Zimmer

Privacy Policy

Last Updated: September 1, 2026

Controller: FIHI LABS UG (haftungsbeschränkt) · support@zimmerapp.co

Zimmer is a local-first AI application. This policy covers Zimmer for macOS, Zimmer for Windows, Zimmer for Android, and Zimmer Server, the self-hosted deployment organisations run on their own hardware. Where platforms differ, the platform is explicitly named.

1. The Core Promise: Your AI Content Never Leaves Your Device

On every platform, all AI processing happens on your own hardware — your device, or your organisation's own Zimmer Server. We never receive, store, transmit, or train on:

  • your prompts, or the assistant's responses
  • conversations, conversation titles, or search indexes
  • attachments, files, or voice recordings
  • downloaded model files
  • your private backups

This is an architectural property, not only a policy commitment: the application has no code path that transmits this content to us. Model downloads go directly from the source (for example, Hugging Face) to your device.

What we do receive is limited to accounts, billing, licensing, a small set of usage counters on your account, and — where you have switched it on — anonymous performance telemetry. Each of those is itemised in section 2.

We do not sell your data. We do not train models on your data. We do not log your conversations.

2. What We Do Collect

2.1 Account Identity (Both Platforms)

Accounts are handled by Google Firebase Authentication, which stores your email address, a unique user identifier, whether your email is verified, and authentication metadata such as sign-in timestamps.

  • Android: Uses email and password. We never receive your password; Firebase handles it, and Zimmer never sees, stores, or logs it.
  • macOS and Windows: Use Google Sign-In, through your system browser.
  • Zimmer Server: Has no consumer account at all. See section 2.7.

An account on one platform is not automatically the same account on another. They are linked only if you explicitly connect them.

Alongside your account we store which desktop operating system you last opened Zimmer on (mac or windows), the app version, and the time of that launch, so we can tell which builds are in use and support them. This is a single label per account, not a device history.

2.2 Access and Entitlement Data (Android)

Zimmer for Android offers a seven-day free trial and a one-time Zimmer Lifetime purchase. To manage access, our entitlement service stores, against your account identifier only:

  • whether your trial has started, and its start and end times
  • whether you own the lifetime product, and a version number for that record
  • a one-way cryptographic fingerprint of a security key generated on your device and never leaving it
  • a one-way hash of your Google Play purchase token
  • an internal derived identifier linking a purchase to an account
  • technical records that make repeated requests safe to retry, and security audit events

We do not store your email address alongside purchase data.

2.3 Payments

Payments are processed entirely by Google Play (Android) or Stripe (desktop and Zimmer Server). We never see or store your card number or bank details. We receive only confirmation that a purchase occurred, the organisation name and billing email given at checkout, plus refund and cancellation notices.

2.4 Website Analytics (zimmerapp.co)

First-party analytics record sessions, page views, clicks, referral source, UTM campaign fields, device category, and coarse country. They do not record raw IP addresses, raw referral codes, prompts, files, emails, or in-app activity. Retained for 180 days. Do Not Track browser signals are respected. Analytics do not run on the account-deletion page.

2.5 Crash Reports

Opt-in only. Stack traces and hardware specifications; never prompts, content, or code.

2.6 Zimmer Server: Registration and Licensing

Zimmer Server runs on your own hardware. Your models, prompts, documents, chat history, and search indexes stay on that machine and are never transmitted to us — there is no code path that would send them.

Two things do reach us, and nothing else:

  • Pilot registration (once, at setup). Activating the free 3-seat pilot sends the organisation name, the registering administrator's name, and their work email, plus the app version and host platform. This is the only point at which Zimmer Server transmits a name or an email address, and it also opts that administrator into product update emails. Purchased licences instead carry the organisation name and billing email you gave at checkout, which we receive from Stripe.
  • Licence check-ins (roughly every 7 days). An activation key identifier, a random installation identifier, a single-use anti-replay token, the app version, the host platform, and a count of how many seats are currently in use. The seat figure is one integer for the whole deployment. It is never broken down per person and carries no names or addresses.

