Bifolium

Privacy Policy

What Bifolium keeps on your device, what it sends to other services, and the choices you have.

Effective

Who we are

Bifolium is a Markdown and plain-text reader for iPhone, iPad, and Mac, provided by Fernando Flores, based in the United States. In this policy, “we” and “us” mean the provider of Bifolium. This policy covers the app, this website, and messages you send us.

You do not need a Bifolium account. Reading, document rendering, search, and matching related documents and passages run on your device. We do not operate a server that receives your documents for those tasks, and we do not use your documents to train a model.

Some features contact other services. Apple handles purchases and private iCloud sync. GitHub supplies repository snapshots. Images and web links connect to their hosts when you load them. Optional usage and diagnostics sharing sends limited events to TelemetryDeck. These flows are described below.

We do not sell personal information, serve advertisements in Bifolium, or use app events to track you across other companies’ apps and websites.

Files and data on your device

Bifolium opens files you select and keeps their original format. Reading, highlighting, and taking notes do not change the original file. Editing an existing writable Markdown file is a separate action that saves changes back to that file.

The app stores information locally to support reading:

  • Document names and locations, file-access permissions, recent and pinned documents, reading positions, and preferences.
  • Highlights, quoted passages, attached notes, and information used to find their position in a document.
  • A search index that can include document text, headings, and on-device mathematical representations used to match related passages.
  • Downloaded GitHub snapshots, Synced Paper editions, retained shared documents, and editing recovery drafts and history.
  • Themes and, on iPhone and iPad, reference-browser tabs, saved pages, and website data.

Opening a document can add it to the local search index. A containing-folder grant can also let Bifolium read supported files and resources in that folder. The index is separate from your original files. Notes are not used for search embeddings or related-passage matching.

Sharing a file into Bifolium can create a retained reading copy in storage shared by the app and its Share extension. It stays separate from the original. The app asks you to save or discard a retained copy when its storage limit is reached; it does not silently evict an older shared document to accept a new one.

Files stored in iCloud Drive, Dropbox, or another file provider remain subject to that provider’s own syncing and privacy practices. Opening a file in place does not prevent its provider from downloading it or syncing an edit.

Your private iCloud

Documents, annotations, and reading position

When you use Make Available on My Devices on a Mac, Bifolium uploads copies of the selected documents and supported companion resources to your private iCloud storage. A selected folder can include future supported files unless you exclude them. Your Mac originals remain in place. Your iPhone or iPad downloads verified editions for offline reading.

For Synced Papers, private CloudKit records also carry highlights and notes, quoted text and surrounding text needed to locate a highlight, document identifiers, changes and deletions, and reading positions. Reading-position anchors can include heading and nearby text. Synced Paper annotations sync automatically after account verification, subject to app access. Annotations on ordinary local files and GitHub sources stay on that device; this is not a general sync of every annotation you make.

Shared source setup

Share Source Setup exchanges public GitHub source definitions, including repository identifiers, selected branches or other references, paths and update preferences, and Synced Paper discovery details and reading positions through private CloudKit. These source-setup records do not contain downloaded repository contents. Sync records use identifiers and timestamps, including an installation identifier, to coordinate changes between your devices. GitHub credentials and private-repository source definitions are excluded.

Share Source Setup is enabled by default when the relevant iCloud and app-access conditions are met. You can turn it off in Settings. This stops that device’s source-catalog exchange; it does not erase records already in iCloud, stop every other iCloud feature, or delete your documents.

Trial dates

When iCloud is available, Bifolium automatically reconciles your trial’s start date and latest observed date through a separate private CloudKit record. This keeps the same trial timing across your devices. The record contains those dates and a format version, not document content, GitHub credentials, or purchase details.

Trial-date sync is independent of Share Source Setup and document sync. There is no separate in-app switch for it. A local trial can start without iCloud. The device also keeps a local trial marker and a local binding to the iCloud account so an account change does not transfer another account’s trial history.

Apple operates these services under its Privacy Policy. Using private iCloud storage does not mean that every field has end-to-end encryption. We do not receive a copy of your private iCloud document collection on a Bifolium server.

GitHub sources

Adding or refreshing a source requests repository information and selected files directly from GitHub. Keep up to date can also check for changes while the app or source is in use. It is optional; manual refresh remains available. Bifolium does not run a scheduled GitHub refresh while the app is closed.

GitHub receives the repository, branch or commit, requested paths, and ordinary connection information such as your IP address and request headers. The app saves source metadata and downloaded snapshots on your device. A private repository’s downloaded content is a real local copy, not just a link.

Public sources do not require a GitHub account. For private sources, you connect a GitHub account and authorize repository access with GitHub. Bifolium keeps the account identity and access and refresh credentials in this device’s Keychain. Credentials do not sync through iCloud Keychain or Share Source Setup. Repository requests send an access token only to GitHub’s API and raw-content hosts for sources bound to that account; sign-in and token refresh also contact GitHub.

