Checklist

What makes an AI assistant private? A checklist for iPhone

UPDATED 29 SEPTEMBER 2026 · 7 MIN READ · ORVENA LABS

If you are looking for a private AI assistant for iPhone, the hard part is that the word means three different things on app pages, and only one of them is something you can check yourself. Below are the three meanings, then seven checks that take a few minutes each and need nothing but the phone, with what you will see if you run them on Orvena.

Orvena is free for iPhone 15 Pro and newer. The model runs on the phone itself. Download

Three meanings of the same word

The first meaning is a policy. The model runs in a company's data center, and the company promises to delete conversations after a while, or not to train on them, or to encrypt them while stored. Plenty of companies keep these promises. They are still promises: they live in a document that can be edited, and they depend on every contractor and employee downstream doing what the document says.

The second meaning is a setting. The conversation still travels to the server to be answered, and a switch in the app limits what happens to it afterwards. Your words leave the phone either way; what changes is what the company agrees to do with them once they have arrived.

The third meaning is an architecture. The model runs on your own device, so the conversation has nowhere else to go. Whether your words stay with you stops being a question about behaviour and becomes a question about capability: software cannot send what it never transmits. Orvena is built this way, and it is what "private by architecture" means at the top of our homepage.

None of the three is dishonest. They are different products, and app pages rarely say which one they are describing. The checks below tell you.

Seven checks for a private AI assistant on your iPhone

1. Turn on airplane mode and ask something

Everything else depends on where the model runs, and this settles it in ten seconds. If the assistant answers a real question with the radios off, the model is on the phone. If it apologizes about the connection, it is not, whatever the page said. Orvena keeps answering with its own model or Apple Intelligence, and its calendar, reminder, alarm and photo tools keep working; only web search, opening web pages, weather, place lookups and connected services stop, because those need the outside world. Private Cloud Compute and cloud models need a connection too, if you chose one.

2. Open App Privacy Report

iOS can keep a log for you. Go to Settings, then Privacy & Security, then App Privacy Report, and tap Turn On App Privacy Report; from then on, for every app it lists which internet domains the app contacted in the last seven days, and how often it used the microphone, camera, location, photos and contacts. This is the closest thing to a network monitor that needs no technical knowledge, and it works on any assistant from any company.

What you should see for Orvena: the model download hosts (models.orvena.app, or huggingface.co as a fallback) while the model and voices download; Apple's weather service if you keep weather on the Today page; duckduckgo.com on the days you asked for current information; any site you asked it to open; and openrouter.ai once a day when you open the Models page (Orvena refreshes OpenRouter's public model list) and whenever you use a cloud key. If you choose Private Cloud Compute, each answer also goes to Apple's servers. iOS also keeps an Apple Intelligence Report on the same Privacy & Security screen; Apple says "You can generate a report of requests your iPhone has sent to Private Cloud Compute." There is no analytics or crash-reporting domain, because there is no analytics or crash-reporting SDK in the app.

3. Look for the account

An account attaches an identity to every request. Most cloud services ask for one, because someone has to be billed or rate-limited for each message. A model on your phone has nothing to bill per message, so an account would exist only to identify you. Look at the first screen after install. Orvena has no account and no sign-in, and no Orvena server that holds user data for one to live on.

4. Read the permission prompts

When an iPhone app asks for your microphone, calendar or health data, iOS shows the reason the developer wrote. Read it; vague reasons are a signal. Orvena's microphone prompt says: "Orvena listens only during an active voice conversation. The system microphone indicator shows whenever the mic is in use." Its Health prompt says it reads activity and sleep on this iPhone and "asks before a requested result is sent to a cloud or live voice provider." Each permission is requested the first time it is needed, not all at once on launch.

5. Does it ask before your data leaves, and name where it is going?

Most useful assistants send something somewhere eventually: a search query to a search engine, a request to a cloud model. The question is whether the app stops and tells you, at that moment, what is being sent and to whom. In Orvena, an action that needs your approval shows a card that states where it runs: either "Runs on this iPhone. Nothing leaves your device." or "Sends the data needed for this action to" a named service. Before the first request in a conversation to a cloud model on your own key, a sheet headed "Before anything is sent" asks whether to send this conversation and its tool results to that provider, with Allow for this conversation, Allow once or Always allow. Private Cloud Compute asks once instead, when you choose it on the Models page: "Each answer sends your conversation, and the tool results it needs, to Apple's servers. Apple doesn't keep them. Health and financial data still ask every time." If the conversation contains health or financial data, it asks again every single time; that consent cannot be saved.

6. Can you see afterwards what it did?

An assistant that acts on your phone should leave a trail. After it moves a meeting or sets an alarm, is there a record, and can you undo it? Orvena writes a card for every action, with an Undo button on the ones that can be reversed: calendar events, reminders, alarms and timers. Anything that deletes or cancels asks first, every time. A separate Activity screen keeps 30 days of what ran and where it went, and Settings has a Data sharing page where every saved consent can be revoked one by one.

7. Ask how the company makes money

Not a privacy property in itself, but it explains the incentives. A cloud model costs money on every message, and something has to cover that: a subscription, advertising, or your data. A model on your phone costs the company nothing per message. Orvena's assistant is free without limits, and a single $14.99 purchase covers voice, connections, scheduled tasks, Private Cloud Compute on iOS 27 and cloud models with your own key. There is no subscription because there is no per-message bill to pass on.

Then read the policy as a list

A privacy page written as paragraphs can be true and still leave out the part you care about. Look for a list: each category of data, whether it stays, and under which condition it leaves. Orvena publishes one on its homepage with twelve rows, from Your conversations (stays on device) to Cloud models (your key, your call), and its privacy policy is written the same way. Then compare it with the App Privacy section on the App Store page. The two should describe the same product.

Where your history lives

With an on-device assistant, the conversation history is a file on the phone, so it is worth knowing how that file is kept. Orvena stores it with iOS complete file protection, which means it is encrypted whenever the phone is locked, and excludes it from iCloud and computer backups. Deleting a conversation also revokes any consent you gave for that conversation. Deleting the app deletes the history, the model and the voices with it.

The tradeoff

A model that fits in a phone is smaller than one that fills a data center. For the things people mostly ask an assistant to do, moving a meeting, drafting a message, reading a photo, summarizing a page, the difference is hard to notice. For long research or a very specialized field it is real. Orvena handles this by keeping the choice with you: on iOS 27 you can choose Apple's Private Cloud Compute, or add a cloud model with your own API key, and the consent gates above apply to every request that would use it.

Common questions

Is on-device AI the same as end-to-end encryption?

No. End-to-end encryption protects data on its way to a server that still receives and processes it. On-device means there is no server in the conversation: the model answers on the phone, so there is nothing to encrypt in transit.

Can a private AI assistant still search the web?

Yes. When you ask for current information, Orvena sends the query to DuckDuckGo, the way a browser would. With its own model or Apple Intelligence it reads the results on the phone; with Private Cloud Compute the results go to Apple's servers with the rest of the answer. It happens because you asked, at that moment, and the search shows up in Activity. If the query would carry data from your calendar or another protected source, Orvena asks first.

Does a private AI assistant send my conversations to the company?

No. There is no Orvena account, and no Orvena server that receives your conversations. Conversations are answered on the iPhone, or by the cloud engine you chose, and are never transmitted to the company.

Check it yourself.

Orvena is free on the App Store for iPhone 15 Pro and newer. Its own model or Apple Intelligence answers on the phone, so airplane mode is a fair test.

Download on the App Store