Privacy notice

Website data and app data are explained separately.

SourcePath is local-first, but the website may still process contact information you choose to submit. These are different data boundaries.

Last updated: 2 September 2026

1. Who handles website data

The SourcePath developer is responsible for information related to this website and app support. Use the email on the support page for privacy questions.

2. What the website collects

If you contact us or send feedback, it may include email, name, devices, library size, formats, role and a task description. Do not submit documents, API keys, passwords or sensitive content.

3. Why it is collected

To answer support requests, understand whether the product fits your workflow, improve positioning, and send product updates only when you separately opt in.

4. How long it is kept

Contact records that do not convert are kept for no more than 90 days after last handling. Records for people who received a test build are kept for no more than 180 days after the relationship ends. Product updates and feedback are managed separately.

5. Providers, processing regions and security logs

Hosting, email and any future feedback service may process necessary network, delivery and security information. Processing regions depend on the relevant provider. Minimal security logs may be retained for abuse prevention, troubleshooting and service protection.

6. Cookies and analytics

The P0 site does not depend on advertising cookies, cross-site tracking or fingerprinting. If aggregate traffic measurement is enabled later, this page will be updated first, and email or form text will not be added to analytics events.

7. How the feedback form is handled

While the structured feedback service is not deployed, the form only prepares an email for you to review and send; it does not silently upload the entries. This page will be updated with the actual endpoint, provider and retention method before that service is enabled.

8. Support email

Content sent to the support address is processed by the email service. Send only the minimum information needed for troubleshooting and do not attach source material, sensitive screenshots or account credentials.

When you start feedback from inside the app, the draft is pre-filled with the SourcePath version and build, macOS version, CPU architecture and app language, for troubleshooting only. The mail is shown in full and stays editable before you send it. The app never adds document content, file paths, library names, Provider settings, API keys or attachments, and never sends the draft for you.

9. Local app data and private iCloud

Originals you select, local library databases, full indexes, reading history and on-device document-generation conversations stay on their respective devices. On iPhone, only material you explicitly give SourcePath through Files, the clipboard or the system share sheet enters the phone inbox; the app does not scan data held by other apps. App Store and TestFlight builds run inside the App Sandbox and use the container assigned by the system. The direct-download Mac build and store-channel builds do not share a data directory: changing channel means importing the library again and re-authorising each source folder.

To show connected Macs, browse selectable scopes, control tasks and display results on iPhone, the current beta stores necessary device registration, a privacy-reduced library catalogue, a remote title index and structured task records in your private CloudKit. The index may include stable and revision identifiers, counts, formats, and encrypted library, collection, source and document display names and membership. It excludes document bodies, snippets, absolute or relative paths, security-scoped bookmarks, full local indexes, API keys and on-device iPhone single-document generation conversations. Result bodies and citations made available on the phone are application-layer encrypted before being stored as CloudKit assets.

This private-iCloud path does not automatically upload or merge imported originals or local libraries across devices. Mac document bodies do not go to the cloud or iPhone, and remote search is title-only. Selecting a file that already lives in iCloud Drive does not copy it into SourcePath; its cloud storage remains governed by the iCloud service applicable to your Apple Account.

For Apple Accounts registered in mainland China, iCloud services including CloudKit are operated by Guizhou-Cloud Big Data Industry Development Co., Ltd. Applicable iCloud data is stored in mainland China and is subject to Chinese law. That regional infrastructure differs from iCloud outside mainland China. The iCloud operator storing such data does not give the SourcePath developer access to your documents.

10. What happens when you connect your own AI service account

SourcePath does not bundle a model service or resell model credit. You choose and connect your own AI service account; most services authorise access with an API key. Credentials stay in the system Keychain of the device that executes the request and are not written to the library, private CloudKit, logs or data exports. The provider’s terms and privacy policy govern its processing, retention and billing.

Questions, summaries and information extraction in the iPhone reader are limited to the current local document. After you confirm sending, the question or extraction objective where applicable, required content from that document and necessary context from the current conversation go directly from iPhone to the AI service address shown in the interface. The conversation, answer and the record of actual coverage remain on that iPhone, are not synced through private iCloud, and are never rerouted automatically to another provider.

Remote analysis runs on the Mac you select. Preparation expands the scope and estimates work locally on that Mac without calling an AI service. Before execution, iPhone shows the Mac, library, scope, document count, AI service, model and input-size range. Only after you confirm does the Mac send the required content from the approved scope directly to that service address. Requests do not pass through SourcePath servers.

11. Access, correction, deletion and unsubscribe

You can use the support email to request access to, correction of or deletion of contact information you submitted, and you can leave optional product updates at any time.

The app provides controls to delete local documents and their on-device single-document generation data, and to cancel or delete eligible remote tasks. Deleting a finished remote task also deletes its timeline and execution receipt, while its generated result is kept by default so removing a task record does not silently destroy your work. The confirmation screen explains this before deletion.

12. Children

SourcePath is intended for people doing material-based research and writing. It is not directed to children and does not intentionally collect their information. Contact support to request deletion if information was submitted in error.

13. Changes and contact

This notice will be updated when the website, feedback service or app data boundary changes and will retain its last-updated date. Before release it must also be reviewed against the App Store privacy nutrition label. Contact details are on the support page.

Privacy contact: sourcepathapp@gmail.com