The short version
Sanctum starts with one rule: your notes are yours. Built In Space LLC does not read your private library or keep a readable copy of it. We take that seriously.
We read the privacy policies and service terms for every company that handles Sanctum's cloud AI work. We send them note content only when you ask for a cloud feature, and only to do that job. It is not sent for ads or model training.
Sanctum does not sell your note content or personal information. The current note processors' published terms say they do not sell it either.
We want to make it cryptographically impossible for a person at Sanctum or one of those companies to read your data while it is being processed. We are not all the way there yet.
For now, we keep the exposure window short and delete temporary copies automatically. We review provider contracts and security audits, and the code sends as little as possible. If a provider changes its terms or stops meeting our privacy standard, we will replace it.
We are also building our own end-to-end processing system so we can control the whole path ourselves and enforce privacy with cryptography instead of promises. It is not finished yet.
Sanctum is the product you pay for. Your data is not the product.
We built Sanctum to keep your notes and your thoughts safe.
Recording, playback, search, editing, organization, sharing, and export all work with files on your device. You do not need an account for any of them. If you choose cloud transcription or synthesis, the processor needs readable audio or text while it does the job. We keep that window short and delete temporary copies.
Optional features can send data off your device:
Cloud transcription
AssemblyAI receives the audio you choose to transcribe. A July 30, 2026 operator record says our production account was opted out of model training and set to one-day retention; this audit did not reverify those live settings. AssemblyAI may need additional time to finish deletion after expiry. Its Trust Center lists its current certifications, including SOC 2 Type II and ISO 27001.
Note synthesis
By default, Sanctum sends synthesis jobs to RedPill and requests zero data retention. RedPill runs them in a trusted execution environment and says its operators cannot read the content. Sanctum does not yet check the signed receipt for each request, so we are relying on RedPill for that claim. If you choose AssemblyAI, or RedPill is down, Sanctum uses AssemblyAI's LLM Gateway. It sends the text to Anthropic's Claude, usually through Amazon Bedrock; the production Gateway retention setting has not yet been live-verified.
Location stamps
Location stamps are off by default. If you enable them, Apple receives your location to look up the neighborhood or town. Precise Location helps find smaller areas; you can choose Approximate Location instead in iOS Settings. Your recordings and text are not sent for this lookup. Sanctum saves the place label with your note, without coordinates, and never sends the stamp for transcription or AI analysis. You can remove a stamp from its note or turn off future stamps in Settings. Optional Private Backup includes the label inside the encrypted note files.
Private Backup
Sanctum encrypts files on your device before uploading them. AWS and Backblaze receive ciphertext and random identifiers, not readable notes. With the default recovery code, Built In Space LLC does not have the key. If you turn on account recovery, the key is stored in your Supabase account. Anyone who can sign in to that account can restore the backup.
Information stored on your device
Sanctum stores your enclaves, note folders, audio, transcripts, markdown notes, tags, optional location labels, settings, trash records, and analysis-cost records on your device. You can see the files in the Files app and control them yourself.
SwiftData stores a rebuildable index with metadata and file locations. The files on disk, not the SwiftData index, are the records Sanctum trusts.
Accounts and purchases
Supabase stores the email address, user ID, sign-in records, and identity-provider links needed for your account. If you sign in with Apple or Google, that company handles the sign-in information. RevenueCat receives your user ID and keeps the purchase, subscription, entitlement, device, and app details needed to run purchases. None of these services receives your notes for these jobs.
The introductory server-analysis trial uses an anonymous guest identity and does not require a full account. More analysis and other paid or cloud services require one. You do not need an account to record, read, edit, delete, share, or export your files.
Private Backup
Private Backup is optional. Sanctum encrypts each file on your device before uploading it. AWS stores account and backup control data. Backblaze B2 stores encrypted chunks and manifests under random names. Neither company can read filenames, titles, note relationships, transcripts, note text, or audio.
A current backup stays until you delete the backup or your account. A replaced object is kept for at least 30 days. An abandoned upload expires after 24 hours. Deleting the backup or account schedules the stored objects for physical deletion.
Your recovery code and the key it protects stay on your device by default. If you turn on account recovery, Sanctum stores the backup key and its random backup identifier in your Supabase account. This means anyone who signs in to the account can restore the backup. Turning account recovery off, deleting the cloud backup, or deleting the account removes the stored key.
Transcription and synthesis
Before Sanctum sends a cloud request, it shows you the audio or text that will leave your device and the companies that may process it. Nothing is sent until you agree. You can withdraw that consent in Settings, and Sanctum will ask again next time. On-device transcription does not use an outside company.
