Privacy Policy

Last updated: 2026-08-29

This policy covers Jodd, a cross-platform Developer Preview for viewing and editing notes on Windows, macOS, and Android. Jodd supports four backends. It reads and writes your existing Apple Notes either directly from iCloud (macOS only), or by connecting to the same data Apple Notes itself creates when you enable Notes sync for a Google account (as Gmail messages) or a Microsoft account (as Exchange items) — or, with a Local Folder vault, it keeps a private, account-free notes store on your device with no connection to Apple Notes at all. What Jodd accesses differs by which backend you use — each is described below.

1. What Jodd accesses

Google / Gmail accounts

When you connect a Google account to Jodd, the app requests the https://www.googleapis.com/auth/gmail.modify OAuth scope. This Google permission is broader than a single label. Jodd's application logic only reads and writes messages carrying the Gmail label your Apple device uses for Notes (Notes by default, or a label you've configured) — plus the sub-labels used for Jodd's own folder structure under it. Jodd does not read, search, or modify any other part of your mailbox: no other labels, no Sent/Inbox/Spam contents, no contacts, no calendar.

Jodd never sends email on your behalf and never permanently deletes messages — deleting a note in Jodd moves the underlying message to Gmail's own Trash, which behaves exactly like deleting a message from Gmail's own web interface (recoverable for the standard retention window).

Microsoft accounts

When you connect a Microsoft account (outlook.com, live.com, or a Microsoft 365 work/school account) to Jodd, the app requests three Microsoft Graph OAuth scopes: Mail.ReadWrite, offline_access, and User.Read. Microsoft Graph does not offer a scope narrower than Mail.ReadWrite for this kind of account, so — exactly like Gmail's gmail.modify — the permission itself is broader than what Jodd's application logic actually touches: only items in the Notes container Apple's Exchange sync creates. Jodd does not read or modify your mail, contacts, or calendar. offline_access lets Jodd sync in the background without asking you to sign in again every hour; User.Read only reads your basic profile so Jodd can show which account is connected.

Deletion works differently here than on Gmail, and this is worth reading carefully. Jodd never sends a permanent-delete request on its own initiative — but unlike Gmail, there is no Microsoft-side Trash for Jodd to route a delete through. Measured directly against a live account: a note deleted from Apple Notes on this backend leaves nothing behind in Deleted Items, so there is genuinely nothing to recover from either direction. Jodd shows a confirmation before every delete on a Microsoft account for exactly this reason, and does not offer a "Recently Deleted" view for it.

iCloud accounts (macOS only)

An iCloud account works differently from the other two: there is no OAuth, no API key, and no token. When you connect one, Jodd opens Apple's own sign-in pages in a window and does not read what you type into them — your Apple ID password and any two-factor code go to Apple, never to Jodd, and Jodd never stores them. What Jodd ends up with is the ordinary browser session Apple issues, held by the operating system's own web-view storage. Jodd keeps no copy of that session: it reads it fresh each time it needs to talk to Apple, because Apple rotates it and a stored copy would be both stale and an unnecessary liability. Jodd's own account record stores only a true/false marker that a session was established.

With that session, Jodd reads and writes the Notes area of your private CloudKit database — the same private web service icloud.com uses in a browser. It does not access Photos, iCloud Drive, Mail, Contacts, Calendar, Find My, backups, or any other iCloud service. This is Apple's private interface rather than a documented public API: Apple can change it at any time, which may break this backend without notice. Your notes are not at risk if that happens — they remain in your iCloud account and in Jodd's local cache — but the connection carries no guarantee from Apple, and Jodd is not affiliated with or endorsed by Apple.

Two consequences worth stating plainly. If your Apple account has Advanced Data Protection enabled, Jodd cannot work with it at all — your note contents are then end-to-end encrypted and unreadable to anything but your own Apple devices; Jodd detects this when you sign in and refuses to create the account rather than storing anything. And removing an iCloud account from Jodd also clears that stored Apple session from the app's web-view storage, so a later sign-in genuinely starts over rather than silently reusing the previous person's session.

Local Folder vaults

A Local Folder vault requests no OAuth scope and makes no network connection at all — there's no account to connect, so there's nothing for this section to disclose. Jodd stores each note as a plain file in a folder on your own device that you choose, and reads only that folder. This mode is unrelated to Apple Notes: it doesn't sync with your iPhone or Mac, and Jodd can't turn it into one that does.

