ForeverLM ("the app", "we", "our") is an independent app developed by Maarten de Vries. Contact: [email protected].
Except for the optional always-on MCP cache described in Section 5, ForeverLM servers do not store your source library or study history. This means:
All app data is stored in your private iCloud container (iCloud.com.foreverlm). In the current app implementation this means a SQLite database plus source files rooted inside the app container. This includes:
iCloud storage is governed by Apple's Privacy Policy at apple.com/legal/privacy. Data is encrypted in transit and at rest by Apple.
Your ForeverLM account session is stored in your device's Keychain. No OpenRouter, Ramp Router, or lab-provider inference key is shipped in the app. If you enable always-on MCP, the additional storage described in Section 5 applies.
Built-in AI requests pass through ForeverLM-operated Cloudflare infrastructure to the OpenRouter or Ramp Router rail you explicitly select. Neither provider is used as an automatic fallback for the other. The content sent can include:
The managed proxy stores billing metadata such as selected provider, model, token counts, exact cost, request identifier, and your Apple-assigned account identifier. It does not add source text or prompt bodies to the billing ledger. Upstream handling of request content is governed by OpenRouter's privacy policy or Ramp's Privacy Center, according to the provider you select.
If you enable always-on MCP, you explicitly authorize a separate CloudKit web session for ForeverLM-operated Cloudflare infrastructure. The service uses that session to read and write the same private Knowledge zone as your apps when no ForeverLM device or browser is running.
The service stores the revocable CloudKit session plus an account-scoped cache of synced source metadata, Project and Schedule relationships, and saved review sessions. This cache can include review transcripts and study state. Original source files remain in iCloud. Readable source text is fetched from iCloud only when an MCP tool asks for it and is returned in that MCP response without being added to the hosted cache.
MCP requests and responses pass through ForeverLM-operated Cloudflare infrastructure. We do not intentionally log MCP request or response bodies, but the connection is a trusted service and is not end-to-end private from ForeverLM infrastructure. Relay and authorization metadata includes OAuth credentials, tunnel records, tokens, connection status, and synchronization timestamps.
You can disconnect always-on MCP at app.foreverlm.com/mcp-connect.html. Disconnecting deletes the hosted CloudKit session and synchronized cache. It does not delete your private iCloud library.
ForeverLM offers optional account connectors. They run only after you explicitly connect them and grant access.
YouTube. ForeverLM uses YouTube API Services to import the videos you have liked on YouTube. Connecting YouTube grants ForeverLM read-only access (the youtube.readonly scope) to your liked-videos feed. ForeverLM reads the title, video ID, position, and uploading channel of each liked video and stores them in your own knowledge base on your Mac and in your private iCloud container. ForeverLM does not read, modify, or upload anything else in your YouTube account.
Google Drive. Google Picker uses the per-file drive.file scope to let you choose a meeting folder. Because Google does not extend that permission to the files inside a selected folder or to files added later, the connector separately requests the read-only drive.readonly scope. That scope permits reading files across your Drive; ForeverLM's connector traverses and imports only folders you explicitly link. Drive OAuth tokens are stored in your Apple Keychain and are not sent to ForeverLM servers. After you connect a folder, ForeverLM refreshes it when the Google Drive tab opens, when the app becomes active, or when you refresh Studio.
X. The X connector uses ForeverLM's production OAuth client to request bookmark.read, tweet.read, users.read, tweet.write, and offline.access. It reads bookmarks from the X account you authorize and can publish a post only when you explicitly ask it to. X OAuth tokens are stored in your device Keychain. Imported posts are saved directly to your knowledge base and private iCloud container; ForeverLM's infrastructure does not receive your X tokens or bookmark collection.
If you later open or review an imported video, document, or post, its transcript or text is stored with the source. As described in Section 4 and Section 5, source content you choose to review may be sent through managed AI to the OpenRouter or Ramp Router rail you selected, or to an AI assistant you have connected over MCP. ForeverLM does not otherwise share connector data with third parties.
By using the YouTube connector you agree to the YouTube Terms of Service. Google's handling of any data it receives is governed by the Google Privacy Policy. You can revoke ForeverLM's access to your Google account at any time from the Google security settings page.
X's handling of data is governed by the X Privacy Policy. You can disconnect X in ForeverLM at any time or revoke ForeverLM from your X account's connected-app settings.
ForeverLM requests microphone access for dictation and realtime voice conversations. When you use voice input:
ForeverLM's infrastructure does not receive or store realtime voice audio. It receives metering totals needed to debit your prepaid balance. The selected provider processes the audio and conversation for the duration of the session under its own privacy policy.
ForeverLM uses Sign in with Apple for authentication. When you sign in:
When you use the browser billing dashboard, ForeverLM stores the managed account session in a secure, HTTP-only browser cookie. The session expires automatically and can be removed immediately by signing out.
Sign in with Apple authentication is governed by Apple's Privacy Policy.
Prepaid AI-balance purchases and optional auto top-up setup use Stripe-hosted Checkout. Stripe stores and processes your payment details and collects your billing location and any optional business tax identifier to calculate tax. ForeverLM does not receive your full card number and does not store your full billing address.
For billing we store your Stripe Customer and PaymentMethod identifiers, selected trigger and target balances, monthly auto top-up limit, consent timestamp, payment status, and prepaid-balance ledger. Auto top-up is off by default, requires explicit setup, and can be disabled in Settings at any time.
The browser billing dashboard reads that same server ledger to show account-wide usage by date, model, feature, and device. It does not send your source content to the website.
ForeverLM does not integrate any third-party analytics SDK (such as Firebase, Mixpanel, or Amplitude).
If you have opted in to sharing analytics with app developers in macOS settings, Apple may provide us with aggregated, anonymized crash reports and basic usage metrics. This data does not include personally identifiable information. You can opt out in System Settings → Privacy & Security → Analytics & Improvements.
On macOS, ForeverLM can read your Safari Reading List bookmarks to automatically surface recently saved articles. This data is:
~/Library/Safari/Bookmarks.plistThis feature requires you to grant Full Disk Access in macOS System Settings. You can revoke this permission at any time.
ForeverLM is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information through the app, please contact us at [email protected].
You can permanently delete your managed ForeverLM account in the iPhone app at Settings → Delete Account. A fresh Sign in with Apple confirmation revokes ForeverLM's Apple authorization before deletion removes your Apple-assigned account identifier, managed-AI balance, usage and MCP metering history, saved Stripe billing link, and auto top-up configuration. The app then removes its session from your device Keychain.
We retain only a one-way hash that cannot be used to sign in or recover your account, to support account deletion, ledger integrity, and abuse prevention, including keeping the one-time starter balance from being claimed repeatedly. Stripe may retain transaction records it is legally required to keep.
Deleting the managed account does not delete your private iCloud source library. That library belongs to your Apple account and remains under your control:
Related app data may also exist in:
If we make material changes to this privacy policy, we will update the effective date at the top of this page and, where appropriate, notify users within the app. Continued use of the app after any changes constitutes acceptance of the updated policy.
Questions or concerns about this privacy policy?
Email: [email protected]
Website: foreverlm.com