Privacy and data boundary

Redact Crash Reports in a Local AI App

Keep prompts, transcripts, images, and documents out of default diagnostics.

Last reviewed: 2026-09-16 · Fact IDs: ANDROID-PRIVACY-01, PRIVACY-01

Direct answer

On-device inference narrows one data flow. Permissions, downloads, purchases, telemetry, backups, logs, clipboard, and sharing remain separate boundaries.

This page does not publish benchmark or compatibility results. It shows the evidence required to answer local AI crash report privacy without turning an assumption into a product claim.

Evidence to collect

The claim becomes reviewable only when the following evidence is attached to the same artifact and test run:

  • Release logging policy
  • Failure-path review
  • Opt-in diagnostic export

A privacy claim needs a data inventory and traffic evidence. A local-model label by itself is not proof.

Implementation workflow

  1. Inventory every content and metadata type.
  2. Enumerate every destination and trigger.
  3. Map user action to code path and request fields.
  4. Verify the core task in airplane mode.
  5. Capture traffic for setup, inference, diagnostics, and export.
  6. Update public disclosure in the same release as behavior.

Keep each transition observable. A failure should identify the stage, artifact, runtime, and recovery action without logging private user content.

Failure patterns to prevent

  • Dumping full requests
  • Calling metadata anonymous without fields

Also prevent silent fallback, unpinned artifacts, missing cancellation, and conclusions that combine unlike configurations. Store unsuccessful runs alongside successful ones.

Minimum reproducibility record

LayerRecord
DeviceManufacturer, model, chipset, RAM class, operating-system build
SoftwareApplication version and git commit
ModelFamily, variant, revision, format, file length, hash, quantization
RuntimeName, revision, requested backend, observed backend evidence
WorkloadFixture revision, input hash, prompt hash, output policy
OutcomeCompleted, failed, cancelled, fallback, and privacy-safe diagnostics

Release checklist

  • ☐ The primary query is answered without an unsupported number.
  • ☐ Every artifact and runtime is pinned.
  • ☐ The representative task and failure policy are explicit.
  • ☐ Lifecycle, cancellation, cleanup, and fallback are tested.
  • ☐ User-content and network boundaries are documented.
  • ☐ Result wording applies only to the recorded configuration.
  • ☐ The page links to raw method or evidence when results are added.

Sources and related evidence

Chinese deployment and troubleshooting content is organized in the 奇连 AI 端侧专题.