Privacy · Brello 1.0 and Brello SI

How Brello handles your questions, photos and answers

Brello 1.0 is a private AI assistant for Android and iPhone, made by Stuvio, that processes your questions, photos and answers on your phone. This page sets out what stays there, what leaves and when, and how we are designing Brello Super Intelligence, which is in development.

This page explains how Brello works. The legal terms are in the Brello privacy policy.

Updated 5 October 2026Brello 1.0, version 1.0.0

Contents12 sections

The short version

Brello 1.0 answers on your phone and keeps its chats there. It goes online only for a model download you start and a web search you allow; a source you tap opens in your browser. Each statement below is paired with its limit.

Table 1Three statements we make about Brello 1.0, each with the limit that applies.
What Brello 1.0 doesThe limit
Your questions, photos and answers are processed on your device.When you choose to search the web, the search text leaves the phone.
Chats are stored only on your phone and are excluded from backups.They are not copied to Google Drive backups or to a new phone, so a lost or reset phone takes its chats with it.
Web search is off by default, and Brello asks before going online.When you search, the search engine and the websites Brello reads see a normal request, including the phone’s IP address.

Where the AI runs

The AI runs entirely on your phone. Your question goes only to the model’s runtime on the device: there is no cloud AI and no Brello server. Brello 1.0 works offline after a one-time download of the model.

Figure 1 draws the boundary. Everything inside the dashed line stays on the phone. Brello sends three kinds of request across it, and each starts only when you do something.

What stays on the phone, and the three requests that leave it A dashed outline marks the phone. Inside it, the on-device model answers a question, and chats, photos and settings are kept in Brello’s private app storage, excluded from cloud backup and device-to-device transfer. Three kinds of request cross the outline, each started by the person using the phone: a model download request to Hugging Face; the search text, sent to a search engine; and requests for up to four result pages, sent to their websites. Search and page requests carry Do Not Track and Global Privacy Control headers, and the search engine and websites see the request and the phone’s IP address. A source the person taps opens in their browser. There is no Brello server, proxy or relay, and the app has no analytics, advertising or crash reporting. On this phone Brello 1.0 Outside the phone Processed here Why is the sky blue? On-device model No cloud AI Air scatters blue light more than red light, so the sky looks blue. 2.4s · On-device Private app storage conversations.json Chats and their thought process images/ Photos you attach, never uploaded SharedPreferences Settings, private to Brello 1 Model download Download Brello Core Once per model 2 Search text Search the web DNT: 1 · Sec-GPC: 1 3 Page requests W N B S Reading 4 sources DNT: 1 · Sec-GPC: 1 Backups Cloud backup Excluded Device transfer Excluded Hugging Face huggingface.co Not contacted Receives: a download request Search engine DuckDuckGo · Bing · Brave · … Not contacted Sees: search text, IP address Websites Up to 4 result pages Not contacted Sees: page requests, IP address No Brello server No proxy · no relay · no logs No analytics, ads or crash reports A source you tap opens in your browser. What stays on the phone, and the three requests that leave it A dashed outline marks the phone. Inside it, the on-device model answers a question, and chats, photos and settings are kept in private app storage that is not backed up. Three kinds of request cross the bottom of the outline, each started by the person using the phone: tapping Download Brello Core sends a download request to Hugging Face, and with web search on, the search text goes to a search engine and requests for up to four result pages go to their websites, which see the request and the phone’s IP address. There is no Brello server, proxy or relay. On this phone Brello 1.0 Why is the sky blue? On-device model 2.4s · On-device Private app storage No backup Chats Photos Settings Download Brello Core Search the web 1 2 3 Hugging Face Not contacted Download request Search engine Not contacted Search text, IP address Websites Up to 4 pages Not contacted Page requests, IP address No Brello server No proxy, relay or logs What stays on the phone, and the three requests that leave it A dashed outline marks the phone. Inside it, the on-device model answers a question, and chats, photos and settings are kept in private storage that is not backed up. Three kinds of request cross the right side of the outline, each started by the person using the phone: tapping Download Brello Core sends a download request to Hugging Face; with web search on, tapping Search the web sends the search text to a search engine; and while Brello reads four sources, requests for those pages go to their websites. The search engine and the websites see the request and the phone’s IP address. There is no Brello server, proxy, relay or logs, and no analytics, advertising or crash reporting. On this phone Brello 1.0 Outside the phone Why is the sky blue? On-device model 2.4s · On-device Private storage No backup Chats Photos Settings Download Brello Core Search the web W N B S Reading 4 sources 1 2 3 No Brello server No proxy, relay or logs No analytics or ads No crash reports Hugging Face Not contacted Download request Search engine Not contacted Search text, IP address Websites Not contacted Page requests, IP address
  1. Questions, photos and answers are processed on the phone. Chats, photos and settings stay in Brello’s private app storage, inside the dashed line.
  2. 1 · A model download, when you start it. The phone sends a standard file download request to Hugging Face, once per model. Then Brello works offline.
  3. 2 · The search text, only when web search is on. A cleaned-up version of the question goes straight to a search engine, which sees the phone’s IP address.
  4. 3 · Up to four result pages, at the same moment. Their websites see a normal request, including the IP address. A source you tap opens in your browser.
  5. Nothing else leaves. There is no Brello server, proxy or relay, and no analytics, advertising or crash reporting. Chats are excluded from backups.
Figure 1What stays on the phone in Brello 1.0, and the three kinds of request that leave it, each started by something you do. The question, answer, model and the sites shown are illustrative; the destinations, headers and storage locations are the ones the app uses.

