Notesage

Privacy Policy

Last updated: 15 September 2026

This policy covers both Notesage apps — the iPhone app and the Mac app. They are built from one codebase but they do not behave identically, and where they differ this policy says so rather than averaging them.

The short version

The iPhone app collects nothing. No account, no analytics, no crash reporting, no identifier. The analytics and crash-reporting libraries are not merely switched off there — they are not compiled into the app at all.

The Mac app also collects nothing until you turn on a Labs feature. Labs features are experimental, and switching any of them on switches on anonymous usage and crash reporting with it — that is how a feature earns its way out of Labs. The app tells you this above the toggles, and you can turn the reporting back off in Settings → Privacy while keeping the feature.

Your notes are never part of any of that. They stay in the folder you chose. The one time note content leaves your device is when you use an AI feature, and then it goes to the provider you configured — never to us.

What Notesage stores, and where

Notesage reads and writes files only inside the folder you grant it access to — typically a folder in iCloud Drive, or one under On My iPhone. On iOS the system enforces this: the app cannot see anything outside that grant.

Kept on your device, outside your library:

Kept inside your own library folder, alongside your notes:

None of this is transmitted to us, and we have no way to read any of it.

When each app uses the network

WhatiPhoneMac
Saving a shared link — fetching the page to build the note, and calling a video provider's public oEmbed endpoint for a video linkYesYes
Loading images a note points at, from wherever the note references themYesYes, off by default for link previews
iCloud sync between your own devices, handled by Apple under Apple's privacy policyYesYes
Checking GitHub for a new version, and for release notes, shortly after launchNo — updates come from the App StoreYes
AI features you invoke — see belowNo — the iPhone app has noneOnly when you use them
Anonymous usage and crash reportingNever — not compiled inOnly with a Labs feature on, or if you switch it on

Requests to fetch a page or an image go to the site in question, not to us. They carry no identifier we assign, and nothing about you beyond what any web request carries.

AI features (Mac only)

The Mac app can send text to an AI model. This only happens when you invoke it — a chat message, an editor action like Improve or Summarize, an agent run — and it goes to the provider you configured, under that provider's privacy policy and terms, using your own API key.

Depending on what you invoke, that can include the text you selected, the document you are working in, and material the assistant is given access to. Treat it as you would pasting the same text into that provider's own app.

Providers are yours to choose and include Anthropic, OpenAI, Google, any OpenAI-compatible endpoint you point at, and any MCP servers you connect. Notesage can also run a model entirely on your machine — through Ollama or a bundled local model — in which case nothing leaves the device at all.

We never receive any of it. There is no Notesage server in this path; the app talks to your provider directly.

Usage and crash reporting (Mac only)

Off by default. It switches on in one of two ways: you enable it in Settings → Privacy, or you turn on any Labs feature, which enables it as part of the bargain and says so on the panel. Either can be reversed at any time, and turning reporting off does not turn the feature off.

Usage analytics record that a thing happened, never what it was about. The event list is fixed and closed — there is no free text in it, no file names, no paths, no note content, no URLs. A document-opened event carries the format (md, pdf); an AI event carries the kind of provider (anthropic, ollama), never its name, address or your key. Each event is sent with a timestamp, your app version, OS name and version, the app engine version, your system locale, and a random session identifier that is discarded after four hours of inactivity. There is no account, device or install identifier, and nothing that follows you between sessions.

Crash reports carry the error, where in the code it happened, and the app version. Personally identifying data is disabled at the SDK level, log breadcrumbs are not collected at all — because our logs contain file paths — and every report is scrubbed before it is sent.

These go to our analytics provider (Aptabase) and our error-reporting provider (Sentry), who process them on our behalf. Neither receives your notes, your files, or their names.

What Notesage does not do

Children

Notesage is a note-taking tool with no social features, no feeds, and no communication between users. The iPhone app collects nothing from anyone. The Mac app collects nothing unless an adult turns on a Labs feature or enables reporting deliberately, and what it then collects is anonymous and carries no identity.

Deleting your data

Your data is your files. Delete them as you would any files — in Notesage, in the Files app, or on your Mac. Removing the app's access (Change library folder) or deleting the app removes the grant and the local preferences; your notes stay where they are, because they were always yours.

To stop usage and crash reporting on the Mac, switch it off in Settings → Privacy. Reports already sent are anonymous and carry no identifier, so there is nothing we could look up to delete on request — and equally nothing that identifies you.

Changes

If this policy changes, the updated version is published at the same URL with a new "last updated" date.

Contact

ADDABLE AB — peter.blenessy@addable.se