Overio
Privacy Policy
This privacy policy explains how we collect, use, store, and protect data in the Bullet macOS and iOS apps. Please read it carefully before using the App.
1. Information We Collect
- Local App data for core features:
- bullet text, notes, hierarchy, order, collapsed state, selection state, pins, and other outline data
- version snapshots, event history, deletion markers, sync metadata, and conflict records
- App preferences such as view state, editor state, selected settings pane, sync state, and other local settings
- macOS AI and chat data:
- chat conversations, user messages, assistant responses, patch proposals, accepted or rejected edits, pinned branch references, and provider thread identifiers
- selected AI provider, selected model, reasoning effort, and related chat settings
- DeepSeek API keys you enter, stored locally in the macOS Keychain
- local Codex or Claude CLI readiness information where Bullet checks for those tools on your Mac
- iOS App data:
- mobile editor state, selected branch state, inline editing state, local outline changes, and sync status
- iOS does not provide the macOS AI chat, MCP, or API-key features unless they are added in a future version
- iCloud and CloudKit data:
- If iCloud sync is enabled and available, Bullet syncs workspace records through Apple's CloudKit private database associated with your Apple account.
- Synced records may include workspace metadata, branches, version snapshots, events, conversations, and conversation messages.
- AI provider request data on macOS:
- When you send a chat message or ask an AI provider to work with your outline, Bullet may send your message, relevant conversation context, selected outline context, tool results, and model settings to the selected AI provider or local CLI.
- App analytics data:
- Bullet may collect limited, product-level analytics events to understand whether the App opens, syncs, edits, navigates, and uses selected features.
- Analytics events may include anonymous install or app instance identifiers, app version, build number, platform, session metadata, event names, feature areas, sync result counts, navigation depth, editor focus category, AI provider or model category on macOS, and whether an AI patch proposal was accepted or rejected.
- Analytics events do not include bullet text, note text, document content, prompts, AI responses, API keys, file paths, Apple account identifiers, email addresses, or raw error content.
2. How We Use Data
We use the collected information only for:
- providing the macOS and iOS outline editor, hierarchy, notes, selection, pins, version history, and restore workflows
- saving and restoring your local workspace
- syncing your workspace across supported Apple devices through iCloud when enabled and available
- providing macOS chat, AI-assisted editing, patch previews, and accept or reject workflows
- storing macOS API keys and provider settings needed to connect to selected AI services
- registering Bullet as an MCP server with supported local AI clients on macOS where the App provides that feature
- improving stability and user experience through local product development, testing, and limited product analytics
We do not perform ad personalization or ad tracking. We do not sell or rent your personal information.
3. Data Storage and Protection
- Bullet stores App data locally on your Mac, iPhone, or iPad using Apple platform storage mechanisms, including SwiftData, Application Support data, UserDefaults, and platform security controls.
- On macOS, DeepSeek API keys are stored in the macOS Keychain. Bullet does not store Codex or Claude subscription credentials itself; those are managed by the respective CLI tools.
- If iCloud sync is enabled and available, workspace data is uploaded to and downloaded from Apple's CloudKit private database for your Apple account.
- On macOS, Bullet may create or update local MCP client configuration entries for supported local clients such as Codex CLI, Claude Desktop, or Claude Code, where supported by the App.
- On macOS, Bullet may send limited analytics events to Google Analytics 4 using Google's Measurement Protocol.
- On iOS, Bullet may send limited analytics events to Google Analytics 4 through Firebase Analytics where analytics is enabled.
- Local data is protected by device, operating system, Apple account, Keychain, and App storage mechanisms. Anyone with access to your unlocked device, user account, backups, or synced iCloud account may be able to access App data through normal system mechanisms.
- We use reasonable technical and organizational measures to protect information we control, but no storage or transmission method is completely secure.
4. Your Rights and Choices
- You may stop using the App and delete local App data by deleting the App and removing its local data, subject to Apple platform backup and restore behavior.
- You may manage or disable iCloud sync in Bullet where available, in Apple device iCloud settings, or by signing out of iCloud.
- You may delete synced Bullet data from iCloud through Apple account and iCloud data management tools where available.
