Your information
Privacy Policy
This policy explains how BigOit handles information when you use the app and these legal pages. BigOit generates its answers on your device, so your conversations have nowhere to go.
The short version
BigOit has no account system, no developer-operated backend, no advertising and no in-app purchases. Your prompts, answers, dictated speech and attached photos are processed on your device and are never sent to us.
1. Scope and who we are
This Privacy Policy applies to the BigOit iOS application and to these legal pages, which are hosted on GitHub Pages. “BigOit”, “we”, “us” and “our” refer to Mohammed Alblooki, the BigOit app developer and data controller, based in the United Arab Emirates.
BigOit is an offline AI assistant. It downloads an open-weights language model to your device and runs it locally, so that chatting, dictation and asking about a photo all happen on the device.
For any privacy question, contact bigoit.support@gmail.com.
2. What BigOit does not collect
BigOit does not operate a user database and does not require an account. We do not ask for or collect:
- your name, email address, phone number, postal address, contacts or social-media profile;
- your precise or approximate location;
- payment information — BigOit sells nothing inside the app;
- advertising identifiers, and BigOit requests no tracking permission;
- your prompts, the model’s answers, your dictation audio or transcripts, or the photos you attach.
If you email us for support, we receive the address, message and any attachment you choose to send, and use it only to reply and to fix the problem.
3. Information used on your device
Everything below is held in BigOit’s private app container, protected by iOS file protection, and never transmitted:
- Your messages and the model’s answers. Saved only while “Save chat history” is on. You can delete any conversation or all of them, and you can have BigOit remove chats automatically after 30 days.
- Photos you attach. Copied into the app container, resized, and used only as input to the on-device model. A message carries at most three.
- Dictation. Audio is written to a temporary file, transcribed by Apple’s on-device speech recognition, and the file is deleted immediately afterwards. BigOit requires on-device recognition, so your speech is not sent to Apple for transcription.
- Your settings, including the model you prefer, the app icon you chose and whether crash reporting is on.
Deleting the app removes all of it. We keep no copy, because we never received one.
4. Permissions BigOit asks for
BigOit asks only at the moment a feature needs it, and explains why. If you refuse, that feature stops and the rest of the app carries on working; you can change your mind at any time in iOS Settings, and BigOit offers a direct link there.
| Permission | When it is requested | What it is used for |
|---|---|---|
| Camera | When you choose “Take photo” | Capturing one image to ask about. The image is stored on the device. |
| Microphone | When you tap the microphone | Recording your speech so it can be turned into text. |
| Speech Recognition | When you tap the microphone | Transcribing that recording on the device. |
Two things BigOit deliberately does not ask for:
- Photo library access. BigOit uses Apple’s system photo picker, which runs outside the app and hands over only the images you select. The app is never granted access to your library, so iOS has nothing to prompt you about. This is Apple’s recommended approach and gives you more privacy than a full-library permission would.
- Network access. iOS has no general internet permission. The only network prompt Apple provides is Local Network, for discovering devices on your Wi-Fi, and BigOit never does that.
5. When BigOit uses the network
| What | Where it goes | Why | Your control |
|---|---|---|---|
| Model download | Hugging Face, operated by Hugging Face, Inc. | To fetch the model weights the first time you choose a model. The request carries no prompt, no chat content and no identifier we attach. | Happens only when you tap Download. Once the file is on your device, BigOit never contacts it again and works in Airplane Mode. |
| Crash diagnostics | Firebase Crashlytics, operated by Google LLC | Technical crash reports — stack traces, timestamps, app and iOS versions, device model and architecture, memory or disk information, and random installation and session identifiers — so that crashes can be found and fixed. | Off by default. You can opt in under Settings › Diagnostics › Share crash reports, and turn it off there at any time. No prompt, answer, photo or transcript is ever included. |
The BigOit app makes no other network requests. There is no analytics SDK, no advertising SDK, no tracking pixel and no attribution framework.
These legal pages are hosted by GitHub Pages. When you visit them, GitHub may process standard web-request information such as your IP address, browser and request time under the GitHub General Privacy Statement. The pages store only your English/Arabic choice in your browser’s local storage; we do not receive that preference and use no advertising or analytics cookies.
6. Storage and retention
On-device data stays until you delete it or remove the app. Model files can be deleted individually from Manage models to reclaim space.
Crashlytics keeps crash stack traces and associated identifiers for 90 days before starting removal from live and backup systems. Turning reporting off stops future reports after the next app launch; reports already sent follow that retention period.
Support emails are kept only as long as reasonably needed to answer you, resolve the issue and maintain necessary records. GitHub controls retention of its hosting logs under its own privacy statement.
8. Children
BigOit is not directed at children under 13 and we knowingly collect no personal information from them. Because BigOit has no account system and transmits no user content, there is no children’s data for us to hold.
Note that AI output is generated text and is not filtered or moderated by us, because it never reaches us. Parents should supervise use accordingly.
9. Security
Chats, attachments and model files are written inside the app container with iOS file protection applied, so they are encrypted while the device is locked. Model downloads use HTTPS and each file is verified against a published SHA-256 checksum before it is used.
No system is perfectly secure, but the strongest protection here is structural: there is no server holding your conversations to breach.
10. Your privacy rights
Depending on where you live — including under the EU and UK GDPR, the California Consumer Privacy Act, and the UAE Personal Data Protection Law — you have rights to access, correct, delete and port your personal data, and to object to or restrict its processing.
For BigOit these rights are satisfied on the device itself: the data is in your possession, you can read it in the app, edit or delete any of it, and removing the app erases it. Crashlytics uses random installation identifiers and BigOit has no account that links an identifier to your identity. We will honour any request we can verify, but we may be unable to locate a particular crash report from an email address alone; reports are otherwise removed under the retention period above.
Crash reporting is based on your consent: it is off by default and begins only if you turn it on. You can withdraw consent at any time with the switch in Settings. Model downloads are made only at your request. Our legitimate interests in securing and operating these legal pages and answering support requests are the basis for related hosting logs and correspondence, subject to your right to object. We do not discriminate against anyone for exercising a privacy right.
11. Changes to this policy
We update this policy when BigOit’s features, providers or legal obligations change. The “Last updated” date above changes with it, and material changes are noted in the App Store release notes.
12. Contact
Privacy questions, requests and complaints: bigoit.support@gmail.com.
If you are not satisfied with our response, you may raise the matter with the data protection authority in your jurisdiction.