Privacy notice
Commonfold is built for private knowledge. This notice explains what information we process, why we process it, who helps us provide the service, and the choices available to you.
1. Who is responsible for your data
Commonfold is the controller of personal data processed to provide the Commonfold website and application. Questions and data-protection requests can be sent to privacy@commonfold.space.
2. Information we process
Account information
We process the identifiers and profile information needed to create and secure your account, such as your name, email address, authentication identifier, and session information.
Content you choose to store
This includes notes, imported Markdown, uploaded files, conversations, tasks, reminders, generated and saved views, document discussions, links, folders, tags, and the context items you choose to keep. It may include personal data about you or other people if you place that information in Commonfold.
Collaboration and sharing information
We process membership roles, invitations, task assignments, editing presence, comments, revision authorship, notification preferences, push subscriptions, API tokens, webhook configuration, and share-link settings so that access, delivery, automation, and changes can be controlled.
Answer feedback
Thumbs-up and thumbs-down ratings record your rating and the answer identifier, without copying conversation text. If you submit a detailed report, you choose the answer, turn, or chat to share and explicitly agree to share its preview with Commonfold’s authorized administrators. Reports include your identity, comment, optional rating, and the selected text so we can investigate them. We retain this copy until you withdraw it in My feedback or delete your account. Deleting the original conversation does not withdraw a submitted report.
Technical and support information
Our infrastructure providers may process IP addresses, device and browser information, request logs, diagnostics, and security events. We also process information you include in a support or privacy request.
3. Why we process information
- To provide the service under our agreement with you. This includes authentication, storage, search, AI-assisted workflows, collaboration, sharing, import, export, and recovery.
- For our legitimate interests in operating a safe service. This includes preventing abuse, debugging failures, responding to support requests, and protecting accounts and infrastructure.
- With consent where consent is appropriate. If we add an optional use that requires consent, we will ask before enabling it and make withdrawal as easy as acceptance.
- To comply with legal obligations. We may preserve or disclose limited information where applicable law requires it.
We do not sell personal data, serve targeted advertising, or use the marketing site for behavioural tracking.
4. How AI processing works
Commonfold uses AI to classify captures, propose links and organization, answer questions, create embeddings for retrieval, transcribe audio, and identify context that may be useful later. Depending on the feature, the content you submit and a limited set of relevant context may be sent to Anthropic or OpenAI for processing.
Commonfold does not send your entire archive to an AI provider for every request. Retrieval is scoped to the active space, and workflows receive the input and context needed for that task. AI suggestions can be wrong; filing proposals require your review, and remembered context remains inspectable and reversible.
In the iOS application, Commonfold asks for your explicit permission before sending personal data to Anthropic or OpenAI. Declining leaves browsing and reading available but prevents AI requests that would share content. You can review or withdraw that permission from Account and settings → AI & privacy. With AI enabled, shared recordings, photos, supported public video links, text and documents are automatically processed for summaries and library search after syncing. Withdrawal turns AI off on that device and, once connected, cancels queued capture processing. Requests already sent to a provider may finish. Saved originals and completed results remain until you delete them.
Automatic project-link research is off by default. The space owner can enable it separately in Space settings → AI & privacy. Selected AI providers then analyze capture text to identify public projects. Project names and brief descriptions are sent to public research services to find official websites or repositories. Turning this option off stops future lookup steps; requests already sent may finish. Existing summaries and links remain until deleted.
Enabled MCP connectors send tool arguments to the service configured in your space when relevant to a request. Returned content and loaded skill instructions may be included in AI context. Connector operators have their own privacy terms; review their identity, endpoint and enabled tools before connecting. You can disable or remove connectors in Space settings → Connectors.
5. Service providers and recipients
We use specialist providers to operate Commonfold:
- Clerk for account authentication and session security.
- Neon for the PostgreSQL database that holds canonical content and metadata.
- Vercel for application hosting, private file storage, temporary media preparation, queues, delivery, and operational logs.
- Liveblocks for realtime editing and collaborator presence.
- Anthropic for language-model workflows such as answers, filing proposals, and context extraction.
- OpenAI for semantic embeddings, public web research, and audio transcription.
- Expo and Apple for push delivery when you enable device notifications. Push payloads use a generic message and notification identifier; note and message previews are fetched after you open the app.
- Resend when you enable or receive email notification delivery.
These providers process data on our behalf or as otherwise described in their terms. We may also disclose information when required by law, to protect the service or its users, or as part of a business transfer with appropriate safeguards.
6. International transfers
Some providers may process information outside your country or the European Economic Area. Where data-protection law requires a transfer mechanism, we rely on an applicable adequacy decision, standard contractual clauses, or another recognised safeguard provided for the relevant service.
7. Retention and deletion
We keep account information and stored content while your account or space remains active. Revoked and expired share links stop granting access. Operational logs and backups are retained only for security, reliability, recovery, and legal needs, then deleted or overwritten on their normal schedule.
You can remove content in the product, export a space, or ask us to delete your account and associated personal data. Some information may remain temporarily in restricted backups or be retained when required to meet a legal obligation, resolve a dispute, or prevent abuse.
8. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, or object to processing of your personal data, and to receive portable data. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also complain to your local data-protection authority.
Email privacy@commonfold.space to exercise a right. We may need to verify your identity before acting on a request. Commonfold also provides a Markdown export so you can take the substance and structure of a space with you.
9. Cookies
The marketing site does not use advertising or behavioural analytics cookies. The application uses essential authentication, security, and session storage needed to provide the service you request. See the cookie notice for details.
10. Security
We use technical and organizational measures intended to protect personal data and review those measures as the service changes. No method of online storage or transmission can promise absolute security. If you believe you have found a security problem, contact us at security@commonfold.space.
11. Children
Commonfold is not directed to children under 16, and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal data without appropriate authorization.
12. Changes and contact
We may update this notice when the product, providers, or law changes. Material changes will be communicated in an appropriate way. For privacy questions or requests, contact privacy@commonfold.space.