Privacy

Why we built an AI that never phones home

The privacy manifesto behind Dhruva: zero telemetry, a downloads-only network, and an open codebase you can audit. Not a policy you're asked to trust, an architecture you can check.

Every mainstream AI chat app today works the same way: you type something, it leaves your phone, and it lands on someone else's server before you get an answer. That's true even for the "private" ones — private usually means "we promise not to look," not "we physically can't." Dhruva takes the second path. Inference runs on your device, on the model weights sitting in your device's storage, using your device's CPU and memory. There is no server in the loop to promise anything about, because there is no server in the loop.

What actually happens on your phone

When you send a message in Dhruva, it goes to a language model running as a local process on your device — the same way a calculator app runs a calculation locally. The weights file lives in your app's storage; the inference engine (llama.cpp, compiled into the app) loads it and generates a response using your phone's own compute. Nothing about that exchange is serialized, queued, or shipped anywhere. If you turn on airplane mode mid-conversation, nothing breaks.

The one network call that exists on purpose

Dhruva is not a hermetically sealed app — you need to get a model onto your device somehow. That's the one deliberate network path: browsing and downloading GGUF model files from Hugging Face, a request you initiate, for a file you chose, that you can inspect the URL of before it starts. No background sync, no "checking for updates" ping, no anonymous usage ID attached to the request. If you sideload a model file instead of downloading it through the app, that path works completely offline too.

What's deliberately absent

No analytics SDK. No crash reporter uploading stack traces with device fingerprints. No A/B testing framework, no remote feature flags, no "anonymous" usage metrics — anonymous telemetry is still telemetry. Firebase appears exactly once in this project, for distributing test builds to testers before release; it has no code path inside the shipped app that talks to it. If you're skeptical of that sentence — and you should be skeptical of sentences like that from any company — the entire codebase is public. Diff the network calls yourself, or point a proxy at the app and watch.

Why open source matters here specifically

A closed-source app asking you to trust its privacy claims is asking you to trust a company. Dhruva is Apache-2.0 licensed specifically so that claim doesn't have to be taken on faith. Every network call, every permission the app requests, every dependency it ships, is sitting in a public repository you can search. That's a stronger privacy guarantee than any policy document, because a policy document can change and a promise can be broken quietly — code you can read doesn't have that failure mode.

The name isn't a coincidence

Dhruva (ध्रुव) is the pole star — the fixed point that doesn't need a network of other stars to be found by. That's the whole design brief in one image: something reliable that works alone, visible only to the person navigating by it. An AI that needs your data on a server somewhere to function isn't that. One that runs entirely in your pocket is.

Made withby Ansh Singh Rajput