Cove is a local-first notes app. We do not operate advertising, analytics, profiling, or developer-hosted servers that read your notes. This policy explains when optional iCloud and external features process data.
Local first
Notes, attachments, and backups stay on your Mac or in a location you choose.
No tracking
No ads, third-party analytics, cross-app tracking, or developer telemetry.
Network by feature
iCloud, weather, book sources, and link previews connect only to do their stated jobs.
1. Scope and controller
This policy applies to the Cove macOS app distributed through the Mac App Store. The data controller is the developer identified on Cove’s App Store product page (“we,” “us,” or “the Cove developer”).
Cove does not require a Cove account. If you choose Apple iCloud, WeRead, or another external service, that provider separately processes data under its own policy.
2. How data is handled
“Process” includes reading, storing, organizing, encrypting, and deleting data on your device, and transmitting only what is needed to complete a feature you request.
Notes, diary entries, tasks, tags, and attachments
These stay by default in the app’s container, Application Support, or a library location you explicitly choose with the system file picker. Cove does not upload them to a server operated by us.
You may paste text, images, or files. Cove reads the pasteboard when you perform a relevant action such as Paste; pasteboard access itself does not send its contents to us.
iCloud sync and preferences
If you enable sync in Cove, notes, folders, attachments, and deletion state are stored through Apple CloudKit in Cove’s private database within your iCloud account. The Cove developer does not operate the server that hosts this data.
Limited preferences such as language, view settings, and tag options may sync using Apple’s iCloud key-value store. A master key used for Cove’s content-lock feature may sync through iCloud Keychain so your devices can decrypt locked content.
Entries or blocks you lock are encrypted on device with Apple CryptoKit before persistence and sync. Content you have not locked does not automatically gain end-to-end encryption from this feature. CloudKit and iCloud protections depend on Apple’s service and your account settings.
Location, place names, and weather
Cove requests location only when you ask for your current place or weather and grant the macOS permission. The app targets city-level accuracy, but the coordinates returned by the system can still be more precise.
Coordinates are given to Apple geocoding to produce a place name. When you request weather for a diary day, Cove gives Apple Weather, through WeatherKit, the coordinates and requested date, then converts the returned condition into a broad tag such as clear, rain, or snow. Cove does not store temperature, precipitation amounts, or the full weather response.
Apple states that WeatherKit uses location information only to provide weather, does not associate it with personally identifiable information, and does not track it between requests. A place, coordinates, and broad weather tag may be saved in the relevant diary entry and included in iCloud sync if you enable it.
You can refuse or later revoke location access. Manual place and weather entry, and the rest of Cove’s notes features, remain available.
Book search and WeRead connection
When Google Books is the selected source, Cove sends your book-search terms to Google Books. Cove does not sign you in to a Google account.
If you connect WeRead, Cove stores the API key you provide in the macOS Keychain and sends it to the WeRead gateway with requests. Book IDs, search terms, and similar request parameters are also sent. Cove receives and locally caches your shelf, lists, reading progress, and highlights. Notes you write in Cove are not uploaded to WeRead.
Disconnecting stops future requests and removes Cove’s local credential. It does not delete account data already held by Tencent or content already imported into Cove.
Link previews and remote images
To create a preview for a link in a note, Cove directly visits the URL to retrieve its title, description, icon, and preview image. To show a remote image, Cove contacts its host or content-delivery network and keeps a local cache.
The destination can normally see the requested URL, IP address, time, and standard network information. Its own policy controls that processing. Avoid embedding sensitive tokens in URLs you do not want contacted.
Backups, import, export, and diagnostics
Cove creates verified backups locally. You can choose library, backup, and export locations using system pickers; Cove retains only the path information and security-scoped bookmarks needed to use those locations.
Cove does not automatically upload crash reports, performance measurements, or usage analytics. If you contact us by email or through App Store support, we use the address, message, and attachments you choose to provide to respond to that request.
Never for advertising or profiling: Cove does not use the data above for third-party ads, developer advertising or marketing, data brokerage, cross-app tracking, or user profiles.
3. External services
Each provider is contacted only for the corresponding feature. Providers may record requests, IP addresses, or account activity under their own policies and are responsible for their retention periods and rights-request channels.
Apple
CloudKit, iCloud key-value storage, iCloud Keychain, location, geocoding, and Apple Weather through WeatherKit.
WeRead (Tencent)
Processes the API key, searches, shelf, progress, and highlight requests after you connect.
WeRead Privacy Policy
The open-source GRDB and Highlightr components used by Cove run locally in the app. Their inclusion does not itself transmit your content to their developers.
4. Storage, security, and retention
Local data
Local content remains until you delete it, empty Trash, remove backups, or uninstall Cove and remove its data. By default, items older than 30 days can be removed from Trash automatically; you can disable automatic removal. Backups follow the rotation shown by Cove and can also be managed directly by you.
Cloud data
Apple and your iCloud settings control the retention, recovery, and final deletion of iCloud data. Turning off Cove’s in-app sync stops new CloudKit synchronization; it does not by itself immediately delete records already stored in iCloud. You can manage the corresponding storage through system iCloud settings.
Security measures
The Mac App Store build enables App Sandbox and Hardened Runtime. External requests use HTTPS. WeRead credentials use the macOS Keychain. Custom folders use system pickers and security-scoped bookmarks. No technical measure can guarantee absolute security, so protect your Mac, iCloud account, content-lock password, and external credentials as well.
5. Your choices and rights
- Location: revoke Cove’s access in System Settings → Privacy & Security → Location Services.
- iCloud: disable notes sync in Cove; manage Cove’s iCloud access and storage in macOS iCloud settings.
- WeRead: disconnect in Cove to remove the local credential; use Tencent’s channels to manage data in your WeRead account.
- Local content: delete items or empty Trash in Cove, and remove local backups, exports, or caches when desired.
- Access, correction, deletion, or complaints: contact us below about support communications or other information the Cove developer actually holds.
Because we do not operate Cove accounts or a centralized content server, we generally cannot locate, export, or delete by email the notes held on your Mac or in your personal iCloud account. Those actions need to be completed on your devices or through Apple’s settings.
6. Children
Cove is a general productivity tool and is not directed specifically to children. We do not serve age-based advertising or knowingly collect children’s personal information through a developer-hosted service. Minors should use features involving location, iCloud, or external accounts with a guardian’s guidance.
7. International processing
Depending on where you are and which features you choose, providers in different regions may process data. Apple provides iCloud, system services, and Apple Weather according to your account and service region; Google provides global services; and WeRead is provided by a Tencent entity in mainland China.
Review a provider’s policy before using the related optional feature. Any separate consent, notice, or transfer mechanism required by applicable law depends on the actual publishing entity, service deployment, and storefront at release.