Privacy policy

Local-first by default.

On the BYOK and Trial tiers, TruNaut is local-first: your books, highlights, notes, and conversations live on your device, and nothing is sent to TruNaut. The optional hosted Subscriber tier works differently, because it needs a server in the loop — that section below is the one place this policy isn't "nothing leaves your device," and we've tried to be exact about what does.

Last updated 2026-08-11

What we collect — BYOK and Trial

Nothing is sent to TruNaut on these two tiers. They run with no backend and no account. We do not collect, store, or transmit your personal data to servers we control.

Everything you create in the app is stored locally on your device:

  • Imported books (EPUB/PDF) and saved web articles
  • Highlights, notes, and bookmarks
  • AI conversations attached to highlights
  • App settings and your reading profile

AI features on BYOK and Trial (bring-your-own-key)

AI conversations and AI-generated insights are optional on these tiers. They only work if you add your own API key for a third-party AI provider (OpenAI, Anthropic, or Google) in Settings → AI Settings.

  • Your API key is stored in the iOS Keychain on your device.
  • When you use an AI feature, the text you selected and its surrounding context (and, for follow-ups, earlier messages in that conversation) are sent directly from your device to the AI provider you chose so it can generate a response.
  • That data is handled under your chosen provider's privacy policy and terms. TruNaut never receives or stores it.
  • AI responses are generated by a language model and can be inaccurate. Treat them as a study aid, not a source of truth.

If you never add an API key and never subscribe to the hosted tier below, no data ever leaves your device through TruNaut.

Web article import

When you add a web page, the app downloads that page over HTTPS to extract the article text for offline reading. The request goes to the website you entered; no copy is sent to TruNaut.

Optional folder export and iCloud

You can optionally export highlights, notes, and AI insights as Markdown files to a folder you choose (for example, an iCloud Drive folder or an Obsidian vault). These files are written only to the folder you select, and syncing is handled by Apple's iCloud under Apple's privacy policy. This is entirely under your control and off by default.

The Subscriber tier (not yet available)

TruNaut's optional hosted plan — chat and insights on a TruNaut-managed model, no API key required — is not sold yet, because the backend it depends on isn't live. This section describes what that tier will involve once it is, so it's on the record before it ships, not after.

The Subscriber tier needs a server for reasons the BYOK and Trial tiers don't: something has to hold your subscription, meter your usage, and stand between your device and the AI model instead of your device talking to the provider directly. Concretely, that means:

  • An account. At minimum an email address, to create and authenticate a subscription and to associate a purchase with a person rather than a device.
  • Entitlement and trial checks. Your device asks our server to confirm you're within your subscription or trial allowance before a hosted conversation starts. This is a small verification request, separate from the conversation itself, and it's how a trial stays a trial — a local-only counter is trivial to reset by reinstalling.
  • Chat content, relayed. For hosted conversations specifically, the passage you highlighted, its surrounding context, and your messages pass through TruNaut's backend on their way to our AI provider, so we can enforce per-account quota and spend limits. The backend relays this content to generate your response; it is not sold, and we intend to keep server-side retention to what's operationally necessary rather than storing full transcripts indefinitely — the exact retention window will be published here before the tier launches.
  • Product analytics. Usage data — which features get used, how often, crash and performance signals — to understand what's working and fix what isn't. This is first-party analytics about product usage, not cross-app or cross-site tracking, and it's not used for advertising.

None of this applies to BYOK or Trial, which keep working exactly as described above — direct device-to-provider, no TruNaut backend, indefinitely. Choosing not to subscribe means none of this section ever applies to you.

Data sharing and tracking

  • We do not sell your data, on any tier.
  • We do not track you across other apps or websites.
  • We do not include third-party advertising SDKs.
  • On the Subscriber tier only, we collect first-party product analytics — see above.

Children's privacy

TruNaut is not directed at children under 13 and does not knowingly collect personal information from them.

Changes to this policy

If this policy changes, the updated version will be posted here with a new "Last updated" date.

Contact

Questions about privacy? Email sid@trunaut.com.