Privacy Policy
Last updated: 2026-08-29
This policy covers Jodd, a cross-platform Developer Preview for viewing and editing notes on Windows, macOS, and Android. Jodd supports four backends. It reads and writes your existing Apple Notes either directly from iCloud (macOS only), or by connecting to the same data Apple Notes itself creates when you enable Notes sync for a Google account (as Gmail messages) or a Microsoft account (as Exchange items) — or, with a Local Folder vault, it keeps a private, account-free notes store on your device with no connection to Apple Notes at all. What Jodd accesses differs by which backend you use — each is described below.
1. What Jodd accesses
Google / Gmail accounts
When you connect a Google account to Jodd, the app requests the
https://www.googleapis.com/auth/gmail.modify OAuth scope.
This Google permission is broader than a single label. Jodd's application
logic only reads and writes messages carrying the Gmail label
your Apple device uses for Notes (Notes by default, or a
label you've configured) — plus the sub-labels used for Jodd's own
folder structure under it. Jodd does not read, search, or modify any
other part of your mailbox: no other labels, no Sent/Inbox/Spam
contents, no contacts, no calendar.
Jodd never sends email on your behalf and never permanently deletes messages — deleting a note in Jodd moves the underlying message to Gmail's own Trash, which behaves exactly like deleting a message from Gmail's own web interface (recoverable for the standard retention window).
Microsoft accounts
When you connect a Microsoft account (outlook.com,
live.com, or a Microsoft 365 work/school account) to Jodd,
the app requests three Microsoft Graph OAuth scopes:
Mail.ReadWrite, offline_access, and
User.Read. Microsoft Graph does not offer a scope narrower
than Mail.ReadWrite for this kind of account, so — exactly
like Gmail's gmail.modify — the permission itself is broader
than what Jodd's application logic actually touches: only items in the
Notes container Apple's Exchange sync creates. Jodd does not read or
modify your mail, contacts, or calendar. offline_access
lets Jodd sync in the background without asking you to sign in again
every hour; User.Read only reads your basic profile so Jodd
can show which account is connected.
Deletion works differently here than on Gmail, and this is worth reading carefully. Jodd never sends a permanent-delete request on its own initiative — but unlike Gmail, there is no Microsoft-side Trash for Jodd to route a delete through. Measured directly against a live account: a note deleted from Apple Notes on this backend leaves nothing behind in Deleted Items, so there is genuinely nothing to recover from either direction. Jodd shows a confirmation before every delete on a Microsoft account for exactly this reason, and does not offer a "Recently Deleted" view for it.
iCloud accounts (macOS only)
An iCloud account works differently from the other two: there is no OAuth, no API key, and no token. When you connect one, Jodd opens Apple's own sign-in pages in a window and does not read what you type into them — your Apple ID password and any two-factor code go to Apple, never to Jodd, and Jodd never stores them. What Jodd ends up with is the ordinary browser session Apple issues, held by the operating system's own web-view storage. Jodd keeps no copy of that session: it reads it fresh each time it needs to talk to Apple, because Apple rotates it and a stored copy would be both stale and an unnecessary liability. Jodd's own account record stores only a true/false marker that a session was established.
With that session, Jodd reads and writes the Notes area of your private
CloudKit database — the same private web service
icloud.com uses in a browser. It does not access Photos,
iCloud Drive, Mail, Contacts, Calendar, Find My, backups, or any other
iCloud service. This is Apple's private interface rather than a
documented public API: Apple can change it at any time, which may break
this backend without notice. Your notes are not at risk if that happens
— they remain in your iCloud account and in Jodd's local cache — but
the connection carries no guarantee from Apple, and Jodd is not
affiliated with or endorsed by Apple.
Two consequences worth stating plainly. If your Apple account has Advanced Data Protection enabled, Jodd cannot work with it at all — your note contents are then end-to-end encrypted and unreadable to anything but your own Apple devices; Jodd detects this when you sign in and refuses to create the account rather than storing anything. And removing an iCloud account from Jodd also clears that stored Apple session from the app's web-view storage, so a later sign-in genuinely starts over rather than silently reusing the previous person's session.