The app says the same in its own settings. Under Privacy, the Settings sheet shows three rows, quoted here exactly.

Table 2The Privacy rows in Brello 1.0’s Settings, as the app shows them.
RowText in the app
“AI runs on your phone”“Questions, photos and answers are processed locally. No cloud, no account.”
“Chats stay here”“History lives only in Brello's private storage and is excluded from backups.”
“Direct web search”“Searches go straight from this phone to the search engine and the pages you read. No Brello server in between, nothing logged.”

What stays on your phone

Your questions, photos and answers are processed on the phone, and your chats are stored only there. The exception is web search: when you choose to search, the search text and requests for up to four result pages leave the phone, as What leaves, and only when you choose sets out. Table 3 lists where each item lives.

Table 3Where Brello 1.0 keeps what you give it and what it writes.
ItemWhere it is keptDetail
Your questionsProcessed by the model on the phoneThe prompt goes only to the on-device runtime.
Brello’s answersGenerated on the phoneWritten by the model you chose, on this phone.
Photos you attachCopied into Brello’s private app storage, in images/Never uploaded. A question with a photo never triggers a web search.
Chat historyOne file, conversations.json, in Brello’s private app storageWritten atomically, to a temporary file first and then renamed, so an interrupted save doesn’t leave a partial file.
ReasoningStored with the chatShown in the reply’s “Thought process” panel.
SettingsAndroid SharedPreferences, private to BrelloTheme, web search, Think harder, GPU acceleration and the chosen model.

Android normally copies app data to cloud backups and to a new phone. Brello 1.0 turns both off, so its chats stay on the phone where they were written.

Table 4The Android settings that keep chats on one phone.
Copy routeSetting in Brello 1.0Effect
Android cloud backupallowBackup="false", and data-extraction rules that exclude every domain: root, file, database, sharedpref and externalChats are not copied to Google Drive backups.
Device-to-device transferThe same rules exclude every domain from transferChats are not copied to a new phone.

What leaves, and only when you choose

Brello 1.0 sends three kinds of request, each only after you act: a model download, the search text and requests for up to four result pages. A source you tap opens in your browser, like any other link. Table 5 lists what is sent in each case, who receives it and what controls it.

Table 5What leaves the phone in Brello 1.0, when, and who receives it.
WhenWhat is sentTo whomControlled by
Downloading a model, once per modelA standard file download requestHugging Face (huggingface.co, litert-community repositories)You, by starting the download
Web search, only while it is on (choosing “Search the web” on the card turns it on)The search text: a cleaned-up version of your question, sometimes with up to 10 words of the previous question added for context on a follow-upThe search engine that answers: DuckDuckGo, Bing, Brave Search, Google News (RSS) or WikipediaThe “Search the web” setting, or the “Search the web for this?” card
Reading results, at the same momentOrdinary page requests for up to 4 result pagesThe websites in the resultsThe same setting or card
Tapping a source card or citationThe page opensYour browserYou

These requests go directly from the phone. There is no Brello server, proxy or relay between you and the sites, so Brello has no logs to keep. The AI that reads the pages and writes the answer still runs on the phone; only the search text and the page requests go out.

Android permissions, and why

Brello 1.0 asks Android only for what a model download and web search need, and reaches the camera and photos through the system picker when you choose them.

Table 8The Android permissions Brello 1.0 requests, and the reason for each.
PermissionWhy
Internet, network stateModel download and optional web search.
Foreground service (data sync), post notifications, wake lockLets the one-time model download continue, with a notification, while the app is in the background.
Camera, photosRequested by the system picker only when you choose Camera or Photos.

Brello 1.0 requests no contacts, location, microphone, SMS, calendar or storage-wide permissions.

No account, analytics, ads or tracking

Brello 1.0 has no account and contains no analytics, crash-reporting or advertising software. With no Brello server, none of your questions, photos, answers or chats reach us.