Disconnect removes the app’s stored credential on this device. You can keep private offline copies without further updates or remove them; the app presents Keep offline copies first. Removing private copies does not remove their highlights and notes, which have separate deletion controls. Disconnect does not revoke the GitHub App authorization at GitHub or erase copies on another device. Use your GitHub settings if you also want to revoke that authorization.

Bifolium does not push changes to GitHub. GitHub handles its part of these requests under its Privacy Statement.

Images, links, and browsing

Remote images

The reader asks before loading remote HTTPS images unless your saved settings already allow them. You can allow or block remote images in Settings. Fetching missing images for an export requires a separate choice.

An image host receives your IP address, the requested image URL including any query parameters, and technical request headers. A URL can itself contain identifying information, and a uniquely addressed image can reveal that a document was opened. Bifolium does not act as an anonymity proxy. The reader’s image loader does not attach browser cookies or a referring-page header. These restrictions apply to document images, not to websites opened in a browser.

Links and the reference browser

On iPhone and iPad, supported HTTPS links open in the app’s separate reference browser. On Mac, external links open through the system in another app, such as your web browser. A website and any services it loads can receive your IP address, requested URLs, browser information, cookies, and anything you enter or submit. Their privacy policies apply.

The iPhone and iPad reference browser retains cookies, sign-ins, and other website data between visits and app restarts in a store separate from Safari. It is not a private-browsing mode. Bifolium also saves tab URLs and titles. Websites do not receive access to the reader’s document storage or file permissions through the reference browser.

You can save an offline copy of a page already loaded in the reference browser. Optional automatic capture is off by default. Saved copies are held locally, can contain information from signed-in pages, and open in a separate viewer designed to prevent network requests. Closing a tab also removes its saved offline copy. Saving a page does not erase the requests made while loading the live page.

Optional content blocker

If you choose to install uBlock Origin Lite, Bifolium downloads the selected extension release from GitHub after confirmation. It does not silently replace an installed extension with a newer release. When enabled, the extension can read and change pages and filter requests in the reference browser, and keep its settings locally. It cannot read your Bifolium documents. You can disable or remove it in Settings. Its optional problem-reporting flow can include the page address you choose to report.

Optional usage and diagnostics

Usage & Diagnostics is off by default. You can enable it during first-use setup or in Settings, and turn it off at any time, including when retrieving your data after access ends. Your choice applies to this device and does not affect app access.

When enabled, Bifolium sends limited feature-use events, coarse performance measurements, and error categories to TelemetryDeck to help us improve the app. Events include the app version and build, operating-system version, a broad device category, and day or month of use. A temporary session identifier groups events within the running app. We do not send a user identifier or persistent device identifier in these events.

These events exclude document content, notes, highlights, selections, search queries, filenames, paths, website and repository addresses, account details, purchase or trial information, and raw error reports.

The app keeps up to 1,000 unsent events in private storage and removes events older than seven days when it maintains the queue. This queue is excluded from backups. Turning sharing off stops new collection and clears pending events. A request already sent may finish. Turning sharing off does not delete events TelemetryDeck has already received.

TelemetryDeck receives the network connection used to deliver events, including the source IP address. Its Privacy FAQ states that it does not store IP addresses. Its retention explanation distinguishes the period during which events can be queried from their deletion: older events may remain in cold storage. We do not promise a fixed deletion period for those events or complete anonymity.

Purchases and reminders

Apple processes App Store purchases. Bifolium uses Apple’s StoreKit transaction and subscription status to provide access, check renewals, and restore purchases. The app keeps the purchase-status information needed to work offline. It does not send receipts to a Bifolium validation server, and we do not receive your full payment-card details.

The payment-free trial is separate from a subscription. Its dates remain in local app storage, the device Keychain, and, when available, the private iCloud record described above. These records help preserve trial timing after a reinstall or when moving between devices.

If you choose trial reminders, the app asks for notification permission and schedules local reminders before the trial ends. They contain a trial end date, not a document title or contents. You can manage notification permission in system settings. Apple’s system diagnostics and any TestFlight feedback or crash-report sharing are separate from Bifolium’s Usage & Diagnostics switch and follow Apple’s settings and terms.

Retention, deletion, and export

Original files remain wherever you keep them. App data remains until you remove it, a retention rule removes it, or the operating system clears it. Some app data may be included in device backups, depending on the data and your system settings. Exports, backups, Keychain items, and cloud records can outlast the app’s local storage.

