← Back to Raven

Privacy Policy

Privacy Policy

Last updated: July 19, 2026

Raven is a local-first Markdown notes app for Mac, iPhone, and iPad. This policy covers the Raven app and website, explains what they process, and describes the choices you have.

1. What Raven collects

Depending on which features you use, Raven may process:

  • Account identifiers, including your Sign in with Apple user identifier.
  • Your note content, including note titles, bodies, paths, frontmatter, previews, image attachments, and sync metadata.
  • Device and sync information, including device identifiers, platform information, optional device labels, and session metadata.
  • Authentication and session information, including Raven session records and Apple refresh tokens encrypted at rest on Raven’s server.
  • Purchase or entitlement information, including App Store transaction identifiers and related entitlement metadata used to verify paid access.
  • Limited product analytics and diagnostics, including app platform and version, product events, aggregated counts or categories, sanitized diagnostic events, and a random analytics install identifier.
  • Website analytics, including page visits, referral source, browser and device information, interactions with site controls, and session playback used to understand whether the site works as intended.

2. How Raven uses information

Raven uses this information to:

  • sign you in with Apple if you enable cloud sync,
  • sync notes across your devices,
  • keep note history and deletion state consistent across devices,
  • detect and resolve sync conflicts,
  • verify app purchase or entitlement state,
  • understand whether onboarding, discovery, Journal, templates, sync, and the Raven website are useful,
  • identify and fix selected errors, warnings, and sync or authentication issues,
  • support account deletion and session revocation, and
  • operate and secure the service.

Raven does not use your information for advertising or cross-app or cross-site tracking. Raven does not send note bodies, note titles, raw filenames or paths, raw search queries, custom template names, authentication tokens, raw Raven or Apple account identifiers, or full device-log streams to product analytics or remote diagnostics.

3. Where your information is stored

Local storage on your device

Raven stores your notes locally as plain Markdown (.md) files on your device.

Server storage for cloud sync

If you enable cloud sync, Raven stores synced note content, image attachments, and related account and sync metadata on Convex-hosted infrastructure.

Raven does not currently offer end-to-end encryption. Synced note content is stored server-side in a form Raven can process to provide sync functionality.

4. Who can access your information

Your information may be accessible to:

  • you, on devices where you use Raven,
  • Raven’s developer, as needed to operate and maintain the service,
  • service providers that help operate Raven’s infrastructure, such as Convex,
  • PostHog, which provides limited product, website, and diagnostic analytics,
  • Apple, when you use Sign in with Apple or App Store purchase verification, and
  • law enforcement or other third parties if required by law.

5. Data retention

  • Active synced notes and account data are retained until you delete them or delete your account.
  • Deleted-note tombstones may be retained for up to 90 days so other devices can observe and sync deletions correctly.
  • Mutation and idempotency logs may be retained for up to 7 days for sync reliability and replay protection.
  • Inactive devices may be treated as inactive after extended non-use for sync cleanup logic.

6. Account deletion

If you create a Raven account through Sign in with Apple, you can delete your account in the app.

Account deletion is designed to:

  • revoke active Raven sessions,
  • revoke the Sign in with Apple refresh token used by Raven, and
  • delete synced server-side account and note data associated with your Raven account.

Account deletion does not delete local Markdown files already stored on your device. Those files remain under your control unless you delete them yourself.

7. Third parties

Raven currently relies on:

  • Convex for backend and sync infrastructure,
  • PostHog for limited product analytics, website analytics, session playback, and sanitized diagnostics, and
  • Apple for Sign in with Apple and App Store purchase/entitlement infrastructure.

Raven does not directly connect your notes to third-party AI services by default. Because your notes are plain Markdown files in folders you control, you may choose to use them with third-party tools yourself. If you do, that use is governed by those third parties’ terms and privacy policies.

8. Analytics and diagnostics

Raven uses PostHog for a limited, product-owned set of app events and sanitized diagnostics. The app disables automatic screen capture, interaction capture, session replay, surveys, and automatic crash capture. Signed-in app analytics uses a one-way pseudonymous identifier rather than a raw Raven or Apple account identifier.

The Raven website uses PostHog for page and interaction analytics and session playback. The website does not ask for or provide access to your note content. Apple may separately process diagnostics or crash information if you choose to share diagnostics through your Apple device settings.

9. Children’s privacy

Raven is not directed to children under 13, and Raven does not knowingly collect personal information from children under 13.

10. Your choices

  • You can use Raven locally without enabling cloud sync.
  • You can choose whether to sign in with Apple for synced features.
  • You can delete notes locally on your device.
  • You can delete your Raven account in-app if you have enabled cloud sync.
  • You can manage purchases and refunds through Apple.
  • You can use browser privacy controls or a content blocker to limit website analytics.

11. Security

Raven uses reasonable measures to protect information processed by the service. However, no service can guarantee absolute security. Because Raven does not currently provide end-to-end encryption for synced content, you should not assume synced notes are unreadable to the service operator.

12. Changes to this policy

Raven may update this Privacy Policy from time to time. If material changes are made, Raven will update the effective date and may provide notice in the app or on the Raven website.

13. Contact

Raven is operated by Matoya Pty Ltd. For privacy questions, contact thomas@ravennotes.app.