What leaves this app, and what never does
Assisted generation is off until you turn it on. Nodes you mark restricted never reach a model at all. And one file, if you ask for it, carries names out.
The short version
| Does it leave? | |
|---|---|
| Pasting a model's reply into Import | No — the app never made a call. You did. |
| Typing nodes, editing, linking, browsing | No. |
| Syncing a vault | No — it moves between your disk and your account. |
| Generate / Weave / Ask, with hosted AI off | No. The feature declines rather than calling. |
| Generate / Weave / Ask, with hosted AI on | Yes — your request, and (in graph-aware scope) public entries as context. |
| Any node marked restricted | Never, in any mode, with any setting. |
| A downloaded lens skill | It carries entry names — and asks you first, defaulting to no. |
The free lane sends nothing anywhere
This is worth stating first because it is the lane most accounts use and it is the one people assume must involve us. When you download a lens skill, hand it to Claude or ChatGPT, and paste the reply back into Import, this app never contacts a model. It has no key, makes no request, and sees nothing but the text you paste.
Whatever you sent that model went through your account with that provider, under their terms. That is a real consideration and it is not one we can make for you — but it is not this app sending your content anywhere.
Hosted AI is off until you switch it on
A new account has assisted generation off. With it off, nothing you write is sent to any AI provider — the features do not degrade quietly, they decline.
When you turn it on, you also choose how much the model may see:
| Scope | What the model gets |
|---|---|
| Session only the default when you enable it | Only what you type or paste in that exchange. Nothing is read out of your graph — not a title, not a definition, nothing. |
| Graph-aware | The model may also read your existing entries as context, which is what makes an answer about your notes possible. Restricted entries are still excluded. |
The floor no setting can lift
A node marked restricted is never included in anything sent to a hosted model. Not in session scope, not in graph-aware scope, not by a feature that has a good reason.
The thing to notice is where that rule lives. It is not a row in your settings that happens to be set the safe way — it is a single valve in the code that every model call passes through, with no override argument and no parameter to widen it. A setting can be toggled, by you or by a bug or by a future feature that seemed to need it. This cannot.
One consequence worth understanding: restricted nodes are not merely filtered out of an answer, they are never indexed for retrieval in the first place. So a graph-aware answer cannot be built from them, and it also cannot tell you how much it missed — which is why the app reports how many nodes are never searched as a standing fact rather than implying a specific answer was nearly complete.
What is kept when you do use hosted AI
The request you typed is stored beside its results. That is deliberate, and it is the retention this app makes rather than one it merely permits: the point of keeping it is that you can look at what you asked for, edit it, and ask again. A retry that cannot show you the original instructions is not a retry.
It is deleted when you delete that set of results, and it goes with your account when you delete that. Prompts are processed by Anthropic under their terms, and we do not send your email address or account identifier beyond what the request needs.
An import keeps no second copy
Pasting into Import stores a one-line note — that it came from another model, and how many nodes arrived. There is no prompt to keep, because this app never asked anything, and storing the pasted document would be a duplicate of text that is already becoming nodes.
The deliberate exception: a downloaded lens skill
The lens skill file lists the nodes already in your lens, as slug — Title, so the model you hand it to can link to them instead of inventing names. That list is names only — no definitions, no bodies, none of what you actually wrote.
If the lens contains restricted entries, you are asked whether to include their names. Every time, never remembered, and the answer defaults to no.
When names are withheld, the file says how many — so the model knows its list is partial and can tell you, rather than confidently duplicating something it cannot see.
Who at this end can read your entries
Nobody, in the ordinary course. Access is restricted at the database level rather than by policy, so a support request that genuinely needs to see something requires you to share it explicitly. There is no internal view of your private lenses to be tempted by.
And nothing you write is used to train a model — not by us, and the provider that receives your text when you use hosted AI is contracted so that it cannot either.
Related
- Sharing a lens — the other direction: what you deliberately let people see.
- Getting your data out, and deleting it — leaving with everything, or leaving nothing behind.
- Privacy policy — the same commitments, in the register that binds us.