Local Folder vaults
A Local Folder vault requests no OAuth scope and makes no network connection at all — there's no account to connect, so there's nothing for this section to disclose. Jodd stores each note as a plain file in a folder on your own device that you choose, and reads only that folder. This mode is unrelated to Apple Notes: it doesn't sync with your iPhone or Mac, and Jodd can't turn it into one that does.
2. Where your data is stored
Jodd is local-first: everything it reads — from Gmail, from Microsoft Graph, or from iCloud — is cached in a SQLite database file on your own device, inside your OS's normal per-user app-data directory. Jodd does not operate a note-storage or note-sync server; the app talks directly to the Gmail API or Microsoft Graph API using your OAuth-issued access token. On Android, Jodd's website participates only in handing the provider's authorization callback back to the app. That callback request reaches the website, but it contains no note content. A Local Folder vault uses the same local SQLite cache internally, but there's no remote account behind it — the folder you chose is the source of truth, and the plain files in it are what you'd back up or inspect, not the cache.
Nothing about your notes — titles, bodies, attachments, tags, or any other content — is ever transmitted to us, or to any analytics or crash-reporting vendor. We do not have a copy of your data.
For Gmail and Microsoft accounts, that local SQLite cache is encrypted at rest (AES-256, SQLCipher) — see section 6 for detail. This does not apply to Local Folder vaults, an alternative storage mode where notes are kept as plain files in a folder you choose yourself: Jodd discloses this plainly before you finish setting one up.
There is exactly one case where note content leaves your device other than to your notes provider (Google or Microsoft): the optional AI features described in section 4, which are turned off unless you switch them on yourself. With those features disabled — the default — only you and your notes provider ever hold your notes.
3. What we do with the access
The gmail.modify scope exists solely so Jodd can:
- Read messages under your Notes label, so it can display them as notes.
- Insert new messages under that label when you create or edit a note (Gmail's API has no in-place "update," so an edit is technically a new message insert followed by trashing the old one — this is invisible to you and to Apple Notes, which only sees the final state).
- Modify labels on those messages, so that Jodd's folder view (backed by Gmail labels, e.g.
Notes/Projects) can create, rename, and move notes between folders.
The Mail.ReadWrite scope for a Microsoft account exists solely so Jodd can:
- Read items in your Notes container, so it can display them as notes.
- Create, update, and delete those items directly — Microsoft Graph updates a note in place (unlike Gmail's insert-and-trash), so an edit really is an edit to the same item.
- Move a note between folders you already have in Apple Notes. Jodd cannot create, rename, or delete a Microsoft folder itself and does not attempt to — see the limitations on the homepage.
BBMedia does not use either provider's access for anything else: no advertising, no profiling, no resale, no training of any model on your note content.
4. Optional AI features (off by default)
Jodd includes two optional features that use a large language model: Ask Jodd (ask questions across your notes) and Extract (turn pasted text into a structured note). Both are disabled until you configure an AI provider yourself — Jodd ships with none configured, and neither feature can run until you select a provider in Settings and, where that provider requires one, supply its API key or credentials.
If you do enable them, here is what happens: when you ask a question or run an extraction, note text needed for that request is sent to the AI provider you chose so it can produce an answer. This is the only Jodd feature that sends note content anywhere other than your selected notes backend.
- It happens only when you actively use one of those two features — not in the background, and not during normal syncing, reading, or editing.
- The data goes to the provider you configured, under that provider's own privacy policy and terms. Jodd does not operate a server and never receives a copy.
- You choose the provider. If you point Jodd at a model running locally on your own machine, note content never leaves your device at all.
- Jodd never uses your note content, or anything derived from it, to create, train, or improve any machine learning or AI model — ours or anyone else's. The AI features only read your notes to answer the question you just asked.
To turn these features off again, clear the configured AI provider in Settings. Jodd then returns to sending nothing anywhere but Google.
5. Limited Use disclosure
Jodd's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
For Microsoft accounts, Jodd's use of data received through Microsoft Graph adheres to Microsoft's API Terms of Use. The same restrictions apply as above: no advertising, no profiling, no resale, no model training on your note content.
