Your documents stay on your Mac. MojoPad has no accounts and no sync service. Nothing you write is uploaded to us — we could not read your notes if we wanted to, because they never reach us. There is no third-party analytics, no advertising, and nothing that follows you from one visit to the next — on this website or in the app. The few things we do count are described below, in plain terms, because a promise you have to take on faith is worth less than one you can check.
There are two ways for your writing to leave your Mac, both of them off until you choose them. The first is Bring your own model, which asks you to confirm before it sends the pages behind a question to an AI provider of your choosing. The second exists only if you have already installed Claude Code and then pick it as the engine, in which case your question goes to your own copy of it, signed in as you — and only for a question you actually ask: anything MojoPad starts on its own stays here regardless of what you have chosen. An answer that left this Mac is marked in the app as having left. Both are described in full under AI features below. If you never touch it — and most people never will — the sentence above holds without qualification.
A MojoPad document is a folder of plain JSON and your original files, kept wherever you choose. Preferences, automatic backups, and the application log live in your user Library folder. Encrypted pages and password-protected documents are AES-256 encrypted on disk.
Two things happen on their own, and both are small and readable. Everything else on this page happens only when you do something that asks for it — clip a page, run a search, ask a question, look for a picture. Rather than give a count that goes out of date, here is each kind:
Update check. At launch (and when you choose Check for Updates…), the app fetches a small file from mojopad.app containing the latest version number, and tells us which version you are running — that is how we know when a version is old enough to stop supporting. Nothing about you, your Mac, or your documents is sent.
Because that request reaches our server, we count it, so we can tell roughly how many people use MojoPad. We record one row per install per day: the day, the app version, and the country the request came from. Your IP address is never stored — it is turned into a one-way hash that also mixes in the date, so it cannot be reversed into an address, and the same Mac produces a different value tomorrow. That makes the count deliberately incapable of following anyone from one day to the next. Turn the whole thing off in Settings ▸ Updates and you disappear from it entirely.
Downloading the app. When you click a download link, that request reaches our server too, and we record one row: the day, the version, the country, and the browser's user-agent string (which we keep only to tell real downloads from the web crawlers that account for a good share of them). No account, no cookie, no identifier — nothing that distinguishes one download from another or ties it to a person.
We also record which site sent you here and which page of ours you arrived on, because we would genuinely like to know how people find MojoPad and have no other way to tell. That is the host only — “a-forum.example” — and never the full address, so if you arrived from a search we do not see what you searched for, and if you arrived from an article we do not see which one. It is kept in your browser for the length of one visit and is gone when you close the tab; it cannot follow you from one visit to the next, and there is no identifier attached to it. If you never download anything, it is never sent at all. It comes from first-touch.js, which is short enough to read, and turning JavaScript off skips it entirely.
License activation. When you activate a license (and in an occasional quiet re-check), the app sends your license key and your Mac's computer name to Lemon Squeezy, our payment provider, to confirm the key is genuine. No document content, names, or usage data is ever included. During the free trial — and if you never buy — this request never happens.
By default, MojoPad's AI talks only to Ollama running on your own machine (127.0.0.1). Page content is sent to that local process and nowhere else. That is how a fresh install behaves, and most people never change it.
There is one setting that changes this, and it is off until you turn it on and confirm a dialog: Settings ▸ AI ▸ Bring your own model. It exists because a model needs memory, and a Mac that cannot spare enough can only run models that are poor at rephrasing and at languages other than English. With it on, and only then, the pages behind a question you ask are sent to the provider whose API key you entered — a company we have no relationship with, under whatever terms you agreed to with them. We cannot see that traffic, and we cannot make any promise about what they do with it.
Even with it on, the limits are narrow and enforced in the code:
If you have Claude Code installed, MojoPad can hand it a question instead of a model — and it appears only if it is already on your Mac. It runs as your own copy, signed in as you, so what happens to a question you send it is between you and whoever you signed in with: MojoPad has no account, no key, and no part in the middle of it. If you have never installed it, none of this exists for you.
A research run is the larger version of that, and it is the one thing here that keeps working after you walk away. You start each one deliberately. It can search and read the web to answer what you asked, and it can read folders you have chosen, one at a time. It cannot write: it may not create or change a file, or start a program, in either mode, and that is settled when the run starts rather than asked for politely.
Nothing on your disk is readable until you say so. The permission belongs to that one wiki, and you can take it back the same way you gave it. Two folders are refused however you pick them — the wiki itself, because a password on a page is meant to protect its words from exactly this, and your whole home folder, because that is what a chooser hands you when you click past it.
