Scholardo is the agent-native research workspace for macOS, built local-first. This policy explains how we handle your data. The principle is simple: your library stays on your own machine — we do not collect it, upload it, or analyze it.
1. Your data is stored locally
Everything you create in Scholardo — your library, PDFs / EPUBs / web pages, annotations and highlights, notes, session transcripts, citation data, and the vector index — is kept only on your Mac's local disk. By default it lives under ~/.scholardo/ in your home directory and inside each of your own project folders, stored in a local SQLite (GRDB) database and ordinary files.
This data is never uploaded to our servers and never synced to any cloud. We cannot see or access your research. Backup, migration, and deletion are entirely under your control.
2. Zero telemetry
The Scholardo app contains no telemetry, usage analytics, behavioral tracking, or crash reporting. Local use requires no account and no sign-in. We do not track which files you open, which features you use, or how long you stay.
3. API keys are yours, encrypted locally
Scholardo's AI features (selection rewriting, feed digests, embedding search, and so on) are powered by AI provider API keys that you supply yourself — OpenAI, Anthropic, Google Gemini, DeepSeek, or any OpenAI-compatible endpoint. Core features (search, annotations, citations, browser capture) run locally and need no key at all.
Encrypted locally: any API key you enter is stored in the macOS Keychain, protected by the operating system's encryption — never written in plaintext to ordinary config files.
Never sent to us: your API keys are never transmitted to any Scholardo server.
Requests go straight to the provider: when you use an AI feature, the request goes directly from your Mac to the model provider you configured. Scholardo is not a proxy and does not intercept, route, or log the contents of those requests. The data exchanged is governed by that provider's own privacy policy and terms.
4. Network calls we make
These are the first-party network calls Scholardo makes to our servers. Each one is listed in full, including what it sends:
License activation: sends your activation code, the email address you bought with, an anonymous device fingerprint (a hash — never your hardware serial), and a generic device label ("Mac", never your computer's name). The email is required because the server checks it against the purchase before issuing a licence.
License refresh: sends the activation code and the same device fingerprint, periodically, so a licence keeps working without you re-entering anything.
Free trial: sends only the anonymous device fingerprint, so a trial can be granted once per machine. To stop anyone rotating fingerprints to renew a trial indefinitely, the server also records a one-way hash of your IP address, an approximate country, and when you were last seen. These exist only to spot repeated registrations. They are not used to track what you do, and are not linked to your identity or to any of your research.
Deactivating a device: when you release this Mac's seat from the About window, sends the activation code and the device fingerprint.
Contact form: only when you choose to fill in and submit the "Contact us" form on our website does its content reach our endpoint, solely so we can reply (see Section 6).
Rate limiting: to keep these endpoints from being abused, the requests above are rate-limited by source IP, for which the server stores your IP address and a short-window request count. That record is used only for rate limiting and is not linked to your licence, your trial record or any identity.
No local research data is attached to any of these.
Purchases are handled by a merchant of record; we never see your card details. In most countries the sale is completed by Sold through Link, LLC (Stripe's merchant of record programme); in mainland China it is completed by Armitage Labs OÜ (Estonia, registry code 16977866), trading as Creem. Which one applies is set out in Section 3 of the Terms. Card details are entered on that merchant's own checkout pages and never reach Scholardo's servers; the billing and tax details you provide at checkout are handled by that merchant as a data controller under its own privacy policy. To fulfil an order and support it afterwards, we receive from it the email address you bought with, the plan, the amount and currency, the order and subscription identifiers, and the status of any renewal, refund or chargeback. We keep this purchase record for as long as the licence exists and for as long as tax and accounting law requires.
We have a written arrangement with each merchant of record covering our respective data-protection roles in the payment flow. For how it handles your personal data, see the Link or Creem privacy policy — or email us and we will help you reach the right party.
5. Third-party services you opt into
Some features connect to third parties only when you trigger them. Whether to use them is your choice, and the data exchanged is governed by each provider's own policy:
AI / embedding providers: using your own key, with requests going directly (see Section 3). Self-hosted options such as local Ollama stay entirely on your machine.
Web capture: when you open or save a page in the built-in browser or capture tools, a request is made to that URL.
RSS feeds: when you configure a feed, its source is fetched.
Citation styles: CSL styles may be downloaded on demand from a public style repository.
Hypothesis sync: if you enable it, Scholardo communicates with the Hypothesis service.
6. This website
For the marketing website (scholardo.com) itself:
Only essential local storage: it remembers your theme (light / dark) and language preference in your browser's localStorage.
No cookies, no cross-site tracking: this site uses Cloudflare Web Analytics to count page views. It sets no cookie, reads no local storage, and does not fingerprint your browser, and it cannot recognise you across sites; each visit sends a single page record (the page address, the referring page, an approximate location, and a device/browser type), which Cloudflare aggregates and reports without retaining your IP address. All we see are totals, which cannot be traced back to an individual. Nothing else is loaded — no advertising, no behavioural analytics. If a tool that does require consent is ever added, it will load only after you explicitly consent.
Version check: the page makes one anonymous request to the public GitHub Releases API to show the latest version and download link.
Contact form: anything you submit is sent to our endpoint (api.scholardo.com/contact) solely to forward it to us by email so we can reply; it is not otherwise stored.
Web fonts: typefaces are served from this site. They are no longer requested from Google Fonts, or from any third party. Icons and every other asset are served from here too — loading a page talks to this site and nothing else.
Anti-spam on the contact form only: opening the enquiry form loads Cloudflare Turnstile (challenges.cloudflare.com) to check you are not a bot. It runs only when you open that form, never on page load, and Cloudflare states it does not use it to track people across sites.
Checkout: the pricing buttons go through this site's /go/checkout, which reads the country code Cloudflare derives from your IP and sends you to the checkout page hosted by the merchant of record for that country. That country code is used for the redirect and is neither logged nor stored. Nothing about payment happens on this site, and no payment script is loaded here.
7. Retention & deletion
Because your research data never leaves your device, deletion is entirely in your hands: removing a project folder or ~/.scholardo/, or uninstalling the app, removes that data. We hold no copy of your research to retain or delete. Our license records contain only the minimum needed to validate your entitlement.
8. Children
Scholardo is a professional tool for researchers. It is not directed to children under 13 (or the equivalent age in your jurisdiction), and we do not knowingly collect their personal information.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page; continued use means you accept the updated terms.