At a glance
ChatMD Studio is a Windows app that works with files you choose on your own computer. The app has no ChatMD account, advertising, analytics, telemetry, advertising identifier or automatic crash reporting.
- Editing and conversion are local. ChatMD Studio does not upload your files to a ChatMD server.
- Network features are optional and user-started. If you use cloud AI, web clipping, the Contact Us page, or the Secrets checks described below, the information described below goes to the service needed to perform that request. Two checks run on a schedule: if you turn on daily key checks in Secrets, ChatMD Studio contacts each key's own provider once a day until you turn that off; and while a Studio licence key is in use, the app checks it with chatmdstudio.com about once a day, as described below.
- Your vault remains yours. It is made of ordinary files you can open, move, back up or delete without ChatMD Studio.
Files and local data
The app accesses the folders and files you select so it can open, search, edit, organize and convert them. Conversion — including PDF to Markdown and notes to Word, PDF or e-book formats — runs on your PC and can work with the network switched off.
ChatMD Studio also keeps local app data needed to operate and recover work. This can include your theme and layout, selected vault and recent-file paths, selected AI tool and model, onboarding and terms records, maintenance timestamps, local usage totals, recent AI answers, recovery drafts, extracted PDF text caches and temporary safety copies used for undo or recovery. This data stays on your device.
Your vault files remain where you put them until you delete them. App settings and caches can be removed through Windows app-data controls or by uninstalling the app; uninstalling does not delete the vault folders you chose.
AI features and network use
ChatMD Studio uses the network only for a feature you start:
- Cloud AI tools. Ask & Chat, guided knowledge capture and AI-written review launch the compatible command-line AI tool you selected. ChatMD Studio does not include, resell or operate an AI model account. You must install and sign in to a supported tool under your own provider account. That provider may receive your question, ChatMD Studio's task instructions, and context or files the tool reads from the vault scope you chose. The provider processes that information under its own terms and privacy policy and may apply its own usage limits or charges. ChatMD Studio never sends a provider password or API key to a ChatMD server. If you keep a key in the app's Secrets page, it is stored encrypted on your PC and used only in the ways that page lists: an Ask you confirm, a check at the key's own provider, a handover to an AI tool on your PC that you allow, or a file you choose.
- Ollama. When you choose Ollama, AI processing runs locally. Installing Ollama through winget and downloading a model contacts the relevant download servers, but your vault content is not part of those downloads.
- Web clipping. Clipping a web page fetches the address you provide. The destination website receives the normal network information that accompanies a web request, such as an IP address and request headers.
The Brain's local visualization and ordinary file browsing do not require an AI provider. AI-assisted answers, knowledge capture and written review do. You choose the provider, model and file scope before starting those features.
The app has no independent updater. Microsoft Store builds receive updates through the Microsoft Store.
Microsoft Store purchases and licensing. Store builds can offer the optional Studio upgrade as a Microsoft Store add-on. The purchase dialog, payment and any refund are handled by Microsoft under your Microsoft account and Microsoft's own terms and privacy statement; ChatMD Studio never sees your payment details. To know whether Studio has been purchased, the app asks Windows for the licence state of this installation. That check involves Windows and Microsoft Store services, not ChatMD servers. The answer is kept in memory while the app runs, and a short diagnostic record of the result (status and when it was checked, no account details) is kept in the app's data folder to help with support questions.
Website purchases and licence keys. Studio can also be bought on chatmdstudio.com through Stripe, which is the merchant of record: Stripe takes the payment, handles tax and refunds and sends the receipt under its own terms and privacy policy; this website never sees your card. When a payment completes, the website issues a licence key and keeps the Stripe session and payment identifiers and the key. The key has the email address you paid with written into it, so the website keeps that address as part of your licence record, to find a lost key for you and to answer licence and refund questions; it is not used for anything else. The key is also sent once to that address, through an email provider, so that you have your own copy. A licence key works on up to three of your PCs at once. When you enter a key in the app, and about once a day after that while the key is in use, the app sends chatmdstudio.com the key and a one-way hash of your PC's name and user name. The website keeps that hash beside the key to record which PC the key is active on: using the key on a fourth PC moves it there, and the PC where it was activated longest ago turns Studio off at its next check until you choose to use it there again. The same check lets a refunded key be refused. Nothing else about you or your files is sent, and if a check cannot be made the key keeps working. The record of which PCs a key is active on, and when each last checked, is kept for as long as the key is. Buying another PC for a key sends the key to chatmdstudio.com, which checks it is a key it issued and records that purchase against it; Stripe receives only the last part of the key. If you start the purchase from inside the app, the app makes a one-time random token and sends it with the purchase so the key issued for it can be filed against that token, then asks chatmdstudio.com for that key every few seconds until it arrives or the window closes. The token stands for the purchase, not for you: no name, email or account is sent with it, and a collected key still has to pass the same signature check as one you paste.
Contact Us website
chatmdstudio.com is separate from the desktop app. The app does not send your vault or usage history to this website. The site has no advertising and no cross-site tracking. It uses Cloudflare Web Analytics, which counts visits in aggregate without cookies and without keeping your IP address, so the developer sees only totals: those counts and the aggregate request counts Cloudflare records to deliver and secure the pages, described below. No record of an individual visitor is kept. The one cookie Cloudflare may set, cf_clearance, belongs to its bot protection and is not used to measure you.
