What is on-device AI, and does it actually keep your data private?
Apple's AI framework now runs on your phone, on Apple's servers, or on Anthropic's and Google's, behind the same few lines of code. We've shipped apps on both sides of that line. Our own website got it wrong about one of them until we checked the code for this post.
On-device AI is an AI model that runs on your phone’s own chip, so what you type, say or photograph is processed right there and never sent to a server. That is the only kind of AI where “private” means something you can check rather than a promise you have to trust. The catch, as of iOS 27: an app can say it’s built with Apple’s AI and still send your data to the cloud, so you have to look a bit closer.
What does “on-device AI” mean?
It means the model (the trained program that writes, sorts or recognises things) is stored on your phone and runs there. Your input goes in, the answer comes out, and nothing crosses the internet in between.
Cloud AI is the opposite. Your input is sent to a company’s computers, a much bigger model works on it, and the answer is sent back. ChatGPT, Claude and Gemini in their own apps all work this way.
On-device AI isn’t only chatbots. When your iPhone lifts a dog out of a photo, transcribes a voice memo, or finds “beach” in your camera roll, that’s on-device AI too, and it’s been there for years.
Why did this get confusing in 2026?
Because at WWDC in June 2026, Apple turned its AI framework for developers, called Foundation Models, into a switchboard. When it launched in 2025 it gave apps one thing: Apple’s small model that runs on the phone. With iOS 27, released in September, the same framework can also send a request to:
- Apple’s own cloud models, on a system Apple calls Private Cloud Compute. These are much larger than the phone model, and Apple made them free for small apps (those in Apple’s Small Business Program with fewer than 2 million first-time downloads, per Apple).
- Other companies’ models, like Claude and Gemini, which Anthropic and Google plug in through their own Swift packages.
For a developer, switching from the phone model to Apple’s cloud is a one-line change. For you, the app looks identical either way. So “uses Apple Intelligence” on an App Store listing now tells you very little about where your words go.
Apple says as much in its own developer session: “On-device and cloud-based models have very different privacy characteristics, and your users deserve to know which they’re getting.”
How does it work? Think of your tax return
On-device AI is doing your taxes at the kitchen table. The receipts never leave the house. The trade-off is that you’re working with what you’ve got: a small calculator, limited patience, and a shoebox that only holds so much.
Apple’s Private Cloud Compute is sending the shoebox to an accountant who works in a locked room. The accountant is far more capable. The rules say they shred everything once your return is done, nobody at the firm can read your file, and outside inspectors can check the shredder.
Apple says your data is “not stored nor made accessible to Apple or anyone else”, and independent researchers can inspect the server software. It’s a strong promise. It’s still your receipts leaving the house.
A third-party cloud model is sending the shoebox to a different firm. Anthropic, Google or OpenAI handle it under their own terms, and the app’s developer has signed up with them. That can be perfectly fine. It’s just a different deal, and it’s the developer’s choice, not Apple’s.
In numbers: Apple’s standard phone model has about 3 billion parameters, roughly the number of dials the model was tuned with, which is a measure of its size. The newest iPhones get a larger one. It can hold 4,096 tokens at a time on iOS 26, about 3,000 words counting both your question and its answer (Apple). iOS 27 doubles that to 8,192 on newer phones. Apple’s cloud model holds 32,768. The frontier models from Anthropic and Google are bigger still.
Is Apple Intelligence private?
Mostly yes, with three levels to know about (as of October 2026):
- On the phone. Many Apple Intelligence features run entirely on the device. Nothing leaves it.
- Apple’s cloud. Harder requests go to Private Cloud Compute. Apple’s current models were built in collaboration with Google’s Gemini, and the biggest one was tuned for NVIDIA chips together with Google, but they run under Apple’s rules: data used for the request and not kept. In our view this is the most credible cloud privacy design any big company offers. It still needs the internet, and it is still a server.
- ChatGPT and other outside services. Siri and Writing Tools can hand a request to an outside chatbot like ChatGPT. That only happens if you’ve switched the extension on, and by default your iPhone asks before each request.
So Apple’s own features are about as private as AI on a phone gets right now. The question worth asking is about everyone else’s apps.
How can you tell if an app’s AI is really on your phone?
Four checks, from quickest to most thorough:
- Turn on airplane mode and try the AI feature. If it still works, the AI is running on your phone. If it fails or says it needs a connection, your input is going somewhere. This is the only check that doesn’t rely on anyone’s word.
- Don’t read too much into “Data Not Collected”. The App Store privacy label is useful, but Apple’s definition of “collect” only counts data an app keeps for “longer than what is necessary to service the transmitted request in real time” (Apple). An app can send your photo to a cloud AI, get the answer back, have the server delete it, and truthfully say “Data Not Collected”. The label tells you what’s kept, not where the work happens.
- Watch for a permission prompt that names an AI company. Since November 2025, Apple’s App Review Guidelines (rule 5.1.2(i)) require apps to “clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so.” If you got that prompt, the data leaves your phone.
- Search the description and privacy policy for the exact words “on device” or “on your iPhone”. Developers who built it that way usually say so, because it’s a selling point. “Powered by AI” or “uses Apple Intelligence” on its own proves nothing either way.
One more thing, and it catches people out: on-device AI doesn’t make the whole app private. Our scrapbooking app stckrz cuts people out of photos on the phone, using the same Apple tool the Photos app uses, so your kids’ photos never go to a server to be cut out.
But the app also uses analytics, which reports how the app is used. And if you choose to send a page to someone, that page gets uploaded so they can open it. The AI feature is on-device. The app as a whole isn’t “nothing ever leaves”. Both of those are true, and a listing can blur them.
