Privacy Policy for Mouture

Publisher: Advisely (“Doppio-Lab”, “we”, “us”, “our”)

Application: Mouture — a private, on-device Android launcher and AI assistant (com.doppio.android.mouture)

Effective date: September 10, 2026

Contact: hello@doppio-lab.com

1. In short

Mouture is designed to keep your data on your device. We do not require an account, we do not build a profile of you, and by default we collect no analytics or usage data about you.

A small number of clearly listed features connect to the internet — the weather forecast, the one-time download of the on-device AI model, purchases and subscription status, remote configuration, email if you connect an account, and (only if you opt in) anonymous diagnostics. Everything else — your app usage, calendar, contacts, notes, and every AI conversation — is processed locally and never leaves your phone.

Two of those calls are not optional and we would rather say so plainly: the subscription check runs on every launch for every user, and remote configuration is fetched when the app checks the AI model catalogue. Neither carries anything personal, but neither is covered by the diagnostics opt-in either.

You can verify these claims in the app’s Privacy Center (Settings → Privacy), which shows a live view of what Mouture accesses and lets you delete on-device data at any time. For the network side, Every connection Mouture makes lists each host and shows you how to capture the traffic yourself.

2. Who is responsible for your data

The data controller for any personal data processed through Mouture is:

Advisely

35 rue Pouchet, 75017 Paris, France

hello@doppio-lab.com

For most of what Mouture does, there is no controller relationship at all, because the data is processed entirely on your device and is never transmitted to us or anyone else.

3. Data processed only on your device (never transmitted)

The following are read and used exclusively on your device. They are not sent to us, and we have no ability to access them:

DataWhy it is usedWhere it stays
App usage (which apps you open and when) Suggestions, smart folders, digital wellbeing, AI insights On device
Calendar events Showing your agenda; optional correlation with app usage for reminders On device
Contacts Making contacts searchable from the launcher (opt-in) On device
Notes The notes you write in Mouture On device
AI conversations & prompts Running the on-device assistant On device
Email messages & attachments Showing your inbox in Mouture (opt-in) On device — fetched from your own mail provider, never through us (see 4.6)
Home layout, folders, gestures, preferences Your launcher configuration On device
Learned patterns and predictions Proactive suggestions and reminders On device

The AI assistant runs a language model locally using Google AI Edge LiteRT-LM. Your prompts and the assistant’s answers are processed on the device’s own hardware and are not sent to any server for inference.

4. Data that may leave your device

Mouture connects to the internet only for the specific purposes below. Each one is limited to what the feature strictly needs. A plain-language version of this section, with the exact hosts, when each one fires, and how to verify the traffic yourself, is on Every connection Mouture makes.

4.1 Weather (approximate location)

To show local weather, Mouture sends your approximate (coarse) location to Open-Meteo (api.open-meteo.com), a free, key-less weather API. No account or precise GPS location is used, and the request contains no identifier that ties it to you.

4.2 On-device AI model download

When you tap Download for the AI assistant — which only happens after you subscribe to Mouture Pro, never on install — Mouture downloads the model file (~557 MB) from Hugging Face (huggingface.co). This is a standard file download; nothing about you is sent beyond the request metadata any download carries, and once downloaded the model runs fully offline. The download location is read from remote configuration (see 4.4) so a model can be corrected without an app update.

4.3 Optional diagnostics — off by default

If — and only if — you turn on “Usage analytics & crash diagnostics” (Settings → Privacy Center), Mouture shares anonymous feature-usage events and crash reports through Google Firebase Analytics and Firebase Crashlytics to help us fix bugs and improve the app. This setting is disabled by default and can be turned off at any time. We never include your notes, messages, contacts, calendar content, or anything that identifies you.

4.4 Remote configuration

Mouture uses Firebase Remote Config to fetch non-personal configuration — specifically the AI model catalogue (the model’s URL, version, size and checksum). This fetch happens when you tap Download for the model, not at launch. It is not covered by the diagnostics consent in 4.3: it is a functional call, and it involves a Firebase installation identifier managed by Google’s SDK. That identifier does not identify you personally.

