Altretta Privacy
Effective 1 August 2026
Our privacy policy is in two halves, and this is one of them. Together they are the whole picture; neither is complete on its own.
This half is about your notes — the Altretta application, synchronisation, hosted publishing, the AI features and the connectors. It is where you find out what leaves your computer and what does not.
The other half is about you as a customer — your account, your payments, our websites, who processes data for us, how long we keep it and how to have it erased. That is the Apilium Privacy Policy, and it is the company-level document that governs your rights.
They are split this way because the answers are genuinely different. Almost nothing you write in Altretta ever reaches us; almost everything about your account does. Putting both in one document would make the first sound less true than it is.
In short
| Surface | What we hold |
|---|---|
| The app on your computer | Nothing. Your notes are files on your disk. |
| Sync | Nothing readable. Encrypted on your device, stored where you choose, and we do not have the key. |
| Hosted publishing | Only the notes you chose to publish, because we serve them. |
| AI features | Nothing. Your provider, your key, and the request never passes through us. |
Four surfaces, four answers. The sections that follow are the same four answers with the reasons and the exceptions attached.
1. The app on your computer
Altretta is a desktop application. Your notes are Markdown files in a folder you chose, and the index, the search, the graph and the version history are computed on your machine.
There is no telemetry. No analytics library, no crash reporting, no usage statistics. You can download the app, use it for years and never create an account.
The app makes two kinds of network request, and both are worth naming:
- It checks for updates when it starts. This sends no version number, no identifier and nothing about you. You can turn it off in Settings.
- If you hold a licence, it revalidates it when it starts. That sends the licence key and a device fingerprint. An installation that has never held a licence makes no such request.
The device fingerprint is a one-way hash of three things: your computer's host name, its operating system and its processor architecture. It exists so a seat can be released when you stop using a machine. Your host name is also sent in clear when you activate a licence, so the device list in your account is readable to you. We do not collect your MAC address, your processor count, your memory, or a list of your network interfaces.
Any request over the internet necessarily tells the receiving server your IP address. That is true of every application, and it is why the two above are named.
2. Sync
Sync copies your vault between your own devices through storage you choose — a folder in Dropbox, OneDrive, a network drive, anything that appears as a folder.
We are not in the path. The vault is encrypted on your device before it is written, with a key generated there and wrapped by your passphrase. The wrapped key lives in your own sync folder, which means your storage provider holds a passphrase-protected copy and we hold nothing at all. We cannot read your notes, we cannot recover them, and if you lose both your passphrase and your recovery key nobody can.
File names are hidden — they become keyed hashes — and file sizes are padded, so the storage you use learns the number of files, their approximate sizes and when they changed, and not much else.
The shared team vault works differently in one respect: it encrypts file contents but not file names or folder structure. Someone with access to that encrypted store learns the shape of the vault and the titles of its notes.
3. Hosted publishing
If you publish notes as a website we host, those notes are on our servers, because that is what serving them means. Only the notes you selected — nothing else from your vault is uploaded, examined or indexed.
We hold the published files, the site's address, and the account that published it. We place no cookies on your readers and do not track them, and we add no analytics to your site.
Two things to know before you publish:
- **A published note that links to an unpublished one may disclose that note's title and folder path** in the page's HTML, as a link that leads nowhere. If a note's name or location is itself sensitive, do not link to it from a page you publish.
- You can take a site down at any time, from the app or from your account. Doing so deletes the hosted copy. Anyone following an old link is told the author took the page down; the notice names neither you nor what was published.
4. AI features
Altretta can answer questions about your notes using an AI provider you choose and pay for — or a model running on your own machine.
We have no AI model and your requests do not pass through us. The application talks to the endpoint you configured, directly. We do not see your question, the notes sent with it, or the answer, and we could not produce them if we were asked to. What that provider does with the material afterwards is governed by their terms, and you should read them.
The application tells you where each request goes: to the device you are using, elsewhere on your network, or over the internet. A model on another machine in your building is still another machine.
5. Plugins and the local connector
A plugin you install runs in a sandbox with no network access unless you grant it, host by host. Anything it then sends goes to whoever wrote it, not to us.
Altretta can also expose a read-only connection to your vault for AI tools you run yourself. It is off unless you turn it on, bound to your own machine, and reachable only with a token you create and can revoke. You can exclude folders from it. A tool you hand a token to can read what the policy allows.
6. Your rights, and everything else
Your account, what we keep, for how long, who processes it for us, and how to have it erased are all in the Apilium Privacy Policy. Anything in your vault is on your own computer and has never been ours to delete.
Questions about this document: [email protected].
Apilium Technologies OÜ · Tallinn, Estonia Registry code 17409213