Most security pages ask you to believe a company. This one asks you to verify an architecture. Your handwriting never leaves your machine — not because we promise to be careful with it, but because there is no code path that sends it anywhere.
Every line below is checkable from your side, with tools you already have. That is the point of them.
| Claim | How to check it yourself |
|---|---|
| Your notes never leave the machine | Run tcpdump, Little Snitch, or your router's log while gemnotes reads a page. The recognition call goes to 127.0.0.1. Pull the ethernet cable and everything still works. |
| The AI runs on your hardware | Watch your own GPU or CPU load while a page is recognised. If the work were happening in someone else's data centre, your fans wouldn't spin. |
| You own the archive | Your strokes are files in ~/gemnotes/notebooks/. Copy the folder to a USB stick. Delete index.db — everything AI-derived disappears and not one stroke is lost. |
| You can leave | Export to SVG, PNG, PDF or .ink. The stroke format is documented, not reverse-engineered from us by someone else. |
A security page that only lists strengths is marketing. Here is both halves.
You will not find a row of trust badges on this site. Every one of them below is either not started or blocked on something specific, and we'd rather show you the real state than a wall of logos you'd eventually check.
| Standard | Status | What it's actually blocked on |
|---|---|---|
| SOC 2 Type II | NOT STARTED | Audits a service organisation's controls over customer data held on its systems. We hold no customer notes, so the scope would be small — but it needs a legal entity, a twelve-month observation window and an auditor. Planned for the firm tier, not before. |
| ISO/IEC 27001 | NOT STARTED | Same dependency: an entity and a real management system to certify. Under consideration after SOC 2, and only if customers ask for it by name. |
| GDPR | BY DESIGN, NOT AUDITED | Your notes are never transferred to us, so for the content itself there is no processing to lawfully justify. The email you give us is personal data and is covered by our privacy policy. A formal DPA needs a legal entity to sign it. |
| HIPAA BAA | BLOCKED | Blocked on a legal entity, because only an entity can sign a Business Associate Agreement. Worth noting: the market leader in this category withdrew its BAA, which is precisely why this line is on our roadmap and not theirs. |
| Independent security review | NOT STARTED | Intended before any paid tier ships. When it happens the report gets linked here, findings included. |
A trust badge for a certification you do not hold is not a design decision, it is a false statement to a buyer — and the marks for SOC 2 and ISO 27001 belong to the bodies that award them. For a product whose entire argument is “trust us with the most private thing you own”, a fake trust signal is the one lie that would end it.
When any row above changes, it changes here first, with the report attached.
No, and not as a policy — as a fact about where the data is. Your notes are read by a model running on your own computer. Nothing is sent to us, so there is nothing of yours in any training set of ours, and we could not put it there if we wanted to.
Your archive is on your disk in a documented open format, and the index rebuilds from it. If this company disappears tomorrow, you still have every stroke and can still export it. That is deliberate: nobody pours five years of notes into something they can't get out of.
Not by us. The recognition and search models run locally. The one place your notes could reach an external AI is if you connect your own assistant to the local MCP server and ask it something — your key, your account, your choice, and writing back is off by default. Quit the app and that door is closed.
Not yet, and we would rather lose the sale than fudge this. Client work needs per-matter separation, device encryption we control, MDM, SSO, remote wipe and a signed BAA — none of which exist today. The local-first architecture is the right foundation for it and the controls on top of it are not built.
If you filled in a form on this site: your email and the answers you typed. That's the whole list, it lives in our own database rather than a third-party form service, and the privacy policy spells out how to get it deleted. There are no analytics scripts and no tracking pixels on this website — you can verify that in your browser's network tab in about ten seconds.