Privacy Policy
Effective July 4, 2026
Bastion is a private, on-device AI chat app. This policy is short because the app is built so there is nothing to disclose.
What we collect
Nothing. Bastion has no accounts, no analytics, no advertising, no crash-reporting service, and no server of ours on the other end. We do not collect, store, transmit, sell, or share any personal data.
Where your data lives
- Conversations are stored only on your device, using Apple's on-device storage. They never leave your iPhone. Deleting a chat deletes it.
- Attachments (photos, PDFs, text files) are processed entirely on your device. Text extraction and OCR run locally using Apple's frameworks. Nothing is uploaded.
- AI processing happens on your iPhone's own hardware — either Apple's built-in on-device model or an open model you download. Your prompts and the replies are never sent to us or anyone else.
Network use
Bastion touches the network for exactly one thing: downloading an AI model you explicitly request (from Hugging Face's public model hosting). Model downloads are Wi-Fi by default; cellular requires your consent. After a model is downloaded, chat works fully offline — including in airplane mode.
Permissions
- Camera (optional): only if you choose to attach a photo you take. Images are processed on-device.
- Photo library (optional): only for photos you explicitly pick, via the system picker.
This website
bastionprivate.ai sets no cookies, runs no scripts, includes no analytics, and loads nothing from third parties. We don't know you visited.
Children
Bastion does not collect data from anyone, including children.
Changes
If this policy ever changes, the updated version will be posted here with a new effective date. Since the app's architecture is no-collection-by-design, meaningful changes are unlikely.
Contact
Questions: brian.kemler@gmail.com