A question you put to your wiki carries the content of your pages with it, and pages arrive from the clipper, from mail, and from wikis other people send you. A research run carries your question and nothing else — which is precisely why it is the one allowed to read a disk.
At the bottom of a page, MojoPad can suggest external pages on its subject. Your local model writes a short search query from the page and that query — a few topic words, never your page content — goes to a search source: Wikipedia, Hacker News and arXiv by default, or Brave, Kagi or a SearXNG instance if you add a key for one. Answers are cached locally for a week so the same question is not asked twice.
A page can carry an identifier — a DOI for a paper, an ISBN for a book, a PubMed number for a study. Ask MojoPad to look one up and it fetches the published record from the catalog that issued it: who wrote it, when, where it appeared.
If you use Zotero, MojoPad asks it before it asks anybody else — and nothing leaves your Mac to do it. It reads the copy of your library already on this computer, over an address that never leaves the machine, and only ever reads: it does not add to your library or change it. It happens only while Zotero is running with the setting that lets other programs on your own computer talk to it switched on. If you do not use Zotero, nothing here applies.
What goes out is the identifier, and nothing else. Not the page, not its title, not your notes, not the words around it. You can read the identifier in the field before you ask, and MojoPad names the catalog it is about to ask.
Two exceptions, for a paper that prints no number at all — and the button says which one it is before you press it. A paper with no identifier cannot be looked up by one, so MojoPad can instead ask a registry which work has this title: the title goes out — the page's own Title, or its name where that reads as one — and the first author's surname where the page itself keeps one, to tell two works of the same name apart. A value a page merely inherits from its Kind is never sent: it belongs to the kind rather than to the paper, and sending it would put one title on the wire on behalf of every page of that kind. Nothing else does — not the page, not your notes — and an answer is taken only when the titles match word for word. And a file named like a DOI whose slashes were written as underscores can have a few spellings of that name checked instead: each one is identifier-shaped, none of them is your words, and one is taken only if the registry knows exactly one. A page that carries a number never sends either.
It can ask four, and the list is fixed in the app — not a setting, and not something a document you were given can add to. Three answer the question what is this work: Crossref for a DOI, Open Library for an ISBN, and PubMed for a PubMed number, and for the PubMed and PubMed Central numbers of a paper you know only by its DOI. A fourth, Semantic Scholar, answers what became of it — how often the work has been cited, and whether there is a copy anybody can read. It is asked by DOI only, so it is not asked at all about a book, and it is asked alongside whichever of the first three settles the identifier. All four are public catalogs.
None of them needs an account, and MojoPad sends no address and nothing that identifies you or your Mac. Three of the four are asked with no key of any kind. PubMed asks every program that uses it to say which program it is and give a contact address; MojoPad gives the app's own name and the app's own address, never yours. Semantic Scholar gives everyone who has not asked for one a shared allowance, and when it runs out you simply do not get the citation count; if you would rather have one of your own, you can request a key from them and put it in Settings ▸ Sources. If you do, it is sent to Semantic Scholar and to nobody else — never to the other three, and never carried along if one of them redirects. It is encrypted by macOS, kept out of the settings file, and never included in a diagnostic report, so it is not carried along when settings are copied to another Mac or sent to us.
What they learn, plainly: that somebody at your internet address asked about that one work, at that time. It is the same thing they would learn if you typed the identifier into their own website — because it is the same request, made from the same place.
Nothing happens on its own. There is no background enrichment and nothing runs when you import. A document cannot start a lookup by itself; it takes an ask, every time. And when an answer arrives it is offered — shown beside what your page already says, for you to take or leave — so a catalog never quietly overwrites something you wrote.
One consequence worth knowing, since documents travel: the note recording that a value came from a catalog, and when, is stored on the page like any other property. If you share that document, whoever opens it can see that the lookup happened.
Each of these happens because you did something, never on its own:
None of these carries your page content. What goes out is the address you asked for, or the words you typed into a search box.
If you ask us for help, you may choose to send a diagnostic report (Help ▸ Save Diagnostic Report…). It contains technical details — versions, preferences, document statistics, and recent log lines — and never page names, page content, or passwords. You can read the file before sending it; nothing is transmitted automatically.
The optional Clip to MojoPad browser extension has its own privacy policy. In short: what you clip goes only to the MojoPad app on your own computer — never to a server.