Privacy policy

Local-first by default.

TruNaut is local-first: your books, highlights, notes, and conversations live on your device, and reading, highlighting and note-taking never involve a server. The exceptions are listed below rather than rounded away — signing in, which both paid tiers require and which is the only reason we ever learn an email address; buying an unlock; crash reports, which contain no reading content; usage analytics, which stay off until you switch them on; and hosted AI, which is the Trial and the Subscriber tier. In hosted AI, the passage you ask about and your messages pass through TruNaut's server to an AI model — described in full under Hosted AI below. On BYOK, none of that happens: your conversations go straight from your device to the provider you chose. The Trial needs no account at all. Nothing you read or write leaves your device unless you use a hosted AI feature or turn something on.

Last updated 2026-09-21

What we collect — BYOK

Nothing you read, write, or highlight is sent to TruNaut on the BYOK tier. BYOK needs an account — see Your TruNaut account below — but signing in tells us only who you are, never what you read. The other exception is buying the unlock, described under Purchases — it involves no personal data, but it is not nothing, so we say so rather than rounding it to zero. The Trial and Subscriber tiers are different because their AI runs on our server; that is under Hosted AI.

Everything you create in the app is stored locally on your device:

  • Imported books (EPUB/PDF) and saved web articles
  • Highlights, notes, and bookmarks
  • AI conversations attached to highlights
  • App settings and your reading profile

AI features on BYOK (bring-your-own-key)

AI conversations and AI-generated insights are optional on this tier. They only work if you add your own API key for a third-party AI provider (OpenAI, Anthropic, or Google) in Settings → AI Settings.

  • Your API key is stored in the iOS Keychain on your device.
  • When you use an AI feature, the text you selected and its surrounding context (and, for follow-ups, earlier messages in that conversation) are sent directly from your device to the AI provider you chose so it can generate a response.
  • That data is handled under your chosen provider's privacy policy and terms. TruNaut never receives or stores it.
  • AI responses are generated by a language model and can be inaccurate. Treat them as a study aid, not a source of truth.

If you never add an API key, never start the Trial and never subscribe, nothing you read or write ever leaves your device through TruNaut.

Web article import

When you add a web page, the app downloads that page over HTTPS to extract the article text for offline reading. The request goes to the website you entered; no copy is sent to TruNaut.

Optional folder export and iCloud

You can optionally export highlights, notes, and AI insights as Markdown files to a folder you choose (for example, an iCloud Drive folder or an Obsidian vault). These files are written only to the folder you select, and syncing is handled by Apple's iCloud under Apple's privacy policy. This is entirely under your control and off by default.

Purchases

This applies on every tier, including BYOK — buying the one-time unlock is the one moment a device with no API key and no subscription still touches our infrastructure.

Payment itself is handled entirely by Apple. We never see your name, email, card, or billing address; Apple does not give them to developers.

To know whether a given device has paid, we use RevenueCat, a subscription-management service. When you buy, RevenueCat records the transaction and issues an anonymous identifier for your install — not an account, not tied to your Apple Account, and not linked to anything that identifies you. RevenueCat then notifies our server, which stores that identifier alongside what you bought, whether it is still valid, and when it expires or was refunded. That row is what the app checks to unlock features.

  • What is stored: an anonymous install identifier, which product was purchased, and its current status and expiry.
  • What is not: your name, email, payment details, or any of your books, highlights, notes, or conversations.
  • Why: so a purchase you made keeps working, and so a refund correctly removes access. There is no other use — it is not sold, not used for advertising, and not used for tracking.

Apple's handling of the payment falls under Apple's privacy policy, and RevenueCat's handling of the purchase record falls under theirs.

Hosted AI — the Trial and the Subscriber tier (not yet available)

Two tiers run their AI on TruNaut's own model access instead of your API key: the Trial (a fixed number of free messages, no account) and the optional Subscriber plan. Neither is live yet, because the backend they depend on has not been switched on. This section describes what they involve, so it is on the record before they ship rather than after.

They need a server because something has to hold your allowance, meter usage, and stand between your device and the AI model. Concretely:

  • Chat content, relayed. When you use hosted AI, the passage you highlighted, its surrounding context, your messages, and the earlier turns of that conversation are sent from your device to TruNaut's server, which forwards them to an AI model and streams the reply back. TruNaut does not store any of it. Our server keeps no transcript, and its logs record only counts — tokens, cost, timing, and which tier — never the text and never who sent it. Your conversations stay on your device, exactly as on BYOK.
  • Who else sees it. Your request passes through two companies that act for us. OpenRouter is the routing service our server calls; it forwards the request to the model maker. Anthropic makes the Claude models that generate the reply. We have asked OpenRouter not to keep prompts and to route only to providers that do not store or train on data, and we send the request to Anthropic only. Anthropic handles it under its own terms and privacy policy, which we do not control, and it may keep it for a limited time under them. Neither company is given your name, email address, or account — the request carries no identifier for you.
  • Not sold, not used for advertising. Your content is used to generate your reply and for nothing else on our side.
  • Trial: a device check, not an account. To keep a free trial from being reset by deleting and reinstalling the app, your device proves to our server that it is a genuine copy of TruNaut using Apple's App Attest. This produces a random key identifier that lives in your device's secure hardware and is not tied to your name, your Apple Account, or your email. Our server stores that identifier and how many trial messages it has used. Apple's DeviceCheck also stores two yes/no flags for your device — "has had a trial" and "has used it up" — which is how a reinstall is recognised. We never see a device identifier for you from this, and Apple's handling of those flags falls under Apple's privacy policy. We keep the trial record for as long as the trial could otherwise be started again; deleting the app does not clear it, by design.
  • Subscriber: your account. The hosted plan is keyed to your TruNaut account, described under Your TruNaut account below. An earlier version of this policy said the tier would need no account; that is no longer true, and the reason is in that section — without one, a subscription you paid for could not follow you to your second device.
  • Entitlement checks. Every hosted request is checked on our server against your subscription or trial allowance before any AI runs. This is how a trial stays a trial: a counter kept only on your device is trivial to reset.
  • Product analytics. Covered under Crash reports and usage analytics below, which applies on every tier — crash reports on by default, usage analytics off until you turn them on.

