This privacy notice explains what the ternii app and the ternii.com website do — and do not do — with information about you. It is written to be read. Middletech Limited, a company registered in England and Wales (company number 16955822) with its registered office at 55 Colmore Row, Birmingham, England, B3 2AA ("Middletech", "we", "us") is the data controller for any personal data described here. Contact: [email protected].
The ternii app has no accounts, so it never asks for your name, email address, phone number or a profile. (The one exception is if you choose to buy a Founding Membership on the website — that is described in section 6a.) The app contains no advertising, analytics, crash-reporting or push-notification SDKs, uses no advertising identifiers, and does not build a behavioural profile. There is no "phone home": the app never checks in with us, and nothing about how you use it is reported to us. Your conversations, notes, documents, photos and voice are processed on your device and are not transmitted to Middletech.
How it is protected. On Android, conversations, imports and settings are encrypted at rest with a key held in the device's hardware Keystore, and the app is excluded from Android cloud backup and device-to-device transfer. On iOS, conversations and imports are stored with iOS file protection; passwords and API keys are kept in the iOS Keychain, marked this device only so they are never synchronised to iCloud; other settings are stored in the app's standard preferences. Files you deliberately export (for example a PDF or CSV you share) are written unencrypted so that other apps can open them. Your phone's own backup (for example an iCloud backup) may include app data according to your device settings.
Deleting it. You can clear all conversations, clear your notes vault, remove each connected tool's details, and delete downloaded models from within the app. Uninstalling the app removes everything it stored.
ternii is offline by default. The features below use the internet. Each is opt-in: web features require the Online switch (off by default) and, for actions taken by the assistant, a consent prompt before each one. Only the item in the "what is sent" column leaves the device — never your conversation, notes or files, unless the row says so.
| Feature | Who receives it | What is sent | When |
|---|---|---|---|
| Downloading a model or expert pack | Our content host (files served through Cloudflare) | A plain download request. The host sees your IP address, the time, and which file you asked for. No identifier, no content. | Only when you open Model setup / Browse and choose a download. |
| Web search | Wikipedia; Hacker News (via Algolia); Stack Exchange | Your search query text. | Only with Online on, and when you tap "Search the web" or approve a search in a consent prompt. |
| Opening a web page for the assistant to read | The website at the address you (or the assistant, with your approval) give | A page request to that site. | Only with Online on and after a consent prompt. |
| Weather | Open-Meteo | The city name you configured, then its coordinates. | Only with Online on and a city set. |
| News | BBC News RSS by default, or the feed address you set | A request for that feed. | Only with Online on and a feed set. |
| Market check | Yahoo Finance | The ticker symbols on your watchlist. | Only with Online on and a watchlist set. |
| Email inbox summary | Your own mail server (the address you enter) | Your login for that server, over an encrypted (TLS) connection; the app reads message headers (sender, subject, date) only. It never reads message bodies and never sends mail. | Only if you set up the email tool. |
| Optional external AI server (advanced) | A server you configure — there is no default provider | The full prompt: your question and the context the app assembled for it. This is the only feature that sends conversation content off the device. | Only if you turn it on and enter a server address. Answers from it are marked with a cloud badge. |
| Voice input on Android | Your phone's speech-recognition service (usually Google's) | Your voice, if the phone has no on-device recognition. ternii asks the system to prefer on-device recognition and shows you a one-time notice stating which applies on your phone before the first use. | Only when you tap the microphone. |
| Voice input on iPhone | Nobody | Nothing — ternii requires Apple's on-device recognition and refuses to dictate if it is unavailable, rather than using a server. | — |
Wikipedia, Algolia, Stack Exchange, Open-Meteo, the BBC, Yahoo and your mail or AI provider each process the request they receive under their own privacy policies; they receive it directly from your phone, not through us. Reading text from photos and documents happens entirely on the device (Google's ML Kit text recogniser bundled inside the Android app; Apple's Vision framework on iPhone) — no image ever leaves your phone. Routines that run on a schedule use the same tools with the same switches, and only ever show you a notification on the device.
| Permission | Why ternii asks |
|---|---|
| Calendar (read) | To answer "what's on today?". Creating an event opens your calendar app's own editor for you to save — ternii does not write to your calendar itself. |
| Contacts (read) | To look up a name, number or email when you ask. Read-only. |
| Reminders (iPhone) | To read your reminders and, when you confirm, create one. |
| Photos | To read text from a photo you choose, on the device. |
| Microphone & speech recognition | Only while you dictate. Nothing is recorded or stored. |
| Notifications | To show the result of a routine you scheduled. |
| Alarms | To set an alarm or timer you ask for, via your Clock app. ternii never reads or changes your other alarms. |
| Internet | Only for the features in section 3. |
ternii does not request your location (weather works from a city name you type), camera, health data, SMS, or access to your files beyond what you attach. Sending an email or text message, dialling a number, or opening a map always hands over to the relevant app with the details pre-filled — you decide whether to send.
ternii.com runs no analytics, no advertising and no tracking of any kind, and sets no cookie at all unless you sign in to the members' area. When you do sign in, we set one strictly-necessary cookie, ternii_session — it holds nothing but a random session identifier, is HttpOnly, Secure and SameSite=Lax, lasts 30 days, and exists only to keep you signed in. It is not used for analytics or advertising, and no consent banner is required for it. Signing out deletes it. The rest of the site is served statically by Cloudflare. Cloudflare processes basic technical logs (such as IP address and request time) to deliver and protect the pages. The site loads its typefaces from Google Fonts, which means your browser requests font files from Google's servers under Google's privacy policy. The expert-request and feedback forms open your own email app with a pre-filled message. The organisation, collaboration and investor enquiry form is different: it submits what you type (your organisation, name, email and message, with your consent) to our site, which stores it on Cloudflare (D1, EU/UK-region best effort), emails it to us through Resend and sends you an acknowledgement; we keep a hashed form of your IP address for one hour only to limit abuse, and we keep enquiries for as long as we are in conversation with you and then up to two years. Lawful basis: our legitimate interest in answering an enquiry you chose to send. You can ask us to delete an enquiry at any time. Videos on the site load from Cloudflare only when you press play, and the Founding Membership payment page is hosted by Stripe on its own domain, where Stripe sets its own cookies under its own policy.
