Skip to content
Legible
  • Features
  • Pricing
Try it free
Features Pricing Try it free

Privacy

Privacy Policy

Last updated: 13 July 2026 · Effective: 13 July 2026

Legible is a local-first Mac app. Your notes stay on your machine unless you switch on an optional AI feature and point it at a cloud provider yourself, and we collect almost nothing about you. This page explains, in plain terms, exactly what we do collect, why, and what you can do about it.

Who we are

Legible is operated by PF Creative Ltd, a company registered in the United Kingdom. For the purposes of UK GDPR, we are the data controller for the limited personal data described below. You can reach us about anything in this policy at hello@getlegible.app.

What information do we collect?

We collect only what's required to sell you the app, deliver your license key, and verify that key when you launch Legible.

When you buy Legible

Our payments provider, Paddle, collects the information needed to process your purchase: your name, email address, billing address, country, and payment details. We never see your card number. After a successful purchase, Paddle shares your email address and order ID with us so we can issue your license key.

When you use Legible

The app itself does not transmit your notes, your vault contents, or any usage telemetry anywhere. Reading happens entirely on your machine. Unless you enable an optional AI feature (covered in its own section below), the only network traffic Legible initiates is:

  • Validating your license key with our license server on launch and when you activate a new device, plus a periodic "last seen" heartbeat so we know an activation is still in use.
  • Checking for app updates by fetching a small version manifest from our download server. This request carries no personal data.

The license requests carry only your license key and a non-reversible identifier for your Mac (a one-way hash derived from the system hardware ID). The Mac identifier is never linked to your name or email outside of your own license record. It exists solely to enforce the per-license activation limit.

Optional AI features

Legible includes optional AI features (semantic search and "Ask your notes"). They are off by default, and none of them route anything through us. What happens to your notes depends entirely on which option you choose in Preferences:

  • Semantic search runs entirely on your Mac. The index is built and stored inside your vault folder. Nothing is sent anywhere.
  • The built-in local model also runs entirely on your Mac. Enabling it downloads the model file once (about 1.1 GB, fetched from Hugging Face, a model-hosting service). That download is a plain file fetch: it contains no data about you, and none of your notes are sent. After it, the model works fully offline.
  • Your own cloud provider (an OpenAI or Anthropic key you supply): when you ask a question, the relevant note excerpts and your question are sent directly from your Mac to that provider, under your account and their privacy terms. We never see, store, or proxy any of it. Your API key is stored in the macOS Keychain, not in our systems.
  • A local server (Ollama or LM Studio): everything stays on your machine.
  • Claude over MCP: notes you ask Claude about are read by the Claude app locally and handled under your own Claude account's terms with Anthropic.

In every case the app asks for your consent before the first use of a cloud provider, and you can turn any of this off again at any time.

When you contact us

If you email hello@getlegible.app, we keep your message and our reply for as long as needed to resolve your query and for a reasonable period afterwards in case it becomes relevant again (typically up to 24 months).

What we do not collect

  • The contents of your notes, vault, or any markdown file.
  • Which files you open, how often you read, or how long you spend in the app.
  • Analytics, telemetry, crash reports, or behavioural fingerprints.
  • Cookies for tracking on this website. The marketing site uses no analytics scripts and sets no advertising cookies.

This stays true even with the optional AI features enabled: any AI traffic goes directly from your Mac to the provider you chose. It never passes through our servers.

Why we process this data, and our lawful basis

Under UK GDPR we rely on two lawful bases:

  • Performance of a contract. To sell you the license, deliver your key, and verify it on the devices you activate. Without this we cannot fulfil the purchase.
  • Legitimate interest. To prevent license abuse (e.g. one key activated on hundreds of unrelated machines), to respond to your support queries, and to keep our records of purchases for accounting and tax purposes.

Who we share it with

We share the minimum required with a small set of trusted processors, each bound by contract and operating under their own published privacy terms:

  • Paddle. Payment processing and merchant of record. Paddle holds your purchase record and handles VAT and sales-tax compliance on our behalf. See paddle.com/legal/privacy.
  • Supabase. Hosts the license database: your email, license key, order ID, and activation records. Data is held in the EU (Ireland). See supabase.com/privacy.
  • Brevo. Sends transactional emails such as your license-key delivery. Brevo holds your email address for as long as we keep your license record. See brevo.com/legal/privacypolicy.

We do not sell or rent your data to anyone, and we do not share it for advertising or profiling purposes.

How long do we keep your information?

We keep your license-key record for the lifetime of the license (typically 12 months from purchase, plus a reasonable period afterwards in case you ask us to look it up). Purchase records are kept by Paddle and by us for the period required by UK tax law (currently six years). Support emails are deleted after roughly 24 months of inactivity.

How do we keep your information safe?

License data is held in a Postgres database with row-level security policies that restrict access to a single service role. Communication between the app and our license server is over HTTPS. Webhook events from Paddle are verified using HMAC-SHA256 before we accept them. Passwords and license keys are never logged.

What are your privacy rights?

You have the following rights under UK GDPR:

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Ask us to correct anything that's wrong.
  • Erasure. Ask us to delete your data. We can delete your license record, but note that this will invalidate your license. Paddle and your bank will keep their own records regardless.
  • Portability. Receive your data in a machine-readable format.
  • Objection and restriction. Object to or restrict how we use your data.
  • Complaint. Complain to the UK Information Commissioner's Office at ico.org.uk if you believe we've handled your data improperly.

To exercise any of these rights, email hello@getlegible.app. We aim to respond within 14 days; the statutory limit is 30 days.

International transfers

Our license database is hosted in the EU (Ireland). Paddle and Brevo operate internationally and may process your data outside the UK or EU under their respective standard contractual clauses. We have chosen processors with adequate data-protection commitments.

Children

Legible is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

Changes to this policy

If we make material changes, we'll update the "Last updated" date at the top of this page and, where the change affects your rights, notify you by email before the change takes effect.

How to contact us about this policy

Email hello@getlegible.app with "Privacy" in the subject line. We read everything that comes in.


© 2026 PF Creative Ltd. All rights reserved.

  • Features
  • Pricing
  • Terms
  • Privacy
  • Refunds
  • Contact
Legible.