Skip to content

Third-Party Provider Disclosure

Last updated: 20 August 2026

The default: the model runs on your computer

Out of the box jhint answers with a model running on your own computer. The app ships with the inference engine inside it (llama-server, from the open-source llama.cpp project) and, the first time you use it, downloads the model weights you choose from Hugging Face. Speech recognition already runs on-device. In that configuration your conversation content is not sent to any model provider — including us.

Two things do involve the network even then, and they are ordinary file downloads rather than conversation data: fetching the model weights themselves, and refreshing the list of models the app offers from updates.jhint.ai. Both are described in the Privacy Policy.

Choosing an external provider is a deliberate act: the app shows what the service is, what categories of data will leave your computer, and links to that provider’s terms, and it will not route anything externally until you accept that disclosure. If the disclosure text changes in a new version, the app asks again rather than assuming the old answer.

Model providers you can choose

Eleven entries. The first one is built in; the rest are optional and configured by you. External requests go from your computer directly to the provider — never through our servers.

ProviderWhere it runsCredentialsTerms
Built in — default, the bundled engine running the model you downloadedYour machineNoneApache-2.0 and MIT models only; the licence of each model ships next to its files
Ollama — local models on your computerYour machineNoneollama.com
LM Studio — local models on your computerYour machineNonelmstudio.ai
Claude APIAnthropicYour API key, in Keychainanthropic.com
ChatGPT APIOpenAIYour API key, in Keychainopenai.com
Gemini APIGoogleYour API key, in Keychainai.google.dev
GroqGroqYour API key, in Keychaingroq.com
OpenRouter — router in front of many vendorsOpenRouter and the vendor it routes toYour API key, in Keychainopenrouter.ai
OpenAI-compatible endpoint — any address you enter, including your own serverWherever you point itYour API key, in KeychainWhatever applies to that endpoint

We have no partnership or affiliation with any of these companies, and we do not resell their capacity. Their pricing, rate limits and data-retention policies are between you and them — we have no control over how long they keep what you send, and no access to your account there.

What is actually sent

Only when you press Answer, and only what the current session’s switches allow. By default that is the current question alone.

  • Recent conversation context — off until you turn it on, per session.
  • Your profile (what you told the app about yourself) — off until you turn it on.
  • Screenshots — only ones you took yourself, and you see a preview before they go. A screenshot travels inside the request itself and is never written to disk.
  • Your system prompt — the instruction you wrote for the session.
  • The answer language, if you chose one for the session.

Audio never goes anywhere. It is recognised on your computer and discarded; no provider receives sound, only text you chose to send.

A filter runs before every external request and blocks the send if it cannot confirm the payload matches what you allowed — it fails closed rather than sending something extra.

When the built-in model searches the web

This is the one case where the app itself goes out to a third party rather than sending your request to a provider you chose. It is off until you turn it on, and turning it on asks you to accept a separate notice.

WhatDetail
Who receives itThe search engine — DuckDuckGo, whose applicable machine-readable rules currently permit the endpoint jhint uses. There is no choice of engine and no default we picked for you elsewhere.
Where the request comes fromYour computer, your connection, your IP address. Not our servers.
What it containsA query the model composes from what it was given, which can include what other people said in your conversation. The app shows you every query.
What it does not containSecrets, credentials and payment details: a filter blocks the send outright rather than trimming it. No logins, and no cookies from your browsers.
What is read backOnly pages that appeared in that search, over https, and only where the site’s own machine-readable rules allow it. Untrusted text: instructions inside a page cannot change what the model may do.
What we never doWork around a block, a CAPTCHA or any technical control. If a search is challenged, it fails and says so.

DuckDuckGo is a third party we have no relationship with. It sees what any visitor’s browser would show it, and its own privacy policy governs that.

What we never do

  • No shared developer key. There is no account of ours behind the models — you connect your own.
  • No proxying. Your prompts do not pass through our servers on the way to a provider.
  • No credential harvesting. We never read browser cookies or OAuth tokens to reuse someone’s session.
  • No key exfiltration. API keys live in the macOS Keychain, never in settings files, logs or prompts, and are never sent to us.
  • No claimed partnerships. We do not describe a third-party service as if it were our own model.
  • No executing model output. Whatever a model returns is displayed, never run.

Infrastructure behind jhint

Separately from the models, these services keep the product itself running. None of them ever receives your conversations.

ServiceWhat it doesWhat reaches it
PaddleMerchant of record: sells the subscription, charges tax, issues invoicesYour payment details — held by Paddle, not by us
CloudflareHosts this site, the licence service and its database, and forwards support mailLicence key, installation identifier, subscription status, the email address your licence is registered to
ResendDelivers the one email with your licence keyYour email address, at the moment of sending
updates.jhint.ai (Cloudflare R2)Serves app updates and the list of models the built-in engine offersA file download request: the version you run and your IP address
Hugging FaceHosts the speech-recognition and language model filesA file download request, nothing about you

The Privacy Policy sets out exactly which fields are stored and for how long.

Changes to this disclosure

This document is versioned, and so is the disclosure inside the app. Adding a provider or changing what is sent means a new version — and the app asks for your acceptance again before routing anything externally under it. Silent expansion of what leaves your computer is precisely the thing this page exists to prevent.

Questions about this document? Write to support@jhint.ai .