Skip to main content
Security & transparency

Concrete facts, not security slogans.

What runs locally, what is transferred, how encrypted sync works, which metadata remains visible, and how published builds can be verified.

The standard

Every claim needs a defined scope.

“Local”, “encrypted”, or “verified” never applies automatically to every Priviot feature and version. This page separates local core features, optional online services, technical metadata, and version-specific build evidence.

Security and data model

What actually happens.

Local core features

PDFs, text documents, snippets, and notes are processed on the device by local core features.

Required account
No. Local core use works without a Priviot account.
Transfer
Signing into an account alone does not upload documents or personal content.
Online
Sync, collaboration, and external AI providers are separate features activated deliberately.

Builds and platform checks

Signing and notarization are only claimed for the exact product version that was verified.

macOS
The changelogs document Apple Developer ID signing and notarization per version, including PDF 1.3.2, Write 1.4.2, and Paste 1.3.4.
Windows
The respective Microsoft Store listing is the distribution route provided by Microsoft.
Limit
Evidence for an older version is not presented as blanket evidence for later builds.

Report a vulnerability

Security-relevant observations can be reported directly to Priviot.

Contact
support@priviot.com or the feedback page with the “Bug” category.
Useful details
Include the product, version, operating system, reproducible steps, and expected behaviour.
Sensitive data
Do not send confidential documents or credentials unless they are explicitly required for the investigation.

No advertising profiles

Priviot is not funded by personalised advertising and does not build advertising profiles from personal content.

Website
No download tracking and no marketing click counters.
Content
Personal documents and notes are not evaluated for advertising purposes.
Evidence
Changes are documented in concrete product changelogs instead of blanket promises.

Desktop technologies

Selected desktop applications are based on Electron, which provides the local application interface and runtime.

Data transfer
Electron by itself does not upload documents to a cloud.
Optional
No, where it forms the technical foundation of an application.
Strategy
Review security updates, scope, and possible alternatives regularly.

Account and synchronization

An account associates optional online services, purchased services, and subscriptions with a person.

Data transfer
Sign-in and functional data for the online services consciously used.
Optional
Generally not required for local core features.
Strategy
Limit account data and separate local use clearly from online services.

Infrastructure

Supabase is currently used in the website, account, and backend context.

Data transfer
Depends on the account, synchronization, or backend function actively used.
Self-hosting
Technically possible, but not automatically the current operating model.
Strategy
Review data locations, operating model, and more controllable alternatives.

AI models

Priviot AI 1.0.0 was released as a standalone application on September 3, 2026. AI functions are also integrated into the current versions of PDF, Write, Paste, and Notes.

Processing
The model, provider, and processing route depend on the configuration in each application and are identified there.
Optional
AI is not required for the local core features of PDF, Write, Paste, or Notes.
Strategy
Prefer local processing and clearly label external processing.

Stores and distribution

Applications may be distributed through priviot.com and, where applicable, platform providers.

Data transfer
Depends on the selected distribution channel and its operator.
Optional
The current route is named on each product page.
Strategy
Maintain direct, understandable downloads and disclose distribution channels.

Payment processing

Payment data should be processed separately from personal documents and content.

Data transfer
Only information required for purchase, billing, and entitlement.
Optional
Only for paid services.
Strategy
Minimize data and identify payment services specifically.

Open-source components

Priviot uses open source to avoid rebuilding proven technical foundations without reason.

Data transfer
An open-source component does not automatically transfer data.
Evidence
Licenses and key components should remain documented.
Strategy
Prefer maintainable, replaceable, and controllable components.

Encrypted synchronization

Supported private content is encrypted client-side once encrypted sync has been configured for the relevant product. The actual supported scope depends on the product version, object type, and device state.

Required by the server
Technical metadata such as account and device identifiers, product area, revision, timestamps, and ciphertext size.
Encrypted
Content and attachments explicitly identified by the relevant product as end-to-end encrypted.
Keys
The specific key and recovery flow is documented per product; signing into an account alone does not activate document uploads.
No blanket guarantees. Claims about encryption, synchronization, and local processing apply only to the specifically described function and the verified technical state. Operationally necessary metadata is not end-to-end encrypted.