AnvilNote
Back to home

Privacy Policy

Last updated: July 2026
Effective date: July 2026

AnvilNote values your privacy and your right to control your own personal data. This Privacy Policy explains how data relating to your use of AnvilNote is stored, transmitted, processed, and used, and describes the data processing that may be involved when third-party services are used.

AnvilNote is designed on a local-first basis. Unless you actively enable a feature that requires a connection to a third-party service, your document content is, in principle, stored only on your own device and is not transmitted to any server operated by the AnvilNote maintainers.

By using AnvilNote, you acknowledge that you have read and understood this Policy.

1. Scope of application

This Policy applies to the desktop app, the web app, and related program components officially provided by the AnvilNote project maintainers.

This Policy does not apply to the following services or circumstances:

  1. Forks of AnvilNote that have been modified, repackaged, or distributed by third parties on their own initiative;
  2. Third-party services that you connect to or use through AnvilNote;
  3. Data collection, processing, or use carried out by GitHub, OpenAI, operating system vendors, software distribution platforms, or other third-party platforms;
  4. Websites, services, or programs that are not controlled or operated by the AnvilNote project maintainers.

The third-party services referred to above process data in accordance with their own respective terms of service, privacy policies, and applicable law.

2. Storage and management of local data

AnvilNote does not require you to register an account, nor does it require you to sign in to any cloud service operated by AnvilNote.

The following data that you create or edit in AnvilNote is, in principle, stored entirely on your own device:

  • Document content;
  • Drafts;
  • Document version history;
  • Imported or attached files;
  • User preference settings;
  • Templates, fonts, and other local data necessary to carry out the software's functions;
  • Other content that you create or retain through AnvilNote.

Depending on which version you use, the data described above may be stored in the desktop app's application data directory, in a file location you specify, or in local storage provided by your web browser.

Your use of AnvilNote does not cause the AnvilNote project maintainers to automatically obtain, read, back up, or retain the data described above. Unless you provide a document to the project maintainers yourself, the project maintainers have no access to your document content.

You may manage or delete local data using features provided by AnvilNote, your operating system, or your browser. Because the AnvilNote project maintainers do not hold a copy of your local data, they are unable to recover documents that are deleted, corrupted, or lost.

3. Collection, processing, and use of personal data

In normal offline use, AnvilNote does not transmit your documents, drafts, version history, or other content to any server operated by the AnvilNote project maintainers.

AnvilNote also does not proactively collect, process, or use your personal data for any of the following purposes:

  • Building profiles of user behavior;
  • Building profiles for advertising or marketing purposes;
  • Conducting cross-site or cross-service tracking;
  • Analyzing document content;
  • Selling, renting, or exchanging user data;
  • Providing document content to advertisers or data brokers.

Merely downloading, installing, or running AnvilNote does not cause the AnvilNote project maintainers to obtain the documents or other private data on your device.

4. AI Smart Mode

4.1 Enabling the feature

AI Smart Mode is an optional feature. AnvilNote will transmit specific data to the API provided by OpenAI, based on your actions, only if you have configured your own OpenAI API key and actively use AI Smart Mode.

If you have not configured an API key, or do not use AI Smart Mode, AnvilNote will not transmit your document content on account of this feature.

4.2 Data that may be transmitted

When you use AI Smart Mode, AnvilNote may, depending on the feature you select, transmit the following data directly to OpenAI:

  • The instructions, questions, or prompt text you enter;
  • Document content you have actively selected or specified;
  • Context necessary to complete the operation you have requested;
  • The content of files you actively attach or specify, where the feature supports attachments;
  • Other data you expressly choose to provide for processing by the AI model.

AnvilNote does not, absent your action or selection, proactively transmit the entirety of the documents on your device to OpenAI.

4.3 API keys

The OpenAI API key you configure is stored only on your own device:

  • In the web app, it is, in principle, stored in browser session storage or other local storage;
  • In the desktop app, it is, in principle, retained through the secure storage mechanism provided by the operating system.

When you use AI Smart Mode, your API key is transmitted directly to OpenAI for authentication and to authorize the API request. Your API key is not transmitted to any server operated by the AnvilNote project maintainers, nor is it held in custody by the AnvilNote project maintainers on your behalf.

You are responsible for safeguarding your API key and for bearing the risks arising from key leakage, unauthorized use, API charges incurred, or access obtained by a third party.

4.4 Third-party data processing

Data transmitted to OpenAI through AI Smart Mode will be processed by OpenAI in accordance with its then-current terms of service, data processing terms, privacy policy, and related settings.

The AnvilNote project maintainers are not OpenAI's agent and have no control over the retention periods, security measures, processing locations, cross-border transfer methods, or other data processing practices that OpenAI applies to such data.

Before using AI Smart Mode, you should confirm for yourself that:

  1. You are authorized to provide the relevant documents or data to OpenAI;
  2. Such data is not subject to restrictions arising from contract, confidentiality obligations, trade secrets, professional ethics, or other legal obligations;
  3. You have obtained the consent or other lawful basis necessary to process the personal data of others;
  4. You have read and accepted OpenAI's applicable terms of service and privacy policy.

Unless you have confirmed that you have lawful authority and fully understand the associated risks, we do not recommend transmitting the following to any third-party AI service:

  • National ID numbers, passport numbers, financial account information, or other highly sensitive identifying data;
  • Medical, health, or biometric data;
  • Unpublished research results;
  • Trade secrets or confidential business information;
  • Content protected by the professional confidentiality obligations of attorneys, physicians, accountants, or other professionals;
  • Personal data obtained without the consent of the data subject;
  • Data whose transmission is prohibited by law, contract, or organizational policy.