4.5 Purchases and subscriptions

The RevenueCat SDK is initialised when Mouture starts and asks whether this installation has an active Pro entitlement. This happens on every launch, for every user, including users who have never purchased anything, because the app has to know which features to unlock. RevenueCat receives a pseudonymous app-user identifier and, if you have purchased, purchase metadata. It is not covered by the diagnostics consent in 4.3.

The purchase itself is handled by Google Play Billing. Payment card details are handled by Google and are never seen by us.

4.6 Email (opt-in)

If you connect an email account, Mouture acts as a plain IMAP client: it connects directly to the mail server you specify (for example imap.gmail.com) to fetch your messages, and syncs periodically — roughly every 30 minutes — while an account is connected. Your credentials are stored on the device, encrypted with the Android Keystore, and your messages are stored on the device.

This traffic goes to your mail provider, chosen by you. It does not pass through any server operated by us, and we never see your credentials or your mail. The email module is off by default; removing the account stops the syncing and deletes the locally stored messages.

5. Permissions we request and why

PermissionPurposeOptional?
Internet / Network state Weather, model download, purchases, remote config, email sync, opt-in diagnostics Required for those features
Approximate location (ACCESS_COARSE_LOCATION) Local weather Yes — decline to disable weather-by-location
Usage access (special access) App-usage suggestions, wellbeing, AI insights Yes — grant in system settings
Calendar (READ_CALENDAR) Show your agenda; optional usage correlation Yes
Contacts (READ_CONTACTS) Search contacts from the launcher Yes (opt-in)
Notifications (POST_NOTIFICATIONS) Reminders and briefings Yes
Notification policy / Do Not Disturb Focus features Yes
Request delete packages Let you uninstall apps from the launcher Used only when you choose to uninstall

You can grant or revoke each permission at any time in Android system settings. Denying a permission disables only the feature that needs it.

6. Legal bases (GDPR / UK GDPR)

Where the GDPR applies, we rely on the following legal bases:

7. Third-party services (sub-processors)

We do not sell your personal data. We do not share it with third parties except through the services strictly required to run the features above:

ServicePurposeData involvedTheir policy
Open-Meteo Weather forecast Approximate location open-meteo.com/en/terms
Hugging Face One-time AI model download Standard request metadata (e.g. IP) huggingface.co/privacy
Google Firebase (Analytics, Crashlytics, Remote Config) Opt-in diagnostics; app config Anonymous events/crash data; installation ID firebase.google.com/support/privacy
Google Firebase (Hosting) Serving this website None. The site has no form, sets no cookies and stores nothing about you. firebase.google.com/support/privacy
Google Play Billing Payment processing Handled by Google policies.google.com/privacy
RevenueCat Subscription management (checked on every launch) Pseudonymous app-user ID, purchase metadata revenuecat.com/privacy
Your mail provider (opt-in) Fetching your email over IMAP Your credentials and messages, sent directly to the server you chose — not to us Set by your provider

8. Data retention

Uninstalling Mouture removes all on-device data.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability.

For EEA/UK users (GDPR): you also have the right to lodge a complaint with your local data protection authority.

For California users (CCPA/CPRA): we do not sell or “share” your personal information, and we do not use it for cross-context behavioral advertising. You may exercise your rights by contacting us at hello@doppio-lab.com. We will not discriminate against you for exercising them.

10. Children’s privacy

Mouture is not directed to children under the age of 13 (or the minimum age required in your country), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Security

Your data is stored in the app’s private storage on your device and protected by Android’s application sandbox and the device’s own security (lock screen, encryption). Network requests use HTTPS. Because most processing is local, the primary safeguard for your data is the security of your device itself. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

12. International data transfers

The optional third-party services above (Google, RevenueCat, Hugging Face, Open-Meteo) may process data on servers located outside your country, including the United States. Where required, these transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses, as described in the providers’ respective privacy policies.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated “Effective date” and, where appropriate, announced in the app or on our store listing. Continued use of Mouture after an update constitutes acceptance of the revised policy.

14. Contact

Questions or requests about this policy or your data:

Advisely

35 rue Pouchet, 75017 Paris, France

hello@doppio-lab.com