Privacy Policy

Effective 20 September 2026 · Daksh Patel · info@getreservoir.app

Reservoir keeps what you save on your phone. Your library is on the device and works with no network; an account is what lets it reach your other devices.

If you sign in, your library is copied to our server so your other devices have the same things — the index and the contents both, on every plan. Saving and syncing are not metered.

AI that reads your saves runs on your phone. Three features are exceptions, all off unless you turn them on and each asking for consent first: the weekly digest, which sends a short summary of your week; Listen, which sends the same summaries to write a narrated programme; and Recall, which sends the text of articles we already hold so it can quote them back to you accurately.

We do not use analytics, advertising or tracking of any kind. We do not sell your data. The app does send us a small amount of technical information about how it is performing — never what you saved — and you can turn it off.

If you share a save, the people who can open it see your note, your highlights and comments, and a link to the original — never our copy of the article.

What Reservoir stores on your device

Everything you save, and this is the primary copy — not a cache: links and the readable copy of the page fetched at save time, so it survives if the original disappears; photos and PDFs, and any text recognised in them; titles, excerpts, authors, site names and thumbnails; notes you write, tags and collections; AI summaries and tag suggestions produced on the device; and numeric representations of your saves that make search work.

Your session token is held in the operating system's secure keychain. All of this lives in a database and files private to the app, one database per account. Deleting the app deletes all of it.

What we store on our servers

Only when you are signed in, and only what sync requires.

We hold your library, on every plan. There is no limit on how much you save and no difference between plans about what syncs. This changed in September 2026; earlier versions of this page described a ten-item limit on the free tier, and that limit no longer exists.

For a saved item we store its links, title, excerpt, author, site name, thumbnail, kind, saved and read timestamps, the readable copy of the page, text recognised in images, transcripts of videos and podcasts, and any note you wrote on it — along with your tags, collections, summaries, embeddings and digests. Photos and PDFs are uploaded to private file storage readable only by your account.

If you ask us to keep a page completely, we hold the whole page. That is what archiving a save does, and it is a paid feature: we fetch the page and the images and stylesheets it needs to look like itself, and store the result as one file in the same private storage. Scripts are removed, so an archived page cannot run code. It is stored so you can read it after the original goes away, which is the point of asking for it.

If your subscription lapses we hold those complete copies for 90 days and then delete our copy. The readable text stays, as it does for every save, and the copy on the device that made it is untouched — we stop holding a second copy, we do not reach into yours.

For a synced item we store its links, title, excerpt, author, site name, thumbnail, kind, saved and read timestamps, whether it is set to sync, the readable copy of the page, text recognised in images, and any note you wrote on it. We also store your tags, collections, AI summaries, embeddings and generated digests. Photos and PDFs you sync are uploaded to private file storage readable only by your account.

We want to be plain about this: the readable copy of a saved article is stored on our servers for synced items. It is stored so you can read it on another device and after the original goes away. It is not published, not shared, and not used to train anything.

For your account we store your email address and an authentication record. If you sign in with Apple or Google we receive whatever that service returns — for Apple, that may be a relay address rather than your real one. We never see your password.

AI

On your device, by default and at no cost: summaries, tag suggestions, collection-name suggestions, text recognition in photos, and search embeddings all run on the phone. Nothing is sent anywhere, whether or not you have an account.

Three features use a cloud model, and all are off until you turn them on.

The weekly digest. It is off until you enable it, and asks for explicit consent the first time. When it runs it sends, for up to forty items from the past week: the title, the site, and the date you saved it; a short excerpt or the on-device summary; any note you wrote on the item; and the tags on it. Excerpts and notes are trimmed to 400 characters.

The digest does not send the readable copy of any article, its HTML, text recognised in your photos, the files themselves, your email address, or any identifier for you.

Notes are included deliberately: a note is the best evidence of why you kept something, and the digest is much worse without it. If you would rather a note never leave the device, do not enable the digest.

Listen, which turns your saves into something narrated. It is a paid feature and it works two ways, which send different things.

A programme — your week, a collection, or saves you pick — is written from the same material as the digest and under the same consent: titles, sites, dates, excerpts or on-device summaries, your notes, and tags. It does not send the readable copy of any article. The script is written by a cloud model; the voice that reads it runs on your phone, so the audio itself is never sent anywhere and never leaves the device.

Reading one save aloud does not send anything. It uses the copy already on our servers — the readable text, what was recognised in a photo, or the note you wrote — and turns it into the sounds the voice needs, on our servers rather than your phone for a licensing reason: the pronunciation software is published under a licence we cannot include in the app.

No language model sees it and no provider is involved. References, stray links and image credits are taken out by a plain set of rules, and nothing is rewritten or shortened — what is read to you is what you saved.

So no part of Listen sends the text of a save anywhere.

Recall, which answers questions about your library. It is a paid feature, off until you turn it on, and it asks for its own separate consent — separate because it sends more than the digest does.

