The short version
Sanctum starts with one rule: your notes are yours. Built In Space LLC does not read your private library or keep a readable copy of it. We take that seriously.
We read the privacy policies and service terms for every company that handles Sanctum's cloud AI work. We send them note content only when you ask for a cloud feature, and only to do that job. It is not sent for ads or model training.
Sanctum does not sell your note content or personal information. None of those companies does either.
We want to make it cryptographically impossible for a person at Sanctum or one of those companies to read your data while it is being processed. We are not all the way there yet.
For now, we keep the exposure window short and delete temporary copies automatically. We review provider contracts and security audits, and the code sends as little as possible. If a provider changes its terms or stops meeting our privacy standard, we will replace it.
We are also building our own end-to-end processing system so we can control the whole path ourselves and enforce privacy with cryptography instead of promises. It is not finished yet.
Sanctum is the product you pay for. Your data is not the product.
We built Sanctum to keep your notes and your thoughts safe.
Recording, playback, search, editing, organization, sharing, and export all work with files on your device. You do not need an account for any of them. If you choose cloud transcription or synthesis, the processor needs readable audio or text while it does the job. We keep that window short and delete temporary copies.
Your note data can leave your device in three cases:
Cloud transcription
AssemblyAI receives the audio you choose to transcribe. Our production account is opted out of model training and set to keep data for one day. AssemblyAI may need additional time to finish deletion after that. Its Trust Center lists its current certifications, including SOC 2 Type II and ISO 27001.
Note synthesis
By default, Sanctum sends synthesis jobs to RedPill and requests zero data retention. RedPill runs them in a trusted execution environment and says its operators cannot read the content. Sanctum does not yet check the signed receipt for each request, so we are relying on RedPill for that claim. If you choose AssemblyAI, or RedPill is down, Sanctum uses AssemblyAI's LLM Gateway. It sends the text to Anthropic's Claude, usually through Amazon Bedrock, with the one-day input and output setting explained below.
Private Backup
Sanctum encrypts files on your device before uploading them. AWS and Backblaze receive ciphertext and random identifiers, not readable notes. With the default recovery code, Built In Space LLC does not have the key. If you turn on account recovery, the key is stored in your Supabase account. Anyone who can sign in to that account can restore the backup.
Information stored on your device
Sanctum stores your enclaves, note folders, audio, transcripts, markdown notes, tags, settings, trash records, and analysis-cost records on your device. You can see the files in the Files app and control them yourself.
SwiftData stores a rebuildable index with metadata and file locations. The files on disk, not the SwiftData index, are the records Sanctum trusts.
Accounts and purchases
Supabase stores the email address, user ID, sign-in records, and identity-provider links needed for your account. If you sign in with Apple or Google, that company handles the sign-in information. RevenueCat receives your user ID and keeps the purchase, subscription, entitlement, device, and app details needed to run purchases. None of these services receives your notes for these jobs.
You need an account for server analysis and other paid or cloud services. You do not need one to record, read, edit, delete, share, or export your files.
Private Backup
Private Backup is optional. Sanctum encrypts each file on your device before uploading it. AWS stores account and backup control data. Backblaze B2 stores encrypted chunks and manifests under random names. Neither company can read filenames, titles, note relationships, transcripts, note text, or audio.
A current backup stays until you delete the backup or your account. A replaced object is kept for at least 30 days. An abandoned upload expires after 24 hours. Deleting the backup or account schedules the stored objects for physical deletion.
Your recovery code and the key it protects stay on your device by default. If you turn on account recovery, Sanctum stores the backup key and its random backup identifier in your Supabase account. This means anyone who signs in to the account can restore the backup. Turning account recovery off, deleting the cloud backup, or deleting the account removes the stored key.
Transcription and synthesis
Before Sanctum sends a cloud request, it shows you the audio or text that will leave your device and the companies that may process it. Nothing is sent until you agree. You can withdraw that consent in Settings, and Sanctum will ask again next time. On-device transcription does not use an outside company.
