Last Updated: September 1, 2026
Controller: FIHI LABS UG (haftungsbeschränkt) · support@zimmerapp.co
Zimmer is a local-first AI application. This policy covers Zimmer for macOS, Zimmer for Windows, Zimmer for Android, and Zimmer Server, the self-hosted deployment organisations run on their own hardware. Where platforms differ, the platform is explicitly named.
On every platform, all AI processing happens on your own hardware — your device, or your organisation's own Zimmer Server. We never receive, store, transmit, or train on:
This is an architectural property, not only a policy commitment: the application has no code path that transmits this content to us. Model downloads go directly from the source (for example, Hugging Face) to your device.
What we do receive is limited to accounts, billing, licensing, a small set of usage counters on your account, and — where you have switched it on — anonymous performance telemetry. Each of those is itemised in section 2.
We do not sell your data. We do not train models on your data. We do not log your conversations.
Accounts are handled by Google Firebase Authentication, which stores your email address, a unique user identifier, whether your email is verified, and authentication metadata such as sign-in timestamps.
An account on one platform is not automatically the same account on another. They are linked only if you explicitly connect them.
Alongside your account we store which desktop operating system you last opened Zimmer on (mac or windows), the app version, and the time of that launch, so we can tell which builds are in use and support them. This is a single label per account, not a device history.
Zimmer for Android offers a seven-day free trial and a one-time Zimmer Lifetime purchase. To manage access, our entitlement service stores, against your account identifier only:
We do not store your email address alongside purchase data.
Payments are processed entirely by Google Play (Android) or Stripe (desktop and Zimmer Server). We never see or store your card number or bank details. We receive only confirmation that a purchase occurred, the organisation name and billing email given at checkout, plus refund and cancellation notices.
First-party analytics record sessions, page views, clicks, referral source, UTM campaign fields, device category, and coarse country. They do not record raw IP addresses, raw referral codes, prompts, files, emails, or in-app activity. Retained for 180 days. Do Not Track browser signals are respected. Analytics do not run on the account-deletion page.
Opt-in only. Stack traces and hardware specifications; never prompts, content, or code.
Zimmer Server runs on your own hardware. Your models, prompts, documents, chat history, and search indexes stay on that machine and are never transmitted to us — there is no code path that would send them.
Two things do reach us, and nothing else:
Nothing about the people who enrol devices against your server ever reaches us. Their names, emails, devices, and activity exist only in your own server's directory, under your control. Air-gapped deployments using an offline signed licence file transmit nothing at all. The exact field list is published in our Licensing Payload Disclosure.
If your organisation runs Zimmer Server, connecting the desktop app to it asks for your name, work email, and a device name. Those details go to your employer's server, not to us. They are recorded in your organisation's own directory so an administrator can identify your device, and Zimmer receives no part of them.
Enrolling this way creates no Zimmer account. Sessions connected to a company workspace make no calls to our consumer services at all — no account records, no subscription records, no usage counters, and no telemetry.
Off unless you turn it on in Settings. When enabled, Zimmer sends anonymous performance summaries keyed to a random device identifier that is never linked to your account: model names, generation counts and speeds, context sizes, failure counts, and error categories. It never includes prompts, responses, file names, or any content. Sessions connected to a company workspace never send it, regardless of the setting.
Separately from the opt-in telemetry above, and unlike it, we keep a small set of usage counters on your account. We use them to run the service: to see which builds are actually in use, to know whether a release has broken something, to plan capacity, and to understand how much Zimmer is used overall. This is the only in-app measurement that is linked to your identity, which is why it is described separately rather than folded into section 2.8.
Stored under your user account, and nothing else:
These are numbers, not a record of what you did. There is no event log, no history of which screens or features you opened, no timestamps of individual actions, and — as everywhere else in Zimmer — no prompts, responses, file names, model names, or content of any kind. Knowing that you sent forty turns tells us nothing about what any of them said, and we have no way to find out.
They are sent at most every 30 minutes while you are signed in and using the app, and once when you quit. They are not controlled by the "Share anonymous performance data" setting, because they are not anonymous performance data — that setting governs section 2.8 only. These counters are part of operating an account-based service, and we rely on our legitimate interest in running Zimmer reliably to keep them. Sessions connected to a company workspace send none of it: enterprise sessions have no Zimmer account to attach it to.
Deleting your account deletes these counters along with everything else, including the per-day records. See section 4.
When you send feedback or a bug report from within Zimmer, you can tick "Include diagnostics" to attach a summary of what your local models did during that session: model names, how many times they ran, their speeds, context sizes, and error categories. The box shows you exactly what will be sent before you send it, and unticking it sends nothing.
