Privacy policy
The most important page on this site. Edmund’s privacy story is its product story, so here it is, in plain English.
Last updated July 2026 · England & Wales
The short version
Edmund has no account, and no server of mine ever holds your notes: they’re processed on your device and sync only through your own iCloud, so I never receive them. (One tiny, note-blind Worker connects a few integrations, spelled out below, and even it never sees your notes.) The only personal data that reaches me is what you send me directly: a message if you email support, your name and email if you sign up for the beta, or just your email if you ask to be told when it launches. That’s the whole of it; everything below is the detail.
Who I am
Edmund is made and run by Will Wilson, a sole trader in England, who is the data controller for the limited personal data described here. You can reach me any time at hello@edmundapp.com or through the support form.
Edmund is sold and distributed only through Apple’s App Store. Apple’s own privacy policy covers your App Store account, your purchase, and the iCloud service your notes sync through, none of which I see.
What stays on your device
The heart of Edmund runs entirely on your device. When you capture a note, typed or dictated with on-device transcription, and Edmund reads it, classifies it and files it into a project, all of that happens locally. Your note content, your voice, and the classifications never leave your device for me to see, and most of it never leaves your device at all.
Sync is your iCloud
If you use more than one device, Edmund keeps them in sync through your own iCloud, using Apple’s CloudKit. Your notes live in your private iCloud account, inside Apple’s infrastructure, not on any server of mine. I have no way to read what’s in your iCloud. Sync is governed by Apple’s terms and your iCloud settings, and you can turn it off on your device.
On-device AI, and the optional cloud engine
By default the AI that reads and classifies your notes is on-device: Apple’s on-device models where your device supports them, or a simpler on-device match otherwise. Nothing is sent anywhere for this.
Optionally, you can add your own Anthropic API key to use a cloud engine instead. If you do, the text of the notes you choose to triage is sent from your device directly to Anthropic, under your own Anthropic account and their terms. It does not pass through me. Your key is held in your device’s Keychain. This is the one path where note content leaves your device to a third party, it is entirely your choice, and it is off unless you set it up. (Anthropic processes data in the United States.)
Sending notes onward
When you choose to route a note to Linear, GitHub or Apple Reminders, only that note’s content is sent, only at that moment, and only to the service you picked, under that service’s own terms. Apple Reminders is handled on-device through Apple’s own framework. Any access tokens you connect are stored in your device’s Keychain. Nothing is routed automatically without your action unless you deliberately turn on auto-routing for a project.
Separately from routing, Edmund can copy the reminders you set onto notes into an “Edmund Nudges” list in Apple Reminders, so you see them without opening the app. This is off unless you switch it on in Settings, which is when your device asks you for Reminders access. It uses the same on-device Apple framework, so the reminder’s title and a link back to the note are written straight into Apple Reminders on your device and travel no further than your own iCloud. Nothing about it reaches me, and no server of mine is involved. Switch it off and Edmund stops writing to Reminders, though anything already there stays until you clear it yourself.
Reading the page behind a link
Share a link into Edmund and the note can end up being nothing but the address, which is no use to anyone reading it back a week later. So when a note is only a link, your device fetches that page and takes its title, the same request your browser would make if you opened it. The title goes into the note. Nothing of yours is sent: the site learns that someone visited, and sees your device’s IP address as it would for any visit, and that is the whole of the exchange. No server of mine is involved and nothing about it reaches me.
It only happens when the note is just a link. If you wrote a sentence with a link in it, that is your writing and Edmund leaves it alone rather than quietly fetching every address you note down. It is on by default, because a note that reads as a bare address is the problem it solves, and you can switch it off under Settings, Data, “Look up link titles”. With it off your device makes no such request.
The one small piece of cloud
I want to be exact about this, because “no servers” is almost true, and almost isn’t good enough for a privacy page. A handful of integrations (currently Jira, Notion, ClickUp, Asana and Todoist) use a kind of sign-in that can’t be done safely from an app on its own. For those, and only those, connecting runs through a small, stateless Cloudflare Worker that I operate, and its entire job is the sign-in handshake: it swaps the one-time code the service hands back for an access token, then passes that token straight to your device, where it lives in your Keychain like any other. That’s the whole of it.
