Local Waifu is a local-first desktop application for macOS and Windows. The short version: nothing about your conversations, characters, or use of the app leaves your computer unless you explicitly turn on a feature that requires it. There is no "Local Waifu cloud", no account, no analytics endpoint, no telemetry.
One honest note before the details: conversations with a companion tend to contain intimate things. That is exactly why the app keeps them on your device by default, and why every feature below that sends anything anywhere is opt-in and named explicitly. If a feature is not listed here, it does not phone home.
1. Data controller
The controller of any personal data processed in connection with the app and this website is:
Łukasz Blania prowadzący działalność gospodarczą pod firmą
Lumi Zone Łukasz Blania
ul. Zabrska 15, 40-083 Katowice, Poland
NIP: 1990132289
Email: contact@localwaifu.com
We are a small business and have not appointed a Data Protection Officer (DPO), Art. 37 GDPR does not require us to. For any privacy-related matter, contact us directly at the address above.
2. What stays on your computer
Everything by default.
- Conversations, characters, memories, knowledge graph, mood,
relationship XP live in
~/Library/Application Support/com.lumizone.localwaifu/on macOS and in the app's data folder inside your user profile on Windows. Soul files are encrypted with ChaCha20-Poly1305 using a key derived from your passphrase + your device's hardware identifier + a per-install random salt. - The local LLM (bundled Ollama) runs on your CPU/GPU. Prompts and replies never leave the process.
- Photos you share with her are analyzed on-device (on macOS via Apple's Vision framework). Nothing is uploaded unless you have selected a cloud model (see section 3).
- Images she draws for you are generated locally on your device, unless you have configured a cloud image provider (see section 3).
- Voice: her speech is synthesized on-device, your voice messages are transcribed on-device (Whisper), and any voice clone you create is built from your recording and stored on your device only. Your voice never leaves your computer.
3. What leaves your computer (only with your action)
- Model & engine downloads. When you first set her up,
the app downloads the AI model files she runs on from public
registries (Ollama's registry; Hugging Face for models you install
through the in-app model browser and for the image, speech, and
transcription models). The optional voice features additionally
install their open-source engines on demand: the
uvinstaller fromastral.shand packages from PyPI. These are one-way downloads of public files; nothing about you or your conversations is sent with the request beyond standard HTTP metadata (your IP, as with any download). - Cloud chat / image generation (your own account), if
you connect a cloud provider in Settings, the app forwards your prompts
(which can include your messages and photos you attach) to that
provider whenever you select one of its models. Supported providers:
OpenAI (via API key, or via "Sign in with ChatGPT", an OAuth flow with
auth.openai.comafter which chat requests go to OpenAI's servers), Anthropic, DeepSeek, Google, Mistral, Groq, OpenRouter, fal.ai, and any custom OpenAI-compatible endpoint you configure yourself. The provider sees the prompt; we never see your API key or sign-in token (they are stored in your device's secure credential storage, e.g. the macOS Keychain). We do not proxy these calls, and each provider processes them under its own privacy policy. - Calendar / Reminders / iMessage tools (macOS), if enabled, the LLM reads your local data via Apple EventKit / SQLite. Nothing is uploaded; the read happens on-device and the result is fed back into the local prompt context.
- Web search, if invoked, sends a search query to
DuckDuckGo (
duckduckgo.com) and parses the HTML response. - Weather, if she checks the weather for you, the app
sends the coordinates of the location you configured (never your GPS
position; the app does not access location services) to the free
Open-Meteo API (
api.open-meteo.com). No key, no account, nothing else. - Home Assistant MCP, if enabled with
LW_HA_URLandLW_HA_TOKENenv vars set, the app talks to your HA instance. - Telegram bridge, if enabled, the app long-polls Telegram's Bot API, and your messages to your bot pass through Telegram's servers under Telegram's privacy policy.
- Update check. On macOS the app checks
github.com/lumizone/local-waifu/releases/latest/download/latest.jsonon launch; on Windows it checks the GitHub Releases API (api.github.com) only when you press Check for updates in Settings. Either check is a public, unauthenticated GET; GitHub sees your IP as it does for any HTTPS request. - License validation, talks to Dodo Payments on first redeem and when you deactivate a device in Settings → License. There is no recurring background revalidation at this time.
