What Data the App Stores on Your Device
The following data is stored locally in the app's sandbox container. If iCloud Backup is enabled on your device, iOS may include the container in a device backup:
- Notes, prompts, and skill recipes you add in the Library tab.
- Cached chat messages between you and the on-device model.
- User preferences (selected engine, UI state, onboarding completion).
AxisMCP also stores security credentials in the iOS Keychain, including the connection password, the local TLS identity, certificate pins, approved-device pairings, and any bearer tokens you configure for upstream MCP servers. These Keychain items are stored separately from the app's sandbox container.
Deleting the app removes its sandbox container from that device. iOS may retain Keychain items after an app is deleted, so AxisMCP does not promise that uninstalling removes every credential. Before uninstalling, you can replace the connection password with Create new password in Connect → Advanced or Settings → Advanced; this disconnects current clients and invalidates the previous password.
What Data Leaves Your Device
Nothing is sent to the developer.
AxisMCP opens a TCP listener on port 5648 on your local network and advertises itself via Bonjour as _axismcp._tcp. Trusted MCP clients on the same network can connect only after you approve their six-digit pairing code or when they present the connection password. If you enable Local Discovery Beacon, the app also broadcasts non-secret discovery details on the local network.
Clients must be approved on this device with a six-digit pairing code or use the fallback connection password. After approval, a client can receive only the Library content and tool results you allow. We do not operate a server, do not run a relay, and do not see this traffic. A connected client may process or forward data according to that client's own behavior and privacy policy.
When you run Chat, the prompt you type is processed on-device by Apple's Foundation Models framework. The prompt and the response never leave your device. We do not have a developer backend.
Apple Intelligence
If you choose to use Chat, the app calls Apple's Foundation Models framework (SystemLanguageModel). Apple processes the prompt and response on-device when Apple Intelligence is enabled and supported on your hardware. Otherwise, the app displays a status indicating that Apple Intelligence is unavailable. The app does not collect telemetry about which path is used.
For more information on Apple Intelligence and privacy, visit Apple's Apple Intelligence & Privacy Guide.
Children
The app is not directed at children under 13. We do not knowingly collect personal data from children. The app does not include any content that would be inappropriate for users of any age.
Permissions
The app requests the following permission on your device:
- Local Network: Used to listen for MCP client connections on your Wi-Fi or local network.
Third-Party Services
The app does not embed any third-party SDKs that collect data. The only frameworks used are Apple's Foundation Models, Network framework, SwiftUI, and standard Swift open-source cryptographic libraries.
If you connect an external MCP client (such as Cursor, Claude Code, VS Code, or Codex) to AxisMCP, that client is governed by its own privacy policy. You control client access at any time from the Server tab and Library Tool Access.
Required Reason APIs
The app's privacy manifest (PrivacyInfo.xcprivacy) declares Required Reason API usage for:
- System Boot Time (35F9.1): Used to log the boot timestamp when the MCP server starts.
- Disk Space (E174.1): Used to surface available storage in the Library tab.
- User Defaults (CA92.1): Used to persist on-device preferences and server options.
The privacy manifest declares no tracking (NSPrivacyTracking = false) and zero collected data types.
Data Retention & Your Choices
The app retains sandbox data until you delete individual items or remove the app. There is no developer-operated off-device data retention.
You can at any time:
- Delete all on-device sandbox data by removing the app.
- Reset or replace the connection password from Connect → Advanced or Settings → Advanced to immediately disconnect and invalidate existing clients.
- Forget individual paired computers at any time from the Server tab.
- Disable Apple Intelligence for the app from iOS Settings.
- Stop the local network listener using the Server toggle on the Server tab.
If you are located in the European Union / European Economic Area, you have the right to lodge a complaint with your local supervisory authority.
Contact
For privacy questions or data inquiries, email privacy@axismcp.tech. For product help and troubleshooting, visit Support.
Security vulnerabilities can be reported privately by email to security@axismcp.tech.