5. Update checks

The AnvilNote desktop app may connect to GitHub's public Releases API to check whether a newer version is available for download.

The update check does not proactively transmit any of the following:

  • Your document content;
  • Drafts or version history;
  • Your OpenAI API key;
  • Document titles;
  • Text you have entered;
  • Files you have attached in AnvilNote.

However, any network connection may allow the third-party service receiving the request to obtain standard network communication data, such as your IP address, the time of the request, browser or application identification information, operating system information, and other standard HTTP request data.

This data is processed by GitHub in accordance with its own privacy policy and terms of service. The AnvilNote project maintainers do not obtain or retain your document content through the update check.

6. Analytics, advertising, and tracking technologies

AnvilNote does not build in any of the following:

  • Usage behavior analytics services;
  • Advertising tracking tools;
  • Cross-site tracking tools;
  • Third-party advertising SDKs;
  • Telemetry tools used to build user profiles;
  • Data collection tools used for sales or marketing purposes.

AnvilNote does not sell, rent, exchange, or otherwise provide your document content to advertisers, data brokers, or other third parties.

If error reporting, usage statistics, or other telemetry features are added in the future, AnvilNote will update this Policy before enabling them and will provide appropriate notice and choice mechanisms suited to the nature of the feature.

7. Third-party platforms and external links

AnvilNote may provide links to GitHub, OpenAI, Typst, or other third-party websites and services.

Once you click an external link or use a third-party service, the resulting data processing is not governed by this Policy. The AnvilNote project maintainers have no control over, and make no warranty regarding, the content, availability, security, data processing practices, or privacy measures of any third-party service.

When you submit an Issue, Discussion, Pull Request, or other public content through GitHub, your GitHub account name, comments, attachments, and other data you provide may be displayed publicly in accordance with GitHub's platform settings. Please do not disclose API keys, personal data, confidential documents, or other content unsuitable for public disclosure in a public Issue or Discussion.

8. Data security

AnvilNote adopts a local-first design to reduce the risk of data breaches that can arise from documents being centrally stored on a remote server. However, local storage does not mean your data is absolutely secure.

The security of your data may still be affected by factors such as:

  • Loss or theft of your device;
  • Unauthorized access to your operating system account;
  • Malware, ransomware, or other security incidents;
  • Damage to your hard drive or storage device;
  • Clearing of browser data;
  • Incomplete backup arrangements;
  • Leakage of your API key;
  • Accidental deletion or user error;
  • Security vulnerabilities in third-party packages or the operating system.

We recommend that you take appropriate security measures, including:

  • Using a device login password and screen lock;
  • Enabling disk encryption;
  • Regularly backing up important documents;
  • Installing versions of AnvilNote released only through trusted sources;
  • Keeping your operating system and AnvilNote up to date;
  • Avoiding sharing your API key with others;
  • Periodically reviewing and revoking API keys that are no longer in use;
  • Avoiding processing confidential documents on public devices or devices controlled by others.

9. Data retention and deletion

The AnvilNote project maintainers do not, in principle, retain your local documents, and are therefore unable to determine the retention period for such data.

Your documents, drafts, version history, and local settings will continue to be retained according to your own actions and device environment, until you delete them yourself, clear your browser data, remove the application's data, or they are lost due to device damage, a system reset, or similar causes.

Whether simply uninstalling AnvilNote also deletes your documents or related settings may vary depending on the operating system, the installation method, and the data storage location. Before uninstalling, you should first confirm that important documents have been properly backed up.

The retention period and deletion method for data retained by a third-party service are governed by that third-party service's own privacy policy and account settings.

10. Personal data rights

Because the AnvilNote project maintainers do not, in principle, hold your local documents or related personal data, they are generally unable to access, correct, restrict the use of, or delete such data on your behalf.

You may manage the relevant data directly through your own device, operating system, browser, or third-party service account.

If you believe the AnvilNote project maintainers hold your personal data as a result of a bug report, email correspondence, GitHub interaction, or other means, you may request, in accordance with applicable law:

  • Access to or review of the data;
  • A copy of the data;
  • Supplementation or correction of the data;
  • Cessation of collection, processing, or use of the data;
  • Deletion of the data.

The exercise of the foregoing rights remains subject to identity verification, statutory retention obligations, prevention of abuse of rights, and other limitations under applicable law.

11. Children and minors

AnvilNote is not designed for the purpose of collecting personal data from children or minors.

Because AnvilNote does not require account registration and documents are, in principle, stored on the user's own device, the AnvilNote project maintainers generally have no way of knowing a user's age.

Minors using AI Smart Mode, the OpenAI API, or other third-party services should confirm that such use complies with the applicable age requirements of those services and, where necessary, obtain the consent of a parent or legal guardian.

12. Changes to this policy

AnvilNote may revise this Policy in response to feature changes, technical changes, changes to third-party services, or legal requirements.

The revised Policy will be published on the AnvilNote official website or project page, with the latest update date indicated at the top. If a material change involves new data collection, remote transmission, analytics or tracking, or other matters that could substantially affect users' rights and interests, additional notice will be provided by reasonable means.

Unless otherwise stated, the revised Policy takes effect on the date it is published.

13. Contact

If you have any questions about this Policy, about how AnvilNote processes data, or about exercising your personal data rights, you may contact the project maintainers through AnvilNote's GitHub project pages:

Please do not submit API keys, identification documents, unpublished documents, confidential data, or other sensitive information through a public GitHub Issue, Discussion, or other public channel.