Privacy Policy
Last updated: 2026-06-25
Introduction
Anasa is a local-first desktop application that keeps your notes on your device. This Privacy Policy explains what data we collect, how we use it, and your rights. We take privacy seriously and aim to comply with GDPR, CCPA, and other major privacy regulations.
1. What Data We Do NOT Collect (App Usage)
When using Anasa as a local desktop app:
- Your notes are never sent to us. Notes remain on your device as plain Markdown files.
- No telemetry by default. We do not collect usage data, crash reports, or interaction logs.
- No account required. The app works fully offline and requires no login to function.
- No tracking. Anasa does not track your activity, screen time, or behavior.
2. Data Collected via the Website and Account System
When you visit anasa.md or create an account to purchase a license or AI credits:
Clerk (Authentication)
- Email address: Used to authenticate your account and confirm your identity.
- Name (optional): If you provide it during signup.
- Clerk securely stores and manages these credentials. See Clerk's Privacy Policy for details.
Polar.sh (Payment Processing)
- Payment data: Card details, billing address, and purchase history are handled directly by Polar as our Merchant of Record.
- Anasa does NOT process or store payment card information.
- See Polar's Privacy Policy for payment data handling.
CapyDB (Database)
- Email address: Linked to your account.
- License key: Generated when you purchase a license.
- Account tier: Free or paid tier status.
- AI credit balance: Number of AI credits remaining in your account.
- Device identifiers: Device names and activation records to enforce per-seat licensing and usage limits (typically a hardware identifier and timestamp).
Account data is stored on CapyDB, our managed PostgreSQL platform, hosted in the EU (Hetzner, Finland). All data is encrypted in transit (TLS) and at rest. We retain this data only as long as your account is active, then delete it within 90 days of account closure.
Cloudflare R2 (Anasa Cloud transfer storage)
- Capture content: If you use Anasa Cloud capture sync, notes and attachments you capture on mobile are held temporarily (markdown in CapyDB, attachments in Cloudflare R2) until your desktop app imports them.
- Synced captures are deleted from our servers immediately after your desktop imports them — Anasa Cloud sync is a transfer queue, not a copy of your vault.
- Captures are encrypted in transit (TLS) and at rest.
3. How Anasa AI Uses Your Content
When you use optional AI features ("Anasa AI"):
- Content is sent to AI providers. When you invoke an AI feature, the specific note content you select is sent to third-party AI model providers (e.g., Azure OpenAI) to process your request.
- Bring-your-own-key (BYOK) mode: If you provide your own API key, content is sent only to your chosen provider's API. Anasa's servers are NOT involved.
- Local/on-device models: If you run Ollama or other local models, content is processed entirely on your device and never leaves it.
- Anasa-managed AI: If you use Anasa's managed AI service, content is sent via Azure OpenAI to fulfill the request. We do not retain or train on your content.
For details on how your chosen AI provider handles data, review their privacy policy, e.g. OpenAI, Google, or Anthropic.
For a detailed description of exactly what the managed Anasa AI service sends, forwards, and records, see the [Anasa AI Privacy](/ai-privacy) page.
4. Cookies and Authentication Sessions
- Session cookies: Stored only while you are logged into anasa.md. They are cleared when you log out.
- Authentication: Clerk manages session tokens. You may revoke access at any time by logging out or deleting your account.
- Locale preference: A cookie remembers your chosen language for the website.
5. Third-Party Processors
We work with the following data processors (Data Processing Agreements available on request):
| Service | Role | Data |
|---|---|---|
| Clerk | Authentication | Email, name |
| Polar | Payment processing | Payment & billing (Merchant of Record) |
| CapyDB | Database | Email, license, tier, device identifiers, in-transit sync captures |
| Cloudflare R2 | Sync transfer storage | Capture attachments (only while awaiting desktop import) |
| AI Providers | AI processing | Note content (only when you invoke AI features) |
6. Data Retention
- Active accounts: Kept as long as your account is active.
- Deleted accounts: Email, license, and device records are permanently deleted within 90 days.
- AI processing: AI providers may retain logs per their own policies; Anasa does not retain AI request content.
7. Your Data Rights (GDPR & Similar Laws)
You have the right to access, correct, delete, and export your data, and to object to non-essential processing (e.g., marketing emails). To exercise these rights, email hey@anasa.md with "Data Request" in the subject line.
8. International Data Transfers
Anasa uses processors that may operate servers outside your country (e.g., the United States). Such transfers are made under appropriate safeguards, including GDPR Standard Contractual Clauses where applicable.
9. Children's Privacy
Anasa is not intended for children under 13, and we do not knowingly collect their data. If we learn we have, we will delete it. Contact hey@anasa.md with concerns.
10. California Privacy Rights (CCPA/CPRA)
California residents may request to know, delete, or correct their personal information, and to opt out of any "sale" or "sharing" of data. Anasa does not sell personal data. Submit requests to hey@anasa.md with "CCPA Request" in the subject.
11. Security
We use TLS for data in transit, encryption at rest, and do not store unencrypted payment data. No method of transmission or storage is perfectly secure, but we work to protect your information.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be announced on our website or by email to active account holders. Continued use constitutes acceptance.
13. Contact
For privacy questions or data requests, email hey@anasa.md (Entro314 Labs). We aim to respond within 30 days, or as required by law.