Caliu is where you think, and that only works if nothing is watching over your shoulder. This article explains, in plain words, where your notes live, how they are protected, and the choices behind the design. The legal version lives in the privacy policy.
Why privacy comes first
Caliu is built by one person in Spain, not by a data company. There are no investors to feed and no advertisers to please. The business model is boring on purpose: the app is free, and Caliu Pro pays the bills. When writing pays the bills, your words are the product we protect, not the product we sell.
So there are no ads. No selling or renting your data. No tracking you across the web. And nothing you write is ever read, mined, or used to train AI.
Where your notes live
Your notes are stored on your device first: in your browser's local database for the web app, and in a local database for the iPhone, iPad, and Mac apps. That is why Caliu opens instantly and works fully offline.
When you are online, your notes sync through Caliu's own infrastructure, running on Cloudflare's network, so they can reach your other devices, your share links, and the tools you connect through the API. Attachments live there too.
Caliu operates from Spain, and GDPR applies to every account, wherever you live: the right to see, export, correct, and erase everything you have written.
How your notes are protected
- Every connection is encrypted. Your notes always travel over HTTPS, never in the clear.
- Passwords are stored hashed, never in plain text. API keys are stored as hashes too.
- Sessions use secure, httpOnly cookies, and sign-in endpoints are rate-limited.
- Trash is purged for good 30 days after deletion. Delete your account and your data goes with it. Deleted means deleted.
- Product analytics are minimal and hosted in the EU: they tell us which features get used, never what you write. No advertising cookies, no third-party trackers.
The decisions behind it
Our own sync instead of iCloud. iCloud would have been the easy road, but it chains your notes to Apple hardware. Caliu runs on iPhone, iPad, and Mac, and just as fully in any web browser, with your notes reachable by the API and AI tools you choose. iCloud cannot do that. So Caliu runs its own sync and takes on the responsibility that comes with it. Your notes follow you, not your hardware brand.
Local-first instead of cloud-first. The copy on your device is the primary one. If Caliu's servers vanished tomorrow, your notes would still be with you, intact and exportable. A sync server should be a convenience, never a hostage situation.
No end-to-end encryption, on purpose. Caliu does not use end-to-end encryption. We could stay quiet about that; most apps do. Here is the trade-off, plainly. With E2E, a forgotten password would mean losing every note, opening your notes in a browser would require juggling keys, and the AI tools you connect could not read a word. Caliu chose recoverability and openness, backed by encryption in transit, a locked-down infrastructure, and a strict rule: nobody looks. If your threat model truly requires end-to-end encryption, we would rather you know this before you trust us than after.
Export always. Notes are plain Markdown underneath, and you can take everything out whenever you like: export a single note in Markdown, plain text, HTML, RTF, ePub, or TextPack (the iPhone, iPad, and Mac apps add PDF), or select many notes and export them all at once as a ZIP. See the export article for the details. Leaving must always be easy.
The fine print
The formal version of all this lives in the privacy policy. If anything is unclear, or you have a request about your data, write to hola@caliuapp.com and a human answers. The only one here, in fact.