This is how the thing is built rather than a promise in a policy: your documents never pass through a service of ours, so there is nothing for us to lose, look through, or be asked to hand over. You point at where the archive should live, and that is the only place it exists.
On the way between your devices
Traffic between a device and your server is encrypted, and each device has its own key that you can revoke from the server. Whether that server can be reached only from your living room or from anywhere is entirely your call.
Backups you can actually restore
Backups can run on a schedule and be locked with a passphrase. Restoring checks the backup before it overwrites anything — because a backup nobody has ever restored is a guess, not a backup.
And because your documents sit in your Documents folder, whatever already backs that folder up covers them too.
Deleting is undoable, until you mean it
A deleted document goes to the trash and stays there for as long as you decide, so a wrong click is a five-second fix. When the time is up it is removed for real, on every device — not left behind on the one computer that happened to be off that week.
What leaves your machines
- Your documents and what is in them: never — not to us, not to anyone else
- Usage tracking from the app: none is collected
- Error reports: off unless you switch them on, in every released version
- Reading text out of scans on your computer: done locally, never sent anywhere