Privacy policy

We collect nothing.

Last updated 19 September 2026

Summon is made by Hein de Wilde, an independent developer in the Netherlands. This policy covers the Summon apps for Mac, iPhone and iPad, and this website. The short version: we do not collect, receive, store or sell any of your data. There is no Summon account and no Summon server. The rest of this page explains where your data does go, so you can check that for yourself.

What stays on your device

Everything you put in Summon lives in a library on your device: snippets, images, files, folders, tags, and your settings. How often you use each item, and in which app, is kept on each device separately and never synced.

Text recognition in images, reading PDFs, and suggested titles, tags and summaries all run on your device, using Apple's on-device frameworks. Nothing is sent to a server for any of it — ours or anyone else's. Items you mark sensitive are never given to the language model at all.

What syncs through your iCloud

If you use Summon on more than one device, your library syncs through your own private iCloud database, using Apple's CloudKit. It is stored in your iCloud account, counts against your iCloud storage, and is covered by Apple's privacy policy. We have no access to it.

What Apple can read depends on what you choose:

  • Items you mark sensitive are encrypted on your device before they sync, with a key that Apple never sees. Their contents cannot be read by Apple or by us. Their titles stay readable, so they remain findable by name.
  • With “Encrypt everything” turned on in Settings, every item is encrypted that way.
  • Other items sync like the rest of your iCloud data. Unless you have turned on Advanced Data Protection for iCloud, Apple holds the keys to that data.

One thing to know: marking an item sensitive protects it from then on, but cannot recall a plain copy that already synced before you did. Summon tells you this when you seal an item that has synced.

Your vault key travels between your devices in iCloud Keychain, which Apple encrypts end to end. Your PIN and your unlock attempts never leave the device they were entered on.

Permissions the app asks for

  • Accessibility (Mac) — so Summon can paste the item you choose into the app you were using. It sends a single ⌘V keystroke to that app. It does not read your screen, watch your typing, or record anything.
  • Face ID / Touch ID — to unlock sensitive items. Handled entirely by Apple; Summon never sees your biometric data.
  • Pasteboard (iPhone and iPad) — only when you ask Summon to save what you just copied.

No tracking, no analytics, no third parties

The apps contain no analytics, advertising or crash-reporting SDKs, and make no network requests of their own. Sync is performed by the operating system. If you choose to share crash reports with developers in your device's settings, Apple may pass anonymous crash logs on to us; you can turn that off at any time.

This website

This site uses no cookies, no analytics and no tracking scripts, and loads no fonts or scripts from third parties. It is hosted by Vercel, whose servers, like any web server, briefly log technical data such as IP addresses to deliver the site and protect it from abuse. We do not use those logs to identify or profile anyone.

Children

Summon is not directed at children and collects no data from anyone, of any age.

Your rights

Because we hold no personal data about you, there is nothing for us to access, export or delete. Your library is yours: delete an item and it is deleted from your devices and your iCloud. To remove everything, delete the app and, in iCloud settings, delete Summon's data. If you are in the EU, you also have the right to complain to your data protection authority — in the Netherlands, the Autoriteit Persoonsgegevens.

Changes and contact

If this policy changes, the new version will be posted here with a new date. Questions are welcome at info@heindewilde.com.