Privacy Policy — AirPad
Effective August 14, 2026
AirPad is built on a simple principle: your ideas are yours. The app has no server, no account, and no analytics. We do not have access to your notes, and there is no mechanism by which we could.
What AirPad stores, and where
Everything you capture — text, photos, video, audio, links, and the connections between them — is stored in your own iCloud Drive, in a folder you can open, inspect, and copy at any time. It is governed by your Apple account and Apple's privacy terms. Curious Objects operates no servers and receives no copy.
If you disable iCloud Drive, your notes remain on your device.
What we collect
Nothing. AirPad contains no analytics, no telemetry, no crash reporting, no advertising identifiers, and no third-party tracking SDKs. We do not know how many notes you have, what they say, or how you use the app.
Device permissions
AirPad asks only for what a given feature needs, at the moment it needs it — this is the exact text iOS shows you, taken directly from the app's configuration:
- Camera — "AirPad uses the camera to capture photos and videos as ideas."
- Photo library — "AirPad can add photos from your library to an idea." Read access only — AirPad does not write back to or scan your library beyond what you explicitly select.
- Microphone — "AirPad needs microphone access to record voice notes."
- Speech recognition — "AirPad uses speech recognition to transcribe your voice notes." Transcription uses Apple's on-device speech framework where possible.
- Local network — "AirPad needs local network access to reach the Ollama or LM Studio endpoint you configured in Settings. Only used for queries you initiate." Only relevant if you've configured a self-hosted AI model on your own network (see below). Off by default.
AirPad does not request contacts, calendar, location, health data, or Bluetooth access, because it doesn't use any of them.
Any of the above can be revoked in iOS Settings at any time. Revoking one disables the feature, not the app.
On-device intelligence (default)
AirPad's default AI features — summaries, suggested titles, suggested tags, and the Librarian — run on Apple's on-device Foundation Model. Your content is processed on your device and is not transmitted.
Optional on-device local model
AirPad offers an optional, user-downloadable local AI model (Qwen3, ~1 GB) as an alternative to Apple's on-device model, for cases where Apple's model declines to process something. Off until you turn it on in Settings.
- The one-time download of the model's weight files comes from Hugging Face's public model hosting. That download transfers only the model file itself — none of your content.
- After download, all generation using this model happens entirely on your device, the same as Apple's on-device model. Nothing you write is sent anywhere.
- The model is stored in app-support storage on your device (not iCloud, not backed up), and can be deleted at any time from Settings.
When content leaves your device — and only then
There are exactly three cases beyond the local model above, and all three require an action by you.
1. Frontier AI providers (Anthropic, OpenAI, DeepSeek).
If you enter an API key in Settings, requests you make in that mode are sent directly from your
device to that provider's own API — never through any AirPad server, because none exists. Your
key is stored only in the iOS Keychain on your device; we never receive it. Content sent this
way is subject to that provider's own privacy policy, not ours:
AirPad works fully without any key.
2. A model endpoint you configure yourself.
If you point AirPad at your own model server (for example LM Studio or Ollama, on your own
machine), queries go to the address you specified, over your own local network. Where that
traffic goes from there is determined entirely by you.
3. Web search.
If you use the Librarian's web search, your search query is sent to the Brave Search
API if you've supplied your own Brave key in Settings, or to a keyless fallback search
path if you haven't. Only the specific search terms for that chat turn are sent — never your
stored notes.
★ In all cases the app tells you which model produced a given result, so you always know whether something was handled on your device or elsewhere.
Children
AirPad is not directed at children under 13 and collects no information from anyone.
Changes
If this policy changes, the updated version will be posted at https://doctorpresident.pages.dev/airpad/privacy with a new effective date. Because we collect nothing, a change here will describe app behaviour — not a change in what we hold about you. (The clearest anticipated case: the future Sync & Vault feature, which will introduce optional cloud backup and will get its own policy update, describing exactly what it does and doesn't transmit, before it ships — not folded into this document speculatively.)
Contact
tom@doctorpresident.com
Curious Objects