niksmac
← Technology

Blog

Why Private LLM Apps Matter: The Case Behind Merrin

Date —
October 6, 2026
Tags —
Digital Privacy, AI, Products

I value digital privacy and online security. That matters most to people who prefer to keep things in a small circle and have decided to keep things private. You do not want to expose your private life in front of a corporate entity in return for what — more spying?

I maintain many online accounts under almost the same handle, and I am reasonably confident I am not very visible on social platforms like Instagram or Facebook. That is not the case for most people. Maybe you want to be found. Maybe you want to be seen. Maybe you want attention, as part of your career or profession. That is a fair choice. The problem is that the two positions — visible and not visible — used to be separated by a simple rule: you decide what you publish. That rule broke somewhere around the time we all started typing our lives into chatbots.

Why not just use the settings?

The standard reply to all of this is: change your settings. You can tighten the switches, and you should if you are staying on the cloud. But you are then relying on defaults staying put, opt-outs staying honoured, and nobody with your password opening the account. The architecture decides the risk; the settings only negotiate with it.

Whether those switches do what people assume is worth checking. So I read the fine print.

Twenty ears, forty mouths

Imagine telling your life story to a person with twenty ears and forty mouths. Every word goes in, and every word can come out again to someone else. Google has been that person for a decade; so have Facebook and Instagram.

AI assistants are worse. Their purpose is to analyse patterns and remember everything you ever said — that is the product working as designed. A search engine logs what you searched. An AI companion logs the conversation where you explained why you are thinking of leaving your job and what your therapist said. Same text box, far more sensitive material.

The privacy policies of the major assistants say roughly the same thing:

  • Training is on by default for consumer accounts. OpenAI’s privacy policy says it may use content you provide “to improve our Services, for example to train the models that power ChatGPT.” Claude, Copilot, and Grok ship the same default, with the opt-out buried in settings.
  • Google warns you outright. With Keep Activity on — the default — Gemini chats train models “with the help of human reviewers,” and the notice says not to enter anything you would not want a reviewer to see. Reviewed chats can be kept for up to three years, disconnected from your account, so deleting your activity does not delete them.
  • Opting out is weaker than it looks. With OpenAI, rating a response can pull that conversation back into training even after you opted out, and training, retention, and memory are three separate switches — not one.
  • Deletion is a request, not an erasure. Deleted data leaves OpenAI’s systems “within 30 days,” with legal and safety exceptions, and it may hold data longer if it receives a lawful subpoena.

The conclusion is uncomfortable: a privacy policy is a promise about a copy that exists on someone else’s server. That copy is what a breach exposes, what a reviewer can open, what a subpoena asks for — and what the provider can rewrite with notice.

Open weights changed the equation

The alternative used to be unrealistic — run a language model yourself, on hardware you own? That argument died recently, and it died on phones. There are now capable open-weight models that run on modern handheld hardware — Google’s Gemma family is one example, alongside Llama and Qwen variants.

You might think: Google? After all the criticism above? But Google is just the brand here. The point of an open-weight model is that the weights — the trained parameters, the actual model — are published as files you download. You run them on your own device, offline, and Google never sees the conversation. The company that made it is irrelevant to who can read your words, because there is no reader but you.

Two terms that get confused:

  • Open weight means the trained model files are published under a licence that lets you download and run them. You get the model; you do not get how it was built.
  • Open source means the preferred form for modifying the thing — the training code, the data pipeline, the recipe — is also published. By that standard, most “open” models, Gemma included, are open-weight rather than open source. That distinction matters for trust, but for privacy it is secondary: what matters is that inference happens on your device, where nothing leaves.

What we built

That is the reasoning behind Merrin, the private AI companion I work on. We identified open-weight models that run well on supported iOS and Android devices and built the app around them.

What that buys you in practice:

  • Conversations stay on the device. The core AI runs locally, so chat, journal entries, memories, and transcripts are designed to stay on your phone during normal use — not sent to a cloud AI service to be useful. After the models are installed, it works without an internet connection.
  • The app tracks what you tell it — under your control. Merrin keeps track of what you mention, your likes and dislikes, the people and projects that recur in your conversations. You decide what it remembers and for how long: view what is stored, edit individual memories, delete them one at a time, exclude specific conversations, or turn memory off entirely.
  • Deletion means deletion. You can delete a memory and its associated information anytime, and you can wipe all history, chats, and memory from inside the app. There is no server-side copy to also go and request, because the design goal is that one never exists.
  • No advertising model. Merrin is not funded by selling your conversations, so the incentive to keep and analyse them never appears.
  • Full export. Pro lets you take your entire history with you, because data locked in an app is only a nicer kind of lock-in.

Private vs cloud AI at a glance

Eight questions, two answers:

Private LLM app Cloud AI assistant
Where your data lives On your device Vendor servers
Who can read your conversations No one but you — no operator-side copy exists Provider staff, for safety review and, by default, improvement
Used to train models No — inference never leaves the device On by default for consumer plans; opt-out is a setting
Retention Only what you keep; delete is immediate 72 hours to 18 months by default, longer with legal exceptions
Works offline Yes, after model install No
Memory control View, edit, delete, or disable — per memory Separate switches that vary by vendor and plan
Funded by You — subscription or one-time purchase Varies, including advertising
Knowledge-heavy questions Weaker — smaller models Stronger — frontier models

The left column is what Merrin optimises for. The last row is the honest cost of it — which is where the trade-offs come in.

The honest trade-offs

A private LLM app is not a free upgrade. The last row of the table is the real one: for a deep research query, a cloud model still wins, and sending it content you do not care about is a fine trade. The rest of the cost is that your data’s safety becomes your device’s safety — lose the phone with no backup, and you lose the journal.

For the thing people actually use these apps for — thinking out loud, capturing a day, finding the idea you mentioned three weeks ago — the trade is close to a no-brainer. That is the point of the category. The importance of private LLM apps is not that they are more capable. It is that they change who holds the copy: you, instead of a server, a policy, and a retention schedule you do not control.

Bonus: opt out of the major providers

If you are staying on the cloud, do these first — each takes about a minute. They cover training only: retention and memory are separate switches, and in some products, feedback you submit can still be used even after you opt out.

  • OpenAI (ChatGPT) — Settings → Data controls → turn off “Improve the model for everyone”, or use the OpenAI privacy portal to select “Do not train on my content”. Details in the data controls FAQ.
  • Google (Gemini) — turn off Gemini Apps Activity. That stops new chats being used for training and drops retention to 72 hours; the Gemini privacy hub explains the tiers.
  • Anthropic (Claude) — Claude → Settings → Privacy, following How do I change my model improvement privacy settings.
  • Microsoft (Copilot) — Profile → Privacy → switch off “Training on conversation activity” and “Training on voice conversations”. See the Copilot privacy controls.
  • xAI (Grok) — Settings → Data Controls → “Improve the model”, or use Private Chat, which is never used for training. The xAI FAQ has both paths.

Worth repeating: an opt-out is a promise, and promises live in policies that get rewritten. They reduce exposure; they do not remove the copy.

If you want to skip the switches entirely, Merrin is on the App Store and Google Play, with the core private journaling free. The engineering deep dive explains how the local memory loop works if you want the technical version, and the policy review of the major assistants is the research behind the policy sections above.