Privacy & Local-First Guarantees
Markdrip is built local-first and private by default. This page states the guarantee plainly so you don’t have to take it on faith.
Who we are. Markdrip is the controller of the data described here. Contact us with questions or rights requests at [email protected].
Two tiers of data
Section titled “Two tiers of data”Everything Markdrip handles falls into one of two tiers:
Tier 0 — Inviolable
Section titled “Tier 0 — Inviolable”These never leave your device, to anyone, in any mode:
- Audio — microphone and system-audio recordings are processed and discarded locally; raw audio is never uploaded.
- Voice fingerprints / voiceprints — used only to recognize speakers across your own notes, stored locally.
No setting, consent flow, or future feature can override this. It is a hard line, not a preference.
Tier 1 — Protected content (on-device by default)
Section titled “Tier 1 — Protected content (on-device by default)”- Transcripts and notes — stored as Markdown in your vault, on your disk, under your control.
- Summaries, tasks, decisions, names, metadata, and the search index.
- Models — transcription, diarization, voice-ID, and summarization all run on-device.
Your conversations stay on your device by default. Tier-1 content may leave only if you explicitly enable one of the optional egress modes below — each is off by default and tells you exactly what leaves and where.
Optional egress modes (both off by default)
Section titled “Optional egress modes (both off by default)”Mode A — Encrypted sync (not yet available)
Section titled “Mode A — Encrypted sync (not yet available)”Optional cross-device sync of your Tier-1 content to Markdrip’s cloud. The design target is end-to-end encryption: your device holds the keys; Markdrip stores only ciphertext it cannot read. You can stop syncing and delete your cloud copy at any time.
Mode B — Your destination, your key (not yet available)
Section titled “Mode B — Your destination, your key (not yet available)”Send Tier-1 content directly to a destination you own — a calendar provider, your own AI account, your own storage — never through Markdrip infrastructure. You choose the destination, supply your own credentials, and can revoke access at any time. Markdrip never sees, proxies, or stores the content you send.
What Markdrip does not do
Section titled “What Markdrip does not do”- No crash reporting that phones home.
- No hosted or third-party search — search runs against a local index.
- No account required to use the app.
The public Markdrip marketing site uses first-party, privacy-respecting website analytics to understand page popularity. The account portal and this documentation do not load analytics. Marketing page-view data is not linked to your identity, license, or desktop application usage, and sets no tracking cookies.
Outbound channels
Section titled “Outbound channels”License validation
Section titled “License validation”Markdrip contacts the licensing endpoint to start or recover your trial and to issue and validate a paid license (activation, periodic heartbeat, and revocation check). That exchange never includes your audio, transcripts, notes, summaries, voiceprints, contacts, or usage measurements.
What the licensing service processes and about whom:
- Trial subjects. To start or recover a 14-day trial, the app sends a pseudonymous, HMAC-derived device identifier and a nonce — not your name, email, or any meeting content. The raw device fingerprint is never stored.
- License holders. Paid activation and periodic heartbeats carry an activation identifier, a timestamp, and a cryptographic signature only. Where a paid license was purchased via the web, an account record (verified email, plan, billing status) exists for billing management; the app itself does not require an account.
- Licensing-security subjects. The licensing service records the connection IP for exactly four purposes: trial enforcement, repeat-install abuse detection, rate limiting, and concrete security investigations. The IP is encrypted at rest in purpose-separated storage accessible only to a separately authorized investigator. It is not used in support tools, marketing, advertising, analytics, profiling, or visitor classification. It is retained until a verified applicable deletion request requires removal; primary records and replicas are removed within 30 days, and affected backups age out within a further 35 days.
A label note. Any internal view of a license record shows only “last online validation observed” — not “last app use,” “active user,” or “last meeting.” The licensing service cannot see your meeting activity, which never leaves your device.
Our hosting edge keeps ordinary access logs for at most 30 days for security and availability. None of these records contains your meeting content, which never leaves your device.
Product-usage measurements
Section titled “Product-usage measurements”The app sends pseudonymous, content-free usage measurements to help improve Markdrip. These are integer counts of product actions such as completed recordings and feature activations, and current object counts in your vault. No audio, transcripts, notes, summaries, voiceprints, speaker names, or other meeting content is included.
Regional default. Outside the EEA and UK, usage reporting is on by default. Inside the EEA and UK, it is off by default and requires your explicit opt-in — a difference required by applicable law.
Opt-out (or opt-in). Turn usage reporting off — or on — at any time under Settings → Privacy → Share usage data. Turning it off immediately stops future sends and clears any queued measurements on your device; it does not affect recording, transcription, local files, or your license. A “Delete previously shared data” button sends an authenticated deletion request for measurements already sent.
What the service receives. The app sends authenticated numeric measurements bound to an install-specific key. The server observes the connection address and derives a coarse network prefix (/24 for IPv4, /48 for IPv6) and a two-letter country code, stored alongside the measurements for aggregate product analysis. The raw connection address is never written to any database, log, or export.
IP Geolocation attribution. Country-code derivation uses a third-party IP-to-country dataset. IP Geolocation by DB-IP — licensed under CC BY 4.0.
Model downloads
Section titled “Model downloads”The only other network use is explicit, user-initiated downloads of on-device models (e.g. the first time you enable a feature that needs a model you don’t have yet). These are downloads to your machine and send none of your data out. You can see and control them from the Models settings panel; once a model is downloaded, using it needs no network at all.
Calendar access (optional, on-device)
Section titled “Calendar access (optional, on-device)”If you turn on calendar context (Settings → Calendar), Markdrip reads the local calendars you choose to title a meeting and note who was invited. It is off by default, your operating system asks your permission before Markdrip can read anything, and calendar details are used only on your device — they are never uploaded and never ride the licensing channel described above. You can clear every calendar-derived detail from your notes at any time with Forget calendar data.
Visitors to markdrip.app
Section titled “Visitors to markdrip.app”Visiting markdrip.app or this documentation site is not evidence that you have installed the app, started a trial, or hold a license. Hosting and edge providers see connection-level data (IP, path, timestamp, user-agent) for website delivery, security, and availability only. That data never flows into account, trial, license, or security records, and anonymous website visits are never classified as app users, trial subjects, or customers.
Your rights
Section titled “Your rights”Depending on where you are, you may have rights regarding data we hold about you through the licensing and usage-measurement channels described above. These include rights to access, correction, deletion, restriction, and objection (and where applicable, data portability). If you are in the United States, you may also have state-law rights to know, delete, correct, opt out of sale or sharing (we do not sell or share your data), non-discrimination, and appeal.
If you have a paid account, a trial record, a licensing-security record, or a usage-measurement record and want to exercise any of these rights, email [email protected] with a brief description of your request. For a local, pseudonymous-subject request (if you have no account email), describe the nature of your request and we will provide an alternate identity-verification route.
For full details on how we verify requests, the timeline, exceptions, and the relevant regulator contacts, see Rights and data requests.
For voice data rights — including how to erase all enrolled voice data from your device — see the Biometric & Voice Data Notice.
Changes to this guarantee
Section titled “Changes to this guarantee”Any change that would ship a new egress mode — new telemetry, product analytics, content sync, or a user-directed integration — is a non-negotiable CEO review gate + security review gate internally, and does not ship without explicit privacy/security review. If you ever see Markdrip behave otherwise, that’s a bug: please report it.