Like any hosted website, Cloudflare processes standard request information needed to deliver and secure the pages, which can include your IP address and browser or device headers. ChatMD Studio does not use that information to build advertising profiles.
If you choose to send the Contact Us form, ChatMD Studio stores the message, category, time received, app version if supplied, and email address if supplied. Email is optional; without it, the developer cannot reply. The form also records the country code reported by the network and a salted, one-way hash of the IP address for hourly abuse limits. The raw IP address is not written to the support database.
Cloudflare Turnstile protects the form from bots. Cloudflare says Turnstile processes signals including the client IP address, TLS fingerprint, user-agent, sitekey and site origin for bot detection and improvement. Its processing is described in the Cloudflare Turnstile Privacy Addendum.
Contact Us messages are used to answer requests, investigate problems, prevent abuse and maintain a useful support history. They are kept only while reasonably needed for those purposes or until a valid deletion request is completed.
When a message arrives, the developer is notified on their phone through the push service of the company that makes the phone or browser: Apple, Google, Mozilla or Microsoft. The notification is an empty signal. It carries no message text, no email address and nothing about the sender; your message and your email address stay in the Cloudflare database and are read in a private, access-controlled page. Nobody who writes in can choose or change where that notification goes.
You can also write to the support address directly. Email sent there is received by Resend, the email provider, and filed in the same private, access-controlled page as Contact Us messages. What is stored is the message text, the subject, your email address, the time received, and any attachments, up to 15 MB for each file and 30 MB for each message; larger files are listed by name and type only. Long messages are truncated. Attachments are stored with Cloudflare, are kept exactly as long as the message they came with, and are deleted with it. Support email is kept on the same terms as Contact Us messages above, and the developer's notification for it carries no more than it does for a form message. Replies the developer sends from that page are stored with the message they answer, on the same terms, and are deleted when it is.
Support email and Contact Us messages are deleted automatically 180 days after they arrive, unless the developer keeps a particular message for longer because it is needed for a dispute, a refund, or tax and accounting records. Email sent to the developer's own business address at chatmdstudio.com — for example invoices, receipts and account notices from suppliers — is kept for business records until the developer deletes it, and so is anything you send to that address.
Email that reaches the support address gets one automatic reply from that address saying it arrived. The reply contains none of your text and is sent at most once a day to any address. To keep to that limit, a one-way hash of the sender's address is kept for up to three days. No automatic reply is sent to automated, bulk or mailing-list mail.
Service providers
ChatMD Studio does not sell personal information and does not share it for cross-context behavioral advertising. Information can be processed by these categories of provider only when needed:
- Your chosen AI provider, when you start a cloud AI feature.
- Cloudflare, which hosts and secures this website, stores Contact Us submissions, support email and its attachments, and the developer's replies to them, stores issued licence keys and the PC each key is active on, and runs Turnstile.
- Stripe, which takes payment for Studio bought on this website as merchant of record and sends the receipt.
- Apple, Google, Mozilla or Microsoft, whichever makes the developer's phone or browser. Its push service carries the developer's notification that a message arrived and receives an empty signal: no message text, no email address and nothing about the sender.
- Resend, the email provider, which sends licence keys and which receives, processes and stores email sent to our email addresses — including the message, its subject, the sender's address and any attachments — and which carries any reply the developer chooses to send you.
- Microsoft and package or model hosts, when Windows delivers an update, when you make or restore a Microsoft Store purchase or the app checks its Store licence, or when you request an installation or model download.
- A destination website, when you ask ChatMD Studio to clip it.
Those providers may process information in countries other than your own, according to their own terms, privacy policies and transfer safeguards.
Your choices
You choose which folders ChatMD Studio can work with. You can use the free editor without cloud AI, choose local Ollama instead of a cloud provider, avoid web clipping, and choose not to use the Contact Us form.
You can inspect, copy, move and delete your vault with normal file tools. You can clear local ChatMD Studio data through Windows. Requests to access, correct or delete a Contact Us message can be sent through Contact Us, subject to applicable law. An email address or enough specific message details may be needed to locate it; a fully anonymous message may not be identifiable. Requests about data held by an AI provider must be made to that provider through your account with it.
Security
Local files use the permissions and security controls provided by Windows. User-started requests to AI providers, the Store and this website use HTTPS. Web clipping fetches the address you give it, which can be an http address, and Ollama on your own PC is reached over plain http on your machine. Contact Us messages are stored in a private database and the administrative view is access-controlled. No system is completely secure, so keep backups of important files and protect access to your Windows and AI-provider accounts.
Children
ChatMD Studio is not directed to children under 13. Children under 13 should not submit personal information through Contact Us without a parent or guardian. ChatMD Studio does not knowingly collect personal information from children under 13. If such information is discovered, request deletion through Contact Us.
Changes
This policy will be updated when ChatMD Studio's data practices change. The date at the top identifies the current version. Material changes will also be called out in the app when appropriate.
Contact Us
ChatMD Studio's developer operates this app and website from Ohio, United States. Privacy questions and requests can be sent through the Get Help page inside the app or the message form at chatmdstudio.com/support.