The most private AI assistant is one that runs entirely on hardware you own, because your requests never reach a server at all. Among the big names, Siri keeps the most on the device and sends heavier requests to Apple’s Private Cloud Compute. Gemini and ChatGPT process chats in the cloud and can use them to improve their models unless you change a setting. Alexa sends voice requests to Amazon’s cloud.
The trade-off is what an assistant can do. A local model can’t dim your lights, set a timer on a speaker, or tell you tomorrow’s weather. Most people end up with two: the built-in assistant for tasks, something local for anything personal.
How do the major AI assistants handle your requests? #
| Assistant | Where your request is processed | Used to improve models? | Human review | Main privacy controls |
|---|---|---|---|---|
| Siri and Apple Intelligence | On the iPhone for many requests; Apple’s Private Cloud Compute for heavier ones; OpenAI only if you turn on the ChatGPT extension | Siri audio only if you opt in to “Improve Siri & Dictation” | Only for opted-in audio samples | Analytics & Improvements; ChatGPT extension toggle |
| Google Gemini | Google’s cloud, with some small Gemini Nano features on recent Pixels | Yes, while Keep Activity is on | A subset of chats, disconnected from your account and kept up to three years | Turn off Keep Activity; temporary chats |
| ChatGPT | OpenAI’s cloud | By default on consumer plans unless you turn it off | Possible, under OpenAI’s policies | Data Controls; Temporary Chat |
| Amazon Alexa | Amazon’s cloud; the wake word is detected on the device | Amazon uses voice data to improve its services, subject to your settings | Governed by your Alexa Privacy settings | Alexa Privacy; voice history deletion |
| Home Assistant Assist | Your own hardware at home, if you configure it that way | No | No | You run it |
| Local model app | On your phone | No | No | Delete the chat |
Google’s Gemini privacy notice is unusually direct: a subset of chats is read by human reviewers, including trained service providers, reviewed chats are kept up to three years even if you delete your activity, and with Keep Activity off chats are still held for 72 hours. That’s ordinary for cloud AI. It’s worth knowing before you ask about a rash or a debt.
What happens to your voice, step by step #
A spoken request goes through four stages, and each one can happen on the device or in the cloud:
- Wake word. Listening for “Siri,” “Hey Google” or “Alexa.” This is almost always on the device, and audio before the wake word isn’t meant to leave it.
- Speech to text. Turning your voice into words. On-device on many recent phones for supported languages.
- Understanding and answering. Working out what you meant and producing a reply. This is where most assistants call a server, especially for anything that needs a real answer.
- Reading it back. Text-to-speech, often on the device.
An assistant can be fully on-device for stages 1 and 2 and still send your request text to a server at stage 3. That’s why the honest answer to “is my assistant private?” is usually “partly.”
Three things go wrong in practice. False triggers, where the device mishears a phrase and records what follows. Storage, where requests sit in your account history. Human review, where staff or contractors read or listen to samples. False triggers aren’t hypothetical: in 2025 Apple agreed to pay $95 million to settle a US class action over Siri recordings made after accidental activations, while denying wrongdoing.
Why are smart speakers cloud-first? #
A speaker listens locally for its wake word, then streams what you say next to the company’s servers, which work out what you meant and send back an answer or a command. That design is what lets a cheap speaker feel smart, and it’s why your requests live in someone else’s data centre.
Home devices are more mixed than they used to be. Many cameras now detect people, pets and packages on the camera itself before deciding whether to alert you, and some hubs run automations locally so the lights still work when the internet is down. If that matters to you, look for on-device detection and local video storage rather than a cloud subscription, and check what stops working offline. None of it makes the conversational part private: asking a speaker a question still goes to the cloud.
Settings to change on Siri, Gemini and Alexa #
Siri on iPhone
- Settings, Privacy & Security, Analytics & Improvements: turn off Improve Siri & Dictation. If you opted in, Apple may review a subset of transcripts, and reviewed transcripts can be kept for more than two years.
- Open Siri & Dictation History in Siri settings and delete it.
- Turn off Siri on the lock screen so nobody can use it without unlocking the phone.
- Switch off the wake word if you only ever use the side button. That removes false triggers completely.
- Leave the ChatGPT extension in Apple Intelligence off unless you want those requests sent to OpenAI.
- Apple’s Siri and Dictation privacy page says your device indicates in Siri settings whether what you say is processed on the device, so check there rather than guessing.
Gemini on Android
- Turn off Keep Activity in Gemini Apps Activity, from the Gemini app or at myactivity.google.com.
- Remember the 72-hour rule: even with it off, Google keeps chats with your account for up to 72 hours to respond and for safety.
- If you keep activity on, shorten auto-delete. The default is 18 months and you can choose 3.
- Turn off “Hey Google” and Voice Match if you don’t use hands-free activation.
- Review lock-screen access so the assistant can’t be used from a locked phone.
Alexa
- In the Alexa app, open Alexa Privacy and review your voice history.
- Set recordings to delete automatically, and delete what’s already there.
