Private by
architecture,
not by promise.
AI iOS apps whose models run on your device. No accounts, no advertising, no tracking, and no server holding your work.
The apps are small on purpose. Each one does a single thing well, and none of them are built on the assumption that your data is the product.
If you are evaluating Cloister AI for a workplace, the trust page has the documents your procurement team will ask for.
Projects — 5
- 01
Cloister AI
Confidential AI, offline.
Coming soon iOS - 02
Auto Brightness Clock
A clock that dims itself.
TestFlight beta iOS - 03
Bilingual Baby
Coaches the parent, not the baby.
In development iOS - 04
Jesus — WWJD
Ask. Only your phone will hear.
In development iOS - 05
Best Dad
Year one, one week at a time.
In development iOS
Four decisions the claim rests on.
01
The device is the server
Models run on your phone. There is no inference endpoint to subpoena, no prompt log to leak, and no bill that scales with how much you use it.
02
No account
None of these apps ask who you are. No sign-up, no email, no identity to correlate. The data protection story is short because there is very little data.
03
Nothing sold, nothing tracked
No advertising, no ad identifiers, no data brokers, no cross-app tracking. Some of the apps make no network requests at all.
04
Say exactly what happens
Every app has its own privacy annex naming each thing that leaves the device, who receives it, and why. Where something does go out, we name it rather than round it down to zero.
For enterprise buyers
The whole compliance pack, published rather than requested.
Data Processing Addendum, subprocessor list, security overview and a per-app data-flow disclosure. No sales call, no NDA, no portal.
Open trust page →