Privacy Policy

Last updated: September 3, 2026

1. Information We Collect

Content You Provide

When you use Sensefold, you may save links and article text, AI conversations you capture (ChatGPT, Claude, Gemini, Grok), social threads and their comments, YouTube pages and available transcripts, PDFs, images, screenshots, Office documents, highlights and comments, and notes you write. We store this content on your behalf to provide the Sensefold service, including AI enrichment (summaries, tags, and content extraction) of the items you capture.

Account Information

We use Clerk for authentication. When you sign up, Clerk collects your email address and authentication credentials. We receive a user identifier from Clerk but do not store your password.

Billing Information

Web subscriptions and credit packs are paid through Stripe, which collects your payment method and billing details under its own privacy policy. Sensefold never receives or stores card numbers; we keep a Stripe customer identifier, your subscription status, invoices, and a ledger of the AI credits you have received and spent. App Store purchases are handled by Apple; we receive the purchase and subscription status needed to activate your subscription.

Usage Analytics

We use PostHog to understand how the public website and product are used. Browser requests go through our first-party analytics host. PostHog assigns a pseudonymous analytics identifier; the public website does not send email addresses, saved content, page titles, or full URLs in custom analytics events.

Outside the EU/EEA, United Kingdom, and Switzerland, first-party analytics cookies are used by default. Visitors in those regions are asked before analytics cookies are stored. If they decline, PostHog runs without cookies or browser storage and counts visits with a privacy-preserving hash that changes daily. During a four-week transition, we also operate cookieless Plausible Community Edition on OVHcloud infrastructure.

Session replay is disabled on this marketing website. It is used only in the signed-in web app to diagnose product usability, with input values and user content masked. We do not use analytics for advertising, retargeting, or cross-site profiling.

Sensefold for Chrome

On your first page-access action — choosing Capture, or turning on the highlighter — the extension shows a disclosure and Chrome asks for optional permission to access pages on all websites, remembered until you revoke it in Chrome's extension settings. Only after you choose Capture does Sensefold for Chrome read the active page's URL, title, domain, readable content, and an available thumbnail. On supported YouTube pages, it may also read transcript content that the page makes available. Depending on the page you choose, readable content can include social posts and comments or AI conversation history.

While the side panel is open — and only after you have accepted the extension's page-access disclosure — the extension sends the current page's address to Sensefold to show whether that page is already in your library.

The extension also includes a highlighter you can turn on per site. On the exact sites you enable, the extension runs when those pages load: it sends the page's address to Sensefold to check whether the page is already in your library, and reads the page's text locally in your browser to restore your saved highlights and quoted comments. Highlights, quoted comments, page comments, and video timestamp comments you create are saved to your Sensefold account; drafts are staged in local extension storage until they upload. You can disable the highlighter for any site at any time, which stops it from running there. Outside Capture and the sites you enable the highlighter on, the extension does not read page content.

When you click a video chapter or timestamp in the side panel, the extension runs a packaged command in that tab only to seek or pause the page's player; no page content is read.

Sensefold for Chrome temporarily stores recent page captures, note and highlight drafts, reading-size settings, the sites you enabled the highlighter on, and the page-access disclosure acknowledgement in Chrome's local extension storage. Capture and highlight drafts are separated by Sensefold user ID. Captured page data is sent to Sensefold over HTTPS to create a preview, summary, and suggested tags and, when you choose Save, to store the item in your Sensefold account. A note title and body remain a local draft until you choose Save, when they are sent to Sensefold; later saves update that authored note.

Authentication is provided by Clerk. The extension reads the Sensefold authentication session cookie only from Sensefold's Clerk host and does not read cookies from unrelated websites.

Sensefold for iOS and Mac

The iOS and Mac apps send the content you choose to save to Sensefold over HTTPS and keep your library in sync with your account. The iOS app receives silent background push notifications through Apple Push Notification service so it can refresh; those pushes carry sync signals, not your saved content.

2. How We Use Your Data

Your content is processed to provide the following features:

  • AI Enrichment: Items you capture are processed by AI services to generate summaries, tags, extracted text, OCR for images and PDFs, and chapter guides for videos. Notes you write are indexed for search but are not rewritten by Sensefold's automatic AI; only agents you authorize can edit them, and every edit is versioned.
  • Agent access (MCP): When you connect an AI client with an Agent key or OAuth authorization, it can search, read, and — depending on the permission tier you choose — write items in your library at your direction. Every connection is revocable. See Connected AI Clients below.
  • Search: Your content is indexed to enable full-text and semantic search.
  • Export: You can export your whole library as a Markdown ZIP from the web app, or copy individual items as Markdown, at your direction.