Table 9The software and services Brello 1.0 leaves out.
ItemIn Brello 1.0
Account or sign-upNone.
AnalyticsNone. No analytics SDK is among the app’s dependencies.
Crash reportingNone. No crash-reporting SDK is among the app’s dependencies.
AdvertisingNone. No advertising SDK is among the app’s dependencies.
Brello serverNone. Requests go directly from the phone, so there are no Brello logs.

The Brello 1.0 system card gives the technical account of the app, and the Brello Charter commits us not to use your conversations to train models.

Claims we won’t make

Some phrases sound like privacy but are not true of Brello 1.0, so we don’t use them. Table 10 lists each, with the reason.

Table 10Privacy claims we don’t make about Brello 1.0, and why.
We don’t sayWhy
“Anonymous web search” or “untraceable”Search engines and websites receive the request and see the phone’s IP address.
“End-to-end encrypted”There is nothing to encrypt end to end: no Brello server receives your messages. The app also makes no encryption claims about local storage.
“Never connects to the internet”It connects to download a model and, when you allow it, to search the web.
“Nothing leaves your device”, unqualifiedThe search text leaves when you choose to search the web. Our wording is about AI processing, which stays on the phone.
“No internet needed”, unqualifiedTrue only after the one-time model download.
“Private web search”, unqualifiedSearch is direct and Brello logs nothing, but the search engine and websites still receive the query and the request.
“Military-grade” or “unhackable”Neither phrase names a mechanism anyone can check, and no software can promise either.
“Powered by Google”, or anything implying that Google or Alibaba endorse BrelloBrello is built on open models from Google and Alibaba. It is not affiliated with or endorsed by either company.

Brello Super Intelligence: the privacy design

Brello Super Intelligence is in development. This section describes design intent, not a product anyone can use.

Brello Super Intelligence, or Brello SI, is being designed to keep work on your device whenever it can, and to send work elsewhere only to sealed compute that your device has verified first. Table 11 pairs each intention with the part of the Brello Charter, version 1.0, that states it. Section 4 describes design intent; the numbered commitments, and the section 4 pledge to publish the architecture, are obligations.

Table 11The privacy design of Brello SI, with the part of the charter that states each element. Design intent, not results.
Design intentCharter v1.0
Work is intended to run on your device whenever it can.Section 4
When a task needs more than the device can give, it is intended to run on hardware-isolated, stateless servers designed to keep nothing: no logs, no retention and no human access.Section 4, commitment 03
Brello SI is being designed so that your device verifies a server before sending it anything.Section 4
Fresh facts are intended to come from the web only when you allow it.Section 4
We will not use your conversations to train models.Commitment 01
Brello SI will not remember anything about you beyond a single chat unless you can see what it holds, correct it, export it and erase it.Commitment 07
We will publish its architecture, including what each layer can and cannot see, before anyone outside the team uses it.Section 4, published architecture
We are designing it so that independent researchers can verify what runs, where it runs and what it keeps.Commitment 08

The open design questions, including how a phone could check a server before sending it anything, are set out in Private compute you can verify: the design space. Confidential computing for AI, explained introduces the underlying technology.

This website’s own privacy

This website sets no cookies and runs no analytics, and every font, image and script is served from brello.ai.

Table 12What brello.ai does when you visit.
ItemOn brello.ai
CookiesNone.
Analytics, advertising, session recordingNone.
Requests to other sitesNone. Fonts, images and scripts come from this site, which you can confirm in your browser’s developer tools.
Server logsThe service that hosts the site receives the standard information your browser sends with each request, such as your IP address. Section 3 of the privacy policy explains how it is used.

How Brello compares with cloud assistants

The main difference is where the model runs. A cloud assistant answers on its provider’s servers, so each question travels to them and is handled under that provider’s policies. Brello 1.0 answers on the phone.

We describe named assistants only on our comparison pages, where every statement about another product quotes that provider’s own published documentation, with the date we checked it. Table 13 gives Brello 1.0’s side of those comparisons. For a general guide, read How AI assistants handle your data.

Table 13Brello 1.0’s answers to the questions every comparison page asks.
QuestionBrello 1.0
Where does the model run?On the phone.
Is an account required?No.
Does it work offline?Yes, after the one-time model download.
When is the web used?For a model download, and for web searches while web search is on.
Where are chats stored?Only on the phone, excluded from cloud backup and device-to-device transfer.

The privacy policy and how to contact us

This page explains how Brello works; the Brello privacy policy is the legal document. It says who we are, what personal data we receive and what rights you have.

Table 14Where to go next.
If you wantGo to
The legal termsBrello privacy policy
To ask a privacy questionEmail us with “Privacy question” in the subject
To report a request the app shouldn’t make, or another flawSecurity and disclosure

Version history

  1. First published, for Brello 1.0, version 1.0.0.