Privacy Policy
1. Who we are
AIDoJournal is developed and published by Mathieu Barnachon (the "developer"). Contact details are in section 10.
2. Data stored on your device
AIDoJournal stores the following locally, using Apple's SwiftData framework and the app's sandboxed container:
- Notes, folders, tags, to-dos, agenda entries and note versions you create.
- Attachments you add: photos, screenshots, linked documents and their extracted text.
- Generated content: summaries, agent responses, reflections, podcast audio and transcripts, read-aloud recordings.
- Agent definitions, tool settings and app preferences.
- A local search index over your notes and documents used by the Ask feature.
This data is never transmitted to the developer. Deleting the app deletes this data from the device (iCloud copies are covered in section 4).
3. On-device AI
By default AIDoJournal uses Apple's Foundation Models, which run on your device as part of Apple Intelligence. Optionally, AIDoJournal Premium lets you download MLX language and speech models from Hugging Face; the download request reveals your IP address to Hugging Face, and the models then run offline on your device. No note content is included in a model download request.
4. iCloud sync (optional, Premium)
If you enable iCloud sync, your notes and attachments are stored in your private CloudKit container under your own Apple Account. The developer has no access to this container. Apple's privacy policy governs iCloud.
5. Remote AI providers (optional, off by default)
You may connect your own API key for OpenAI, Anthropic, Google Gemini or any OpenAI-compatible endpoint. When you select a remote provider, the text you ask about or run an agent on — and any note content the agent is given — is sent to that provider under your account and their privacy terms. Your key is stored locally on your device. Switching back to Foundation Models stops all remote requests.
6. Agent tools and system integrations
Agents can use tools that call third-party services when you enable them: weather, maps and web search send only the query needed to answer. System integrations (Calendar, Contacts, Reminders, notifications, microphone for dictation, camera and photo library, screen recording for screen capture) are requested through the standard system permission prompts and can be revoked at any time in Settings. Data read from these integrations stays on your device unless a remote provider is selected (section 5).
7. MCP server
AIDoJournal can run a local Model Context Protocol server so that other apps on your machine can read or write notes. It is off by default, listens only on the local network interface you choose, uses a self-signed TLS certificate, and exposes only the tools you enable. Any client you connect is your responsibility.
8. Purchases
Premium is an auto-renewable subscription sold through Apple's App Store. Apple processes the payment; AIDoJournal receives only an anonymised receipt to unlock features. We never see your payment details.
9. What we do not do
- No AIDoJournal account, login or e-mail collection.
- No analytics, crash-reporting or advertising SDKs. Crash reports reach the developer only if you opted in to share analytics with app developers in your Apple device settings.
- No selling, renting or sharing of personal data. There is nothing to share.
10. Your rights and contact
Because your data is on your device or in your iCloud account, you are in full control: export it from Settings › Import & Export, or delete it by removing notes or the app. For questions about this policy write to our support tracker or use the contact address listed on the App Store product page.
11. Children
AIDoJournal is not directed at children under 13 and does not knowingly collect data from them.
12. Changes
We will update this page and the effective date when the policy changes. Material changes will be highlighted in the release notes of the corresponding app update.