Privacy Policy

Last updated: July 31, 2026

1. What We Collect

Account details: If you create an account, we collect the information needed to sign you in and maintain the account, including your email address and, if available, your display name and profile photo. Profile photos are account metadata used for your account; they are not encrypted as Private Storage note content.

Content you choose to capture: Clevernotes stores the notes, recordings, screenshots, files, photos, web clips, meeting captures, tasks, and other material you choose to save, along with generated AI fields such as summaries and memory data. Your captured content, real titles, transcripts, files, and generated AI data are encrypted on a trusted device before they are stored in our cloud. Clevernotes cloud keeps encrypted payloads plus limited operational metadata needed to sync and run the service — for example account identifiers, entry types, timestamps, sync state, device records, and redacted title placeholders such as “Private Entry,” not readable note titles or bodies.

Meeting and audio data: When you use voice capture or meeting recording, the app accesses your microphone only with your permission. On Mac, capturing system audio for meetings may also require Screen Recording permission so the app can record the audio you choose to capture. Meeting features may produce speaker labels and summaries. You are responsible for obtaining any consent required before recording other people.

Photos, camera, and files: With your permission, the app may access the camera, photo library, or files you select so you can capture or import content into Clevernotes. On Mac, optional Folder Watcher (off by default) can watch folders you choose and import new files as captures.

System calendar (optional): If you enable system calendar integration, Clevernotes may read calendar events from your device calendar (via the operating system calendar APIs) to show them alongside your plans. That integration is read-only for display unless you choose to create or save related items in Clevernotes.

Location context: If you grant location permission, Clevernotes may use coarse city or region context for location-aware assistant features. If you enable Location Memory, the iOS app can also attach coarse place details, such as locality, region, country, and accuracy, to personal captures so you can find them later. Location details attached to private captures are encrypted before cloud storage with the rest of the capture.

Notifications: If you allow notifications, the app may use local or system notification services to deliver reminders and product notices you enable (for example task due times or AI-ready alerts). Notification content shown on your device is produced on your device from your local data where possible.

Technical and operational data: Like most online services, our website, hosting, authentication, and backend systems may receive technical data such as IP address, browser or app version, device type, operating system, locale, timestamps, request logs, beta-request source fields, referrer or campaign parameters, account identifiers, app-generated device identifiers, and optional crash diagnostics needed to deliver, secure, troubleshoot, and understand beta demand for the Service.

Local chat history: CleverPal conversation history on your devices is stored locally on that device for your recent sessions and is not synced to Clevernotes cloud as a readable conversation archive.

What we do not currently collect: We do not currently run product analytics or advertising trackers on the marketing site or active beta apps. Optional crash diagnostics for the beta apps are off by default and only sent if you enable that setting.

2. How We Use Information

3. AI Processing

Clevernotes uses Firebase AI / Vertex AI on Google Cloud for built-in AI features such as transcription, reading images and documents, summaries, Sparks, meaning-based search embeddings, and CleverPal. CleverPal also supports additional AI providers that you can select in the app, including an optional secondary built-in path (currently xAI / Grok) and user-configured providers when you add your own API keys.

When you use one of these features, the relevant content is sent for the requested processing. For built-in features, content may pass through Clevernotes-operated Cloud Functions and temporary request storage on our cloud infrastructure solely to complete that request, then to the selected AI provider (for example Vertex AI). Temporary request objects are deleted after processing, with a fail-safe cleanup for any residual temporary files. We try to send only the content needed for that task, not your entire account.

User-configured AI providers (bring your own key): In AI Models settings you can optionally add your own API keys for providers such as OpenAI, Anthropic, xAI, Groq, or Together.ai. Those keys are stored in your device keychain, not in Clevernotes cloud. When you assign a feature or CleverPal conversation to one of those providers, selected content is sent to that provider under that provider's terms. Clevernotes does not hold a durable readable copy of that transit beyond operating the connection you requested.

Processed results may be stored in your account alongside the original content so they can appear in the app later. Those results are encrypted before cloud storage.

Some generated AI data, such as memory data and search data, can be controlled from Data Controls in the app. You can turn certain categories off and, where supported, delete existing generated AI data without deleting the original notes or files. Synced generated AI data is encrypted before cloud storage. When you run a meaning-based search, your search text is processed briefly for that request (including generating a temporary embedding); matching against your notes happens on your device, and the search text is not kept as a permanent readable archive.

Some features, such as local storage and local search indexing, run on your device. Other features require cloud processing. Private Storage protects what Clevernotes keeps in durable cloud storage; it does not mean selected content can never be sent to Clevernotes servers or an AI service for a request you initiate or allow.

Under the Google Cloud / Vertex AI terms we rely on, customer data is not used to train Google foundation models without permission. xAI's API terms similarly do not use API input or output for model training. For other providers you configure with your own key, that provider's terms control training and retention. We also do not use your content to train our own models.

4. Private Storage

Private Storage is active for every account — it is the default and only storage mode. Note content, real titles, transcripts, files, AI summaries, memory data, and search data are encrypted on a trusted device before they sync through Clevernotes cloud storage. Clevernotes stores encrypted content and limited account and sync details, but not a readable copy of private content.

