← All posts

What “never leaves your machine” really means

A reply is one of the most private things you write all day. Here's exactly where your words go when BreatheReply helps you write one — and the two places they never go.

Think about what a reply actually is. It’s not a search query or a document draft. It’s you, talking to a specific person — your boss, your client, your partner, your mom. Often about something delicate. Almost never something you’d post publicly.

Now think about where most AI tools send that.

When you paste a private conversation into a cloud chatbot to “help me reply,” the message — the whole intimate context of it — travels to someone else’s server, gets processed there, and sits in logs you have no visibility into. You’re trading your most private words for convenience, and the trade is mostly invisible.

We didn’t want to build that.

Where your words actually go

With BreatheReply, the path is short and it stays close to home:

Your message → your device → the model you chose → the reply, back on your device.

That’s the whole journey. There are two places your words never go:

  1. They never go to BreatheReply’s servers. We don’t have a copy of your conversations because there’s nothing in our architecture that receives them. We don’t store your messages — not “we delete them after 30 days,” not “anonymized” — they simply never reach us.
  2. They never go anywhere you didn’t point them. You bring your own API key, and the app talks directly to that provider. Or you run a local model — Ollama, LM Studio, localhost:11434 — and the entire thing happens offline, with zero tokens leaving your machine at all.

Your key, your model, your call

“Bring your own key” is a phrase that gets thrown around, so let’s be concrete about what it means here. Your API key is encrypted and stored only on your device — never baked into the installer, never synced to us. The app is a courier between your conversations and a model you control. You’re the one holding the relationship; BreatheReply just makes it effortless.

And if even that feels like too much exposure, the local-model path removes the network entirely. A screenshot of a group chat, an offline model, a reply written with no internet involved whatsoever. That’s as private as typing it yourself — except the hesitation is gone.

Why this matters more for replies than for anything else

Privacy marketing is usually abstract. But replies aren’t abstract. The message you’d least want leaked is exactly the message you’d most want help with — the tense negotiation, the family friction, the thing you can’t say to your boss’s face.

A reply assistant that can’t be trusted with those is useless for the moments that matter most. So we built the trust first: your words reach no one but the model you chose, and the only way out is a path you picked yourself.

Reply calmly. And privately.