- On macOS, you may choose which AI provider to use, change models, remove API keys, or stop using AI chat features.
- Where analytics controls are available in the App, you may disable product analytics. Some pre-release, internal, or debug builds may use separate build-time analytics settings for testing.
- On macOS, you may revoke folder access granted to Bullet through system privacy and file permission settings.
- If you revoke permissions or remove credentials, related features may stop working or become limited, but the App will continue to provide features that do not require those permissions where possible.
5. iCloud and CloudKit Sync
5.1 Data Collection Scope
When iCloud sync is enabled and available, Bullet syncs workspace records through Apple's CloudKit private database. Synced data may include:
- workspace metadata
- bullet branches, text, notes, order, parent-child relationships, collapse state, timestamps, and deletion markers
- version snapshots and event records
- conversations, messages, pinned branch references, provider thread identifiers, and related metadata
5.2 Purpose of Use
CloudKit data is used solely for:
- restoring your workspace on the same or another device signed into the same Apple account
- keeping edits and conversations in sync across supported Apple platforms
- supporting manual restore and conflict handling features
5.3 Apple Services
CloudKit is provided by Apple and governed by Apple's terms and privacy policies. Bullet does not control Apple's iCloud account infrastructure, authentication, storage, retention, or security systems.
6. macOS AI Providers and MCP Integrations
- Bullet for macOS can send your prompts, selected outline context, tool results, conversation history, and related metadata to the AI provider you choose.
- If you use DeepSeek API key mode, requests are sent to DeepSeek using the API key you store in Keychain.
- If you use Codex subscription mode, Bullet may launch the Codex CLI. Codex manages its own authentication, network access, session files, and provider-side processing.
- If you use Claude subscription mode, Bullet may launch Claude Code. Claude Code manages its own authentication, network access, session files, and provider-side processing.
- If you configure Bullet as an MCP server in external clients, those clients may request data from your active Bullet workspace or ask Bullet to apply edits according to the MCP tools available.
- Third-party AI providers and local AI clients have their own terms, privacy policies, security practices, and data retention rules. You should review them before using those integrations.
7. Third-Party Services
- The App may rely on Apple system frameworks and services, including macOS, iOS, iPadOS, iCloud, CloudKit, Keychain, UserDefaults, SwiftData, push notifications for CloudKit changes, and App Store distribution.
- On macOS, the App may integrate with or launch third-party tools and services, including Codex CLI, Claude Code, Claude Desktop, DeepSeek, and supported MCP clients.
- For product analytics, the App may use Google Analytics 4 and, on iOS, Firebase Analytics. These analytics services are used for product measurement, not advertising personalization.
- These services are governed by their respective terms and privacy policies.
- The current version does not use third-party advertising SDKs and does not perform ad tracking.
8. Children's Privacy
- Bullet is a productivity and AI workspace tool and is not specifically directed to children.
- Minors should use the App under the supervision of their legal guardians.
- Guardians may manage device permissions, delete the App, remove synced data where available, or contact us with privacy-related questions.
9. Data Retention
- Local workspace, conversation, preference, and provider setting data remains on your device until deleted, reset, replaced by App rules, removed by the operating system, or removed when you delete the App and its local data.
- macOS Keychain items remain in the Keychain until removed by you, the App, or the system.
- iCloud data remains in CloudKit according to Apple's account, iCloud, backup, deletion, and retention behavior, unless removed through App features or Apple account tools where available.
- AI providers may retain request data according to their own policies.
- Google Analytics 4 and Firebase Analytics may retain analytics events according to Google's service settings and policies.
10. International Use
If you use the App outside the jurisdiction where Overio operates, you understand that Apple platform services, AI providers, device settings, and applicable privacy rights may vary by region. We will handle privacy requests according to applicable law.
11. Changes to This Policy
We may update this privacy policy from time to time. Significant changes may be announced via in-App notices or release notes. Continued use of the App after an update indicates your acceptance of the updated policy.
12. Contact
If you have any privacy-related questions, please contact us:
Email: over.io@icloud.com
Last Updated: June 15, 2026
Any significant changes to this privacy policy will be announced via in-App notifications or release notes. Continued use of the App indicates your acceptance of the updated policy.