Privacy Policy
Effective date: 2026-06-09 Last updated: 2026-06-10
Cairn is a personal project built and operated by AJ Bayoun, an individual ("I", "me", "my"). This Privacy Policy describes what information Cairn (the "Service" — including the desktop app, mobile app, and any related website) collects, how I use it, and the choices you have.
By using the Service, you agree to this policy. If you don't agree, please don't use the Service.
You can reach me at aj@trycairn.io for any privacy question.
1. The short version
- Cairn is a one-person project. There is no company behind it.
- I try to collect as little as possible. Your notes live on your device by default.
- If you turn on Cloud Sync (paid), your notes also live on my hosted backend (Convex), end-to-end encrypted in transit. Sign-in is handled by Clerk.
- When you use AI features on the Cairn AI plan, prompts are proxied through my backend to Anthropic (the Claude API). Bring-your-own-key users send prompts directly to their chosen provider.
- Subscription payments are processed by Paddle or Lemon Squeezy (whichever billing provider I have configured). I never see your full card details.
- I don't use your data to train AI models, and Anthropic doesn't train on data submitted through the API.
- I don't sell your data. I never will.
2. What I collect
2.1 Information you give me
- Account info. When you turn on Cloud Sync or subscribe to a paid plan, you sign in via Clerk (my authentication provider). Clerk receives your email address, display name, and authentication identifier (e.g., from Apple, Google, or email sign-in) and shares it back with the Service so I can associate Your Content with your account.
- Payment info. When you subscribe to a paid tier (Cloud Sync, Cairn AI, Cairn Unlimited) on web or desktop, payment is handled by Dodo Payments as merchant of record. On mobile, payment is handled through Apple App Store or Google Play (via RevenueCat). They collect and process the billing information (card or other payment method, billing address, tax info) directly — I never see your full card number. I receive the subscription status (active / canceled / past-due) via webhook and the email tied to your purchase.
- Your content. Notes, threads, lists, spaces, tags, attachments, and anything else you create in the app ("Your Content"). It's stored locally on your device by default; if you turn on Cloud Sync, it's also stored on the backend described in Section 4.
- Messages to me. If you email me with feedback or bug reports, I'll see your email address and whatever you wrote.
2.2 Information collected automatically
- Crash reports and diagnostics. Stack traces, app version, OS version, and basic device info when something breaks. These do not include the contents of your notes.
- Basic usage events (if enabled). Anonymous events like "app opened" or "note created" — no note content. If I add analytics, it will be a privacy-respecting provider and you'll be able to opt out.
- Local storage. The desktop app stores your notes and settings in your operating system's local application data directory. The mobile app uses the equivalent secure on-device storage.
2.3 AI features
When you use a feature that calls a large language model:
- The text you submit (your "prompt") and any context you attach (e.g., a selected note) is sent to Anthropic, PBC via the Claude API.
- If you're on the Cairn AI or Cairn Unlimited plan, the request is proxied through my Convex backend, which forwards it to Anthropic using my Anthropic key — your request and response transit my servers but are not stored beyond the rate-limit and usage counters needed to enforce monthly token caps. If you bring your own Anthropic or OpenAI key, the request goes directly from your device to that provider; my backend never sees it.
- Anthropic does not train its models on data submitted through the API. I do not train any model on your data either.
- The model's response ("AI Output") is returned to you and only stored if you choose to save it as a note.
3. How I use information
I use the information above only to:
- Run the Service and make it work on your devices.
- Sync Your Content across your devices (only if you turn sync on).
- Process the AI requests you initiate.
- Fix bugs and improve reliability.
- Reply to you if you contact me.
- Comply with the law when I have to.
I do not sell your data, run ads against it, or use Your Content to train AI.
4. Who else sees your data
I keep this list short on purpose. Today, the third parties that may process your information are:
- Convex, Inc. — runs the hosted backend that stores Your Content when Cloud Sync is enabled, and serves the Cairn AI proxy endpoint.
- Clerk Inc. — runs the authentication used to sign in to Cloud Sync and paid plans. Receives your email, name, and authentication identifier.
- Anthropic, PBC — runs the Claude API that generates AI Output from your prompts.
- Paddle.com Market Limited and / or Lemon Squeezy, LLC — process subscription payments and handle tax remittance for paid plans. The active provider depends on the billing configuration in effect when you subscribe; the receipt and your subscription portal will indicate which one collected the payment.
- Apple / Google — if you sign in with Apple or Google, or distribute the app through their stores, they receive what their platforms require.
- Email and crash reporting tools — if I add them, I'll list them here.
I'll share information with law enforcement or other parties only when I genuinely believe I'm legally required to, or to protect someone's safety.
5. How long I keep things
- Your notes live on your device until you delete them. Once deleted in-app, they're gone from your active workspace immediately.
- If sync is enabled, deleting a note removes it from the backend, and it will be purged from any backups within 30 days.
- Crash and diagnostic logs are kept for up to 90 days, then deleted or aggregated.
- If accounts exist and you delete yours, I'll delete your account info and any server-side content within 30 days, except where the law requires me to keep it longer.
6. Your choices and rights
You can:
- Delete your notes at any time inside the app.
- Uninstall the app to remove all local data from your device.
- Email me at aj@trycairn.io to ask what I have, request a copy, request deletion, or correct anything inaccurate.
Depending on where you live, you may have additional rights under laws like the GDPR (EU/UK), the CCPA/CPRA (California), or similar laws elsewhere — including the right to access, correct, delete, or port your data, and to lodge a complaint with your local data protection authority. I'll respect those rights and respond within the timeframes the law requires.
I do not "sell" or "share" personal information for cross-context behavioral advertising as those terms are defined under California law.
7. Security
I take reasonable steps to protect your information — including using providers that encrypt data in transit (TLS) and at rest where supported. But Cairn is a small personal project, not a hardened enterprise system. No method of storing or transmitting data is 100% secure. If a security incident affects your data, I'll let you know and notify regulators where the law requires it.
8. Children
Cairn is not directed to children under 13 (or 16 in the EU/UK), and I don't knowingly collect information from them. If you believe a child has used the Service and provided information, email me at aj@trycairn.io and I'll delete it.
9. International users
I operate Cairn from the United States. If you use the Service from another country, your information will be transferred to and processed in the U.S. and wherever my providers operate. By using the Service, you understand this.
10. Third-party links
The Service may link to third-party sites or services. I don't control them and this policy doesn't apply to them — check their policies.
11. Changes
I may update this policy. If I make a meaningful change, I'll update the "Last updated" date and, where reasonable, notify you in the app or by email before it takes effect. Continued use after the change means you accept the update.
12. Contact
Any question or request: aj@trycairn.io.
This document is a template I wrote for my own project. It is not legal advice. If you're reusing this for your own app, talk to a lawyer.