Your notes stay yours.
What stays on your device, what a network request sends, and what an optional account would change.
Your ordinary local notes are not uploaded to our servers. The desktop needs no account. Update checks make network requests; optional online features would send the data needed for the features you choose.
Who is responsible
Okilum is developed and operated by Oleg Kossoy, an individual, under the BeFeast brand. For questions about your personal data, contact privacy@okilum.app.
On your desktop
Notes, the search index, and application state are stored locally on your device. The desktop does not automatically upload analytics or crash reports.
Local diagnostic logs may include timestamps, a per-launch identifier, build and operating-system information, timings, and vault paths or diagnostic details. These logs stay on your device unless you choose to send them to support. Review a log before sharing it: paths and details can contain personal information.
Update checks and downloads
On macOS, the updater checks automatically, normally about once an hour. Installed Windows builds check at startup; portable Windows builds do not use that updater. On Arch Linux, your package manager handles updates.
The update or download host receives your IP address and ordinary HTTP request information, such as the resource requested. The exact additional headers depend on the updater and platform. These requests do not send your notes or search index.
This website and support
This website is served by Cloudflare, which processes IP addresses and request metadata to deliver and protect the site. These pages include no marketing analytics or advertising trackers.
If you email us, we receive your email address and the message and attachments you choose to send. We use them to respond to your request. Please do not post private notes, credentials, or diagnostic logs in a public GitHub issue.
Optional Inbox and accounts
Inbox is a separate, optional service. Its first planned users are four or five family members and friends, by invitation. The account and data-handling arrangements below describe that planned service, not an available public sign-up.
When enabled, Inbox stores the captures you submit, conversations, timestamps and identifiers, and publication details such as the destination folder, filename, exact content, and status. This information is stored on the server to provide the service. It is not end-to-end encrypted.
Device pairing uses device and vault identifiers, device names, and pairing and synchronisation state. If you enable vault synchronisation, the selected vault is replicated on the server. Pairing does not mean that every folder on your computer is uploaded.
Clerk and Google sign-in
The planned account system uses Clerk. Account data can include a Clerk account identifier, email address, sessions, and authentication metadata. Passkeys use public credential information; we do not receive a biometric template.
If you choose Google sign-in when it becomes available, Google and Clerk provide basic identity information such as your account identifier, email address, name, and profile image, depending on the configured flow. We do not receive your Google password. Basic sign-in does not grant access to your Gmail or Google Drive.
Clerk and Google process authentication information under their own policies: Clerk Privacy Policy and Google Privacy Policy.
Optional AI and integrations
AI integrations can send your prompt, relevant context, and conversation history to the configured model provider. Related agent features may store briefs, answers, execution results, and project references. These features are optional and are not offered to invitees until the providers and data handling are specified.
Cookies and local browser data
The planned Inbox uses essential session and authentication storage. Browser storage may also hold unsent captures, retry information, and an application cache so drafts can survive an interrupted connection.
Signing out does not erase unsent drafts from the browser. On a shared device, local draft data needs to be cleared separately. The local-data controls will be documented with the Inbox rollout. These information pages do not add an analytics cookie or save your theme choice between visits.
Retention, deletion, and your choices
You control your local Markdown files. Deleting server content is a separate action from deleting a local file, signing out, revoking a device, or forgetting a pairing.
The Inbox account-deletion process and exact retention periods for server content, logs, and backups are not yet established. They must be defined and implemented before invitations begin. There is no promise of immediate removal from backups or an automatic account-deletion feature today.
For access, correction, export, deletion, or an objection concerning information you have shared with us, write to privacy@okilum.app. Requests are handled manually; we may need to verify your identity. Your rights depend on applicable law.
Children and policy changes
Inbox is not open for public registration and is not being offered as a service for children. We will establish age and consent requirements before opening access more widely.
We will update this page as data handling changes and revise the date above. Before optional services become available, their actual providers and retention arrangements will be described here.