Nothing about the people who enrol devices against your server ever reaches us. Their names, emails, devices, and activity exist only in your own server's directory, under your control. Air-gapped deployments using an offline signed licence file transmit nothing at all. The exact field list is published in our Licensing Payload Disclosure.

2.7 Enrolling a Desktop App with Your Employer's Server

If your organisation runs Zimmer Server, connecting the desktop app to it asks for your name, work email, and a device name. Those details go to your employer's server, not to us. They are recorded in your organisation's own directory so an administrator can identify your device, and Zimmer receives no part of them.

Enrolling this way creates no Zimmer account. Sessions connected to a company workspace make no calls to our consumer services at all — no account records, no subscription records, no usage counters, and no telemetry.

2.8 Product Telemetry (macOS and Windows, Opt-In)

Off unless you turn it on in Settings. When enabled, Zimmer sends anonymous performance summaries keyed to a random device identifier that is never linked to your account: model names, generation counts and speeds, context sizes, failure counts, and error categories. It never includes prompts, responses, file names, or any content. Sessions connected to a company workspace never send it, regardless of the setting.

2.9 Service Usage Metrics (macOS and Windows)

Separately from the opt-in telemetry above, and unlike it, we keep a small set of usage counters on your account. We use them to run the service: to see which builds are actually in use, to know whether a release has broken something, to plan capacity, and to understand how much Zimmer is used overall. This is the only in-app measurement that is linked to your identity, which is why it is described separately rather than folded into section 2.8.

Stored under your user account, and nothing else:

  • Days you were active. One record per calendar day (UTC) on which you used the app, and the date of your most recent use.
  • Focus time. Roughly how long the Zimmer window was in the foreground, accumulated in whole minutes. Time while the app is in the background, minimised, or while your machine is asleep is not counted.
  • Prompt and agent run totals. How many turns you sent in ordinary chat, and how many in agent mode. Counts only.

These are numbers, not a record of what you did. There is no event log, no history of which screens or features you opened, no timestamps of individual actions, and — as everywhere else in Zimmer — no prompts, responses, file names, model names, or content of any kind. Knowing that you sent forty turns tells us nothing about what any of them said, and we have no way to find out.

They are sent at most every 30 minutes while you are signed in and using the app, and once when you quit. They are not controlled by the "Share anonymous performance data" setting, because they are not anonymous performance data — that setting governs section 2.8 only. These counters are part of operating an account-based service, and we rely on our legitimate interest in running Zimmer reliably to keep them. Sessions connected to a company workspace send none of it: enterprise sessions have no Zimmer account to attach it to.

Deleting your account deletes these counters along with everything else, including the per-day records. See section 4.

2.10 Diagnostics Attached to Bug Reports (macOS and Windows)

When you send feedback or a bug report from within Zimmer, you can tick "Include diagnostics" to attach a summary of what your local models did during that session: model names, how many times they ran, their speeds, context sizes, and error categories. The box shows you exactly what will be sent before you send it, and unticking it sends nothing.

Because a bug report needs a reply, this attachment is stored alongside your report and your email address. That is the difference between it and section 2.8, where the same kind of measurement is deliberately kept anonymous. It is never copied into the anonymous telemetry records, and those records are never linked back to you. It still contains no prompts, responses, or file contents.

2.11 MCP & Third-Party Integrations (macOS)

When you use the Model Context Protocol (MCP) to connect to external services (like Notion, GitHub, or Linear), Zimmer acts as a secure local bridge. Your API keys and OAuth tokens are stored in the macOS System Keychain. Zimmer retrieves these only at runtime and never transmits them to our servers. Connections to third-party APIs are established directly from your machine and are not proxied.

