The privacy story

Most apps write a privacy policy. We’d rather show you the architecture — because promises can change, and architecture is harder to walk back.

Local first, not cloud first

PocketNotes stores your notes in a database on your device. That is the canonical copy — not a cache of someone’s server. The app is fully usable with no account and no network, indefinitely.

No account until you want one

You can write for years without telling us your name or email. An account exists only to power sync, and only if you turn it on.

Sync is opt-in, scoped, and revocable

When you enable sync, your notes are stored on our servers to move between your devices, protected by per-user access rules. Turn sync off and new writing stays local again.

Sharing is deliberate

Nothing is public by default. A share link exists only because you created it, and it stops working when you revoke it.

Your semantic map stays yours

PocketNotes can build a map of related notes so you can see connections you didn’t hand-link. Building it sends note text to an embedding service — only after you explicitly agree, and never for notes you’ve excluded. The map itself is stored on your device, it is disposable, and deleting it never touches your notes.

What we’re still building

End-to-end encryption for your most sensitive notes is designed and on the roadmap. We’ll say clearly what it covers when it ships — and we won’t use the word “encrypted” loosely before then.

Leaving is allowed

Export your notes as Markdown in a ZIP whenever you like. An exit door is part of the privacy story: you can’t be held by an app you can freely leave.

Questions about any of this? Write to info@pocketnotes.io and a human will answer.