What it does not do is the part that matters. It never sees, receives or stores a single word of your notes. Routing a note goes directly from your device to the service you chose, never through this. It keeps no database and holds nothing between requests: once the handshake is done, there’s nothing left of it. It logs only which service you connected and whether it worked (never your tokens, never your data) and, like any web request, it briefly sees your device’s IP address to keep out abuse and then keeps none of it. Most integrations don’t use it at all: GitLab signs in entirely on your device, and the rest connect straight from your device without it. So the honest version of “I run no servers” is this: I run one tiny piece of plumbing to connect a few services, and your notes never go anywhere near it.
The little I do receive
The only ways your personal data reaches me are the ones you choose: if you contact support, if you sign up for the beta, or if you ask to be told when Edmund launches. When you use the support form or email me, I receive your name, email and message so I can reply. When you sign up for the beta, I receive your name, email and an optional note so I can send you an invite. And if you use the “notify me at launch” form, I receive only your email, so I can tell you the day the app is out. In each case I use those details only for that purpose, and they’re never added to a marketing list. The forms are delivered by Cloudflare, which hosts this site and sends the email to me on your behalf. My lawful basis is legitimate interest: responding to something you chose to send me. I keep support correspondence only as long as needed to help you and for a short record afterwards (typically up to 24 months); beta signup details I keep only until I’ve sent your invite or you’ve declined; and a launch-notify email I keep only until the app is out, or until you ask me to remove it. After that they’re deleted.
Purchases are handled by Apple. Apple gives me anonymised, aggregated sales figures. I never see your payment details or your Apple Account.
This website & analytics
This site is a static website that sets no cookies by default. The only times it handles personal data without any cookie are when you submit the support form, the beta signup form, or the “notify me at launch” form, as described above.
I use Google Analytics to understand, in aggregate, how the site is used: which pages people read, roughly where in the world they are, and which links work. Because analytics cookies aren’t essential, they are off until you say yes: on your first visit a banner asks, and nothing analytics-related loads or sets a cookie unless you choose Accept. Choosing Decline keeps it entirely off. The lawful basis is your consent, and you can withdraw it at any time using the Cookie settings link in the footer (or by clearing this site’s data in your browser), which also stops any further data being sent.
When enabled, Google Analytics collects standard usage data (pages viewed, approximate location derived from a truncated IP, device and browser type, and how you arrived) and sets its own cookies in your browser. It does not see your notes, which never leave your device. Google processes this data as described in Google’s privacy policy; data may be processed in the United States. I only ever see anonymised, aggregated reports.
Keeping, exporting and deleting
Your notes are yours, kept on your device and in your iCloud for as long as you keep them. You can export everything from Settings (your notes as Markdown and JSON, with attachments) and because those are open, ordinary formats on purpose, nothing you put into Edmund is ever locked in. You can delete individual notes or wipe everything from within the app, and deleting the app removes its local data. Because I never hold your notes, deleting them is entirely in your hands.
Brain dumps keep a transcript. Capture in brain dump mode and Edmund saves the full text of what you said alongside the notes it splits out of it, so each note can link back to where it came from. That transcript is an ordinary piece of your data and behaves like one: it lives on your device, it syncs through your own iCloud, it goes nowhere else, and I never see it. Dictation is still transcribed on your device, so no audio is sent anywhere and none of it is kept.
Transcripts are kept indefinitely unless you say otherwise, and that default is deliberate: a record of your own thinking shouldn’t disappear because an app decided it had aged out. If you’d rather they didn’t accumulate, Settings ▸ Data ▸ Brain dump transcripts lets you read or delete any of them, and switch on automatic removal after 30 or 90 days. That preference follows your iCloud account rather than one device, and the deletions reach your other devices the same way everything else does. Deleting a transcript leaves its notes untouched.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to the limited personal data I hold (in practice, your support correspondence), to data portability, and to withdraw any consent. Most of your data is already entirely in your hands because I don’t hold it. To exercise a right, email hello@edmundapp.com and I’ll respond within one month. If you think I’ve mishandled your data, please tell me first so I can put it right; you also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk.
Children
Edmund is a general productivity app, not directed at children, and I don’t knowingly collect any data from children.
Changes & contact
If this policy changes, I’ll update the date above and, for anything significant, flag it in the app. The whole point of Edmund is privacy, so any change will be in that spirit. Any question at all: hello@edmundapp.com.