The Zimmer Privacy Guarantee

We will never sell your data. We will never train models on your data. We will never implement cloud-based logging for your prompts. Your intelligence is your own.

3. Where Your Data Is Stored

Your AI content stays on your own hardware and is never transmitted, so it is not stored anywhere by us.

The limited account and entitlement data described above is processed by Google Cloud on our behalf:

DataLocation
Android entitlement records, processing, and signing keysFrankfurt, Germany (europe-west3)
Desktop account, subscription, and usage-counter records (Firestore)United States (multi-region)
Zimmer Server licence, pilot registration, and check-in recordsFrankfurt, Germany (europe-west3)
Firebase AuthenticationOperated globally by Google

Because macOS account records and Firebase Authentication involve storage or processing outside the EU, using Zimmer on macOS involves an international transfer of that limited account data. Google Cloud provides Standard Contractual Clauses for such transfers.

4. How Long We Keep It

RecordRetention
Account and entitlement recordsUntil you delete your account
Registered device keysUntil you delete your account
Service usage counters, including per-day records (§2.9)Until you delete your account
Feedback and bug reports, with any diagnostics you attached (§2.10)Your email and account identifier are removed when you delete your account; the report text is kept unlinked
Purchase recordsRetained after deletion in pseudonymised form (see §5)
Operational logs30 days
Security audit logs400 days
Website analytics180 days
Zimmer Server licence and pilot registration recordsFor the life of the licence, then 24 months

5. Deleting Your Account and Data

Android: Settings → Delete account. We delete your Firebase identity, your account record, your registered devices, and your entitlement record. Your on-device conversations are then deleted from your device with your confirmation.

You can also delete only your on-device data ("Delete local data from this device") without deleting your account. Signing out does not delete anything: it makes local conversations inaccessible until the same account signs in again. Detailed instructions and request forms are available on our Data Deletion Page.

macOS and Windows: Delete the application and its support folder (~/Library/Application Support/Zimmer on macOS, %APPDATA%\\Zimmer on Windows).

Either platform, without opening the app: email support@zimmerapp.co. Please do not include passwords, conversations, prompts, recordings, attachments, or purchase tokens in that email—we do not need them.

What we keep after deletion: If you purchased Zimmer Lifetime, we retain a pseudonymised record of that purchase—your account identifier is replaced with a one-way derived value. We keep it so Google Play / Stripe refunds, chargebacks, and cancellations remain reconcilable after the account is gone, and to prevent duplicate claims. This record grants no access to anything.

If you sent us feedback or a bug report, we keep the report itself but strip your email address and account identifier from it, so what remains is an unattributed description of a problem that cannot be traced back to you or replied to. We do this rather than deleting it because an open bug is a record of a real defect that may still affect other people. Everything else on your account — including the usage counters and per-day records in section 2.9 — is deleted outright.

Warning: A lifetime purchase cannot be restored or transferred to another account after you delete your account.

Zimmer Server: Registration and licence records belong to the organisation rather than to an individual, so deleting a personal account does not remove them. To have a pilot registration or licence record deleted, email support@zimmerapp.co from the registered administrator's address. To be removed from a Zimmer Server itself, ask that organisation's administrator — those records are held by them, and we have no access to them.

6. Your Rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to it or lodge a complaint with a supervisory authority. Contact support@zimmerapp.co.

Most of what people want to export is your conversations—and those are already yours alone, on your device, exportable from within the app without involving us.

7. Children

Zimmer is not directed to children and we do not knowingly collect data from them.

8. Third Parties

We use Google Firebase Authentication and Google Cloud (identity, entitlement storage, signing), Google Play (Android payments), and Stripe (macOS payments). Each processes data under its own privacy policy. Connections you configure yourself—for example MCP integrations on macOS—go directly from your device to that service; we do not proxy or observe that traffic. Credentials for them are stored in your operating system's keychain.

9. Changes

We will update this page and its "last updated" date when this policy changes.