What the Founding Members form keeps on your device. As you fill in the join form on the home page, your browser saves what you have typed so far so that it survives a reload: the tier you picked (£10 or £50), any extra amount, and the name or message you typed. It is stored by your own browser under the key ternii.founders.v3 in localStorage — on your device only. It is never sent to us except when you press the payment button, and the two consent tick-boxes are deliberately not saved, so they always start unticked. It stays there until you clear it, which is entirely in your control: the button below does it, and so does clearing site data for ternii.com in your browser's settings. On a shared or public computer, please use it — otherwise the next person to open the page sees what you typed, and that may be somebody else's name.
This clears only what ternii.com stored in this browser (every key whose name begins ternii, and the session cookie if you are signed in). It does not touch your membership record, your roll number or your certificate, and it does not sign anything out anywhere else.
If you email us — a bug report, a request for a new expert pack, feedback, or a data-protection request — we keep your message and email address for as long as needed to deal with it and for a reasonable period afterwards for our records. We do not add you to any mailing list. The app's "Report a problem" button simply opens your email app with a subject line; it attaches nothing.
This section applies if you buy a Founding Membership through ternii.com. It is the one situation in which we hold personal data about you by name, so it is set out in full. The membership itself is described in section 6a of our terms.
We do not sell this data, use it for advertising, or add you to any mailing list other than the members' site's own updates, which you can turn off there.
If you asked for it, your name or message appears on the published Founding Roll on ternii.com. A fingerprint of the roll — a cryptographic hash of its contents, not the names themselves — may be written into the model files we ship. If you opted in, your name or message may be included in the data used to train future ternii models, and those models may then reproduce it. If you withdraw either choice, your name is removed from the next published version of the roll and from the training data of any model trained after we receive your request. It cannot be removed from model files we have already shipped.
Your certificate and the registry. Once your name or message has been approved, we issue a signed certificate for your entry and record it in our certificate registry. The registry entry holds your certificate number, your roll number, a fingerprint of your entry, the roll's version and fingerprint, the model release it is bound to, whether your entry was included in training, its status, and the display text (your name or message) only if you chose to publish it on the roll — never your email address, payment details or anything else about you. Anyone with a certificate number can look it up at ternii.com/founders/verify; that is the point of it. If you withdraw your name or message, the display text is removed from the registry and the certificate is marked withdrawn. If you correct it, a corrected certificate is issued with the next roll version.
The public anchor. For each version of the roll we publicly anchor a fingerprint of that roll version — a cryptographic hash, not the names — so that anyone can check later that the roll existed in that form at that time. The anchor holds no personal data, and it cannot be changed once written; because it contains no name, that does not affect your rights over your data.
We keep membership records for the life of the membership and for six years after it ends, because tax law requires us to keep payment records for that long. Anything you posted on the members' site is deleted when the membership ends, or earlier if you ask. The certificate registry keeps a certificate marked withdrawn, without the display text, so that its number cannot be reused and a copy of it can still be checked. The public anchor, a fingerprint of each roll version with no personal data, is permanent. A token you asked for is permanent, as explained above.
Everything in section 8 applies. You can ask us for a copy of the data we hold about you, to correct it, or to delete it; you can withdraw either consent at any time; and you can complain to the Information Commissioner's Office. Asking us to delete your data ends the membership; we then keep only the payment record the law requires. Deletion and withdrawal reach everything we hold and everything we publish or train in future — including the display text in the certificate registry — but not model files already shipped, the anchored fingerprint of an earlier roll version (which contains no name), or a token you asked for.
We process the personal data you send us on the basis of our legitimate interest in responding to you, or your consent where you ask us to do something. Any personal data you place in the app is held on your device under your control and is not processed by us. Download logs on our content host are short-term operational records kept by the hosting provider for security and delivery. Our hosting provider (Cloudflare) operates globally; where data leaves the UK it is protected by the provider's standard contractual safeguards. Founding Membership data has its own bases, processors and retention periods, set out in section 6a.
Under UK data-protection law (the UK GDPR and the Data Protection Act 2018) you can ask us to access, correct or delete personal data we hold about you, to restrict or object to its processing, or to receive it in a portable form; where processing relies on consent you can withdraw it at any time. Write to [email protected]. You also have the right to complain to the Information Commissioner's Office (ico.org.uk). Because the app keeps your content only on your device, you are in direct control of it and can delete it yourself at any time.
ternii is not directed at children under 13, and you must be at least 13 to use it. We do not knowingly collect personal data from children; since the app collects nothing about its users, there is nothing for us to hold. A Founding Membership (section 6a) is a contract with an adult: the person paying must be 18 or over. The name on the Founding Roll can be a child's — as a gift — only where the paying adult gives a parent's or guardian's consent for it; that consent, and the choices made with it, are the payer's responsibility. The assistant contains safety filters that refuse harmful requests.
If ternii gains a feature that changes what leaves your device, this notice will be updated before that feature ships, with a new "last updated" date and version at the top. Material changes will also be pointed out in the app's release notes.
Middletech Limited, a company registered in England and Wales (company number 16955822) with its registered office at 55 Colmore Row, Birmingham, England, B3 2AA.
Email: [email protected].