Zimmer

Privacy Policy

Last Updated: August 7, 2026

Controller: FIHI LABS UG (haftungsbeschränkt) · support@zimmerapp.co

Zimmer is a local-first AI application. This policy covers Zimmer for macOS and Zimmer for Android. Where the two differ, the platform is explicitly named.

1. The Core Promise: Your AI Content Never Leaves Your Device

On both platforms, all AI processing happens locally on your device. We never receive, store, transmit, or train on:

  • your prompts, or the assistant's responses
  • conversations, conversation titles, or search indexes
  • attachments, files, or voice recordings
  • downloaded model files
  • your private backups

This is an architectural property, not only a policy commitment: the application has no code path that transmits this content to us. Model downloads go directly from the source (for example, Hugging Face) to your device.

We do not sell your data. We do not train models on your data. We do not log your conversations.

2. What We Do Collect

2.1 Account Identity (Both Platforms)

Accounts are handled by Google Firebase Authentication, which stores your email address, a unique user identifier, whether your email is verified, and authentication metadata such as sign-in timestamps.

  • Android: Uses email and password. We never receive your password; Firebase handles it, and Zimmer never sees, stores, or logs it.
  • macOS: Uses Google or GitHub sign-in.

An account on one platform is not automatically the same account on the other. They are linked only if you explicitly connect them.

2.2 Access and Entitlement Data (Android)

Zimmer for Android offers a seven-day free trial and a one-time Zimmer Lifetime purchase. To manage access, our entitlement service stores, against your account identifier only:

  • whether your trial has started, and its start and end times
  • whether you own the lifetime product, and a version number for that record
  • a one-way cryptographic fingerprint of a security key generated on your device and never leaving it
  • a one-way hash of your Google Play purchase token
  • an internal derived identifier linking a purchase to an account
  • technical records that make repeated requests safe to retry, and security audit events

We do not store your email address alongside purchase data.

2.3 Payments

Payments are processed entirely by Google Play (Android) or Stripe (macOS). We never see or store your card number, bank details, or billing address. We receive only confirmation that a purchase occurred, plus refund and cancellation notices.

2.4 Website Analytics (zimmerapp.co)

First-party analytics record sessions, page views, clicks, referral source, UTM campaign fields, device category, and coarse country. They do not record raw IP addresses, raw referral codes, prompts, files, emails, or in-app activity. Retained for 180 days. Do Not Track browser signals are respected. Analytics do not run on the account-deletion page.

2.5 Crash Reports

Opt-in only. Stack traces and hardware specifications; never prompts, content, or code.

2.6 MCP & Third-Party Integrations (macOS)

When you use the Model Context Protocol (MCP) to connect to external services (like Notion, GitHub, or Linear), Zimmer acts as a secure local bridge. Your API keys and OAuth tokens are stored in the macOS System Keychain. Zimmer retrieves these only at runtime and never transmits them to our servers. Connections to third-party APIs are established directly from your machine and are not proxied.

The Zimmer Privacy Guarantee

We will never sell your data. We will never train models on your data. We will never implement cloud-based logging for your prompts. Your intelligence is your own.

3. Where Your Data Is Stored

Your AI content stays on your device and is never transmitted, so it is not stored anywhere by us.

The limited account and entitlement data described above is processed by Google Cloud on our behalf:

DataLocation
Android entitlement records, processing, and signing keysFrankfurt, Germany (europe-west3)
macOS account and subscription records (Firestore)United States (multi-region)
Firebase AuthenticationOperated globally by Google

Because macOS account records and Firebase Authentication involve storage or processing outside the EU, using Zimmer on macOS involves an international transfer of that limited account data. Google Cloud provides Standard Contractual Clauses for such transfers.

4. How Long We Keep It

RecordRetention
Account and entitlement recordsUntil you delete your account
Registered device keysUntil you delete your account
Purchase recordsRetained after deletion in pseudonymised form (see §5)
Operational logs30 days
Security audit logs400 days
Website analytics180 days

5. Deleting Your Account and Data

Android: Settings → Delete account. We delete your Firebase identity, your account record, your registered devices, and your entitlement record. Your on-device conversations are then deleted from your device with your confirmation.

You can also delete only your on-device data ("Delete local data from this device") without deleting your account. Signing out does not delete anything: it makes local conversations inaccessible until the same account signs in again. Detailed instructions and request forms are available on our Data Deletion Page.

macOS: Delete the application and its support folder (~/Library/Application Support/Zimmer).

Either platform, without opening the app: email support@zimmerapp.co. Please do not include passwords, conversations, prompts, recordings, attachments, or purchase tokens in that email—we do not need them.

What we keep after deletion: If you purchased Zimmer Lifetime, we retain a pseudonymised record of that purchase—your account identifier is replaced with a one-way derived value. We keep it so Google Play / Stripe refunds, chargebacks, and cancellations remain reconcilable after the account is gone, and to prevent duplicate claims. This record grants no access to anything.

Warning: A lifetime purchase cannot be restored or transferred to another account after you delete your account.

6. Your Rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to it or lodge a complaint with a supervisory authority. Contact support@zimmerapp.co.

Most of what people want to export is your conversations—and those are already yours alone, on your device, exportable from within the app without involving us.

7. Children

Zimmer is not directed to children and we do not knowingly collect data from them.

8. Third Parties

We use Google Firebase Authentication and Google Cloud (identity, entitlement storage, signing), Google Play (Android payments), and Stripe (macOS payments). Each processes data under its own privacy policy. Connections you configure yourself—for example MCP integrations on macOS—go directly from your device to that service; we do not proxy or observe that traffic. Credentials for them are stored in your operating system's keychain.

9. Changes

We will update this page and its "last updated" date when this policy changes.