6. Data security
Because Jodd handles Gmail content — a Google-designated sensitive scope — and the equivalent Microsoft Graph mail scope, it applies the following protections to that data at every stage:
- In transit: every request to the Gmail API or Microsoft Graph API is made over HTTPS/TLS directly to that provider's servers. Jodd has no server of its own in the path, so there is no intermediate hop where traffic could be intercepted.
- At rest (Gmail and Microsoft accounts): the local SQLite cache is encrypted with AES-256 (SQLCipher) — an app-level protection independent of whether your operating system's own full-disk encryption is turned on. The encryption key is generated on your device and stored in your OS's secure credential store (macOS Keychain / Windows Credential Manager / Android Keystore); Jodd never transmits this key anywhere. It also lives inside your OS's per-user, access-controlled app-data directory. Jodd does not sync this cache to any cloud storage, backup service, or third-party server. This does not apply to Local Folder vaults — an alternative storage mode where you point Jodd at a folder on disk and it keeps notes there as plain, unencrypted files, by design (so the folder stays directly readable, backupable, and syncable with tools outside Jodd). If you use a Local Folder vault, protecting that folder — full-disk encryption, access controls, backup handling — is your responsibility, and Jodd tells you this explicitly before you finish adding one.
- Credentials: your OAuth refresh token — for either Google or Microsoft — is written only to your OS's protected credential store — macOS Keychain, Windows Credential Manager, or Android secure storage — never to a plain file on disk. The database encryption key above lives in the same store. See section 7 for detail, including a macOS-specific prompt this causes.
- Access: only the Jodd process running on your own device can read the local cache or invoke the stored credential. No Jodd-operated backend exists that could be breached to expose your data — because none holds a copy of it.
- Minimum scope: Jodd requests only the OAuth scopes in section 1, restricted at the application layer to your Notes label or Notes container — not blanket mailbox access.
7. Credentials and authentication
For Google and Microsoft accounts, Jodd uses OAuth 2.0 with PKCE (RFC 7636) to obtain access. (An iCloud account uses no OAuth and has no refresh token at all — see section 1.) Your refresh token is stored in your operating system's protected credential store (macOS Keychain, Windows Credential Manager, or Android secure storage) under a per-account entry — never in a plain file, and never sent anywhere except directly to your provider's token endpoint to obtain a fresh access token. The database encryption key described in section 6 is stored the same way, as its own separate entry.
On macOS specifically, this can mean an extra "Allow" popup. macOS Keychain asks you to approve each individual credential entry the first time an app reads it — Jodd already does this for your OAuth refresh token, and now does it once more for the database encryption key. Choosing "Always Allow" makes it one-time; because Jodd's preview builds aren't stably code-signed release over release, an update can occasionally re-trigger the same prompt for an entry you already approved. This is expected Keychain behavior for an app in this state, not a sign of anything wrong — and it does not happen on Windows (Credential Manager doesn't re-prompt per rebuild the way Keychain does) or on Android (backed by the Android Keystore, silent by default).
8. Revoking access
You can disconnect Jodd from your account at any time:
- From Jodd: remove the account from the account list in the sidebar.
- From Google directly: visit myaccount.google.com/permissions, find Jodd, and remove its access. This immediately invalidates Jodd's refresh token; Jodd can no longer read or write anything in your account afterward.
- From Apple (iCloud accounts): removing the account in Jodd clears the stored Apple session, which is the whole of Jodd's access — there is no token for Apple to revoke, because none was ever issued. You can also sign out of all web sessions from your Apple account settings.
- From Microsoft directly: visit account.live.com/consent/Manage (personal accounts) or your organization's admin-managed app permissions (work/school accounts), find Jodd, and remove its access. Same effect: Jodd's refresh token is invalidated immediately.
Removing an account from Jodd does not delete your notes from Gmail, Microsoft, iCloud, or Apple Notes — it only stops Jodd itself from syncing with that account. You can remove data already cached locally on your device by clearing Jodd's local app data; whether uninstalling also removes it depends on the operating system.
9. Children's privacy
Jodd is not directed at children and we do not knowingly collect data from anyone who does not already have their own Google account, per Google's own account-age policies.
10. Changes to this policy
If this policy changes, the "Last updated" date above will change and, for any material change, we'll surface a notice inside the app.
11. Contact
Questions about this policy or about Jodd's data handling: kaiwan@bbmedia.co.th