Cybara Mobile Privacy Policy
Last updated: August 13, 2026
Privacy policy for the Cybara mobile app. Cybara is self-hosted: the app connects to a gateway you run, collects no personal data, and ships with no analytics, advertising, or tracking SDKs.
The short version
Cybara is a self-hosted AI agent platform. The mobile app (Android package com.ck.cybara) is a client for a Cybara gateway that you run yourself. The developer operates no servers that receive your chats, files, or credentials. The app contains no analytics, advertising, tracking, or crash-reporting SDKs, and no personal data is sold or shared.
What the app collects
No personal data is collected by the developer. Chat messages and attachments are sent only to the gateway you pair with, and from there to the model providers you configured with your own API keys. Your gateway address and access token are stored in encrypted on-device storage and are never transmitted to us. Photos are uploaded only when you explicitly attach them. Camera frames are used solely to scan a pairing QR code and are processed on-device without being stored or sent. App preferences stay on your device.
Permissions
Camera is used only to scan a gateway pairing QR code. Photos and media are used only for attachments you choose. Notifications deliver alerts from your gateway. Network and local network access are required to reach a gateway you host, including over your LAN.
Third parties
If notifications are enabled, a push token is issued by the platform push service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS) and registered with your gateway; that traffic is handled under Google's and Apple's policies. Your gateway forwards prompts to the AI providers you configured, which process that content under their own terms. Cybara never sees your provider API keys.
Retention and deletion
Conversation history lives on your gateway under your control. Delete chats in the app or on your gateway at any time. Uninstalling the app removes all locally stored data, including the saved gateway token. Because we hold no copy of your data, there is nothing for us to delete on request.
Security
Gateway tokens are stored in the platform encrypted keystore. Remote connections use HTTPS; plain-text connections are permitted only for private LAN addresses so you can reach a gateway on your own network. Every request to your gateway is authenticated.
Children
Cybara is a developer and operator tool, is not directed to children under 13, and does not knowingly collect personal information from children.
Contact
Privacy questions: privacy@cybara.ai or the issue tracker at https://github.com/metaspartan/cybara