Because a bug report needs a reply, this attachment is stored alongside your report and your email address. That is the difference between it and section 2.8, where the same kind of measurement is deliberately kept anonymous. It is never copied into the anonymous telemetry records, and those records are never linked back to you. It still contains no prompts, responses, or file contents.
When you use the Model Context Protocol (MCP) to connect to external services (like Notion, GitHub, or Linear), Zimmer acts as a secure local bridge. Your API keys and OAuth tokens are stored in the macOS System Keychain. Zimmer retrieves these only at runtime and never transmits them to our servers. Connections to third-party APIs are established directly from your machine and are not proxied.
We will never sell your data. We will never train models on your data. We will never implement cloud-based logging for your prompts. Your intelligence is your own.
Your AI content stays on your own hardware and is never transmitted, so it is not stored anywhere by us.
The limited account and entitlement data described above is processed by Google Cloud on our behalf:
| Data | Location |
|---|---|
| Android entitlement records, processing, and signing keys | Frankfurt, Germany (europe-west3) |
| Desktop account, subscription, and usage-counter records (Firestore) | United States (multi-region) |
| Zimmer Server licence, pilot registration, and check-in records | Frankfurt, Germany (europe-west3) |
| Firebase Authentication | Operated globally by Google |
Because macOS account records and Firebase Authentication involve storage or processing outside the EU, using Zimmer on macOS involves an international transfer of that limited account data. Google Cloud provides Standard Contractual Clauses for such transfers.
| Record | Retention |
|---|---|
| Account and entitlement records | Until you delete your account |
| Registered device keys | Until you delete your account |
| Service usage counters, including per-day records (§2.9) | Until you delete your account |
| Feedback and bug reports, with any diagnostics you attached (§2.10) | Your email and account identifier are removed when you delete your account; the report text is kept unlinked |
| Purchase records | Retained after deletion in pseudonymised form (see §5) |
| Operational logs | 30 days |
| Security audit logs | 400 days |
| Website analytics | 180 days |
| Zimmer Server licence and pilot registration records | For the life of the licence, then 24 months |
Android: Settings → Delete account. We delete your Firebase identity, your account record, your registered devices, and your entitlement record. Your on-device conversations are then deleted from your device with your confirmation.
You can also delete only your on-device data ("Delete local data from this device") without deleting your account. Signing out does not delete anything: it makes local conversations inaccessible until the same account signs in again. Detailed instructions and request forms are available on our Data Deletion Page.
macOS and Windows: Delete the application and its support folder (~/Library/Application Support/Zimmer on macOS, %APPDATA%\\Zimmer on Windows).
Either platform, without opening the app: email support@zimmerapp.co. Please do not include passwords, conversations, prompts, recordings, attachments, or purchase tokens in that email—we do not need them.
What we keep after deletion: If you purchased Zimmer Lifetime, we retain a pseudonymised record of that purchase—your account identifier is replaced with a one-way derived value. We keep it so Google Play / Stripe refunds, chargebacks, and cancellations remain reconcilable after the account is gone, and to prevent duplicate claims. This record grants no access to anything.
If you sent us feedback or a bug report, we keep the report itself but strip your email address and account identifier from it, so what remains is an unattributed description of a problem that cannot be traced back to you or replied to. We do this rather than deleting it because an open bug is a record of a real defect that may still affect other people. Everything else on your account — including the usage counters and per-day records in section 2.9 — is deleted outright.
Warning: A lifetime purchase cannot be restored or transferred to another account after you delete your account.
Zimmer Server: Registration and licence records belong to the organisation rather than to an individual, so deleting a personal account does not remove them. To have a pilot registration or licence record deleted, email support@zimmerapp.co from the registered administrator's address. To be removed from a Zimmer Server itself, ask that organisation's administrator — those records are held by them, and we have no access to them.
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to it or lodge a complaint with a supervisory authority. Contact support@zimmerapp.co.
Most of what people want to export is your conversations—and those are already yours alone, on your device, exportable from within the app without involving us.
Zimmer is not directed to children and we do not knowingly collect data from them.
We use Google Firebase Authentication and Google Cloud (identity, entitlement storage, signing), Google Play (Android payments), and Stripe (macOS payments). Each processes data under its own privacy policy. Connections you configure yourself—for example MCP integrations on macOS—go directly from your device to that service; we do not proxy or observe that traffic. Credentials for them are stored in your operating system's keychain.
We will update this page and its "last updated" date when this policy changes.