4. Legal basis for processing (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)), license validation via Dodo Payments; processing your order; providing the app.
- Legitimate interest (Art. 6(1)(f)), operational server logs (Netlify) for security and abuse prevention; minimum data needed to keep the website running.
- Answering you (Art. 6(1)(b) or (f)), handling messages you send through the contact form or by email: we process the name, email address, topic, and message you provide, only to reply.
- Legitimate interest (Art. 6(1)(f)), anonymous, cookieless website analytics (self-hosted Umami): aggregated page-view counts with no cookies, no identifiers stored on your device, and no cross-site tracking. Because nothing is stored on or read from your device, the ePrivacy cookie-consent requirement does not apply, which is why this site shows no cookie banner. You can object at any time (section 8), and blocking the script changes nothing about how the site works.
- Legal obligation (Art. 6(1)(c)), keeping invoices and accounting records (issued by Dodo Payments as Merchant of Record on our behalf) for the period required by Polish tax law (6 years).
Data the app processes purely on your device (your conversations, photos, voice) is processed by you, for you; it never reaches us, so we are not processing it in the GDPR sense at all.
5. Recipients & processors
For features you turn on, we route data to the following third parties. Each operates under their own privacy policy.
- Dodo Payments, Inc. (USA), payment processing, Merchant of Record, license management. Receives your name, email, and payment details at checkout.
- Netlify, Inc. (USA), static hosting for this website. Sees standard HTTP request metadata (IP, user-agent).
- Umami, self-hosted on
analytics.darkdynasty.cloud(EU). Cookieless, anonymous page view counts. Loads only after consent. - GitHub, Inc. (USA), delivery of app installers (macOS and Windows) and update checks.
- Hugging Face, Inc. (USA), hosts the model files the app downloads (in-app model browser, image / speech / transcription models).
- Astral (astral.sh) and PyPI (USA), one-time download sources for the optional voice-feature engines. They see a standard download request, nothing more.
- Open-Meteo (EU), receives the coordinates of your configured location when the weather tool is used.
- Our own automation server (self-hosted n8n on
darkdynasty.cloud, EU, the same infrastructure that runs our analytics), receives contact-form submissions and routes them to our inbox. First-party infrastructure, not a third-party service. - Cloud AI providers you connect: OpenAI, Anthropic, DeepSeek, Google, Mistral, Groq, OpenRouter, fal.ai, or a custom endpoint you configure. Each receives only the prompts you send through it, under your own agreement with that provider. If you configure a custom endpoint, you choose the recipient, so check who runs it.
6. International data transfers
Some of our processors are based in the United States (Dodo Payments, Netlify, GitHub) or other non-EEA countries. Transfers to those countries are made on the basis of:
- Standard Contractual Clauses (SCCs) where applicable, and/or
- Certifications under the EU-US Data Privacy Framework.
Cloud AI calls you initiate with your own account (OpenAI / Anthropic / DeepSeek / Google / Mistral / Groq / OpenRouter / fal.ai / custom) are user-initiated transfers under Art. 49(1)(b) GDPR, necessary for the performance of the contract you have with that provider.
7. Retention periods
- Data on your computer, retained until you delete it
(Settings → Advanced → Reset all data; on macOS also by uninstalling
the app and removing
~/Library/Application Support/com.lumizone.localwaifu/; on Windows by ticking "Delete the application data" when uninstalling). - License key (with Dodo Payments), for the life of your license + 6 years afterward, to satisfy Polish accounting law.
- Netlify server logs, up to 30 days, then auto-rotated.
- Umami analytics, anonymous page view counts retained up to 365 days, then aggregated. No individual records.
- Email correspondence and contact-form messages, kept for as long as needed to handle your request, then deleted within 12 months.
8. Your rights (GDPR)
You have the following rights regarding your personal data:
- Access (Art. 15), request a copy of personal data we hold about you.
