← About Inkwave
Inkwave

Privacy Policy

Inkwave Zero · Last updated 17 July 2026

Zero data retention — and minimal data in transit — is our number one priority. It's in our very name. Inkwave Zero is local-first: your writing lives on your device and in the files and drives you choose, never in a database of ours. It works without an account and we run no analytics. We do not retain any of your data. At all, period.

That said, honesty requires caveats: a small number of features do pass data through our servers, or to named services, on its way somewhere else. This policy sets out each one — what leaves your device, where it goes, and why. It covers the web app and the optional Citation Capture browser extension.

Where your writing lives

Documents are stored in your browser (OPFS and IndexedDB) and, when you save or sync, in the destinations you pick: a local file or folder, your OneDrive, or your Google Drive. Cloud sync writes to your account under your login — the file goes from your browser to Microsoft or Google, not to us. OneDrive sync uses the standard file-access permission (Files.ReadWrite) so you can choose any folder; Google Drive uses the narrower per-file permission (drive.file). PDFs you attach to sources are stored the same way — on your device and in your own drives — and reading or annotating them happens entirely in your browser.

Your ledger (session tracking)

Inkwave can keep a ledger of how you work: when a writing session started and ended, how many minutes you were actively editing, word counts before and after, how many edits you made, the breaks between sessions, and whether the session was a Pomodoro block. It is off by default — you turn it on yourself, and can turn it off again, on the ledger page.

The ledger is a file kept in your own storage, exactly like your documents, and it is never sent to us. It records how you worked, not what you wrote: it contains no text from your documents.

We do not collect your location. Inkwave never asks for, reads, or stores your device's location, and asks for no location permission. You may optionally type a place label for yourself — "library", "home" — and, at the end of a session, a note about what you did. Those are words you choose to write, stored in your ledger on your device.

If you later use an AI report on your ledger, the times, word counts and edit counts are what it sees. Your session notes and place labels are not included unless you explicitly opt in, and the text of your documents is only included if you tick it on, per document.

What passes through our servers — and why

A few features need a server. Ours are stateless functions that process each request and keep nothing: no databases of your content, no logging of what you send. In each case this is the minimum the feature needs to work:

  • Provenance signing — receives cryptographic hashes only: never your text, your words, or your identity. Hashes cannot be reversed into writing.
  • Bitcoin timestamping — relays a single document hash to public OpenTimestamps calendars. Nothing personal is anchored.
  • Optional AI features — see the next section; these are off until you switch them on.

We host on Vercel, which — like any web host — keeps standard, short-lived request logs (IP address, browser type) for its platform operations. We add no logging of our own on top of that.

Optional AI features (off by default)

Two features use AI, and both are explicit opt-ins — nothing is sent until you switch them on, and you're asked the first time before anything leaves your device:

  • Snapshot summaries — sends snapshot text through our server to Anthropic (Claude) to describe what changed between versions.
  • URL citation lookup — sends a cited page's address and content through our server to Anthropic to fill in citation details; it can also read a few pages of an attached PDF to detect printed page numbers.

In both cases our server processes the request transiently — nothing is logged or retained — and Anthropic does not train on data sent through its API. Both settings are switched off by default and can be adjusted at any time in Settings. As Inkwave develops we are also exploring browser-local AI models for these features, so that this data truly never leaves your device.

Your work report

Inkwave can keep a record of how you work — how long you wrote for, how many words you added and deleted, when you took breaks — and, if you use them, a short note and a place label you type yourself at the end of a session. All of it stays on your device, in your own storage, exactly like your documents. A place is only ever the word you typed: Inkwave has no access to your location and never asks for it.

To get an AI's read on that record, Inkwave compiles a prompt and you run it in your own AI, then paste the reply back. Inkwave sends nothing — this path needs no account and no key, and it is free. You see the exact prompt before you copy it, and you choose what goes in it:

  • Always included — how you worked: minutes, word counts, edits, breaks, and which document each session was in.
  • Your notes and places — off unless you tick them. These are your own words about your day.
  • The text of your documents — off unless you tick them, one document at a time, so you can share the essay and keep the journal to yourself.

The figures in your report are worked out and drawn by Inkwave on your device. They are never sent to an AI to be recalculated, and nothing an AI says can change them — its contribution is the written reflection, which is labelled as its assessment wherever it appears.

Other services your browser talks to

  • Thesaurus — word suggestions come from the public Datamuse API: individual flagged words (never sentences or passages) are sent as lookups from your browser. We are exploring an on-device thesaurus in the coming weeks so these lookups never leave your machine.
  • Citation registries — DOI, ISBN, arXiv and PubMed lookups go directly from your browser to CrossRef, Open Library, Google Books, arXiv and PubMed; each learns only the identifier you looked up. CrossRef and PubMed requests include our contact email, as those services request.
  • Verification — checking a record at /verify runs entirely in your browser; nothing is uploaded. Confirming a Bitcoin timestamp queries two public block explorers for block information only.
  • Citation styles — choosing a non-default citation style downloads the style file from a public CDN (jsDelivr).

What's in your exported file

A .studio file is self-contained by design — that's what makes it verifiable. It includes your full text, your complete snapshot history (including passages you later deleted), your word-swap record, signed receipts, and a random device identifier used to group sessions. Share it knowingly: anyone you give the file to can read all of it. Embedded PDFs can be stripped with one click before sharing.

The Citation Capture extension

The extension is a separate, optional install. When you capture a page — by clicking the icon, pressing the keyboard shortcut, or revisiting a page you asked it to watch — it reads that page's address and content and sends them through our server to Anthropic to extract citation fields (title, author, date, publisher). As above, nothing is logged or retained on our servers, and Anthropic does not train on it. Identifier lookups (DOI, ISBN, arXiv, PubMed) go directly to the public registries. Captured citations are held in local extension storage until delivered to your Inkwave tab; a short-lived local history that powers "already in library" expires after five minutes. The extension never reads your browsing history or other tabs' content.

Accounts and payments

Ordinary use needs no account. If you choose to sign in — through Clerk, our authentication provider — the only personal information we hold is your email address, used solely to identify your subscription; we never email you except to help you recover your account. Signing in supports Insignia, our paid deep-provenance tier, which is still in development. Payments are handled entirely by Stripe and PayPal; we never see your card or billing details.

What we don't do

No analytics, no tracking cookies, no advertising, no crash reporting, no telemetry. The app never reports anything about you or your session, and there is no usage data to sell or share. The only external services contacted are the ones named on this page, each receiving the minimum needed to do its job.

Contact

Questions about this policy: petergibson127@gmail.com