Skip to content

Privacy Policy

Effective September 6, 2026

This policy describes how the open-source Mold project handles information on its public website and in the Mold apps that link to it: the mobile app for iPhone, iPad, and Android, and the desktop app for macOS, Linux, and Windows. Each is a client for Mold servers that you choose and control. The Mold project does not operate a central account service, hosted generation service, advertising network, or analytics service for these apps.

Website analytics

The public website at utensils.io/mold loads Google Analytics automatically when you visit, without a consent popup.

Google Analytics measures page visits, traffic sources, scrolls, outbound link clicks, and file-download clicks, along with browser/device information and approximate geographic information derived from your connection. It uses cookies scoped to this website to distinguish visits. We use these reports to understand which documentation is useful and how visitors find Mold. We disable Google signals and advertising personalization, do not enable form or site-search measurement, and remove query strings and fragments from the page URLs and referrers we explicitly send. Outbound and download measurements may include the destination link URL.

Google processes this website analytics data under Google's privacy policy. See also how Google uses information from sites that use its services. You can block Google Analytics with your browser's tracking protection or Google's Analytics opt-out browser add-on. You can remove existing cookies through your browser's site-data settings; removing cookies does not erase analytics data already collected.

This website analytics integration does not collect Mold prompts, generated media, server API keys, or usage of the CLI, desktop, mobile, or self-hosted Studio apps.

Information the apps store on your device

Mold stores the information needed to provide its features locally on your device, including:

  • saved Mold server names, addresses, and connection preferences;
  • server API keys — in the iOS Keychain on iPhone and iPad, encrypted with a non-exportable Android Keystore key (AES-GCM, alias com.utensils.mold.remote-api-key.v1) inside private app storage on Android, and in an owner-only application-data file on desktop;
  • appearance preferences, prompt templates, and other app settings; and
  • temporary media and response data needed to display your server's library.

The mobile apps use the platform's local network permission (Apple's Local Network permission on iOS, network service discovery on Android) to find Mold servers that advertise themselves on your current network. Mold does not use this permission to track your location.

Information sent to your Mold servers

When you use the app, it communicates directly with the Mold servers you add. At your direction, those servers may receive prompts, generation settings, source images, masks, model-download requests, and other content needed to perform the requested operation. The app also requests server status, model, queue, download, and gallery information.

Generated media, prompt history, generation metadata, downloaded models, and server logs are stored according to the configuration and practices of the server operator. If you connect to a server operated by someone else, contact that operator for its privacy and retention practices. The Mold project does not receive this server traffic merely because you use the app.

Third-party services

The Mold apps have no advertising or tracking SDKs. A Mold server may contact model catalogs such as Hugging Face and Civitai when you browse or download models. Those requests originate from the server and are governed by the service's policy and the server operator's configuration.

Apple may process TestFlight invitations, diagnostics, crash information, or feedback under Apple's privacy policy when you install a beta through TestFlight or submit feedback to Apple.

Sharing and sale

The Mold project does not sell personal information. The app does not share information with the Mold project, advertisers, or data brokers. Information is sent only to the servers and services described above when needed for an action you request.

Retention, deletion, and your choices

  • Forgetting a server in the app removes its saved connection and API key from the device.
  • Deleting the app removes its local app data according to the platform's own behavior.
  • Gallery media, prompt history, logs, and models stored on a Mold server must be deleted from that server or by its operator. Available gallery deletion controls act directly on the selected server.
  • You can deny local network access in your device's system settings and add a server address manually instead.

Because the Mold project does not maintain user accounts or receive app data, it ordinarily has no centrally stored personal information to retrieve or delete.

Children

Mold is not directed to children under 13, and the Mold project does not knowingly collect personal information from children through its apps.

Changes to this policy

We may update this policy when the website or apps' data practices change. The effective date at the top identifies the current version.

Contact

Questions about this policy can be sent to [email protected]. For information stored by a Mold server you do not operate, contact that server's operator.