Skip to content
LiBarAI · Privacy

LiBarAI privacy policy

LiBarAI is a local iPhone client for viewing AI-provider usage limits. Credentials and usage history stay on the device; GMAC cannot access them.

Effective date: 22 July 2026.

LiBarAI is developed by GMAC, Makowa 7, 66-431 Janczewo, Poland, NIP PL5992961187. Privacy questions can be sent to .

Last updated · 22 July 2026

01

Summary

LiBarAI is a local iPhone client for viewing usage limits from AI providers selected by the user. LiBarAI has no GMAC-operated account system, backend, advertising SDK, analytics SDK, or tracking SDK. GMAC does not collect, receive, store, or have access to provider credentials, provider account details, usage limits, usage history, or notification settings processed by the app.

The app connects directly to the selected provider. That provider receives and processes the request under its own terms and privacy policy. Provider processing is separate from GMAC and may include an account identifier, request or interaction logs, IP-derived approximate location, and other connection metadata.

02

Data stored on the device

LiBarAI may process and store the following data locally:

  • provider credentials, such as API keys, session credentials, and OAuth tokens, in iOS Keychain;
  • provider, account label, region, and any account name or email returned by the provider;
  • usage-limit snapshots, reset times, plan information, and up to 14 days of locally generated usage history;
  • app settings, alert thresholds, widget settings, and Live Activity preferences.
03

Provider connections and sign-in

Limit refreshes are sent over HTTPS directly from the device to Claude (Anthropic), Codex (OpenAI), GLM (Z.ai), Kimi (Moonshot AI), or MiniMax, depending on the accounts configured by the user. Credentials are sent only to the provider to authenticate these requests; they are never routed through a LiBarAI or GMAC server.

Claude and MiniMax credentials are pasted into LiBarAI by the user. Codex uses a device-code flow and opens the provider's verification page in the system browser. LiBarAI does not embed provider websites.

Non-credential data used by widgets and Live Activities is stored in the app's private App Group container. At the user's request, selected limit information may appear in widgets, local notifications, StandBy, or a Live Activity, including while the device is locked.

Each provider controls its own processing and retention. Before connecting an account, review the applicable provider policy:

04

Provider service status

LiBarAI also requests public provider-status information where available. These requests do not include provider credentials, but the status host receives ordinary connection metadata such as the device's IP address.

05

Purchases and Apple services

The optional LiBarAI Pro purchase is processed by Apple through StoreKit and the App Store. GMAC does not receive payment-card details. The app receives only the transaction and entitlement information needed to unlock Pro. Apple's processing is governed by the Apple Privacy Policy: https://www.apple.com/legal/privacy/

Local notifications, widgets, and Live Activities use Apple system frameworks. LiBarAI does not operate a push-notification server.

06

Demo mode

Explore demo creates read-only sample accounts and usage history locally. It does not create provider credentials and does not contact provider usage or status services. Leaving demo restores the preceding local account state.

07

Retention and deletion

Usage history is kept locally for up to 14 days. Other account data remains on the device until the account is removed or the app's data is erased. Removing an account in LiBarAI deletes its credential from Keychain together with its profile, current snapshot, and history.

Deleting the app removes its sandbox and App Group data. iOS may retain Keychain items after an uninstall, so users who want credentials removed should delete each account inside LiBarAI before uninstalling.

GMAC cannot retrieve, export, correct, or delete provider or local app data because GMAC does not receive it. Provider-data requests must be directed to the relevant provider under its policy.

08

Security

Provider credentials are stored with Keychain protection available after the first device unlock so scheduled refresh can work while the device is locked. Network requests use HTTPS. No method of storage or transmission is completely risk-free; users should remove an account immediately if a credential may have been exposed or revoked.

09

Children

LiBarAI is not directed to children and does not knowingly collect children's personal data. A connected provider's age requirements continue to apply.

10

Changes and contact

This policy may be updated when LiBarAI's features or legal requirements change. The effective date above identifies the current version. Questions about LiBarAI can be sent to . Questions or requests about data processed by a supported provider should be sent to that provider.