TruNaut is local-first: your books, highlights, notes, and conversations live on your device, and reading, highlighting and note-taking never involve a server. The exceptions are listed below rather than rounded away — signing in, which both paid tiers require and which is the only reason we ever learn an email address; buying an unlock; crash reports, which contain no reading content; usage analytics, which stay off until you switch them on; and hosted AI, which is the Trial and the Subscriber tier. In hosted AI, the passage you ask about and your messages pass through TruNaut's server to an AI model — described in full under Hosted AI below. On BYOK, none of that happens: your conversations go straight from your device to the provider you chose. The Trial needs no account at all. Nothing you read or write leaves your device unless you use a hosted AI feature or turn something on.
Last updated 2026-09-21
Nothing you read, write, or highlight is sent to TruNaut on the BYOK tier. BYOK needs an account — see Your TruNaut account below — but signing in tells us only who you are, never what you read. The other exception is buying the unlock, described under Purchases — it involves no personal data, but it is not nothing, so we say so rather than rounding it to zero. The Trial and Subscriber tiers are different because their AI runs on our server; that is under Hosted AI.
Everything you create in the app is stored locally on your device:
AI conversations and AI-generated insights are optional on this tier. They only work if you add your own API key for a third-party AI provider (OpenAI, Anthropic, or Google) in Settings → AI Settings.
If you never add an API key, never start the Trial and never subscribe, nothing you read or write ever leaves your device through TruNaut.
When you add a web page, the app downloads that page over HTTPS to extract the article text for offline reading. The request goes to the website you entered; no copy is sent to TruNaut.
You can optionally export highlights, notes, and AI insights as Markdown files to a folder you choose (for example, an iCloud Drive folder or an Obsidian vault). These files are written only to the folder you select, and syncing is handled by Apple's iCloud under Apple's privacy policy. This is entirely under your control and off by default.
This applies on every tier, including BYOK — buying the one-time unlock is the one moment a device with no API key and no subscription still touches our infrastructure.
Payment itself is handled entirely by Apple. We never see your name, email, card, or billing address; Apple does not give them to developers.
To know whether a given device has paid, we use RevenueCat, a subscription-management service. When you buy, RevenueCat records the transaction and issues an anonymous identifier for your install — not an account, not tied to your Apple Account, and not linked to anything that identifies you. RevenueCat then notifies our server, which stores that identifier alongside what you bought, whether it is still valid, and when it expires or was refunded. That row is what the app checks to unlock features.
Apple's handling of the payment falls under Apple's privacy policy, and RevenueCat's handling of the purchase record falls under theirs.
Two tiers run their AI on TruNaut's own model access instead of your API key: the Trial (a fixed number of free messages, no account) and the optional Subscriber plan. Neither is live yet, because the backend they depend on has not been switched on. This section describes what they involve, so it is on the record before they ship rather than after.
They need a server because something has to hold your allowance, meter usage, and stand between your device and the AI model. Concretely:
BYOK does none of this. Its conversations go direct from your device to your chosen provider, never through TruNaut, indefinitely. If you never start the Trial or subscribe, none of this section ever applies to you.
These two are described together because they are often bundled elsewhere, and here they are deliberately not: one is on, the other is off until you turn it on. Both apply on every tier.
Neither is used for advertising, neither is sold, and neither follows you to other apps or websites.
Both paid tiers — BYOK and Subscriber — require a TruNaut account. The Trial does not, and never will. You can read, highlight, take notes, search, bookmark, and export without ever signing in; the account is what a purchase attaches to, not what the app runs on.
The reason is practical. A purchase made on your iPhone has to be recognised on your iPad, and without an account the only thing tying the two together is the device itself. Signing in is what lets something you have paid for follow you, and it is what makes it possible to sync your library between your own devices.
You can sign in two ways:
What the account holds is deliberately small:
You can delete your account from inside the app, under Settings → Account. Deleting it removes the account, its email address, and its sign-in sessions from our servers, and if you signed in with Apple it also tells Apple to revoke the connection between your Apple Account and TruNaut. Your books, highlights, and notes are on your device and are yours to keep or delete there.
iCloud sync is available on the paid tiers only, and it is off until you turn it on. When it is on, your library syncs through your own iCloud account under Apple's privacy policy — it does not pass through TruNaut, and we cannot read it.
This section describes something that does not exist in the app yet, published here before it ships rather than after. Until it does, none of it is happening.
TruNaut is the first product under the TruNaut brand, and others are coming. If you separately agree to join the wider TruNaut product line, we would collect one specific thing from your second brain:
#stoicism and #grief often sit on the same note, we learn that those two topics are connected for you.This is a separate decision from signing in, and it always will be. Having an account does not opt you into it, and it is never a condition of subscribing, of using the app, or of any feature you have paid for. You would be able to withdraw at any time in Settings → Privacy, and withdrawing would delete the tag data we hold for you rather than merely stopping new collection.
Tag names are your words, and they can be revealing — which is exactly why this is opt-in, why the note behind the tag would never leave your device, and why it is asked separately from signing in.
TruNaut is not directed at children under 13 and does not knowingly collect personal information from them.
If this policy changes, the updated version will be posted here with a new "Last updated" date.
Questions about privacy? Email sid@trunaut.com.