Privacy Policy — AirPad

Effective August 14, 2026

AirPad is built on a simple principle: your ideas are yours. The app has no server, no account, and no analytics. We do not have access to your notes, and there is no mechanism by which we could.

What AirPad stores, and where

Everything you capture — text, photos, video, audio, links, and the connections between them — is stored in your own iCloud Drive, in a folder you can open, inspect, and copy at any time. It is governed by your Apple account and Apple's privacy terms. Curious Objects operates no servers and receives no copy.

If you disable iCloud Drive, your notes remain on your device.

What we collect

Nothing. AirPad contains no analytics, no telemetry, no crash reporting, no advertising identifiers, and no third-party tracking SDKs. We do not know how many notes you have, what they say, or how you use the app.

Device permissions

AirPad asks only for what a given feature needs, at the moment it needs it — this is the exact text iOS shows you, taken directly from the app's configuration:

AirPad does not request contacts, calendar, location, health data, or Bluetooth access, because it doesn't use any of them.

Any of the above can be revoked in iOS Settings at any time. Revoking one disables the feature, not the app.

On-device intelligence (default)

AirPad's default AI features — summaries, suggested titles, suggested tags, and the Librarian — run on Apple's on-device Foundation Model. Your content is processed on your device and is not transmitted.

Optional on-device local model

AirPad offers an optional, user-downloadable local AI model (Qwen3, ~1 GB) as an alternative to Apple's on-device model, for cases where Apple's model declines to process something. Off until you turn it on in Settings.

When content leaves your device — and only then

There are exactly three cases beyond the local model above, and all three require an action by you.

1. Frontier AI providers (Anthropic, OpenAI, DeepSeek).
If you enter an API key in Settings, requests you make in that mode are sent directly from your device to that provider's own API — never through any AirPad server, because none exists. Your key is stored only in the iOS Keychain on your device; we never receive it. Content sent this way is subject to that provider's own privacy policy, not ours:

AirPad works fully without any key.

2. A model endpoint you configure yourself.
If you point AirPad at your own model server (for example LM Studio or Ollama, on your own machine), queries go to the address you specified, over your own local network. Where that traffic goes from there is determined entirely by you.

3. Web search.
If you use the Librarian's web search, your search query is sent to the Brave Search API if you've supplied your own Brave key in Settings, or to a keyless fallback search path if you haven't. Only the specific search terms for that chat turn are sent — never your stored notes.

In all cases the app tells you which model produced a given result, so you always know whether something was handled on your device or elsewhere.

Children

AirPad is not directed at children under 13 and collects no information from anyone.

Changes

If this policy changes, the updated version will be posted at https://doctorpresident.pages.dev/airpad/privacy with a new effective date. Because we collect nothing, a change here will describe app behaviour — not a change in what we hold about you. (The clearest anticipated case: the future Sync & Vault feature, which will introduce optional cloud backup and will get its own policy update, describing exactly what it does and doesn't transmit, before it ships — not folded into this document speculatively.)

Contact

tom@doctorpresident.com
Curious Objects