Cloud transcription uses AssemblyAI. A July 30, 2026 operator record says our production account was opted out of AssemblyAI's Model Improvement Program and set to one-day retention; this audit did not reverify those live settings. AssemblyAI says opted-out submitted files are not used to train its models. The Sanctum app cannot enforce those account settings. Sanctum deletes its temporary copy in AWS S3 when the job ends. S3 is also set to delete that copy after one day if the first deletion fails. The job record expires after 24 hours. An hourly cleanup worker keeps asking AssemblyAI to delete the provider job after the deadline until AssemblyAI confirms it.
RedPill is the default synthesis route. Sanctum asks RedPill to use confidential computing with zero data retention. A job may pass through Phala, Chutes, NEAR AI, Tinfoil, or another company named in its receipt. Sanctum does not yet verify those receipts, so we have not independently checked the hardware claim.
You can also use AssemblyAI's LLM Gateway. For the Claude model used by Sanctum, AssemblyAI says it normally runs through Amazon Bedrock. Bedrock does not store or log prompts or completions. AssemblyAI may instead send the request directly to Anthropic with zero-day retention. AssemblyAI says every Gateway model provider is opted out of training. AssemblyAI clears inputs and outputs hourly when an account TTL is configured, but Sanctum has not yet live-verified the production Gateway TTL and does not promise a duration. Some logging and billing data remains.
Feedback you send us
Sending feedback in the app is optional. Sanctum does not attach anything from your library. You choose a category and write the message. You can also attach one voice note, up to five screenshots, and one screen recording. Feedback is kept separate from your notes and search index.
We keep a feedback report for one year. Its text and details are stored in AWS DynamoDB, and its attachments are stored in AWS S3. Both are deleted if you delete your account. AssemblyAI transcribes a voice attachment under the account settings above. Sanctum asks AssemblyAI to delete its copy when transcription is done.
Permission to contact you is off by default. If you turn it on, we receive the email address on your account and nothing else. Feedback is not a support inbox, and we cannot promise a reply.
Diagnostics
Sentry receives crash and performance data from the app and server. This may include error types, stack traces, app and device versions, route templates, and timing. Sanctum configures Sentry not to send recordings, transcripts, notes, credentials, account IDs, screenshots, replays, or request bodies. AWS CloudWatch stores server logs for 30 days.
We configured the Sentry project not to store IP addresses. Other diagnostic events stay for the retention period set on the project.
Push notifications
If you allow notifications, Sanctum gives Apple a device push token linked to your Sanctum identity so Apple can deliver note-ready alerts, minute gifts, and necessary service notices. These alerts contain public copy and opaque identifiers, never a note title, recording, transcript, or note text.
Occasional recording prompts are a separate choice and are off by default. After Sanctum has made a note, you may choose to receive invitations to take a walk, ramble, and record a thought. You can turn them off at any time in Settings. The token and that choice stay in AWS until the device stops registering for 180 days, Apple reports the token invalid, or you delete the account. Sanctum does not use the token for cross-app tracking or advertising measurement.
Website data
Vercel hosts this site and may receive the IP address, browser type, requested page, time, and security details that come with an ordinary web request. After the page loads, Umami Cloud records pageviews, referrers, browser, operating system, device type, country, and session timing. Umami does not use cookies. It creates an anonymous session hash from the IP address, user agent, and this site's Umami ID. Sanctum does not send URL query strings, visitor IDs, custom events, or session properties. The analytics stay in Umami Cloud until the site data or account is deleted. We do not promise a shorter expiry date.
The signup form is the only public visitor form on this site that asks for personal information. Resend receives the email address, sends the signup email, and keeps the address on Sanctum's mailing list. We use the list to send the App Store download link and other Sanctum updates. The address stays on the list until it is removed. Unsubscribing marks it as unsubscribed instead of deleting it. We turned off open and click tracking. Every list email has an unsubscribe link. Unsubscribing from that list does not block account emails you request later. The IP address used to submit the form is held briefly in memory for rate limiting and is not stored.
Retention and deletion
Local files stay until you delete them, clear eligible audio, remove the app under your device and backup settings, or empty Sanctum's trash. A normal in-app deletion moves recoverable files to trash first.
Deleting your account removes Private Backup data, feedback, unused analysis minutes, the RevenueCat customer profile, stored Apple revocation data, and the Supabase user. It does not cancel an App Store subscription or delete the notes on your device. Analysis job records that contain no content expire on their 24-hour schedule.
Your choices, changes, and contact
You decide whether to use server analysis or Private Backup. You can grant or withdraw cloud-processing consent, and you control the files on your device. Built In Space LLC operates Sanctum in the United States. Depending on your state, you may have the right to access, correct, delete, or export personal information held by Sanctum.
We will date any important change to this policy and may also notify you in the app. Send privacy questions to support@speakwithsanctum.app.