Should your app’s AI run on the phone or in the cloud?
This part is for founders and anyone deciding how to build an AI feature. Here is how the three options compare, as of October 2026:
| On the phone (Apple’s on-device model) | Apple’s cloud (Private Cloud Compute) | Another company’s cloud (Claude, Gemini, OpenAI) | |
|---|---|---|---|
| Where the user’s data goes | Nowhere | Apple’s servers, not stored | The provider’s servers, under its terms |
| Works offline | Yes | No | No |
| Cost to you per request | $0 | $0 under 2M downloads, with a daily limit per user | Pay per use |
| How capable | Short, focused tasks | Much stronger, long inputs | Strongest available |
| Which phones | iPhone 15 Pro, iPhone 16 and later | iOS 27, with a connection | Any phone with a connection |
| What you owe the user | Nothing to disclose | No rule, but say it’s the cloud | A clear disclosure and explicit permission (rule 5.1.2(i)) |
When on-device wins
Pick the phone when the data is personal and the AI’s job is small.
Our journaling app Senba is the example. People write about their days, record voice notes and attach photos. All of that stays on the phone: speech is transcribed on the device, the photo tagging runs on the device, and Apple’s on-device model writes the short reminder lines. Senba has no servers at all. Its App Store label says “Data Not Collected”, and that’s true in the strict sense too, not only Apple’s narrow one. The one exception is optional sync, which goes to the user’s own private iCloud.
That also means Senba has no server bill. It costs us the same to run with ten users as with ten thousand, which means it can stay on the App Store indefinitely without needing to make money first. For a small studio, that’s a big deal.
When the cloud wins
Pick the cloud when the quality of the AI’s output is the product.
Our bedtime story app Storynite runs in the cloud on purpose. It writes a full story in several languages and illustrates it, and the phone model can’t do either well yet. English stories are written by Anthropic’s Claude Haiku 4.5, other languages by Claude Sonnet 4.6, and the pictures come from Google’s Gemini 2.5 Flash Image. Each English story costs us about $0.15, measured in September 2026, and 78% of that is the three illustrations.
Here’s the embarrassing part. Until this week, our own website described Storynite as “generated on device”. It isn’t, and it never was. Nobody meant to mislead anyone. It was a line of copy that nobody checked against the code.
If the people who built the app can get this wrong, the wording on an App Store listing deserves some suspicion. We’ve fixed the page.
What the small model is actually like
The phone model is good at small, well-defined jobs: summarising, tagging, filling in a structured form, writing a sentence or two. It’s bad at knowing facts and at writing anything long.
We learned that the hard way in Senba. In July we caught the model writing reminder lines that sounded like a subscription email (“you’ve been subscribed… we’re committed to…”), and we had to add a check that throws away copy like that. We built a feature where the model rewrote the daily journaling prompts, merged it, and pulled it ten days later because the prompts it produced were confusing. We replaced it with plain text substitution and no AI.
What works is splitting the job. Ordinary code picks the facts, meaning which of your old entries to show you, and the model only writes the sentence around them. We wrote that up in how to use Apple Foundation Models without them making things up. And when the model isn’t available, because the phone is too old or Apple Intelligence is switched off, Senba falls back to sentences we wrote by hand. Plan for that from day one.
Our take
“Private” on an AI app should mean the AI runs on your phone. Anything else is “private by policy”, which can be a fine thing to be, but it’s a different claim, and it should say so.
For anything personal (journals, health, messages, photos of your kids), on-device should be the default. Reach for the cloud when the output has to be good enough that people would pay for it, and then tell users plainly where their data goes. Apple’s Private Cloud Compute is the best deal in cloud AI right now, private by design and free for small apps. Just don’t call it on-device.
If you’re a user, the airplane-mode test takes ten seconds. If you’re a builder, put one honest line on your listing: “runs on your iPhone”, “runs on Apple’s servers” or “runs on Anthropic’s servers”. Hardly anyone does, which makes it a cheap way to stand out.
FAQ
Does on-device AI work offline? Yes. That’s the easiest way to tell it apart: if an app’s AI feature works in airplane mode, it’s running on your phone. Apple’s cloud models and third-party ones like Claude and ChatGPT all need a connection.
Is on-device AI worse than ChatGPT? For open questions, general knowledge and long writing, yes, by a long way. Apple’s phone model is a few billion parameters and can only hold a few thousand words at a time. For short, focused jobs inside an app, like summarising a note or tagging a photo, it’s good enough, and it’s free and private.
Does on-device AI drain your battery? A short task like writing one notification line costs very little. The real drain we’ve seen came from a bug: Senba kept retrying failed indexing on every launch, re-running its on-device models each time, until we capped the retries. We haven’t measured normal use, but an app whose AI runs constantly in the background is where we’d look first.
Which iPhones support on-device AI? Apple Intelligence and its on-device language model need an iPhone 15 Pro or 15 Pro Max, or any iPhone 16 or newer, as of October 2026. Simpler on-device AI, like cutting a subject out of a photo or on-device dictation, works on much older iPhones. stckrz’s cutouts run on anything with iOS 17.
Does Apple’s Foundation Models framework send data to the cloud? The on-device model doesn’t. Since iOS 27, the same framework can also call Apple’s Private Cloud Compute or a third-party model like Claude or Gemini, and the developer chooses which for each request. From the outside you can’t tell, so use the airplane-mode test or ask the developer.
We build apps like this at Tennnis, on the phone where it fits and in the cloud where it doesn’t. If you’ve got one that needs building, get in touch.