Cloud transcription uses AssemblyAI. Our production account is opted out of AssemblyAI's Model Improvement Program, so AssemblyAI says it does not use submitted files to train its models. This is a setting on our AssemblyAI account; the Sanctum app cannot enforce it. Sanctum deletes its temporary copy in AWS S3 when the job ends. S3 is also set to delete that copy after one day if the first deletion fails. The job record expires after 24 hours. AssemblyAI starts deleting the audio after 24 hours, though deletion may take longer to finish. An hourly cleanup worker keeps asking AssemblyAI to delete the job until AssemblyAI confirms it.
RedPill is the default synthesis route. Sanctum asks RedPill to use confidential computing with zero data retention. A job may pass through Phala, Chutes, NEAR AI, Tinfoil, or another company named in its receipt. Sanctum does not yet verify those receipts, so we have not independently checked the hardware claim.
You can also use AssemblyAI's LLM Gateway. For the Claude model used by Sanctum, AssemblyAI says it normally runs through Amazon Bedrock. Bedrock does not store or log prompts or completions. AssemblyAI may instead send the request directly to Anthropic with zero-day retention. AssemblyAI says every Gateway model provider is opted out of training. Our account keeps Gateway inputs and outputs for one day, and AssemblyAI clears expired content hourly. Some logging and billing data remains.
Feedback you send us
Sending feedback in the app is optional. Sanctum does not attach anything from your library. You choose a category and write the message. You can also attach one voice note, up to five screenshots, and one screen recording. Feedback is kept separate from your notes and search index.
We keep a feedback report for one year. Its text and details are stored in AWS DynamoDB, and its attachments are stored in AWS S3. Both are deleted if you delete your account. AssemblyAI transcribes a voice attachment under the account settings above. Sanctum asks AssemblyAI to delete its copy when transcription is done.
Permission to contact you is off by default. If you turn it on, we receive the email address on your account and nothing else. Feedback is not a support inbox, and we cannot promise a reply.
Diagnostics
Sentry receives crash and performance data from the app and server. This may include error types, stack traces, app and device versions, route templates, and timing. Sanctum configures Sentry not to send recordings, transcripts, notes, credentials, account IDs, screenshots, replays, or request bodies. AWS CloudWatch stores server logs for 30 days.
We configured the Sentry project not to store IP addresses. Other diagnostic events stay for the retention period set on the project.
Website data
Vercel hosts this site and may receive the IP address, browser type, requested page, time, and security details that come with an ordinary web request. After the page loads, Umami Cloud records pageviews, referrers, browser, operating system, device type, country, and session timing. Umami does not use cookies. It creates an anonymous session hash from the IP address, user agent, and this site's Umami ID. Sanctum does not send URL query strings, visitor IDs, custom events, or session properties. The analytics stay in Umami Cloud until the site data or account is deleted. We do not promise a shorter expiry date.
The signup form is the only place on this site that asks for personal information. Resend receives the email address, sends the signup email, and keeps the address on Sanctum's mailing list. We use the list to send the App Store download link and other Sanctum updates. The address stays on the list until it is removed. Unsubscribing marks it as unsubscribed instead of deleting it. We turned off open and click tracking. Every list email has an unsubscribe link. Unsubscribing from that list does not block account emails you request later. The IP address used to submit the form is held briefly in memory for rate limiting and is not stored.
Retention and deletion
Local files stay until you delete them, clear eligible audio, remove the app under your device and backup settings, or empty Sanctum's trash. A normal in-app deletion moves recoverable files to trash first.
Deleting your account removes Private Backup data, feedback, unused analysis minutes, the RevenueCat customer profile, stored Apple revocation data, and the Supabase user. It does not cancel an App Store subscription or delete the notes on your device. Analysis job records that contain no content expire on their 24-hour schedule.
Your choices, changes, and contact
You decide whether to use server analysis or Private Backup. You can grant or withdraw cloud-processing consent, and you control the files on your device. Built In Space LLC operates Sanctum in the United States. Depending on your state, you may have the right to access, correct, delete, or export personal information held by Sanctum.
We will date any important change to this policy and may also notify you in the app. Send privacy questions to support@speakwithsanctum.app.