- Rectification (Art. 16), correct inaccurate data.
- Erasure / "right to be forgotten" (Art. 17).
- Restriction of processing (Art. 18).
- Data portability (Art. 20).
- Objection to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time, for processing based on consent (Art. 7(3)). Withdrawal does not affect lawfulness of prior processing.
- Lodge a complaint with the supervisory authority. In Poland: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, kancelaria@uodo.gov.pl. You may also contact the supervisory authority in your country of habitual residence.
To exercise any of these rights, email contact@localwaifu.com. We respond within 30 days (typically within a few business days).
Worth knowing: because your conversations never reach us, most requests about them are answered by the app itself, export and deletion are built-in (see section 13), and there is nothing on our side to hand over.
9. US state privacy rights
For residents of California (CCPA/CPRA) and other US states with consumer privacy laws (Virginia, Colorado, Connecticut, Texas, and others): we do not sell your personal information, do not "share" it for cross-context behavioral advertising, do not use it for targeted advertising, and do not profile you. We are a small business that most of these laws' thresholds do not even reach, but we honor access, deletion, correction, and portability requests from anyone, anywhere, at contact@localwaifu.com, and we will never discriminate against you for exercising a privacy right. This website sets no tracking cookies and loads no advertising or tracking scripts, so opt-out signals such as Global Privacy Control are honored by default: there is nothing to opt out of.
10. Adults only, children's data
Local Waifu is an adults-only product; our Terms require every user to be at least 18. We do not knowingly process personal data of anyone under 18, and in particular not of children under 16 (the default age of digital consent under GDPR Art. 8, which Poland applies) or under 13 (COPPA, USA). The app has no accounts, so the only personal data that could reach us is what is sent at checkout or by email; if you believe a minor has provided us with personal data, contact us and we will delete it.
11. Automated decision-making
We do not engage in automated decision-making or profiling that produces legal effects on you (GDPR Art. 22). The AI character's replies are not "decisions" within the meaning of Art. 22, and they are generated on your device, not on our servers.
12. Data breach notification
If we ever experience a personal data breach likely to result in a risk to your rights and freedoms, we will notify the supervisory authority (UODO) within 72 hours of becoming aware (GDPR Art. 33), and affected users without undue delay (Art. 34). Because your conversations are stored only on your device, a breach on our side cannot expose them.
13. About this website
localwaifu.com uses Umami (self-hosted in
the EU, cookieless) to count anonymous page views and download-button
clicks. The analytics script sets no cookies, stores no
identifiers on your device, does no fingerprinting and no cross-site
tracking, and its aggregated counts cannot be tied back to you. That is
why the site shows no cookie banner: there is nothing stored on your
device to consent to. If you block the script with a content blocker,
the site works exactly the same.
Standard Netlify server logs contain HTTP metadata (IP, user-agent, timestamp) for operational and security purposes. These are not used for advertising.
The site has one form: the contact form. It sends your name (optional), email, topic, and message to our own self-hosted automation server in the EU, which forwards them to our inbox. Used only to answer you; retention in section 7. There is no newsletter, and community links point to our Discord server, which operates under Discord's own privacy policy once you join.
14. Your data, your call
- Export, Settings → Characters → Export gives you a JSON file with the character profile, chat history, memories, and knowledge graph.
- Delete, Settings → Advanced → Reset all data wipes the
database, soul files, and voice clones. On Windows, ticking "Delete the
application data" during uninstall removes her files as well. Note:
Reset all data does NOT clear the entries in your system's secure
credential storage (license key, trial timer, cloud API keys and
sign-in tokens, Telegram bot token). On macOS, wipe those with
Keychain Access.app or
security delete-generic-password -s "com.lumizone.localwaifu"; on Windows, use Credential Manager. If you want every trace gone, email us and we will walk you through it for your platform.
15. Changes to this policy
We may update this policy. Material changes will be announced in the app's CHANGELOG and on the GitHub release notes. The "Last updated" date at the top reflects the most recent change.
16. Contact
Email contact@localwaifu.com for questions, deletion requests, or anything else GDPR-shaped.