Your voice stays on your phone.
This is the same privacy policy the WANDA app shows you. It reflects how the app is actually built, not a generic template.
Wanda AI is a voice and chat assistant that runs its speech processing entirely on your device and connects to an AI agent server that you choose and configure. This policy explains what we collect, what we do not, and what leaves your phone.
The short version
- Your voice is never uploaded. Speech recognition and speech synthesis both run on your device.
- We do not sell your data, show ads, or use your conversations to train models.
- Your conversations are sent to the agent server you paired with. We do not operate that server unless you were told otherwise.
What we collect
Account information. When you create an account we store your email address, your display name if you provide one, and an account identifier. Sign in with Google or Apple gives us the same fields from that provider. Accounts are handled by Firebase Authentication, operated by Google. If you sign in with Apple and choose to hide your email, we only ever see Apple's relay address.
Connection settings. The address of the agent server you pair with and the access token you enter are stored in your device's encrypted storage. They are kept separately for each account signed in on the device, and they are never transmitted to us.
Diagnostic logs. The app keeps a short, rolling log in memory to power the in-app Connection Debug screen. It stays on your device and is cleared when the app closes.
What we do not collect
- Audio. Microphone audio is processed on your device and discarded. No recording is stored or transmitted.
- Voice transcripts. Text produced from your speech goes only where your typed messages go: to the agent server you configured.
- Contacts, location, photos, or advertising identifiers. The app does not request them.
How your speech is handled
Speech recognition and text-to-speech both use models bundled inside the app and run in the background on your phone's processor. This works with no network connection, and audio never reaches us or any third party.
The app needs microphone access to listen when you start a voice turn. If you enable the optional wake word, the microphone stays active while the app is open so it can detect that phrase — the audio is still processed only on your device. You can turn the wake word off, or deny microphone permission entirely and use the app by typing.
Your conversations and the agent server
Wanda is a client. The messages you send, and the replies you receive, travel to and from an AI agent server whose address and credentials you supply during setup. That server is operated by you or by whoever gave you the connection details.
What happens to your conversations on that server is governed by the operator of that server, not by this policy. If your organisation provided the address, ask them what they retain. If the server forwards your messages to a third-party AI model provider, that provider's terms apply to the forwarded content.
The app also keeps a local copy of your conversations on your device so history loads quickly and remains readable offline.
Service providers
- Google Firebase — authentication, remote configuration, and the storage holding this document.
Firebase processes data under Google's privacy policy. We use no analytics, crash-reporting, or advertising SDKs.
Your choices
- Clear chat history in Settings deletes your conversations from your device and asks the agent server to delete its copies.
- Unpair this device in Settings removes the stored server address and token.
- Delete your account in Settings permanently deletes your account and erases the app's data on this device. See Deleting your account below.
- Uninstalling the app removes everything stored on the device, including your local history, credentials, and settings. It does not delete your account.
Deleting your account
You can delete your account at any time from Settings → Account → Delete account. You do not need to contact us to do it.
Deletion is immediate and permanent. There is no grace period, no recovery window, and no way to restore the account afterwards.
What is deleted from our systems. Your Firebase Authentication record — the email address, the display name if you gave one, the Google or Apple link if you used one, and the account identifier. That record is the only information about you that we hold: we do not operate a database of your conversations, profile, or usage.
What is erased from your phone at the same time:
- your cached conversation history
- the agent server address, access token, and device token stored for the account
- every app setting on this device, including tone, voice, wake phrase, speech rate, and text size
- the trust the app had recorded for your agent server's certificate
- the signed-in Google session, if you used Google to sign in
You are then signed out and returned to the sign-in screen.
What is not deleted. Conversations held on the agent server you paired with are not affected. That server belongs to you, or to whoever gave you the connection details, and we cannot reach it. If you want that history removed, use Clear chat history in Settings before deleting your account, or ask the operator of that server.
If you are asked to sign in again. For security, deletion can require a recent sign-in. When that happens the app signs you out and asks you to sign in and try again. Nothing is erased unless the account is actually deleted, so a cancelled or failed attempt leaves your data intact.
Children
Wanda is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will remove it.
Security
Credentials are held in the platform's encrypted storage — the Android Keystore or the iOS Keychain. Traffic to your agent server uses the transport you configure; where that server presents a self-signed certificate, the app trusts it only for the exact host you paired with, and never for any other.
No system is perfectly secure, and we cannot guarantee the security of a server we do not operate.
Changes
We may update this policy. The version and the date it was last updated are shown at the bottom of this screen, and material changes will be announced in the app.
Version 1.0 · Last updated August 2026