

There’s only one thing you can do: stop using it, stop giving them [an opportunity to use your data for] money. Everything other solution is mediocre at best. Thanks for sharing, though.


There’s only one thing you can do: stop using it, stop giving them [an opportunity to use your data for] money. Everything other solution is mediocre at best. Thanks for sharing, though.


No, they’re just morons and sadists.


No, the actual AI runs locally, on the phone. What MLKit does is two things:
Downloads the actual AI models from Google’s servers — not sure, but maybe they can be bundled or downloaded from other sources.
Send the usage analytics about those models — again, don’t remember exactly what’s being sent but the actual prompts/source images/model responses shouldn’t be sent in normal operation.
Why I highlighted the normal operation thing is because Google is kinda famous for collecting data it shouldn’t be collecting, e.g. read this README for example: https://github.com/PlqnK/magisk-supl-replacer


Not to bash them or something, but just FYI: I got interested in how they’ve implemented AI client-side, and they use Android MLKit in their Android app for that.
The problem with MLKit is that it phones back to… ta-dam!.. Google, even if it’s not actually used by the app, and that telemetry can’t be legally (and neither in any convenient and reliable way te technically) disabled, even by the app developer.
It doesn’t seem to be sending any sensitive information in that telemetry, but I don’t know Rick: changing Google for… Google?



Yes, with something like OpenRouter (or Mistral’s own API) you should be able to integrate it everywhere. Also, OpenRouter, while being a US company AFAIK, seems to be pretty transparent and lets you evaluate a lot of models from different developers and running on different platforms.


I’ve used their devstral (latest one) + goose for a side project. It worked pretty decently, on par with Claude 3.7-ish Sonnet, maybe even better. And it’s not the largest: 123B. If you can have access to their larger models, that should be even better.


Thankfully, this particular kind of tracking can be reduced practically to 0 with good informational hygiene: don’t give location permissions to crappy apps. Basically, don’t give it to any app (yes, google apps included), unless you’re absolutely sure this app doesn’t spy on you — or even better — doesn’t have internet access at all. Make it a rule: an app should either access internet or access your location, but never both.
who we can trust with our personal data
Well, the answer to that question is extremely easy: “no one” :)
But that’s a nice article, thanks for sharing.


It has nothing to do with KeepassXC, it’s still early development and you won’t be able to backup or extract your passkeys because it stores them in the hardware secure element on the phone (if it’s available), but it works: https://git.noisruker.de/Juhu1705/open-passkey-authenticator
Yes, for small, especially non-IT businesses, it’s really hard. But thank you again for the article, I think we might (unfortunately) need such setup for different other things in the near future too.