PRIVACY POLICY

Your data
starts with you.

DropNest is a local-first iOS app. This policy explains how the app and this website handle data, including what happens when you choose to connect a third-party AI service.

Effective dateJuly 19, 2026
Applies toDropNest 0.1.0 and later
01

No account

The launch version requires no registration and includes no advertising or cross-app tracking.

02

Local files

Original notes and attachments stay in the folder you choose.

03

Consent first

Before third-party AI is used, the app identifies the recipient, data, and purpose.

1

Scope

This policy applies to the DropNest iOS app, its Share Extension, and the public product website. It does not cover an AI provider, cloud drive, or other third-party product you choose; those services process data under their own privacy policies.

The current launch version has no DropNest account, hosted AI, advertising SDK, or analytics SDK.

We therefore do not use the app to build user profiles, sell personal data, or share it for advertising.

2

Data processed on your device

To provide features you actively use, the app processes the following on your device:

  • What you capture: text, links, photos, files, recordings, and speech transcripts.
  • Your knowledge files: the Markdown folder you select, ordinary attachment files, and related file timestamps.
  • Rebuildable data: local search indexes, citations, summaries, weekly review state, and weekly reports.
  • App settings: onboarding state, selected-folder permission, third-party AI configuration, and token totals counted on device.
  • Credentials: an API key you provide is stored in the iOS Keychain, not in Markdown, ordinary preferences, or logs.

The Share Extension first places content you explicitly share into an App Group queue, then writes it reliably to your chosen folder. Photo text recognition uses Apple Vision on device. We do not upload this local content to DropNest servers; the current version has no DropNest server designed to receive it.

3

When you connect a third-party AI service

Third-party AI is optional. You provide a compatible HTTPS endpoint, model, API key, actual service operator, and the operator's privacy policy. Before saving, the app shows the recipient, destination, data categories, and purpose, and requires an affirmative choice from you.

A cited-answer request may send the following directly to your chosen provider:

  • the question you enter;
  • titles and excerpts from up to five relevant records selected by local search;
  • the API key used for authentication; and
  • network information naturally produced by the request, such as IP address, time, and device network information.

Testing a connection or listing models sends the API key and standard network-request information to that provider, but does not include your question or record excerpts. Requests go directly from your device to the configured service and do not pass through DropNest servers. The provider's terms and privacy policy govern retention, training, sharing, and deletion; review them before you consent.

Consent is tied to the current recipient and configuration.

If the endpoint, operator, privacy policy, or disclosure version changes, prior consent expires. You can also revoke it at any time in the app.

4

System permissions and Apple services

The app asks for a system permission only when you use the related feature:

MicrophoneRecords a voice note only after you start recording.
Speech recognitionUses Apple Speech to turn a recording into text. Whether recognition occurs fully on device depends on the system, language, and device; Apple may process speech data under its own policy.
Photos and filesReads only the photo, file, or folder you explicitly choose through a system picker. Photo OCR uses Apple Vision on device.
ClipboardReads an available link or text only when you tap the clipping action.

You can revoke microphone or speech-recognition permission at any time in iOS Settings, but the corresponding feature will stop working.

5

When you visit this website

This website sets no marketing cookies, embeds no advertising, and runs no behavioral analytics. To deliver pages and protect the service, hosting and network providers may temporarily process standard server-log data, including IP address, request time, browser identifier, and requested page. This supports delivery, troubleshooting, and abuse prevention—not cross-site tracking.

6

Retention and deletion

  • Original material: remains in your chosen folder until you delete it with DropNest, the Files app, or another tool.
  • Local caches and settings: generally remain until cleared in the app or the app is uninstalled; rebuildable indexes can be deleted and regenerated.
  • API configuration: can be deleted in Settings, and consent can be revoked separately. Deleting the configuration removes the API key from the Keychain.
  • Data held by third-party AI: direct access, correction, or deletion requests to your chosen provider; DropNest cannot act on its behalf.

Uninstalling the app does not automatically delete Markdown and attachments that you intentionally stored in an external folder. This preserves portability. To delete everything, you must also remove the folder and any copies held by your cloud-drive provider.

7

Security measures and your choices

The app stores API keys in the iOS Keychain, accepts only HTTPS third-party AI addresses, and blocks cross-origin redirects. No system can guarantee absolute security, so protect your device with a passcode and choose AI and cloud-storage providers carefully.

You may decline optional permissions, choose not to connect third-party AI, or use only local capture, search, and review features.

8

Children’s privacy

DropNest is a general productivity tool and is not directed specifically to children under 13. We do not knowingly collect children's personal information through the app. If a guardian believes a child sent information through a third-party service, the guardian should also contact that provider.

9

Changes to this policy

We may update this policy when features, data flows, or legal requirements change. Material changes will be communicated through this page, release notes, or an in-app notice, and the effective date above will change. A new data-transfer flow will not rely on prior consent that no longer matches the disclosure.

10

Contact us

For questions about this policy, data on your device, or DropNest's privacy practices, contact the developer through the “Developer Website” or “App Support” channel listed on the App Store product page. To protect your privacy, do not include an API key, full notes, or other sensitive material in your first message.