LocalAI

Legal

Privacy Policy

Effective Date: May 15, 2026

1.Introduction

LocalAI ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the LocalAI platform.

This policy is compliant with the Nigerian Data Protection Regulation (NDPR) 2019, issued by the National Information Technology Development Agency (NITDA).

By using LocalAI, you consent to the collection and use of your information as described in this policy.

2.Information We Collect

2.1 Information You Provide

When you create an account and use LocalAI, we collect:

  • Account information — Full name, email address, phone number, and password
  • Business information — Business name, category, WhatsApp number, and business description
  • Product information — Product names, descriptions, prices, stock levels, and photos you upload
  • Order information — Customer names, phone numbers, delivery addresses, and order details
  • Payment information — Subscription plan and billing details (processed by Paystack; we do not store your card details)
  • Team member information — Names and emails of team members you invite

2.2 Information We Collect Automatically

When you use our Service, we automatically collect:

  • Usage data — Features you use, pages you visit, and actions you take on the platform
  • Device information — Browser type, operating system, and device identifiers
  • Log data — IP address, access times, and referring URLs
  • Analytics data — Order counts, revenue figures, and product performance data

2.3 Information from Third Parties

We may receive information about you from:

  • Paystack — Payment confirmation and subscription status (not full card details)
  • Supabase — Authentication and session management data

3.How We Use Your Information

We use your information to:

  • Create and manage your LocalAI account
  • Provide, operate, and improve the Service
  • Process your subscription payments through Paystack
  • Generate AI marketing content based on your business context
  • Send you service-related notifications and updates
  • Respond to your support requests and enquiries
  • Monitor and analyse usage patterns to improve the platform
  • Comply with legal obligations under Nigerian law
  • Detect, investigate, and prevent fraudulent or illegal activity

We do NOT sell your personal data to third parties. We do NOT use your data for advertising purposes outside of LocalAI.

4.How We Store and Protect Your Data

4.1 Storage

Your data is stored securely on Supabase infrastructure, which uses enterprise-grade PostgreSQL databases with encryption at rest. All data transmission between your browser and our servers is encrypted using HTTPS/TLS.

4.2 Row-Level Security

LocalAI implements Row-Level Security (RLS) policies on all database tables. This means your business data is isolated — only you and your authorised team members can access your account data. Our team cannot query your data without explicit authorisation.

4.3 Access Controls

Access to user data within our team is restricted on a need-to-know basis. All team members with data access are bound by confidentiality agreements.

4.4 Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • Your personal data is deleted within 30 days
  • Order and transaction records may be retained for up to 7 years for legal and tax compliance purposes
  • Anonymised analytics data may be retained indefinitely

5.Payment Data

All payment processing is handled by Paystack (paystack.com), a PCI-DSS compliant payment processor. LocalAI does not store, process, or have access to your full payment card details. Paystack's privacy policy governs how they handle your payment information.

6.AI and Your Business Data

When you use the AI marketing engine:

  • Your business name, product details, and campaign context are sent to Groq AI to generate content
  • Groq does not retain this data after processing your request
  • We do not use your business data to train AI models
  • AI-generated content is stored in your LocalAI account and only accessible by you

7.Sharing Your Information

We share your information only in the following circumstances:

  • Service providers — Supabase (data storage), Groq AI (content generation), Paystack (payments). These providers process data on our behalf and are bound by data processing agreements.
  • Legal requirements — We may disclose your information if required by Nigerian law, court order, or government authority
  • Business transfers — If LocalAI is acquired or merged, your data may be transferred to the new entity, subject to the same privacy protections
  • Your consent — We may share your information for other purposes with your explicit consent

We never sell, rent, or trade your personal information to third parties for their marketing purposes.

8.Your Rights Under NDPR

Under the Nigerian Data Protection Regulation (NDPR), you have the following rights:

  • Right to Access — Request a copy of the personal data we hold about you
  • Right to Rectification — Request correction of inaccurate or incomplete data
  • Right to Erasure — Request deletion of your personal data (subject to legal retention requirements)
  • Right to Object — Object to the processing of your data in certain circumstances
  • Right to Data Portability — Request your data in a structured, machine-readable format
  • Right to Withdraw Consent — Withdraw your consent to data processing at any time

To exercise any of these rights, please contact us at support@localaing.com. We will respond to your request within 30 days.

9.Cookies

LocalAI uses cookies and similar tracking technologies to:

  • Keep you logged in to your account (session cookies)
  • Remember your preferences and settings
  • Analyse how the platform is used (analytics cookies)

You can control cookie settings through your browser. However, disabling certain cookies may affect the functionality of the Service.

10.Children's Privacy

LocalAI is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.

11.Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the platform. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

12.Contact Us — Privacy

For any privacy-related questions, requests, or complaints, please contact our Data Protection Officer:

We take all privacy concerns seriously and will respond within 30 days.