Privacy Policy

Last updated: October 8, 2026

noodle is a chat app for iPhone and iPad that connects you to AI models using your own API keys. This policy explains what data noodle handles, where it goes, and what we never do with it.

The short version

What stays on your device

These are stored locally on your device, and nowhere else unless you turn on iCloud sync:

Searching your history happens on your device.

Sign in with Apple and iCloud sync

Sign in with Apple is optional. It's used only to turn on syncing between your Apple devices. When you sign in, Apple gives the app an anonymous user identifier and, if you choose to share them, your name and email. These are stored on your device. They aren't sent to the noodle backend and we don't create an account for you.

With sync on, your chat history, attachments and preferences are stored in noodle's private area of your iCloud Drive. Your API keys sync through your iCloud Keychain. This data is governed by Apple's privacy policy, and we can't access it. You can turn sync off at any time in Settings. To remove the synced copy, delete noodle's data in your device's iCloud settings.

What leaves your device when you chat

To get an answer, noodle sends the following to the backend you've selected:

The backend forwards the request to the AI provider and streams the answer back to you. It also uses your key to do small helper tasks for you, such as titling a conversation, suggesting a memory or summarizing a long chat. These requests go to a fast Gemini model through the same providers.

Where it goesWhat happens there
Hosted noodle backend (default)Processes the request in memory to route it to the provider, then discards it. Your messages and API keys aren't saved.
Your self-hosted backendRuns on your own computer or server. We never see the traffic.
OpenRouterReceives requests for models you use through OpenRouter, and passes them to the model's maker.
Google Gemini APIReceives requests when you use a Gemini key directly.
Web search enginesWhen a model searches the web, it sends a search query to its search engine: Google Search, the model maker's built-in search, or Exa through OpenRouter. The app shows which engine was used on each answer.
MCP connectors you addReceive the tool requests a model makes to them, such as a search query.

AI providers have their own policies

Once a request reaches a provider, its policies govern whether prompts and responses are logged, how long they're kept and whether they can be used for training. This depends on your account settings with that provider, and noodle can't override it. Please review them:

Note that Google may treat free-tier Gemini API usage differently from paid usage, including using it to improve its products. See the Gemini API Additional Terms for details.

What the hosted backend does keep

To keep the service running and secure, the hosted backend handles a small amount of operational data:

Signing in to OpenRouter and connectors

When you sign in with OpenRouter, the provider sends you back to the app through the noodle backend. The backend only relays the one-time sign-in code to your device and doesn't keep it. Your OpenRouter key is created on your device and stored in its Keychain.

When you connect an MCP connector that uses sign-in, the backend completes the sign-in with that service and stores the access token it receives, so it can call the connector's tools for you. The token is used only for that connector. Disconnecting the connector in the app deletes it.

Device permissions

Feedback you send us

If you send feedback from the app, we receive the title and description you write, plus your email if you choose to include it. We use it only to respond and improve noodle. It's stored in our private issue tracker.

Your choices

Children

noodle is intended for people 18 and older. We don't knowingly collect data from children.

Changes

We'll update this page if the app or our practices change, and revise the date at the top. Significant changes will also be noted in the app's release notes.

Contact

Questions about privacy? See the support page for ways to reach us.