Last Updated: August 7, 2026
Controller: FIHI LABS UG (haftungsbeschränkt) · support@zimmerapp.co
Zimmer is a local-first AI application. This policy covers Zimmer for macOS and Zimmer for Android. Where the two differ, the platform is explicitly named.
On both platforms, all AI processing happens locally on your device. We never receive, store, transmit, or train on:
This is an architectural property, not only a policy commitment: the application has no code path that transmits this content to us. Model downloads go directly from the source (for example, Hugging Face) to your device.
We do not sell your data. We do not train models on your data. We do not log your conversations.
Accounts are handled by Google Firebase Authentication, which stores your email address, a unique user identifier, whether your email is verified, and authentication metadata such as sign-in timestamps.
An account on one platform is not automatically the same account on the other. They are linked only if you explicitly connect them.
Zimmer for Android offers a seven-day free trial and a one-time Zimmer Lifetime purchase. To manage access, our entitlement service stores, against your account identifier only:
We do not store your email address alongside purchase data.
Payments are processed entirely by Google Play (Android) or Stripe (macOS). We never see or store your card number, bank details, or billing address. We receive only confirmation that a purchase occurred, plus refund and cancellation notices.
First-party analytics record sessions, page views, clicks, referral source, UTM campaign fields, device category, and coarse country. They do not record raw IP addresses, raw referral codes, prompts, files, emails, or in-app activity. Retained for 180 days. Do Not Track browser signals are respected. Analytics do not run on the account-deletion page.
Opt-in only. Stack traces and hardware specifications; never prompts, content, or code.
When you use the Model Context Protocol (MCP) to connect to external services (like Notion, GitHub, or Linear), Zimmer acts as a secure local bridge. Your API keys and OAuth tokens are stored in the macOS System Keychain. Zimmer retrieves these only at runtime and never transmits them to our servers. Connections to third-party APIs are established directly from your machine and are not proxied.
We will never sell your data. We will never train models on your data. We will never implement cloud-based logging for your prompts. Your intelligence is your own.
Your AI content stays on your device and is never transmitted, so it is not stored anywhere by us.
The limited account and entitlement data described above is processed by Google Cloud on our behalf:
| Data | Location |
|---|---|
| Android entitlement records, processing, and signing keys | Frankfurt, Germany (europe-west3) |
| macOS account and subscription records (Firestore) | United States (multi-region) |
| Firebase Authentication | Operated globally by Google |
Because macOS account records and Firebase Authentication involve storage or processing outside the EU, using Zimmer on macOS involves an international transfer of that limited account data. Google Cloud provides Standard Contractual Clauses for such transfers.
| Record | Retention |
|---|---|
| Account and entitlement records | Until you delete your account |
| Registered device keys | Until you delete your account |
| Purchase records | Retained after deletion in pseudonymised form (see §5) |
| Operational logs | 30 days |
| Security audit logs | 400 days |
| Website analytics | 180 days |
Android: Settings → Delete account. We delete your Firebase identity, your account record, your registered devices, and your entitlement record. Your on-device conversations are then deleted from your device with your confirmation.
You can also delete only your on-device data ("Delete local data from this device") without deleting your account. Signing out does not delete anything: it makes local conversations inaccessible until the same account signs in again. Detailed instructions and request forms are available on our Data Deletion Page.
macOS: Delete the application and its support folder (~/Library/Application Support/Zimmer).
Either platform, without opening the app: email support@zimmerapp.co. Please do not include passwords, conversations, prompts, recordings, attachments, or purchase tokens in that email—we do not need them.
What we keep after deletion: If you purchased Zimmer Lifetime, we retain a pseudonymised record of that purchase—your account identifier is replaced with a one-way derived value. We keep it so Google Play / Stripe refunds, chargebacks, and cancellations remain reconcilable after the account is gone, and to prevent duplicate claims. This record grants no access to anything.
Warning: A lifetime purchase cannot be restored or transferred to another account after you delete your account.
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to it or lodge a complaint with a supervisory authority. Contact support@zimmerapp.co.
Most of what people want to export is your conversations—and those are already yours alone, on your device, exportable from within the app without involving us.
Zimmer is not directed to children and we do not knowingly collect data from them.
We use Google Firebase Authentication and Google Cloud (identity, entitlement storage, signing), Google Play (Android payments), and Stripe (macOS payments). Each processes data under its own privacy policy. Connections you configure yourself—for example MCP integrations on macOS—go directly from your device to that service; we do not proxy or observe that traffic. Credentials for them are stored in your operating system's keychain.
We will update this page and its "last updated" date when this policy changes.