$ROTLI — Room to think. Coins you keep. ↓ CA

Updated September 23, 2026

Privacy

rotli is built so there is nothing about you to collect. This page explains exactly what it does with your data, what connects to the internet, and why it works that way.

Secure notes stay home. A model on your own Mac may read them. Remote models, the clouds outside, never see them, and no model can edit a note you lock.

The short version

  • No account. There is nothing to sign up for, and no rotli server that holds your notes.
  • No tracking. No product analytics, no advertising, and no automatic crash reports.
  • Your notes are files. They live in one folder you choose, on your computer, as plain Markdown.
  • AI is optional and yours to limit. You choose where it runs and, note by note, what it may read or change.
  • Nothing leaves without a reason you can see. Updates, a chat you start, or a web search you ask for.

Your notes stay yours

rotli reads and writes the folder you pick: notes, chats, attachments, and anything else you keep there. Its own settings and search indexes live in a hidden .rotli folder inside it, or in the app's settings on your Mac, and it can rebuild them at any time. Main and named views are arrangements of the same files, not copies. Passwords and keys you give rotli go into the macOS Keychain, never into your notes or settings files.

Why: a notes app should never be the only way to reach your notes. Because everything is an ordinary file, you can open it in another app, back it up however you already back things up, or delete rotli and keep every word. There is no copy on a server for anyone to lose, leak, or lock you out of.

What connects to the internet, and when

rotli has no analytics or account server to talk to. It goes online only for things you can see:

  • Updates. The Mac app checks rotli's release page on GitHub for a new version shortly after it opens, a few times a day, and when you press Check for updates. The request carries no account, vault, or note data. Nothing downloads until you choose Install, and Settings → General turns the automatic check off.
  • A chat you start with connected AI. rotli runs the Claude Code, Codex, or Cursor app you already have signed in on your Mac. That app sends the conversation and the context it needs to its provider, under that provider's terms. rotli never sees or stores your provider login.
  • A web search or page you ask for. Only the query or address needed for that request is sent.

Features still in development, such as scheduled briefs and remote agents, are switched off in released builds. When one ships, this page will say what it connects to before it does.

Why: every connection is a place your data could go, so rotli keeps the list short and tied to something you did. Adding a new destination, telemetry, or an account service is a deliberate, reviewed change, not something that slips in with an update.

AI and your notes

AI in rotli is a visitor, not the owner of your workspace. You can leave it off entirely. If you use it, an on-device model runs on your Mac and works without a network. Connected AImeans the tools you already use, like Claude Code or Codex, and rotli labels them as remote.

What each kind of AI may do with a note
NoteOn-device modelConnected AI
Everyday noteThe defaultReads and editsReads and edits
Secure noteRight-click → Mark secureReads and editsNever sees it
Locked noteRight-click → LockReads onlyReads only

Secure notes are never sent to a remote model, not even their titles, and the Librarian leaves them alone. An on-device model reads them by default, since it cannot send anything anywhere; you can turn that off for one note from its menu, or for the whole vault in Settings → Security. Nothing turns it on for a remote model.

Locked notes can be read by any model, and edited by none. Locking protects the words; it doesn't hide them.

Secure is an AI access rule, not encryption. A secure note is still a plain file on your disk, protected the way your other files are, by your Mac account and FileVault. Boards don't have a secure setting yet, so keep secrets out of them.

Why: AI is useful with context and risky with the wrong context. Deciding per note means you can let a model help with your plans without ever handing it your salary review. The rule is enforced in the app itself before anything reaches a model, not left to the model to respect.

How rotli connects to AI tools

Connected AI works through the command-line tools the AI companies publish: Claude Code from Anthropic, Codex from OpenAI, and Cursor's agent. You install one in Terminal and sign in to it yourself, the way its maker describes. rotli then runs that tool on your Mac and passes it your message, just as you could from Terminal.

rotli never signs in on your behalf, never reads the tool's login files, and never stores its credentials. There is no rotli server in between and no shared account. The tool's own company handles the request under its own terms. On-device models skip all of this: they run on your Mac and need no network.

Why: using each company's own published tool keeps your plan working the way it was sold to you, and keeps rotli out of the middle. rotli can switch between tools without ever holding a key to any of them. The install commands are on the Features page.

Rotli Web and Rotli Helper

Rotli Web, at rotli.fun/app, keeps every note as a file in a folder on your computer. In Chrome, Edge, or Arc it writes to that folder directly. In Firefox, Zen, or Brave, Rotli Helper, a small program you install yourself, reads and writes the one folder you pick with your computer's own folder picker. It listens only on your own computer, starts when you log in, and removes itself with its installer's uninstall option. Safari and phones aren't supported yet: they can't reach a folder on your computer.

The page's security policy lets it load only its own files and connect to nothing but Rotli Helper on your computer. Pairing uses a code in the part of the address browsers never send to a server. Unsaved typing is held briefly in your browser so a refresh can't lose it, then written to your folder and cleared. The one way out is a chat you start: the Helper runs your own AI tool, which contacts its provider, and secure notes are refused before it runs.

Why: a web app usually means your notes live on someone's server. Rotli Web is built the other way around: the page is just the editor, and your folder stays on your computer.

This website

rotli.fun sets no cookies and runs no analytics, ads, or third-party scripts. Fonts, images, and the film are served from this site. Two badges in the footer, from Launch Llama and Founder.best, are images loaded from their own servers, so those services see a request from your browser when a page shows them. Our hosting and DNS providers, Railway and Cloudflare, process standard request details such as your IP address to deliver pages.

Why: a site about keeping your work private shouldn't watch you read it.

Keeping and deleting

There is no rotli server holding your notes, so there is nothing for us to keep or delete. You decide how long your files exist and where they are backed up. Services you deliberately send something to, like an AI provider or a website you search, keep it under their own policies.

Changes to this page

This page describes rotli as it works today. It changes whenever a kind of data, a destination, a retention rule, or a control changes, and the product's own record of it is PRIVACY.md in the source code, with its full history. It is a plain description of how the software works, not legal advice.