Effective Date: July 19, 2026 Last Updated: August 21, 2026 Publisher: Red Warden Studios LLC (operating through its Red Warden Bastion division) Governing State: Kentucky, United States Contact for privacy requests: support@redwardenstudios.com
Red Warden Studios LLC ("Red Warden," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we do and do not collect in connection with the LLypses desktop and mobile applications (the "Software") and the redwardenstudios.com website (the "Site"), and how that information is handled. It is written to apply globally, including to visitors in the EU/UK and California.
By using the Software or the Site, you agree to the practices described in this Policy.
1. Our Privacy-First Design
LLypses is built to be local-first. The core of the application runs on your own device using your own Third-Party AI Provider API keys. As a result, we deliberately collect as little information about you as possible. In most cases, using LLypses involves no transmission of your content to Red Warden at all. The Site itself is a simple informational and checkout-referral site — it has no user accounts and no logins.
2. Information the Software Does NOT Collect
- Your conversations and content. All conversation data, session history, boardroom minutes, and knowledge base entries are stored locally on your device. We do not collect, access, store, or transmit them. The single exception is a diagnostic or content report that you choose to compose and send us — see Section 4, which describes exactly what such a report contains and what is optional within it.
- Your API keys. Your Third-Party AI Provider API keys are stored locally on your device and are never transmitted to Red Warden.
- No account. LLypses does not require you to create a Red Warden account. We do not collect a username or password from you to use the Software.
- No prompt tracking, and no telemetry. We do not log the prompts you write or the outputs you receive. There is no background analytics, crash beacon, or usage reporting in the Software: nothing leaves your device unless you press a button that says it will.
3. Information Handled by Third Parties When You Use the Software
Third-Party AI Providers. When you send a message to an advisor, the Software transmits your input directly from your device to the Third-Party AI Provider you addressed. That data is handled under that provider's own privacy policy and terms, not ours. We are not a party to, and have no visibility into, that exchange. You should review each provider's privacy policy to understand how they handle your data, including whether they use it for model training. We encourage you not to submit sensitive personal information you would not want processed by a third-party AI service.
Which providers are available differs by edition. The authoritative list is always the one shown inside the app under Settings → API Keys. As of the Last Updated date above:
- LLypses for Android supports Google, OpenAI, Cohere, xAI (Grok), Groq, Mistral, DeepSeek, OpenRouter, and Perplexity. It does not support Anthropic.
- LLypses Desktop supports Google, OpenAI, Anthropic, xAI (Grok), Groq, Mistral, and Cohere.
Your input only ever reaches a provider you have supplied an API key for and addressed. A provider you have not configured receives nothing.
Photos and files you attach. “Your input” includes anything you attach to a message. A document is read on your device and its text is sent as part of your message. A photo is sent to the AI provider as an image, but only where that provider supports images and accepts that image’s file format — the app tells you when a photo could not be delivered. Image support differs by edition and by provider; as of the Last Updated date above, LLypses Desktop can send images to Google, OpenAI and Anthropic, and LLypses for Android to Google and OpenAI. A provider that is not sent the picture receives only the description you typed, and the advisor running on it is told that an image was attached which it did not receive, so that it does not describe a photo it cannot see. A photo is sent with the message you attached it to and is not re-sent with your later messages. LLypses keeps a copy of the photo on your device so it stays visible in your own transcript and Knowledge Base; that copy is never transmitted to Red Warden, and deleting the session or the Knowledge Base entry deletes it. The only path by which anything from a conversation reaches us is a report you choose to send under Section 4, and a report carries the text of a conversation — never an attached image.
OpenRouter is a router, not a model host. If you address an advisor through OpenRouter, your input is forwarded by OpenRouter to whichever upstream model provider serves the model you selected. That onward transfer is governed by OpenRouter's privacy policy and by the upstream provider's own policy.
Web search. Some advisors are configured to search the web in order to answer you. Where that is enabled, the AI provider handling your request may derive search queries from your input, run them on its own infrastructure, and return source links alongside its answer. That exchange happens between you and that provider. Red Warden does not run, receive, or log those searches.
4. Diagnostic and Content Reports You Choose to Send
LLypses includes a reporting feature you can use to send us a bug report, or to report AI-generated content you found offensive or harmful. This is the only path by which your in-app content can reach Red Warden, and it is entirely under your control.
Nothing is sent automatically. The Software contains no background telemetry, no usage analytics, and no automatic crash reporting. A report exists only because you composed one and pressed Send.
You see the report before it is sent. The Software builds the report, displays it to you in full — including the log excerpt — and only then offers to send it. You are sending exactly the content you were shown, and you can cancel or copy it instead at any point.
