Local core features
PDFs, text documents, snippets, and notes are processed on the device by local core features.
- Required account
- No. Local core use works without a Priviot account.
- Transfer
- Signing into an account alone does not upload documents or personal content.
- Online
- Sync, collaboration, and external AI providers are separate features activated deliberately.
Builds and platform checks
Signing and notarization are only claimed for the exact product version that was verified.
- macOS
- The changelogs document Apple Developer ID signing and notarization per version, including PDF 1.3.2, Write 1.4.2, and Paste 1.3.4.
- Windows
- The respective Microsoft Store listing is the distribution route provided by Microsoft.
- Limit
- Evidence for an older version is not presented as blanket evidence for later builds.
Report a vulnerability
Security-relevant observations can be reported directly to Priviot.
- Useful details
- Include the product, version, operating system, reproducible steps, and expected behaviour.
- Sensitive data
- Do not send confidential documents or credentials unless they are explicitly required for the investigation.
No advertising profiles
Priviot is not funded by personalised advertising and does not build advertising profiles from personal content.
- Website
- No download tracking and no marketing click counters.
- Content
- Personal documents and notes are not evaluated for advertising purposes.
- Evidence
- Changes are documented in concrete product changelogs instead of blanket promises.
Desktop technologies
Selected desktop applications are based on Electron, which provides the local application interface and runtime.
- Data transfer
- Electron by itself does not upload documents to a cloud.
- Optional
- No, where it forms the technical foundation of an application.
- Strategy
- Review security updates, scope, and possible alternatives regularly.
Account and synchronization
An account associates optional online services, purchased services, and subscriptions with a person.
- Data transfer
- Sign-in and functional data for the online services consciously used.
- Optional
- Generally not required for local core features.
- Strategy
- Limit account data and separate local use clearly from online services.
Infrastructure
Supabase is currently used in the website, account, and backend context.
- Data transfer
- Depends on the account, synchronization, or backend function actively used.
- Self-hosting
- Technically possible, but not automatically the current operating model.
- Strategy
- Review data locations, operating model, and more controllable alternatives.
AI models
Priviot AI 1.0.0 was released as a standalone application on September 3, 2026. AI functions are also integrated into the current versions of PDF, Write, Paste, and Notes.
- Processing
- The model, provider, and processing route depend on the configuration in each application and are identified there.
- Optional
- AI is not required for the local core features of PDF, Write, Paste, or Notes.
- Strategy
- Prefer local processing and clearly label external processing.
Stores and distribution
Applications may be distributed through priviot.com and, where applicable, platform providers.
- Data transfer
- Depends on the selected distribution channel and its operator.
- Optional
- The current route is named on each product page.
- Strategy
- Maintain direct, understandable downloads and disclose distribution channels.
Payment processing
Payment data should be processed separately from personal documents and content.
- Data transfer
- Only information required for purchase, billing, and entitlement.
- Optional
- Only for paid services.
- Strategy
- Minimize data and identify payment services specifically.
Open-source components
Priviot uses open source to avoid rebuilding proven technical foundations without reason.
- Data transfer
- An open-source component does not automatically transfer data.
- Evidence
- Licenses and key components should remain documented.
- Strategy
- Prefer maintainable, replaceable, and controllable components.
Encrypted synchronization
Supported private content is encrypted client-side once encrypted sync has been configured for the relevant product. The actual supported scope depends on the product version, object type, and device state.
- Required by the server
- Technical metadata such as account and device identifiers, product area, revision, timestamps, and ciphertext size.
- Encrypted
- Content and attachments explicitly identified by the relevant product as end-to-end encrypted.
- Keys
- The specific key and recovery flow is documented per product; signing into an account alone does not activate document uploads.