Cove is a local-first notes app. We do not operate advertising, analytics, profiling, or developer-hosted servers that read your notes. This policy explains when optional iCloud and external features process data.
Local first
Notes, attachments, and backups stay on your Mac or in a location you choose.
No tracking
No ads, third-party analytics, cross-app tracking, or developer telemetry.
Network by feature
iCloud, weather, and link previews connect only to do their stated jobs.
1. Scope and controller
This policy applies to the Cove macOS app distributed through the Mac App Store. The data controller is the developer identified on Cove’s App Store product page (“we,” “us,” or “the Cove developer”).
Cove does not require a Cove account. If you choose Apple iCloud, Apple Weather, or ask Cove to visit a link for a preview, the relevant provider processes the data needed for that feature under its own policy.
2. How data is handled
“Process” includes reading, storing, organizing, encrypting, and deleting data on your device, and transmitting only what is needed to complete a feature you request.
Notes, diary entries, tasks, tags, and attachments
These stay by default in the app’s container, Application Support, or a library location you explicitly choose with the system file picker. Cove does not upload them to a server operated by us.
You may paste text, images, or files. Cove reads the pasteboard when you perform a relevant action such as Paste; pasteboard access itself does not send its contents to us.
iCloud sync and preferences
If you enable sync in Cove, notes, folders, attachments, and deletion state are stored through Apple CloudKit in Cove’s private database within your iCloud account. The Cove developer does not operate the server that hosts this data.
Limited preferences such as language, view settings, and tag options may sync using Apple’s iCloud key-value store. Content locking creates a random master key on device and wraps it with a key derived from your password. If iCloud sync is enabled, CloudKit receives only a vault header containing salt, password-wrapped key material, fingerprints, and revisions. The password and unwrapped master keys are never written to disk, Keychain, or the cloud.
Locked text and structured content are encrypted on device with Apple CryptoKit before local persistence and sync. Related images and videos are encrypted before optional iCloud transfer, but remain ordinary files in the local library on that Mac. Unlocked content does not automatically gain end-to-end encryption from this feature. CloudKit and iCloud protections depend on Apple’s service and your account settings.
Location, place names, and weather
Cove requests location only when you ask for your current place or weather and grant the macOS permission. The app targets city-level accuracy, but the coordinates returned by the system can still be more precise.
Coordinates are given to Apple geocoding to produce a place name. When you request weather for a diary day, Cove gives Apple Weather, through WeatherKit, the coordinates and requested date, then converts the returned condition into a broad tag such as clear, rain, or snow. Cove does not store temperature, precipitation amounts, or the full weather response.
Apple states that WeatherKit uses location information only to provide weather, does not associate it with personally identifiable information, and does not track it between requests. A place, coordinates, and broad weather tag may be saved in the relevant diary entry and included in iCloud sync if you enable it.
You can refuse or later revoke location access. Manual place and weather entry, and the rest of Cove’s notes features, remain available.
Link previews and remote images
To create a preview for a link in a note, Cove directly visits the URL to retrieve its title, description, icon, and preview image. To show a remote image, Cove contacts its host or content-delivery network and keeps a local cache.
The destination can normally see the requested URL, IP address, time, and standard network information. Its own policy controls that processing. Avoid embedding sensitive tokens in URLs you do not want contacted.
Backups, import, export, and diagnostics
Cove creates verified backups locally. You can choose library, backup, and export locations using system pickers; Cove retains only the path information and security-scoped bookmarks needed to use those locations.
Cove does not automatically upload crash reports, performance measurements, or usage analytics. If you contact us by email or through App Store support, we use the address, message, and attachments you choose to provide to respond to that request.
Never for advertising or profiling: Cove does not use the data above for third-party ads, developer advertising or marketing, data brokerage, cross-app tracking, or user profiles.
3. External services
Each provider is contacted only for the corresponding feature. Providers may record requests, IP addresses, or account activity under their own policies and are responsible for their retention periods and rights-request channels.
Apple
CloudKit, iCloud key-value storage, location, geocoding, and Apple Weather through WeatherKit.
The open-source GRDB and Highlightr components used by Cove run locally in the app. Their inclusion does not itself transmit your content to their developers.
4. Storage, security, and retention
Local data
Local content remains until you delete it, empty Trash, remove backups, or uninstall Cove and remove its data. By default, items older than 30 days can be removed from Trash automatically; you can disable automatic removal. Backups follow the rotation shown by Cove and can also be managed directly by you.
Cloud data
Apple and your iCloud settings control the retention, recovery, and final deletion of iCloud data. Turning off Cove’s in-app sync stops new CloudKit synchronization; it does not by itself immediately delete records already stored in iCloud. You can manage the corresponding storage through system iCloud settings.
Security measures
The Mac App Store build enables App Sandbox and Hardened Runtime. External requests use HTTPS. Custom folders use system pickers and security-scoped bookmarks. Content-lock passwords and unwrapped master keys stay on the device and in the current unlocked session. Images and videos remain ordinary files in the local library, so protect your Mac, disk, iCloud account, and content-lock password.
5. Your choices and rights
- Location: revoke Cove’s access in System Settings → Privacy & Security → Location Services.
- iCloud: disable notes sync in Cove; manage Cove’s iCloud access and storage in macOS iCloud settings.
- Local content: delete items or empty Trash in Cove, and remove local backups, exports, or caches when desired.
- Access, correction, deletion, or complaints: contact us below about support communications or other information the Cove developer actually holds.
Because we do not operate Cove accounts or a centralized content server, we generally cannot locate, export, or delete by email the notes held on your Mac or in your personal iCloud account. Those actions need to be completed on your devices or through Apple’s settings.
6. Children
Cove is a general productivity tool and is not directed specifically to children. We do not serve age-based advertising or knowingly collect children’s personal information through a developer-hosted service. Minors should use features involving location, iCloud, or external accounts with a guardian’s guidance.
7. International processing
Depending on where you are and which features you choose, Apple may provide iCloud, system services, and Apple Weather according to your account and service region. A website or content-delivery network contacted for a link preview or remote image may also operate in another region.
Review a provider’s policy before using the related optional feature. Any separate consent, notice, or transfer mechanism required by applicable law depends on the actual publishing entity, service deployment, and storefront at release.