Private by architecture

What makes an AI assistant private? A checklist you can verify

3 SEPTEMBER 2026 · 6 MIN READ · ORVENA LABS

"Private AI" is on a lot of app pages now. The phrase is doing three different jobs, and only one of them is something you can check yourself.

Orvena is free for iPhone 15 Pro and newer. The model runs on the phone itself. Download

Three things "private" can mean

The first meaning is a policy. The model runs in a company's data center, and the company promises to delete your conversations after a period, or not to train on them, or to keep them encrypted at rest. These promises are often real and often kept. They are still promises. They live in a document that can change, and they depend on every contractor and every employee downstream doing the right thing.

The second meaning is a setting. Your conversations still travel to the server to be answered, but a switch limits what happens to them afterwards. This is the first meaning with a toggle. The data still leaves; what changes is what the company agrees to do with it once it has arrived.

The third meaning is an architecture. The model runs on your own device, so the conversation has nowhere else to go. Privacy stops being a description of behaviour and becomes a description of capability: the software cannot send what it never transmits. Orvena is built this way, and this is the meaning we have in mind when we say private by architecture.

None of these meanings is dishonest. But they are not interchangeable, and app pages rarely say which one they mean.

A checklist you can verify on your own phone

You do not need to read source code. Each item below comes with a check that takes a minute or less.

1. Where does the model run?

This is the question the others depend on. Turn on airplane mode and ask something. If the assistant answers, the model is on the phone. If it apologises about the connection, it is not. Orvena answers: its model, Qwen 3.5 4B, is downloaded once and runs on the iPhone's own chip.

2. Do you need an account?

An account attaches an identity to every request. Sometimes there is a good reason for one; a cloud model has to know whom to bill. On an assistant that runs locally there is nothing to bill per message, so an account would exist only to identify you. Look at the first screen after install. Orvena has no account and no Orvena server for one to live on.

3. What leaves the phone, and when?

Almost every useful assistant sends something somewhere at some point. A web search goes to a search engine. A weather question goes to a weather service. The question is whether the app tells you the complete list. Look for an enumeration, not a paragraph. Orvena publishes a ledger on its homepage: every category of data, whether it stays, and under what condition it leaves. Its privacy policy reads the same way, as an inventory.

4. Does protected data leave only with your knowledge?

Calendar, health, photos, contacts. When an assistant reads these on your behalf, the important question is what happens if a later step would send them off the phone, for example to a cloud model you chose to connect. Does the app ask, naming the destination, at that moment? Orvena shows a consent gate that names the provider before any protected data leaves, and health data can only ever be approved for the current request.

5. Can you see what it did?

An assistant that acts on your phone should leave a trail you can read. After it moves a meeting or sets an alarm, is there a receipt, and can you undo it? Orvena writes a receipt for every action and asks before anything consequential runs.

6. What does the App Store label say?

Every app has an App Privacy section on its store page. Read it alongside the privacy policy. If the label lists collection the marketing never mentions, you have your answer. The label should match the ledger.

7. How does the company make money?

Not a privacy property, but it explains incentives. A cloud model costs money for every message, and something has to pay for that. A model on your phone costs the company nothing per message. Orvena's assistant is free without limits, and one purchase unlocks the extras. There is no subscription because there is no per-message bill to pass on.

The tradeoff, stated plainly

A model that fits in a phone is smaller than one that fills a data center. For everyday requests, moving meetings, drafting a message, reading a photo, summarising a page, the difference is hard to notice. For long research or very specialised knowledge, it is real. Orvena's answer is to keep the choice yours: you can add a cloud model with your own API key, and the app asks for consent per provider and again before sensitive history would leave. The default stays local. Leaving it is a decision, not a surprise.

The two-minute test

Install the assistant. Turn on airplane mode. Ask it something. Then read its ledger or policy and see whether it is a list. Those two steps separate the three meanings of "private" faster than any comparison chart.

Common questions

Is on-device AI the same as end-to-end encryption?

No. End-to-end encryption protects data on its way to a server that still receives and processes it. On-device means there is no server in the conversation at all.

Can a private assistant still search the web?

Yes. When you ask for current information, the query goes to the search provider, as it would from a browser. The difference is that it happens because you asked, in that moment, and the app tells you.

Does Orvena send conversations to Orvena?

No. There is no Orvena server and no Orvena account. The company cannot read conversations because they are never transmitted to it.

Try the architecture, not the promise.

Orvena is free on the App Store for iPhone 15 Pro and newer. The model downloads once and runs on the phone.

Download on the App Store