Trust centre

Know the data path
before the first prompt.

“Private AI” should describe an architecture, not an aspiration. Here is what stays local, what can be on-premises, and where an optional provider may enter the path.

Local model

On your device

Prompts, documents, results, history and memory stay on the device. Local inference has no token meter.

  • No Software Tailor cloud required
  • Can work offline after model download
  • Performance depends on model and hardware
On-premises

On your infrastructure

AI Server hosts models and inference within the environment your organisation chooses and operates.

  • OpenAI-compatible endpoints
  • Organisation-controlled network path
  • Central administration available
Optional route

Third-party provider

Some supported apps offer optional cloud models. The app identifies that path before use; the provider's terms then apply.

  • Not required for the local path
  • Chosen by the user
  • Boundary changes are explicit
Plain-language controls

What we can state today

Content

Local-model inference content stays on the device. On-premises inference content stays within the customer's configured infrastructure path.

Telemetry

Product telemetry is separate from prompts and results and can be disabled. It requires opt-in in specified privacy regions and Apple builds, but may start enabled elsewhere.

Identifiers

Install and machine identifiers are pseudonymous, not anonymous, and can be joined to registration, entitlement or support records in restricted operator tools.

Limits

Privacy boundaries do not remove the need for endpoint security, access control, backups, model governance or user policy.

Buyer evidence

Questions worth asking any AI supplier.

Where does inference run? +

Require an answer for each supported model path—not a single general statement for the whole product.

What leaves the device or network? +

Separate content, identity, entitlement, diagnostic and optional telemetry flows.

Can the useful path work without a vendor cloud? +

Test the real workflow, including model acquisition, updates, licence checks and recovery.

What evidence can administrators retain? +

Define audit requirements without collecting prompt content by default.