To answer with quotes, Recall first divides your saved articles into passages and writes a short sentence describing where each passage sits in its article. That step sends the readable copy of the article to a language model provider. It happens once per article, on our servers, not on your device.

Preparing them does not send anything new from your phone: it uses the copy already on our servers. If we do not hold an article, it is not processed and Recall cannot quote it.

Searching sends nothing — finding the passages happens entirely on your device. Asking a question does send something: your question and up to twelve short extracts that might answer it, including from items we do not otherwise store. Nothing else about those items goes with them, and the question itself is not kept — we record only its length, how many extracts were sent, what it cost, and whether an answer was found.

Requests for these features go to OpenRouter, which routes them to a language model provider. We send no account identifier. We do not permit this content to be used to train models, and select providers on that basis. If you turn neither on, nothing you save is ever sent to a cloud AI service.

Collections you publish

Publishing a collection creates a secret link. Anyone holding that link can see it without an account, so treat the link as the access control.

A published collection exposes only the collection's name and description, and for each item its title, excerpt, author, site name, thumbnail, source link and kind.

It deliberately does not expose the readable copy of any article, text recognised in your photos, your notes, whether you synced or read something, or anything identifying you. Unpublishing revokes the link.

Saves you share

Sharing one save creates a link. You choose who it opens for: anyone holding the link, without an account, or only the people you add, each of whom gets a link of their own. The name you give a person is a note for you; nobody else sees it.

A shared save shows its title, excerpt, author, site name, thumbnail, source link and kind; the note you wrote on it; and your highlights and the comments on them, unless you switch "Include my highlights" off. A note you typed yourself shares its text, and a passage you saved from a page shares the passage and where it came from. A photo shares the image only if you tick "Include the photo", and even then the image is served through a check that the share still stands, never from a permanent address. Your name appears only if you chose to show one in your sharing settings.

It never shows our copy of an article, an archived page, a PDF file, a transcript beyond the passages you highlighted, text recognised in your photos, whether you read something, or your email address.

A link you make for a person belongs to the first signed-in account that opens it. You see that account's sharing name, if it shows one, and can let the link be claimed again. You can let a person comment. What they add — comments, replies, and highlights of their own — is stored on our server with the save, under their account, and is shown to you and to the other people you added, never to someone holding only the general link. You can remove anything added to your save; they can edit or remove their own while they still have access, and what they wrote stays if you take their access away.

When a save is shared with you and you open it signed in, we record that you received it — which share, and when you opened it — so it appears under Shared with you. Only you can see that record. The person who shared it cannot see who opened a link meant for anyone, and a save leaves your list when its link stops working.

The browser extension can show a sharer's highlights on the original page. To do that it downloads the highlights of the saves shared with you and matches the page on your computer; it never tells us which pages you visit.

Stopping sharing makes every link to the save stop working at once, the general link and each person's. Sharing again makes new ones.

Websites you save

When you save a link, the app fetches that page to make the readable copy. That request goes to the site directly, so the site's operator can see it in their logs, as with any visit. We do not send them anything about you beyond what a normal request contains. The same is true when you ask us to keep a page completely: we fetch the page and its images, from the sites that host them.

Videos and podcasts are transcribed, and that involves one more party. If you save a podcast episode we ask Apple's public directory which feed it belongs to and read the transcript the show publishes, if it publishes one — ordinary requests for public documents. If you save a video, the link is sent to a transcript provider, because the platform no longer serves captions to anyone else. What is sent is the link and nothing about you: no account, no identifier, nothing about the rest of your library. Only public media at a public address is transcribed this way.

Permissions

The camera, only when you choose to capture something. Your photo library, only when you choose to import a photo. Photos are processed on the device. We do not read your library in the background, and we do not upload anything you have not saved into Reservoir.

What we do not do

As of the effective date above, Reservoir contains no analytics SDK, no crash-reporting SDK, no advertising and no third-party tracking. We do not record which screens you visit, which features you use, or how often you open the app. We do not build a profile of you, do not sell or share personal information, and do not use your saved content to train AI models. (Test builds are the one exception, and the Diagnostics section below says exactly what they record.)

Reservoir does record problems for itself. When something goes wrong — a crash, or an internal check that fails — it is written to a list you can read under Settings, Diagnostics. It contains counts and version numbers, never the content of your library.

Some of that is sent to us, and the next section says exactly what.

If we ever add a third-party analytics or crash-reporting service, this policy will be updated and the store privacy disclosures with it, before the code ships.

Diagnostics

Reservoir is made by one person with a small number of testers, and nobody writes in to say that search felt slower this week. So the app tells us instead — and this section exists because that is a real thing leaving your device, however small.

What is sent. How long things took: a search, a sync, an import, opening a save, Recall’s first answer, how long a new save waits for its readable copy, how long the app takes to start, and generating a narration. How much there was to do at the time, as a number — how many saves, how many are waiting. Counts of internal checks that failed: the name of the check and a number, never the message that came with it, because an error message can quote a link or a title and those are yours. Your device model, its operating system version, and the app’s version. That is the whole list.