A report contains:
- The description you write, and, for a content report, the specific AI-generated message you are reporting;
- Technical context: app version, operating system and device model, and which AI providers and models your advisors were configured to use;
- A summary of the session's shape — how many messages, which advisors spoke, whether images or diagrams were present. This is counts and flags, not the words you wrote;
- A short, scrubbed excerpt of the application's own diagnostic log.
Two things are included only if you choose them, each separately, each per report:
- The full conversation transcript, if you tick the box to attach it — the text of the conversation; attached images are never included. It is off by default;
- An email address, if you type one so that we can reply. We do not obtain it from anywhere else and we do not infer it.
Credentials are removed before sending, and the send fails closed. Before a report leaves your device, the Software redacts API keys, authorization tokens, email addresses and operating-system user names from every part of it, including any transcript you attached and the log excerpt. The redacted report is then re-examined, and if anything in it still resembles an API key the report is blocked rather than sent, and you are told so. We would rather lose a diagnosis than carry your credentials.
Where reports go, and how long we keep them. A sent report is transmitted to a diagnostic endpoint operated by Red Warden Studios on Cloudflare's infrastructure, and you receive a short ticket reference. Reports are used solely to diagnose faults, to review reported content, and to reply to you if you supplied an address. They are not used for advertising, sold, or used to train any AI model.
A report is automatically deleted from that endpoint 90 days after it arrives. The expiry is set on the record at the moment it is stored, so it takes effect regardless of any action by us. Where we act on a report, we keep the redacted copy as a support record — so that we can recognise your ticket reference if you quote it back to us, and so we have a record of what was changed and why. We keep that copy only for as long as it is useful for support and quality purposes, and it contains no credentials, because those are removed before the report leaves your device.
If you would rather not use the in-app reporter, you can email us at support@redwardenstudios.com and include only what you choose to include.
5. Information We Collect Through Purchases
How a purchase is handled depends on which edition you buy, and the two differ in what reaches us.
LLypses Desktop. Checkout is handled by our third-party merchant of record, which processes your payment and collects the billing information necessary to complete the transaction (such as your name, email address, billing location, and payment method details) under its own privacy policy. From that process we receive limited order information — typically your email address, order identifier, and country/tax region — which we use to:
- Deliver your license key;
- Provide customer support and handle activation or delivery issues;
- Keep records of the transaction for accounting, tax, and legal-compliance purposes; and
- Detect and prevent fraud and abuse.
LLypses for Android. Checkout is handled entirely by the Google Play Store under Google's own privacy policy, and your entitlement to the app is managed by Google Play. There is no license key for the Android edition, and the app never asks you for one. We do not receive your email address or your payment details from a Play purchase. Google Play provides us with order and sales reporting — such as order identifiers, country or tax region, and counts of installs, refunds, ratings and reviews — which we use for accounting, tax, fraud prevention, and to understand how the app is performing. If you contact us for support and choose to give us your email address, we hold it for that purpose only.
Red Warden does not receive or store your full payment card details for either edition. Payment data you enter at checkout is governed by the privacy policy of our third-party merchant of record (Desktop) or of Google (Android). We encourage you to review whichever applies to your purchase.
6. Information We Collect Through the Website
- Contact form. If you contact us through the Site, we collect the information you provide — typically your name, email address, inquiry type, and message — solely to respond to your inquiry. Our contact form is processed by Formspree, a third-party form-handling service that receives your submission and forwards it to us. Formspree processes this data on our behalf under its own privacy policy.
- Server and hosting logs. Our website host may automatically record standard technical log data (such as IP address, browser type, and pages requested) for security, diagnostics, and abuse prevention. This is standard practice for virtually all websites.
- No accounts. The Site does not offer user accounts, logins, or profiles. LLypses is a separate application that runs on your own device and likewise requires no account with us.
7. Cookies and Analytics
We aim to use the least tracking necessary, and we tell you plainly what is in use. Cookies and similar technologies on the Site fall into three categories:
(a) Strictly necessary. Cookies or local storage required for the Site to load and function securely. These are always active and do not require consent.
(b) Analytics / performance. We use our own cookieless website measurement, running on our own servers, to understand aggregate traffic — which pages are read, roughly how long for, how far down the page people get, and which sites and search or AI tools send visitors to us. It sets no cookie, writes nothing to your device, and cannot follow you to any other website. We may additionally use a privacy-respecting third-party service such as Cloudflare Web Analytics, which is also cookieless, for country-level and page-speed reporting.