Connected AI Clients (MCP)

When you connect ChatGPT, Claude, Claude Code, Codex, Cursor, or any other MCP client to the Sensefold MCP server at api.sensefold.app/mcp, the content those tools request — search results, item text, and notes — is transmitted to that client and processed by its provider under that provider's own terms. These clients are not Sensefold subprocessors; you choose which client to connect and what to ask it. You also choose the permission tier (read-only, edit, or full). Edits made by an agent are recorded in the item's Activity history and can be reverted, and you can revoke any Agent key or OAuth grant at any time under For agents in the web app settings. The MCP server runs on Cloudflare Workers alongside the rest of the Sensefold API.

3. AI Data Processing

We use the following AI services to process your content:

  • Google Cloud (Vertex AI / Gemini): Summaries, tags, search embeddings, result ranking, image understanding (OCR and visual descriptions), and processing of YouTube links.
  • LlamaParse (LlamaIndex): Text extraction from PDFs and documents you upload.

Web page content extraction runs on our own infrastructure. When you save a link, the page is fetched and rendered through Cloudflare infrastructure we operate; the page content is not sent to a third-party extraction service.

Your content is sent to these services over encrypted connections for processing. Each acts as our data processor and is contractually prohibited from using your content to train its models. AI processing requires your explicit consent, which you can grant or revoke at any time in Settings. See our Subprocessors page for the full list of third parties that process data on our behalf.

4. Chrome Web Store Limited Use

Sensefold's use of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use and transfer that information only to provide or improve the user-facing capture, enrichment, organization, storage, search, and export features described in this policy; to comply with applicable law; for security and abuse prevention; or as part of a merger, acquisition, or sale of assets after obtaining any consent required by policy.

We do not use or transfer captured content, browsing activity, authentication information, authored notes, or other user data for personalized advertising, retargeting, creditworthiness, or sale to data brokers. Humans do not read this data except with your specific consent for support, when necessary for security, to comply with law, or after the data has been aggregated and anonymized for internal operations.

5. Cross-Border Data Transfer

Your data is processed and stored using the following infrastructure:

  • Cloudflare (Workers, Queues, R2, Browser Rendering; global edge network, primarily United States): API server at api.sensefold.app (including the browser-extension API and the MCP server), background processing, file storage (R2), fetching and rendering of web pages you save, and hosting of this website and the web app.
  • Fly.io (United States): An isolated extraction container (lexi-tools) that extracts content from files and non-webpage links you save.
  • Neon (cloud PostgreSQL): Primary PostgreSQL database storage.
  • Stripe, Inc. (United States): Web subscription and credit-pack payments, invoices, and the billing portal. Sensefold never receives or stores card numbers.
  • Apple Inc. (United States): App Store purchases and subscription management for the iOS app, and Apple Push Notification service for silent background sync pushes to the iOS app.
  • PostHog, Inc. (United States): Product and website analytics. Session replay is used only in the signed-in web app, with input values and user content masked.
  • OVHcloud (Oregon, United States): Cookieless website analytics on an Oregon, United States VPS during the scheduled decommission of Plausible.

By using Sensefold, you consent to the transfer and processing of your data in these locations.

6. Data Retention & Deletion

Your content is stored as long as your account is active. You can delete individual items at any time. When you delete your account, all your data is permanently removed within 30 days. Analytics records linked to your Sensefold account, including its pseudonymous analytics identifier, are also scheduled for deletion with the account.

Transient AI processing caches live only in the memory of the instance handling the request and are discarded within 24 hours; they are not written to persistent storage.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Withdraw consent for AI processing
  • Export your data
  • Object to processing

We aim to comply with GDPR (EU), CCPA (California), and PIPL (China) requirements. To exercise your rights, contact us at hello@sensefold.app.

8. Cookies

Sensefold uses essential cookies for authentication and first-party cookies for analytics as described above. In the EU/EEA, United Kingdom, and Switzerland, analytics cookies are set only after you accept them; declining keeps PostHog in cookieless mode. Your consent choice is remembered for 180 days and is not itself used for tracking. We do not use advertising cookies or create cross-site profiles. Plausible operates without cookies while it remains in parallel operation.

9. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via the app or email. Continued use of Sensefold after changes constitutes acceptance.

10. Contact

For privacy-related questions, contact us at hello@sensefold.app.