- Turn off the use of your recordings to help develop Amazon’s services.
- Use the physical microphone button when you want the speaker deaf. On most Echo devices a red ring confirms it.
Menu names move between versions and phone brands. If a path above doesn’t match, search your settings app for “voice,” “activity” or “recordings.”
Other voice risks worth knowing #
- Voice cloning. A few seconds of recorded audio can be enough to fake a voice on a phone call. Agree a family code word and don’t treat a familiar voice as proof of identity. We cover the scam pattern in AI voice cloning scams.
- Shared speakers. Anyone in the room can ask for your calendar, messages or shopping list. Turn off personal results on devices in shared spaces.
- Linked services. An assistant that can reach your email, calendar and payments is only as private as its weakest integration.
Assistants that keep everything at home #
If you want a speaker-style assistant that never contacts a cloud, Home Assistant’s Assist is the most mature option. It can run speech recognition, command handling and speech output on your own hardware, control smart home devices, set timers and answer from your own data. The catch is setup: you need a Home Assistant server running at home, and local speech recognition wants a reasonably capable machine. It’s a project, not a plug-in speaker.
OpenVoiceOS is the other name to know. Mycroft AI, the best-known open-source assistant, stopped development in early 2023 after a costly patent dispute, and the community carried the work on under the OpenVoiceOS name.
Where a local model on your phone fits #
For the questions you’d rather not hand to anyone, a model running on your phone removes the whole question of who else sees them. No server logs to breach or subpoena, no reviewer, no training on your chats, no account tying questions to your name.
Personal LLM is built for that job. It runs open models such as Qwen 3.5 4B, Gemma 4 E4B and GLM 4.6V Flash on your phone’s own chip, with no account and no server of its own. After the one-time model download from Hugging Face, the only network traffic is AdMob ads in the free version while you’re online, which is the one caveat on calling it fully private. It handles text and photos, answers questions about a PDF you attach, and reads answers aloud with on-device text-to-speech.
Two honest limits. It has no voice input: you type, or you use your phone keyboard’s own dictation, which on recent iPhones and many Android phones runs on the device. And it isn’t a voice assistant, so it won’t respond to a wake word, set timers or control your home. It’s the private option for conversation, not a Siri replacement.
What you give up with any local assistant is live information, since the model’s knowledge stops at its training date, and raw capability, since phone-sized models are smaller than the ones behind the big chatbots. What you keep is the part you actually wanted private. For what cloud providers do with the chats you do send them, see do humans read your AI chats, and to test any app’s claim yourself, how to tell if an AI app is really private.
Make a local model behave like an assistant #
A local model arrives with no personality and no memory of how you like to work, so give it both in a system prompt and save it in a dedicated chat:
You are my personal assistant. Be brief and practical. When I give you a task, break it into steps. When I ask for a list, keep it under 10 items. Ask one clarifying question if my request is vague.
From there it handles the assistant jobs that don’t need the internet: turning a brain dump into a to-do list, drafting replies to messages, planning meals from what’s in the fridge, summarizing a document you attach, rehearsing a hard conversation, or explaining a letter or a bill in plain language. More templates are in our system prompt examples.
Which one should you use? #
- Siri for phone control and hands-free tasks on a recent iPhone: timers, messages, settings, and anything you’d rather not stop driving or cooking for.
- Gemini or ChatGPT for current information and research that needs the web, on the understanding that those chats sit on someone else’s servers.
- A local model for a health worry, a budget with real numbers, a message about a coworker, a journal entry, or work drafts you can’t upload. It’s also the only one that works on a plane or with no signal at all.
Frequently asked questions #
Which AI assistant is the most private? #
One that runs on hardware you control: a self-hosted Home Assistant setup at home, or a local model app on your phone. Among mainstream assistants Siri does the most on-device processing and uses Apple’s Private Cloud Compute for heavier requests, while Gemini, ChatGPT and Alexa process requests on their companies’ servers.
Is Siri more private than Alexa? #
Generally yes. Many Siri requests are handled on the iPhone, and Siri audio is only used for improvement if you opt in, while Alexa sends voice requests to Amazon’s cloud. Both let you review and delete history, and both still need the internet for most answers.
Is my phone always listening to me? #
A small on-device model listens for the wake word, and audio before it isn’t meant to be recorded or sent. The real risk is false activation, when the phone mishears something and records what follows. Turning off the wake word removes that risk entirely.
How do I stop Google from saving my voice? #
Turn off Keep Activity in Gemini Apps Activity and delete your existing activity at myactivity.google.com. Google still keeps chats with your account for up to 72 hours for safety and to respond, even with the setting off.
Can a local AI replace Siri or Google Assistant? #
Not entirely. It can’t control your phone, set alarms or search the web, and it knows nothing after its training cutoff. It can replace them for private conversations, writing help, planning and questions that don’t need current information.
Can I use an AI assistant without internet? #
Yes, if the model is on your device. An app like Personal LLM downloads an open model once and then works in airplane mode, writing, summarizing, explaining and describing photos. It can’t fetch live information such as weather, news or prices.