Legal
Privacy Policy
For Cinna Core, Cinna Desktop, and Cinna Mobile · Last updated 14 June 2026
In short: Cinna does not track you, does not show ads, and the OpenCinna project does not run servers that collect your personal data. The client apps (Desktop and Mobile) keep your settings, credentials, and conversation history on your device. Cinna Core is software you (or another hoster) run yourself — that hoster controls its data. The only data that leaves your device goes to the model providers, services, and instances you choose to connect.
This Privacy Policy explains how the Cinna software handles information. It is published by the open Cinna project (“OpenCinna”, the “Project”, “we”, “us”).
1. What this policy covers
The same policy applies across the Cinna products (together, the “Software”):
- Cinna Core — the open-source agent platform/backend that you or another operator self-host (a “CinnaCore instance”).
- Cinna Desktop — the desktop client application.
- Cinna Mobile — the mobile (iOS) client application.
The client applications (Cinna Desktop and Cinna Mobile, together the “Apps”) and Cinna Core differ in how data is handled, so sections below call out which component they apply to. This policy does not cover the third-party services you connect (see Section 5) or any CinnaCore instance operated by someone other than the Project (see Section 4).
2. Information we do not collect
The Project does not collect, sell, or share your personal information. Across the Software, we do not:
- Operate a central account service or backend that receives or stores your personal data.
- Embed third-party advertising networks or sell data to advertisers.
- Track you across other apps or websites.
Note: Cinna Core is software you run yourself. When you self-host it, you (or your hoster) — not the Project — determine what data it stores and how (see Section 4).
3. The client apps (Cinna Desktop & Cinna Mobile)
To function, the Apps store information locally on your device, such as:
- App settings and preferences.
- Connection details and credentials (for example API keys or server addresses) for the instances, backends, and AI model providers you choose to connect.
- Your agents, prompts, and conversation history.
This data remains on your device under your control. You can remove it at any time by clearing the app’s data or uninstalling the app. Where available, credentials are stored using the operating system’s secure storage (for example the iOS Keychain or the desktop OS keychain).
4. Cinna Core and CinnaAccount (self-hosted)
Cinna Core is open-source software run by whoever operates it (the “hoster”) — which may be you or a third party. A “CinnaAccount” is an account on a particular CinnaCore instance.
Each CinnaCore instance is controlled and operated by its hoster, not by the OpenCinna project. The Project does not operate these instances, has no access to their data or accounts, and is not the controller of any data stored on them. The data an instance collects or retains is determined by its hoster and its configuration. If you have a question, request, or complaint about an account or data on a specific CinnaCore instance, you must contact the operator (hoster) of that instance — not OpenCinna.
5. Third-party services you connect
Cinna lets you build and run your own AI agents. The Software lets you connect third-party services that you choose and configure, including:
- AI model providers — such as Anthropic, OpenAI, or Google, or any other model API or self-hosted model you set up.
- MCP (Model Context Protocol) services and other tools — external tools and integrations your agents call.
- CinnaCore instances — instances you connect to or sign in to with a CinnaAccount (see Section 4).
- Backends and servers — for example a Cinna backend you host yourself.
When you use these integrations, the Software sends the requests you initiate — such as prompts, content, and related context — directly to the provider or service you selected. These services are operated by third parties (or by you), not by the OpenCinna project, and any data sent to them is governed by their own privacy policies and terms — not this one. You are responsible for reviewing the privacy practices of each provider, model, MCP service, or instance you connect before using it. We do not receive or store a copy of that traffic.
6. Diagnostics and crash data
The Apps do not embed third-party analytics or tracking SDKs. For Cinna Mobile on iOS, if you have enabled Apple’s diagnostics sharing on your device, Apple may provide us with anonymized, aggregated crash and usage statistics through App Store Connect. This information is governed by Apple’s Privacy Policy, cannot be used to identify you, and you can control it in your device’s privacy settings. A self-hosted Cinna Core instance may generate its own logs, which are controlled by its hoster (see Section 4).
7. Children’s privacy
The Software is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
8. Data retention and deletion
The client apps store data locally, so we do not retain it on our side; clearing the app’s data or uninstalling it removes the data it stored on your device. Data held on a CinnaCore instance is retained and deleted according to that instance’s hoster and configuration. Data you previously sent to third-party providers is subject to those providers’ retention and deletion practices.
9. Security
We design the Apps to keep your data on your device and to use secure operating-system storage for sensitive values where available. No method of storage or transmission is completely secure, so we cannot guarantee absolute security, but we work to protect your information.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be reflected on this page.
11. Contact us
If you have questions about this Privacy Policy or how the Software handles data, contact us at support@opencinna.io.