BYOK does none of this. Its conversations go direct from your device to your chosen provider, never through TruNaut, indefinitely. If you never start the Trial or subscribe, none of this section ever applies to you.

Crash reports and usage analytics

These two are described together because they are often bundled elsewhere, and here they are deliberately not: one is on, the other is off until you turn it on. Both apply on every tier.

  • Crash reports are on by default. When TruNaut crashes, we receive a technical report — the stack trace, the device model, the OS version, and the app version. These contain no books, no highlights, no notes, no conversations, and no tags. We use them only to find and fix the crash. You can turn them off in Settings → Privacy.
  • Usage analytics are off by default. If you turn them on, we record which features you use and how often — for example, that a highlight was created, or that the tag graph was opened. We record the action, never its content: that you made a highlight, never what it says. You are asked once, plainly, when you first set up the app, and "Not now" is a real answer that we do not ask about again. You can change it at any time in Settings → Privacy.

Neither is used for advertising, neither is sold, and neither follows you to other apps or websites.

Your TruNaut account

Both paid tiers — BYOK and Subscriber — require a TruNaut account. The Trial does not, and never will. You can read, highlight, take notes, search, bookmark, and export without ever signing in; the account is what a purchase attaches to, not what the app runs on.

The reason is practical. A purchase made on your iPhone has to be recognised on your iPad, and without an account the only thing tying the two together is the device itself. Signing in is what lets something you have paid for follow you, and it is what makes it possible to sync your library between your own devices.

You can sign in two ways:

  • Sign in with Apple. If you choose to hide your email, we receive Apple's private relay address and never your real one. Either way, that address is all we get — Apple does not give us your name, and we do not ask for it.
  • An emailed six-digit code. You give us an email address, we send a code to it, and you type the code back. There is no password to reuse or lose.

What the account holds is deliberately small:

  • What is stored: your email address (or Apple's relay address for it), an account identifier, the purchase identifiers described under Purchases that belong to you, and the dates your sign-in sessions were created.
  • What is not: your name, your payment details, and none of your books, highlights, notes, conversations, or tags. Your reading does not live in your account.
  • Why: so a purchase works on every device you own, and so a subscription can be metered against a person rather than a handset. There is no other use — it is not sold, not used for advertising, and not used to track you.

You can delete your account from inside the app, under Settings → Account. Deleting it removes the account, its email address, and its sign-in sessions from our servers, and if you signed in with Apple it also tells Apple to revoke the connection between your Apple Account and TruNaut. Your books, highlights, and notes are on your device and are yours to keep or delete there.

iCloud sync is available on the paid tiers only, and it is off until you turn it on. When it is on, your library syncs through your own iCloud account under Apple's privacy policy — it does not pass through TruNaut, and we cannot read it.

Your second brain and the wider TruNaut line (not yet available)

This section describes something that does not exist in the app yet, published here before it ships rather than after. Until it does, none of it is happening.

TruNaut is the first product under the TruNaut brand, and others are coming. If you separately agree to join the wider TruNaut product line, we would collect one specific thing from your second brain:

  • What would be collected: your tag names, how many notes each appears in, and which tags appear together — the shape of your interests, in other words. If #stoicism and #grief often sit on the same note, we learn that those two topics are connected for you.
  • What would never be collected: the notes themselves. Not their contents, not their titles, not their filenames, not your folder structure, and not your books, highlights, or conversations. We read the labels on the drawers, never what is inside them.
  • Why: to recommend other TruNaut products that suit what you actually think about, and to decide what to build next.
  • Who would see it: only TruNaut. Not sold, not shared with third parties for their own purposes, not combined with data from other companies, and not used for advertising or cross-app tracking.

This is a separate decision from signing in, and it always will be. Having an account does not opt you into it, and it is never a condition of subscribing, of using the app, or of any feature you have paid for. You would be able to withdraw at any time in Settings → Privacy, and withdrawing would delete the tag data we hold for you rather than merely stopping new collection.

Tag names are your words, and they can be revealing — which is exactly why this is opt-in, why the note behind the tag would never leave your device, and why it is asked separately from signing in.

Data sharing and tracking

  • We do not sell your data, on any tier.
  • We do not track you across other apps or websites.
  • We do not include third-party advertising SDKs.
  • We do not store anything you read or write. Hosted AI relays it to an AI model and keeps none of it; BYOK never sends it to us at all.
  • Crash reports are on by default and contain no reading content; usage analytics and second-brain tags are off until you switch them on — see above.
  • Signing in tells us an email address and nothing about what you read, and you can delete your account from inside the app.
  • The companies that handle data on our behalf are Apple (payments, App Attest, DeviceCheck), RevenueCat (purchase records), and — for hosted AI — OpenRouter and Anthropic.

Children's privacy

TruNaut is not directed at children under 13 and does not knowingly collect personal information from them.

Changes to this policy

If this policy changes, the updated version will be posted here with a new "Last updated" date.

Contact

Questions about privacy? Email sid@trunaut.com.