Foxlore Home Privacy Policy EULA

Privacy Policy

Last updated: July 2026

The short version: Foxlore is built around privacy. Your note content, tags, search queries, attached images, audio, and PDFs are stored and processed on your Apple devices. Foxlore has no application server that receives that content. The app makes outbound network calls in five narrow categories: (1) downloading the on-device AI models, (2) syncing through iCloud when enabled, (3) Apple Maps searches and map previews, (4) opt-in anonymous analytics, and (5) opt-in crash reports. Analytics and crash reporting are off by default. Summarisation, search, image captioning, audio transcription, PDF extraction, and Calendar access are on-device.

On-device processing

Note storage, semantic search, image captioning, audio transcription, and PDF text extraction run locally on supported Apple devices using Apple's MLX, Speech, and PDFKit frameworks plus downloadable open-source embedding and vision-language models. Note content, tags, search queries, image bytes, audio bytes, and PDF bytes are not sent to Foxlore during processing.

AI content summarisation — the “Summarize” action on a note and the summary above search results — uses the default on-device model provided by Apple's FoundationModels framework. Foxlore does not configure a cloud model for these features, and the Developer does not receive their inputs or outputs. Apple's system-provided Writing Tools are separate from Foxlore's summarisation features and are governed by Apple's terms and device settings.

Internet connections

Foxlore makes outbound network connections in the following narrow cases:

1. AI model downloads

The on-device search and captioning features rely on open-source models that are too large to ship inside the app bundle. When you complete onboarding, change your Effort tier, repair a model, or install a model on another device, Foxlore downloads the selected static model files from models.foxlore.app. Installed models are then used locally. Model requests do not include note content, tags, search queries, images, audio, or PDFs.

2. iCloud Sync (optional, encrypted)

Notes can be synced across your Apple devices via Apple's CloudKit. Foxlore marks the following as encrypted CloudKit fields: note content; the timestamps a note carries (when it was created, last updated, and moved to trash); tag names; image bytes and captions; audio and transcripts; attached PDF bytes; cached searchable text and the underlying payload for typed attachments; location URLs and Calendar event identifiers; and saved-filter names. CloudKit encrypts these values on-device before upload and decrypts them after download. When you enable Apple's Advanced Data Protection for iCloud, the keys for encrypted fields are available only to you (and participants of records you explicitly share). Otherwise, Apple protects the data under its standard iCloud security model. The Developer operates no iCloud-side server and has no access to data stored in your private iCloud account.

Foxlore also stores the timestamp when a free trial first begins in Apple's iCloud key-value store and in the app's local Keychain. The earliest timestamp is used so the same seven-day trial applies across your devices and after reinstalling the app. Purchase and restore records are handled by Apple through StoreKit.

One transparency note about cross-device deduplication. For attached images, PDFs, and voice memos, Foxlore stores a one-way cryptographic hash (SHA-256) of the file bytes alongside the encrypted file itself. The hash is intentionally NOT encrypted in iCloud so that the same image pasted on two devices collapses into a single shared record, rather than uploading duplicates. The hash cannot be reversed to reveal the file's contents; what it does reveal — to Apple, who hosts the iCloud server — is the bare fact that you have a file whose bytes match a specific known fingerprint. The same trade-off applies to a small number of categorical fields (e.g. "this attachment is a Calendar event", "this image is a PNG") that the sync engine needs to be able to read in order to keep two devices in agreement.

3. Apple system frameworks for note attachments

Foxlore uses Apple's system frameworks to add and display certain attachments. The behaviour differs by kind:

  • Calendar event attachments are fully local — EventKit reads from your local Calendar database. Foxlore makes no network request for this access.
  • Maps attachments can use MapKit to search for places and render a map preview. Those requests go from your device to Apple and may include the search text or the attachment's coordinates. No Maps request passes through Foxlore's servers.
  • Audio attachments on macOS and iOS are transcribed through the Speech framework with requiresOnDeviceRecognition = true. If on-device recognition is unavailable, Foxlore skips transcription rather than sending audio to a cloud service. The transcript becomes searchable text within the note; the audio remains in Foxlore's local store (and your iCloud account when sync is enabled).
  • PDF attachments are read and indexed entirely on-device via Apple's PDFKit framework — page-count and the per-page text body are extracted locally so the PDF's contents become searchable inside the note. PDF bytes stay in the local Core Data store and, when sync is enabled, your personal iCloud account. Reading and indexing a PDF makes no network request.

MapKit search and preview requests are the only network egress in this category. They are handled by Apple under Apple's Privacy Policy.

4. Analytics (opt-in, off by default)

If you choose to enable analytics in Settings → Privacy, pseudonymous usage signals are sent to TelemetryDeck. These signals describe feature interactions and app behavior and may include categorical values or coarse count buckets (for example, an effort tier or “11–50” notes). TelemetryDeck may assign a device identifier for analytics. Signals do not include note content, tag names, search text, filenames, or attachment contents.

5. Crash Reports (opt-in, off by default)

If you choose to enable crash reporting in Settings → Privacy, diagnostic data is sent to Sentry. It can include crash logs, stack traces, performance and hang data, app version, operating-system/device information, and diagnostic app state. Foxlore disables screenshots, view hierarchies, and breadcrumbs and scrubs note identifiers and file paths before sending events. Foxlore does not intentionally include note content, tags, search text, or attachment contents. Disabling crash reporting stops Sentry within the same session.

Your controls

Both analytics and crash reporting are disabled by default. You can enable or disable either toggle at any time in Settings → Privacy. You can enable or disable note synchronization in Foxlore's iCloud settings; the trial timestamp still uses iCloud key-value storage so a trial remains consistent across devices. MapKit requests occur only when you search for a location or display a note's map preview. Model downloads occur during onboarding or when you change, install, or repair models.

Data the Developer never receives

The Developer does not receive and has no access to your note content, tags, search text, images, audio, PDFs, or iCloud records. Foxlore operates no application server that receives that content. Its model host serves static model files only; TelemetryDeck and Sentry receive the limited data described above only when you opt in.

Third-party services

Foxlore uses the following third-party services. Each operates under its own privacy policy:

  • Apple — App Store and StoreKit, iCloud (CloudKit and key-value storage), MapKit, EventKit, Speech, Foundation Models, and system Writing Tools, all governed by Apple's Privacy Policy.
  • TelemetryDeck — analytics, only when enabled.
  • Sentry — crash reporting, only when enabled.

Changes to this policy

If we make material changes to this policy, we will update the date above and note the changes clearly in the release notes.

Contact

Questions? Reach out at feedback@foxlore.app.

© 2026 Foxlore  ·  Privacy Policy  ·  EULA  ·  Contact