Privacy
This page mirrors the in-repo notedocs/permissions-and-data.md. There is no company backend.
On the phone
- Application Support
ledger.jsonl: append-only events. - Application Support
sessions.jsonl: clerk session tree. - Keychain: model API key, this device, unlocked only.
- UserDefaults: onboarding flags, provider kind, model id, base URL. Not the key.
Face ID or passcode unlocks the app on launch.
Network
The only intended egress is the model host you configured. Tapping Propose sends the system prompt, your ramble, optional OCR text, and a ledger summary to that host. No analytics SDK, crash reporter, update ping, or account API.
What never happens
- No account, no cloud sync, no iCloud store in this release.
- No HealthKit read or write.
- No vendor names or sourcing copy.
- The maintainers of this project never receive health data. We ship source.