Privacy policy | Madrid

Privacy policy

This describes what Madrid stores, what leaves your Mac, and who processes it on our behalf. It covers the macOS app, the hosted app, and this website.

Last updated 5 September 2026

What we hold

Your account. Your email address, and any name or avatar you provide, held by our authentication provider so you can sign in and we can tell your vault apart from anyone else's.

Your notes. Note titles, bodies, folders, links, preferences, and any files you attach. While you are signed in, these are stored in a database row secured to your account, and attachments are kept in private storage reached through short-lived links. A copy also lives locally on your Mac so the app works offline.

Your subscription. Whether you have an active subscription and which plan it is. Card details are handled by our payment processor and never reach us.

What leaves your Mac

Notes sync to your account when you are signed in and online. Beyond that, content leaves only when a feature you used requires it:

  • Audio you record for assistive capture is sent to a speech-to-text provider and returned as text.
  • Note text is sent to an embeddings provider when semantic search builds its index.
  • A link you paste is fetched by our server so the preview card can show its title and image.
  • A flight code you use is looked up with a public flight data service.

If you do not use those features, that data is not sent.

Who processes data for us

  • Clerk, for accounts, sign-in, and subscription entitlement.
  • Supabase, for the notes database and attachment storage.
  • Stripe, through Clerk Billing, for payments.
  • xAI, for speech-to-text in assistive capture.
  • An embeddings provider, for semantic search indexing.
  • Vercel, for hosting this site and the app's server routes.
  • GitHub, which serves the Mac app downloads and sees the usual request data when you download.

Each of these processes data on our instructions in order to run the product. We do not sell your data, and your notes are not used to train models.

Analytics

This website uses Vercel Analytics, and Microsoft Clarity when it is configured, to understand which pages people read. The app uses PostHog for product analytics when it is configured. These record usage, not the contents of your notes.

How long we keep things

Notes stay until you delete them. Deleting a note removes its attachments from storage as well as the note itself. Deleting your account removes your notes and account record; backups and provider logs age out on their own schedules.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Contact us from Settings in the Madrid app, or by replying to a purchase receipt. If you are in the UK or the EU, you also have the right to complain to your data protection authority.

Changes

When this policy changes, the date at the top changes with it. The site is open source, so the history of this page is public in the repository.