← Back to home
Privacy Policy
Last updated: September 1, 2026
Undra is local-first software made by Butterstorm LLC. Your data stays on your device by default. This website does not run analytics or behavioral tracking, and the Undra app does not send tracking data or crash reports. The app does check for updates automatically, which you can turn off in Settings.
1) Summary
- Local-first by design: your content stays on your device.
- No website analytics or behavioral tracking.
- No app tracking or crash reports.
- If you email support, we use your message only to help you.
- If you sign in (optional), we keep an account: your name, verified email, the profile you write, what you submit, your messages to us, and any moderation history.
- You can delete your account yourself at any time. It is hidden immediately and erased for good 30 days later, so a mistake can be undone.
- If you use Ask on the website, that question is sent to an AI provider to generate an answer.
- AI features (if enabled) send only the content you choose to your AI provider to generate a response.
2) Data we collect
- Website: we do not run analytics or behavioral tracking. We do not use tracking pixels or behavioral profiling.
- Website: when you request a page, our web server (or hosting provider) may process standard request data needed to deliver the site and keep it reliable (for example, IP address, user agent, and requested URL). We do not use this to build advertising profiles.
- Website: our hosting/CDN provider (Cloudflare) gives us aggregate traffic statistics (for example total visits, top pages, and countries) derived from serving the site. These statistics do not use cookies and do not identify or track you across sites.
- Website: we do not sell personal information and we do not use advertising trackers.
- Contact form: if you use the contact form on this website, we receive the name, the email address (only if you choose to provide one), the topic, and the message you submit, so we can reply. It is delivered to our support inbox. Your browser also reports its time zone with the form, used only to show the correct date on the confirmation and not stored. If you leave an email, we also send a short confirmation to that address that we received your message.
- Website FAQ helper: if you use Ask on the homepage, your question and the recent messages in that chat are sent to our support server and then to an AI provider (OpenAI) to generate an answer. We do not use those questions for advertising. Do not include secrets or personal details you would not want an AI provider to process. The helper is rate-limited and is not a human support agent.
- Spam protection: the contact form and the FAQ helper use Cloudflare Turnstile to tell humans from bots. Turnstile processes limited technical signals (such as your IP address and basic browser information) for that purpose only. It does not use tracking cookies and is not used to profile you across sites.
- For details on what Turnstile collects, see Cloudflare's Turnstile Privacy Policy.
- Component library sign-in: signing in to the component library with Google is optional and only needed for community features like commenting or publishing. When you sign in, Google confirms who you are and we keep your display name and verified email address, so we can credit your published work and reply to you. We never see your Google password, and we do not receive your contacts or profile photo. Sessions expire on their own, and signing out removes the session from your browser.
- Component library sign-in storage: signing in stores a session token in your browser's local storage (not a cookie) so you stay signed in. It expires on its own, signing out removes it, and it is not used for tracking. This website sets no tracking cookies.
- Account and profile: signing in creates an account holding your display name, verified email address, the handle your profile lives at, and anything you choose to write in the profile (a short bio, a specialty line, one link). We do not store a profile photo. Your profile only becomes publicly visible once something you submitted has been approved.
- Account records: the account also holds what you have submitted for review, the notifications we have sent you, your message threads with our team, and - if it ever applies - a record of moderation actions taken on the account and why.
- Deleting your account: you can delete it yourself from your account page. Your profile, comments and anything awaiting review are hidden straight away, and the record is erased for good 30 days later. During those 30 days you can sign in and restore it, which is deliberate: it is what makes the "if this was not you" line in our email worth anything. If you would rather ask us to erase it, email us: we hide everything the same day and erase the record seven days later, and we will tell you the date. Ask us to make it immediate and we will. Work already published stays in the library under its licence but stops being linked to you.
- Component library comments: comments you post are public and stored with your display name and an internal account identifier. They are hidden as soon as you delete your account, and removed with it.
- Component library counters: the library counts views and copies per component with anonymous counters - a number goes up, and no account, cookie, or identifier is attached to it.
- App: Undra is designed to run locally. We do not receive your notes, tasks, canvases, or files by default.
- App: the Undra app does not send tracking data or crash reports.
- Optional features (if enabled): if you choose to use features that communicate with our servers (such as update checks, or fetching the current list of supported AI models), we will receive the network requests necessary to provide that feature.
3) AI features (optional)
- If you enable AI features, the app may send selected content to your connected AI provider (for example Claude, OpenAI/Codex, or Cursor, or a local model via Ollama or LM Studio that runs on your machine) to generate results.
- Provider sign-in happens through each provider's own app or sign-in flow on your device (for example the Claude or Codex command-line tools), and those tools store and manage their credentials locally on your machine. Undra does not transmit your credentials to us and has no server that receives them.
- Chat and agents: when you chat with the built-in AI, it can read content from your workspace and from folders you have connected or approved, and what it reads may be sent to your AI provider to generate the response. Images you attach in chat are sent to your provider as part of that request.
- Scope of AI file access: the app limits AI file access to your workspace, connected folders, and folders you approve when the app asks. Commands an AI runs in a terminal, and any external tool servers (MCP) or outside AI apps you choose to connect, operate under their own permissions and are not confined by that file scope.
- Notes text AI: by default, only the text you select is sent. If you enable whole-note context, the full note body may be sent as read-only context for that request.
- Canvas image AI: image AI is off by default. If you enable it, the app may upload the image(s) you select for actions like OCR, describe, stylize, or background removal (with confirmations). Outputs are created as new assets and do not overwrite the original.
- Third-party processing: your AI provider processes these requests under its own terms and policies. The same applies to any external tool server (MCP) or outside AI tool you choose to connect. We do not control how third parties log or retain data.
- Tip: avoid including secrets (passwords, API keys, private keys) in prompts or context you send to an AI provider.
4) Updates
- By default, the app periodically contacts Undra update servers to check for and download newer versions, so you stay current with fixes and security patches.
- You can turn automatic updates off in Settings; with them off, the app only contacts update servers when you check manually.
- Requests may include basic technical information needed to deliver updates (for example, app version and operating system).
- We do not use update checks for behavioral tracking or to identify you across sessions.
5) Email and support
- If you contact us by email, we use your message only to respond and provide support.
- In-app feedback: if you use the Send feedback button inside the app, we receive your message along with basic technical details (app version and operating system) so we can diagnose issues. It is delivered to our support system and used only to help you.
- Email may include any information you choose to share; please avoid sending sensitive data you do not want stored in email.
- We only receive what you choose to send us (for example, your message and any attachments).
- We may keep support emails as needed to resolve issues and maintain continuity of support conversations.
- We do not use support emails for advertising profiling.
6) Your rights, retention, and children
- You can email us to ask what information we hold about you, to correct it, or to have it deleted, and we will honor reasonable requests. Because the app does not transmit your data to us, the only information we could hold is the contact-form and support messages you have chosen to send us.
- Questions sent through Ask are processed to generate an answer and are not kept in our support inbox. The AI provider may process them under its own terms.
- We keep contact-form and support messages only as long as needed to help you and maintain continuity of support, generally no more than 24 months, unless you ask us to delete them sooner.
- If you are in the EU or UK, you also have the right to complain to your local data protection authority.
- Undra is not directed to children under 13, and we do not knowingly collect personal information from them.
7) Changes
- If this policy changes, the version published on this page is the current version.
8) Contact
- Contact page
- Email support
9) External links
- If you follow a link to a third-party site, that site has its own policies. We are not responsible for third-party privacy practices.