What is never sent. Nothing you saved, and nothing you wrote. No titles, links, notes, article text, photographs, tags or collection names. No questions you asked Recall, and no search terms. In the App Store release, no screens you visited and no record of which features you use.

It is attached to your account, so that a problem on one device can be told apart from a problem everywhere, and so we can ask you about it.

Turning it off. Settings, then Diagnostics, and it stops immediately. In test builds distributed before release it is on to begin with, because finding these problems is what a test period is for; in the App Store release it is off until you turn it on. Either way the switch is in the same place and it works the same.

Test builds record a little more, and only test builds. A build given to testers before release — TestFlight, or one installed from a developer — also records which screens you opened and which of a short list of features you used: saving, asking Recall, making a highlight, sharing, generating a digest, starting Listen, opening the page that describes Plus. A screen is recorded by its name in the app, a feature by the name of the action — never what you saved, searched for or wrote. That is how a test period finds the parts of the app nobody can work out. The App Store release cannot record any of it: it is left out of that build entirely, not switched off in it. The same Diagnostics switch turns it off in a test build.

It is not the same consent as the AI features. The weekly digest and Recall ask separately, because they send something entirely different — what you saved, and in Recall’s case the text of your articles. Agreeing to one has never meant agreeing to the other, and turning diagnostics on does not send a word of your library anywhere.

If you write to us

There is a "Contact us" screen in the app and on the website. What you send stays only as long as it is useful and is yours to ask about.

What we keep. The message you wrote, the address to reply to — your account's, unless you give another — and, if you left the switch on, the summary of your app's state that the screen shows you before you send. That summary is versions, counts and the names of internal checks that failed. It carries no titles, links, notes or article text.

What we do with it. It is stored so we can answer it, and a copy is emailed to the developer so somebody sees it the same day rather than the next time they look at a dashboard. Sending that email means it passes through our email provider, in the same way any reply to you would.

It is not the same as diagnostics. Diagnostics is a background trickle of timings and counts that you can switch off. This is a message you chose to write, and writing it is the agreement to send it. Turning diagnostics off does not stop you contacting us, and contacting us does not turn diagnostics on.

We do not delete it on a timer, because a bug reported six months ago is sometimes the reason a fix makes sense today. Deleting your account deletes it, with everything else.

Paying for Plus

We never see your card. A subscription bought on a phone is bought from Apple or Google, and one bought on the web goes through Stripe, which takes the payment and is the seller of record for it. They hold your payment details; we do not, and we have no way to ask for them.

RevenueCat sits between those stores and us. It records the purchase against your account and tells our server what you are entitled to. What it holds for that is your account’s identifier, the plan you bought, its dates, and — when you buy on the web — the email address you gave at checkout, so the receipt and the billing page can reach you.

What we store is the result: which plan you are on, whether it is a trial, when the period ends, where it was bought, and what each payment was worth to us. That is what decides whether a paid feature works, and what tells us whether the thing is viable. It is deleted with your account.

Managing or cancelling happens where you bought it: your Apple or Google account settings for a phone purchase, or the billing page we open for you for a web one. We cannot cancel or refund an App Store subscription on Apple’s behalf.

Retention and deletion

Delete an item and it is removed from the device, and from our servers on the next sync. Stop keeping a complete copy of a page and the archived page is deleted from our servers — the save, its readable text and your own device's copy all stay.

Delete your account, from Settings, and your authentication record is deleted, every row belonging to it is deleted with it, and your uploaded files are removed. This is immediate and cannot be undone.

Moving a shared save to the trash stops its links working at once. When the trash empties, its links, the conversation on it, and every record of it in other people's Shared with you are deleted. Deleting your account deletes the saves you shared and everything attached to them, your record of what was shared with you, and what you wrote on other people's saves.

Deleting your account does not wipe the copy on your own device — delete the app for that. Backups may retain deleted data for a short period before rotating out.

Where your data is stored

Our database, file storage and server functions run on Supabase infrastructure in the United States. Email we send — a reply to you, or a copy of your message to ourselves — goes through an email provider, which sees the address and the contents of that mail. Digest requests are processed by OpenRouter and the model provider it routes to, which may also be outside your country. Subscriptions are recorded by RevenueCat, and web payments are taken by Stripe; both are outside your country unless you live where they operate. If you are in the UK, EU or EEA, your data may therefore be transferred outside your jurisdiction.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your data, and to object to certain processing. The app gives you most of this directly: everything you have saved is visible in it, and account deletion is built in. For anything else, write to us.

Children

Reservoir is not directed at children and we do not knowingly collect data from anyone under 13, or 16 where that is the local threshold.

Changes and contact

If this policy changes materially we will say so in the app before the change takes effect. The effective date above always reflects the current version.

info@getreservoir.app