Because we set no identifier, we work out whether two page views came from the same person by combining your IP address and browser user-agent with a secret value that changes every day and turning the result into an irreversible code. The daily secret is permanently deleted after two days. From that point the stored records cannot be linked back to you or to each other — not by us, and not by anyone who obtained the data. A consequence worth stating plainly: we cannot recognise a returning visitor across days, and we have chosen that trade deliberately. We do not store your IP address, and we discard the query string of any address you arrive on. Records are deleted after 400 days.
If we later adopt a cookie-based analytics service (such as Google Analytics 4), we will disclose it here and, where required, request your consent through a cookie-consent banner before it runs.
(c) Advertising. We do not currently use advertising or cross-site tracking cookies. If in the future we introduce advertising technologies, we will update this Policy, identify the providers, and — where required by law — obtain your consent through a cookie-consent banner before any advertising cookies are set.
Where a cookie-consent banner is presented, you can accept or decline the non-essential categories and change your choice at any time. Because our current analytics are cookieless and we run no advertising trackers, at present there is nothing non-essential to consent to.
A Cookie preferences control is available in the footer of every page. Opening it shows each category, whether anything in that category is currently in use, and lets you set or change your choice. Your choice is stored in a first-party cookie on this site for twelve months and is never shared. If we later add a category, or change what an existing one covers, we will ask again rather than carry your previous answer over.
8. How We Use Information
We use the limited information described above only to:
- Fulfill and support your purchase (deliver license keys for the Desktop edition, and provide customer support for either edition);
- Respond to inquiries you send us;
- Operate, secure, and improve the Site;
- Comply with legal, tax, and accounting obligations; and
- Detect, prevent, and address fraud, abuse, or security issues.
We do not sell your personal information, and we do not use your information for third-party advertising.
9. How We Share Information
We share information only with:
- Our payment processors (our third-party merchant of record for Desktop purchases; Google Play for Android purchases) — to process payments and deliver licenses;
- Our form processor (Formspree) — to receive and forward contact-form messages;
- Our diagnostic endpoint provider (Cloudflare) — to receive and store the reports you choose to send us;
- Service providers who help us operate (for example, our website hosting and business email providers), bound to handle data only on our behalf;
- Authorities or third parties where required by law, to enforce our agreements, or to protect the rights, safety, and property of Red Warden or others; and
- A successor entity in connection with a merger, acquisition, or sale of assets, consistent with this Policy.
10. Data Retention
We retain the limited order and contact information described above only as long as necessary for the purposes set out in this Policy — for example, to provide support, honor your license, and meet tax and legal-record obligations — after which it is deleted or anonymized.
Diagnostic and content reports are retained separately. A report is automatically deleted from our diagnostic endpoint 90 days after it arrives. Where we have acted on a report, we keep the redacted copy as a support and quality record for as long as it remains useful for those purposes. Section 4 describes what a report contains and what within it is optional.
Because your conversations and app content otherwise remain on your own device, you control their retention and deletion directly.
11. Your Privacy Rights
EU / UK residents (GDPR). You have the right to access the personal data we hold about you, and to request its correction, deletion, or portability; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. Our lawful bases are performance of a contract (fulfilling your purchase), our legitimate interests (operating and securing the Site and preventing fraud), and consent (where a cookie banner applies, and where you choose to send us a report). You may also lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA). You have the right to know, access, delete, and correct the personal information we hold, and to be free from discrimination for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law — so there is no "Do Not Sell or Share My Personal Information" action required, though we honor these rights regardless.
Because most of your data never leaves your device, many of these rights you can exercise yourself directly within the app. For any personal information we do hold — such as purchase records, contact-form messages, or a diagnostic or content report you chose to send us — submit a request by emailing support@redwardenstudios.com, and we will respond as required by applicable law. If you are asking about a report, quoting the ticket reference you were given lets us find it immediately.
12. Children's Privacy
LLypses is intended for adults. LLypses for Android is distributed on Google Play with a declared target audience of 18 and over, and the Desktop edition and the Site are likewise not directed to minors. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us at support@redwardenstudios.com and we will delete it.
13. International Users
Red Warden Studios LLC is based in the United States. If you access the Software or Site from outside the United States, any limited information we handle may be processed in the United States or in the countries where our service providers operate. Third-Party AI Providers, our merchant of record, and our other processors may process data in their own respective locations under their own policies.
14. Security
We implement reasonable technical and organizational measures to protect the limited information we handle. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above and, where appropriate, provide additional notice. Your continued use of the Software or Site after changes take effect constitutes acceptance of the revised Policy.
16. Contact Us
If you have questions about this Privacy Policy or your information, contact:
Red Warden Studios LLC United States support@redwardenstudios.com
© 2026 Red Warden Studios LLC. All rights reserved.