Trusted devices hold the keys needed to read private notes locally. Your sign-in password is not the key to your notes. The app also supports a 24-word recovery key. If you lose every trusted device and your recovery key, Clevernotes cannot recover private notes for you.

Email capture through capture@clevernotes.ai is disabled: forwarded email would reach Clevernotes cloud before a trusted device could encrypt it, so it is dropped instead of being stored.

Private Storage does not hide every account detail. Account identifiers, timestamps, entry types, sync state, processing status flags, pin or exclusion flags, attachment counts or sizes, device records, redacted title placeholders, and similar service details may still be visible to Clevernotes because they are needed to run sync, security, and account services.

5. Shared Spaces (Beta)

Shared Spaces let you share notes with other people while keeping the space encrypted between members' devices. Clevernotes syncs the space but cannot read the notes, space name, or members' display names. Only approved members' devices receive access.

Invites work through links. The secret part of an invite stays after the # in the URL, which browsers do not send to servers. To show a useful preview, an invite stores a small amount of information Clevernotes can read: a short invite label chosen by the owner (it defaults to the space name), the inviter's display name, and a member-count snapshot. The space owner approves every join request.

Removing a member rotates the space key, so content added after removal is encrypted under a key the removed member never receives. As with any end-to-end-encrypted system, content a member could already read while they had access cannot be retroactively made unreadable.

Clevernotes stores the service details needed to run Spaces, such as space and membership records, timestamps, sync state, and device records. Shared Spaces are in beta; this section will be updated as the feature evolves.

6. Third-Party AI Assistants and Local Tool Access

On Mac, Clevernotes can optionally run a local API server and MCP endpoint on your machine so tools you trust (for example Claude Code, Codex, or other local assistants) can read from and write to your Clevernotes data. These connections are not on by default.

7. Website Data and Storage Technologies

Marketing site: The Clevernotes marketing site does not use advertising or analytics cookies today. It stores your theme preference in your browser's local storage so the site can remember light or dark mode. If you submit a beta request, we may record the page, source label, referrer, and campaign parameters submitted with that form.

Hosting and security: Our hosting or security services may set basic cookies or similar technical signals when needed to keep the site working, protect the service, or support form submissions. We do not use those mechanisms for cross-site profiling.

Third-party page requests: Fonts on the marketing site are self-hosted, so pages do not request fonts from third parties. The beta signup form on the homepage uses Cloudflare Turnstile for bot protection, which loads from Cloudflare when that form is used.

Browser extension (in development): When our browser extension ships, it will store local state, such as sign-in state, pending uploads, cached clips, and preferences, in browser-provided local storage.

8. Storage and Security

No internet-connected service can promise perfect security, but we use reasonable technical and operational safeguards for a beta product.

9. Sharing, Legal Requests, and Service Providers

We do not sell your personal information. We do not share your content for cross-context behavioral advertising, ad targeting, or data brokerage.

We share data only when needed to run the Service, when you direct us to do so, or when we are legally required to do so. Our durable cloud records are designed to contain encrypted content rather than readable notes. During an active AI processing request, content may exist temporarily in request payloads and temporary storage as described in AI Processing above; a valid legal process could target that path while a request is in flight. We may still be able to provide account records, service details needed for sync and security, encrypted content, and encrypted storage objects in response to a valid legal request. Clevernotes does not possess your trusted-device keys or 24-word recovery key and cannot decrypt private content for a legal request without them.

10. Retention and Deletion

We keep account and content data while your account remains active and the beta service is operating.

If you delete content or delete your account, we will remove cloud-stored data from the active service within a reasonable period, typically within 30 days. Residual copies may remain for a limited time in backups, logs, or security systems before normal rotation and deletion.

Data stored locally on your own devices — including local working copies, CleverPal chat history, and extension state — may remain there until you remove it, sign out, clear local app or extension data, or uninstall the app or extension.

Where the app offers deletion of generated AI data, that process targets generated search and memory data while leaving your original captured content in place.

11. Your Choices and Privacy Rights

Depending on where you live, you may have rights to access, correct, export, delete, or object to certain uses of your personal data.

We do not sell personal information or share it for cross-context behavioral advertising. If local law gives you additional rights, contact us and we will handle the request in line with applicable law.

To make a privacy request, email privacy@clevernotes.ai.

12. International Transfers

Clevernotes uses services based in the United States, including Firebase and Google Cloud. If you use the Service from another country, your information may be transferred to and processed in the United States or other places where those services operate.

13. Children's Privacy

Clevernotes is not directed to children under 13, and to children under 16 where a higher minimum age applies under local law. If you believe a child has provided personal information to Clevernotes, contact privacy@clevernotes.ai so we can review and remove it.

14. Changes to This Policy

We may update this policy as the beta product evolves. If we make a material change, we will post the update here and may also notify users through the product or by email when appropriate. The date at the top of the page shows the latest revision.

15. Contact

If you have questions about this policy or want to make a privacy request, contact Twill Signal LLC at:

privacy@clevernotes.ai