<!--
  Markdown representation of https://jotaid.com/privacy
  Generated by scripts/gen-markdown-variants.mjs — do not edit by hand.
  Served from the canonical URL under `Accept: text/markdown`.
-->

> By default, your note content stays on your device and in your personal iCloud account; Jotaid does not operate a server that receives notes. Selected content goes directly to your chosen provider when you invoke AI. On a Mac, turning on the knowledge base server also lets an agent you authorise read your notes locally (off by default). We do not sell data or use it for advertising or tracking. Release builds use Sentry for stability and diagnostic data that excludes note content and API keys.

## Data Collection

- By default, notes are stored on your device and in your personal iCloud account; opt-in AI is the exception described below.
- Jotaid does not operate a server that receives or stores note content; optional AI sends content you select directly to the third-party provider you choose.
- No advertising or user-tracking SDKs are used, and we never build an advertising profile of you.
- **Crash & diagnostics:** In release builds we use Sentry to collect crash reports, app-hang (freeze) reports, MetricKit stability signals, and a 20% sample of startup and frame-performance data. This helps us fix bugs. It may include device model, OS version, sanitized errors and diagnostic breadcrumbs, but excludes note content and API keys. Automatic network capture is disabled, so request URLs, query strings, and fragments are not collected; failed requests, UI interactions, sessions, file paths, and Core Data tracing are also disabled. This data is not used for tracking.

## iCloud Sync

- iCloud sync is entirely optional and can be disabled at any time in Settings.
- When enabled, your data is synced through your own Apple iCloud (CloudKit private database) and protected by Apple's iCloud security — encrypted in transit and at rest on Apple's servers.
- The sync stays inside your personal iCloud account. Jotaid developers have no access to it — only you do.

## Permissions & System Access

- **Images:** Inserted via clipboard paste only. The app does not request access to your camera or photo library.
- **iCloud:** Used optionally to sync notes across your Apple devices.
- **Network:** Math formulas and Mermaid diagrams use bundled resources and render entirely on-device, with no network request for rendering. The app makes network connections in other cases, including: optional iCloud sync; opt-in AI (to the provider you choose); fetching a remote image from its source address when a note references one; and reaching an external website when you open a link or use the built-in browser. These connections go to the third-party address involved, not to Jotaid servers.

## AI Features

- AI features are optional and off by default. They are powered by third-party providers (OpenAI, Anthropic, Google, DeepSeek) using your own API key. You may also configure a custom OpenAI-compatible provider (for example a self-hosted or local model).
- Your API key is stored in the device Keychain and is sent only to the selected provider for authentication when making an AI request; it is never sent to Jotaid servers.
- When you trigger an AI action, selected note content and context go directly to the provider with authentication, so the provider may associate the request with your provider account. Retention, human review, and model-training rules depend on the provider's policy and your account settings. Nothing is sent without your action, and AI traffic does not pass through Jotaid servers.
- For a custom provider, remote endpoints must use HTTPS (plain HTTP is allowed only for localhost). You choose the endpoint, so any data sent to a custom endpoint is under your control and responsibility.

## Knowledge Base Server (Mac)

- This feature is macOS only and off by default. It requires Pro and you switch it on yourself in Settings. While it is off, Jotaid listens on no port and issues no credential.
- When it is on, Jotaid serves a read-only interface on the local loopback address (127.0.0.1) that only processes on the same Mac can reach. It accepts no connections from the network, and uploads nothing to a Jotaid server — we do not run one.
- Connecting requires an access token. By default the token can read every project, including ones you create later; in Settings you can untick the projects you do not want it to read. The token is kept in the system Keychain, and you can regenerate it at any time, which invalidates the old one immediately. Settings shows when the token was last used.
- Please note: what an agent you authorise does with your notes after receiving them — including whether it sends them elsewhere — is decided by that agent and its provider, and is outside Jotaid's control. Only give the token to software you trust, and in Settings leave ticked only the projects it needs.

## Share Extension

- When you share text, a URL or an image into Jotaid from another app, the Share Extension reads that shared content and saves it as a note in Jotaid's shared on-device App Group storage. If you have iCloud sync enabled and available, that note then syncs to iCloud under the same rules as your main library.
- The Share Extension runs in its own process with only Sentry crash/app-hang reporting and sanitized manual diagnostic breadcrumbs enabled; automatic network, UI, and performance tracing are disabled. Shared content is written only to your own note storage.

## Backups & Exports

- Backup files exported from Jotaid are encrypted with AES-GCM before being written to disk, and contain both your notes and their attachments.
- Note exports (Markdown, PDF, HTML, plain text, JSON) are different: they are written as plain, unencrypted files and contain the text of your notes but not your image attachments. Use an encrypted backup when you need a complete copy.
- You are responsible for securing exported files stored outside the app.
- If you choose to export a diagnostic report to help with support, it contains device, error and redacted log information (never your note content). It is written as a plain file, so only share it with someone you trust.

## Data Deletion

- Deleting the app from your device removes all locally stored data.
- iCloud data can be deleted via: **Settings → \[Your Name\] → iCloud → Manage Storage → Jotaid**.

## Changes to This Policy

We may update this policy from time to time. Significant changes will be reflected by updating the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.

## Contact Us

For privacy or other inquiries, contact us at contact \[at\] jotaid.com.