  • Highlights and notes: forgetting a document or clearing Recents does not delete its annotations. Use the separate annotation-deletion controls. Deletions for Synced Papers can propagate through iCloud when sync is available.
  • Search data: Forget removes the search-index entry associated with opening or pinning that document. A document can remain indexed if a folder you granted access to still includes it. Removing folder access clears the entries associated with that folder; another folder or a retained document entry can still keep the same document indexed. To remove that document’s indexed text, remove each remaining source of indexing. Clearing library history leaves folder-indexed content. Reopening a document or indexing its folder again can add it back.
  • Recovery history: editing can save local recovery text automatically. History uses a seven-day limit and a maximum of 50 snapshots per document, applied during maintenance. Saving or discarding an edit clears its pending-draft status but can leave retained history. Recovery history is not a permanent backup.
  • Synced Papers: removing a download removes that device’s reading copy. Stopping publication removes the cloud reading package and keeps your Mac original. Annotations can remain. Turning a sync switch off is not the same as erasing its cloud records.
  • GitHub: remove sources or downloaded copies using the app’s controls, and use Disconnect to remove its credential. Content already downloaded can remain when remote access ends. Follow the disconnect choices if you want to remove private copies as well.
  • Browsing: Clear Website Data removes cookies, caches, and website sign-ins; it does not remove saved tab records or offline copies. Closing a tab also removes its saved offline copy. You can remove a saved copy without closing the tab. Removing the content blocker does not guarantee that WebKit removes all compiled caches.
  • Diagnostics: switching Usage & Diagnostics off clears unsent events. Previously received events have the separate retention described above.

When app access ends, Retrieve Your Data still lets you export existing highlights and notes to Markdown and retrieve retained local documents, recovery text, and saved reference archives. It does not download missing content. Account and file-access safeguards still apply. Expiry itself does not erase your files or shorten existing retention rules.

When you share or export, the selected destination receives the content you choose. Its provider or recipient can keep a separate copy under its own practices. We cannot erase those copies. Deleting Bifolium does not cancel an Apple subscription or guarantee deletion of private iCloud records, Keychain entries, external files, or backups.

Support and this website

If you email us, we receive your address, your message, and any attachments you choose to send. We use them to answer you and resolve the issue. Describe the problem without sending a private document when possible, and share only the material needed for the request.

We keep support messages and attachments while handling your request and for follow-up, then delete them within 90 days after the request is resolved. We retain them longer only where an active dispute or legal obligation requires it, and delete them when that reason no longer applies. You can request earlier deletion; any applicable legal exceptions still apply.

This website is hosted in the United States. It serves static pages using local assets and has no advertising, analytics scripts, or contact forms. We do not keep visitor request logs. The hosting server receives your IP address and the requested URL to deliver a page; that connection information is not retained as a visitor log. Following an external link connects to that destination.

Your rights and our responsibilities

Where data-protection law requires a legal basis, we rely on performing our agreement for the app features and access you request. We use support correspondence on the basis of our legitimate interests in answering inquiries, resolving problems, and handling disputes. Processing required by law relies on the relevant legal obligation. Optional usage and diagnostics sharing relies on your consent; you can withdraw it without affecting earlier lawful processing. A connected feature needs the information described for that feature to work; agreement to the Terms does not give consent for optional analytics.

Apple, GitHub, websites, file providers, and destinations you select process information for their part of a feature. TelemetryDeck processes the limited events described above. Service providers may process support correspondence or website requests on our behalf. We may disclose information we hold if legally required. This does not give us access to information held only on your device.

Depending on applicable law, you may have rights to access, correct, delete, or receive a portable copy of personal information; restrict processing; object to processing based on legitimate interests; withdraw consent; or appeal a refusal. These rights are subject to applicable conditions and exceptions. You can also complain to the data-protection authority where you live or work.

Contact us about information we can identify and control, such as support correspondence. We may request information reasonably needed to verify your request and will respond within the period required by applicable law. For data held only on your device or in your private iCloud, we can explain the available app and Apple controls; we cannot remotely retrieve or erase it. Because diagnostics events contain no name or email address, we may not be able to identify particular events from those details. We do not collect extra identifying information merely to match you to diagnostics events.

We use Apple’s file-access controls, device Keychain, and private iCloud services where relevant. No storage system or connection can guarantee against loss or unauthorized access. Apple, GitHub, and other services you use may process data outside your country under their own policies.

Children

Bifolium is a general-purpose document reader. Documents and linked websites are not curated for children. If you believe a child has sent us personal information without consent required by applicable law, contact us so we can investigate and remove information we control where required.

Changes

For material changes to this policy, we will update that date and provide appropriate notice in the app or on this website. A policy update does not turn on analytics or authorize a new use of personal information that requires separate consent. We will seek consent where required.

Contact

Provider: Fernando Flores
Privacy and support: support@bifolium.app

For the rules governing use of Bifolium, see the Terms.