your data in other countries under their own safeguards. Those transfers are governed by the terms of the service you selected and by Apple’s standard agreements. Apple separately handles purchase processing and developer reports under its privacy policy and applicable transfer safeguards. Where you contact us about a subscription, the providers and transfer safeguards for our correspondence are described in the Website & Project Participation Privacy Notice.
7. Your Rights (GDPR)
Conduck sends us no app content, provider keys, device identifier, or Usage records, so we cannot access or erase those data on your behalf. There is no Conduck account system. Apple sales and subscription reports and information you choose to send us in correspondence are separate: where we hold personal data in those records, you may request access, correction, erasure, restriction, or portability as applicable. We may need information sufficient to locate the relevant record; we do not require you to disclose your conversations or provider keys.
Your right to object. You may object to processing based on our legitimate interests on grounds relating to your particular situation by emailing privacy@gigaduck.ai. We stop that processing unless overriding legitimate grounds or the establishment, exercise, or defence of legal claims justify continuing. Erasure rights remain subject to applicable legal retention duties.
You remain in full control of the data the app does touch:
- Your conversation history: view, edit, or delete it directly in the app on any of your devices; deletions sync via iCloud. Removing the app and its iCloud data erases it entirely.
- Your private Usage records: view them in Settings → Usage. Clearing Usage History writes a private sync cutoff so every device removes records at or before it; deleting a conversation alone does not clear its Usage record.
- Your keys and tokens: forget a connection in Settings to remove Conduck’s saved copies from devices that receive the change. Rotate the credential at its server or provider to revoke every copy, including a lost or offline device.
For any data you believe we hold, or to ask about this policy, email privacy@gigaduck.ai; we will respond within 30 days. Under the GDPR you also have the right to lodge a complaint with a supervisory authority; our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
For data held by a cloud transcription provider or by the AI gateway you use, exercise your rights directly with that provider or with the gateway’s operator — they — not us — are the controller for what you send them.
8. Children’s Privacy
Conduck is not directed at children under 16. We do not knowingly collect data from children; the app sends us no content or telemetry from anyone. For questions about the app, email privacy@gigaduck.ai.
9. Changes to This Policy
We may update this policy from time to time. We will update the “Last Updated” date and post the current version in the app and on our website. Please review it periodically; the current version always governs.
10. Contact
Email: privacy@gigaduck.ai Data Controller: GigaDuck OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia · Registry code 17501858 · General: info@gigaduck.ai