2. Where your data is stored

Jodd is local-first: everything it reads — from Gmail, from Microsoft Graph, or from iCloud — is cached in a SQLite database file on your own device, inside your OS's normal per-user app-data directory. Jodd does not operate a note-storage or note-sync server; the app talks directly to the Gmail API or Microsoft Graph API using your OAuth-issued access token. On Android, Jodd's website participates only in handing the provider's authorization callback back to the app. That callback request reaches the website, but it contains no note content. A Local Folder vault uses the same local SQLite cache internally, but there's no remote account behind it — the folder you chose is the source of truth, and the plain files in it are what you'd back up or inspect, not the cache.

Nothing about your notes — titles, bodies, attachments, tags, or any other content — is ever transmitted to us, or to any analytics or crash-reporting vendor. We do not have a copy of your data.

For Gmail and Microsoft accounts, that local SQLite cache is encrypted at rest (AES-256, SQLCipher) — see section 6 for detail. This does not apply to Local Folder vaults, an alternative storage mode where notes are kept as plain files in a folder you choose yourself: Jodd discloses this plainly before you finish setting one up.

There is exactly one case where note content leaves your device other than to your notes provider (Google or Microsoft): the optional AI features described in section 4, which are turned off unless you switch them on yourself. With those features disabled — the default — only you and your notes provider ever hold your notes.

3. What we do with the access

The gmail.modify scope exists solely so Jodd can:

The Mail.ReadWrite scope for a Microsoft account exists solely so Jodd can:

BBMedia does not use either provider's access for anything else: no advertising, no profiling, no resale, no training of any model on your note content.

4. Optional AI features (off by default)

Jodd includes two optional features that use a large language model: Ask Jodd (ask questions across your notes) and Extract (turn pasted text into a structured note). Both are disabled until you configure an AI provider yourself — Jodd ships with none configured, and neither feature can run until you select a provider in Settings and, where that provider requires one, supply its API key or credentials.

If you do enable them, here is what happens: when you ask a question or run an extraction, note text needed for that request is sent to the AI provider you chose so it can produce an answer. This is the only Jodd feature that sends note content anywhere other than your selected notes backend.

To turn these features off again, clear the configured AI provider in Settings. Jodd then returns to sending nothing anywhere but Google.

5. Limited Use disclosure

Jodd's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

For Microsoft accounts, Jodd's use of data received through Microsoft Graph adheres to Microsoft's API Terms of Use. The same restrictions apply as above: no advertising, no profiling, no resale, no model training on your note content.

6. Data security

Because Jodd handles Gmail content — a Google-designated sensitive scope — and the equivalent Microsoft Graph mail scope, it applies the following protections to that data at every stage:

7. Credentials and authentication

For Google and Microsoft accounts, Jodd uses OAuth 2.0 with PKCE (RFC 7636) to obtain access. (An iCloud account uses no OAuth and has no refresh token at all — see section 1.) Your refresh token is stored in your operating system's protected credential store (macOS Keychain, Windows Credential Manager, or Android secure storage) under a per-account entry — never in a plain file, and never sent anywhere except directly to your provider's token endpoint to obtain a fresh access token. The database encryption key described in section 6 is stored the same way, as its own separate entry.

On macOS specifically, this can mean an extra "Allow" popup. macOS Keychain asks you to approve each individual credential entry the first time an app reads it — Jodd already does this for your OAuth refresh token, and now does it once more for the database encryption key. Choosing "Always Allow" makes it one-time; because Jodd's preview builds aren't stably code-signed release over release, an update can occasionally re-trigger the same prompt for an entry you already approved. This is expected Keychain behavior for an app in this state, not a sign of anything wrong — and it does not happen on Windows (Credential Manager doesn't re-prompt per rebuild the way Keychain does) or on Android (backed by the Android Keystore, silent by default).

8. Revoking access

You can disconnect Jodd from your account at any time:

Removing an account from Jodd does not delete your notes from Gmail, Microsoft, iCloud, or Apple Notes — it only stops Jodd itself from syncing with that account. You can remove data already cached locally on your device by clearing Jodd's local app data; whether uninstalling also removes it depends on the operating system.

9. Children's privacy

Jodd is not directed at children and we do not knowingly collect data from anyone who does not already have their own Google account, per Google's own account-age policies.

10. Changes to this policy

If this policy changes, the "Last updated" date above will change and, for any material change, we'll surface a notice inside the app.

11. Contact

Questions about this policy or about Jodd's data handling: kaiwan@bbmedia.co.th