Second

Privacy policy

Last updated: September 24, 2026

Who this policy covers

This policy covers Second, maintained by thedevdavid, including the website, connected service, native apps, browser extensions, CLI, and integrations. Contact contact@thedevdavid.com with privacy questions or requests.

We use information to provide capture, storage, search, organization, synchronization, AI features, account security, support, and service diagnostics. Your connected AI host and other services you choose have their own privacy policies.

What we collect

Account data: your name, email address, and a hashed password when you create an account. If you use passkeys, the public key credential is stored with your account.

Content you save: URLs, titles, metadata, canonical Markdown, notes, retained original files, extracted text, content revisions, and source or handoff provenance. We also store PARA destinations, rules, Daily Focus items, preferences, and records needed for synchronization and organization history.

AI Profile: the optional, user-authored context sections you save for assistant personalization, along with immutable profile versions, activation state, and the compiled Markdown for each version. Imported Markdown is always saved as a draft and never activates itself.

Weekly-review activity: user-authored assistant prompts and bounded MCP tool metadata (tool name, success, result class/count, timestamp, and whether a client session id was supplied). These rows and generated review snapshots are retained for 35 days. That review-activity log does not store MCP arguments, search terms, URLs, notes, result bodies, or bearer credentials. Requested saves, conversations, handoffs, and operation records are stored separately as needed for those features.

Assistant history: your assistant conversations (your prompts and the assistant's answers) are stored so you can reload past chats on any device. You can delete any conversation at any time from the assistant's History menu or the API; deleting your account removes all of them.

Credentials: API tokens you create are stored as SHA-256 hashes. OAuth connections also retain client registration, consent, permission, session, and credential-generation records. Opaque access and refresh tokens are stored hashed; signed access tokens are verified against the account and current authorization. Revocation records prevent disconnected credentials from becoming valid again.

Billing and subscription records: where billing is enabled for your account or platform, we retain account-bound purchase and subscription metadata such as provider and product identifiers, catalog and price references, billing periods, entitlement state, and cancellation, refund, or revocation status. Usage records may include the operation, metric, units, and outcome needed to provide and reconcile service access. We do not store full card or bank details from hosted checkout forms.

Usage during the beta: we record service operations and usage, such as processing and storage, to understand service costs and show account usage. Recording usage does not create a charge or activate a paid plan.

Complimentary access: we store invitation-code hashes, optional recipient-email hashes, redemption deadlines, account links, and grant, redemption, and revocation records. Grant records include administrator references and reasons for granting or revoking access. The redeemable code is shown only when issued and is not stored in plaintext. Used-code records remain after account deletion to prevent reuse; account references are cleared.

Browser extension

When you open the popup or invoke a save command, the extension reads the active tab or selected link URL and title. When you save a supported page, it may also extract the page text as Markdown so saved pages remain readable. Saving a selection sends the text you select. Save-window commands read the URLs and titles of tabs in that window; save-and-close commands close successfully saved tabs. Safari falls back to URL-only capture when its scripting API is unavailable. The extension does not continuously collect your browsing history.

Sign-in uses OAuth 2.1 with PKCE. Tokens are kept in your browser's sync storage and refreshed silently; browser sync storage may synchronize them through your browser account. They are sent to Second for authentication and token refresh.

If a save fails (for example, while offline), its URL, title, notes, destination, and any extracted or selected text are queued in local extension storage and retried automatically. Queued content is sent to Second when the retry succeeds. Pending captures are bound to their account, with recovery, export, and discard controls for records that cannot be delivered.

Native apps

The Mac app keeps a local library with protected content encrypted at rest and can synchronize supported content with your Second account. The iPhone and iPad app accesses your connected library and keeps pending captures locally until they can sync. Connected search and AI features require a network connection. This is not end-to-end encryption: content synchronized to Second is processed by our servers.

iOS dictation and Share extension image OCR run on-device. On macOS, voice capture can retain the original recording locally; if you choose managed transcription, selected audio is sent to Cloudflare Workers AI. Native capture can also retain original images, screenshots, audio, and other files when you explicitly add or upload them; those originals remain associated with the item until removed. Native sign-in credentials use the system Keychain. When you enable an integration, the credentials needed for that integration are stored so its authorized sync can operate.

Third-party processors

Your data is stored in Cloudflare D1 and served by Cloudflare Workers. Saved attachments and generated artifacts may also use Cloudflare R2, and content prepared for search is processed by Cloudflare AI Search.

Sentry receives technical error and crash diagnostics from the web app, browser extension, and native apps to help us fix failures. Performance tracing and session replay are disabled, and default personal information collection is disabled. Native events are scrubbed for user-derived content. Web or extension error messages can still contain contextual values such as item titles; capture bodies and credentials are not intentionally attached. We do not use advertising tracking.

If you use AI text features (filing suggestions, the assistant, managed agent turns, or weekly review), the relevant capture fields and user-authored prompts are sent to OpenAI GPT-5.6 Luna through Cloudflare AI Gateway for processing. When your AI Profile is active, its compiled Markdown is included as personalization context; profile text is not sent for assistant turns while the profile is off. AI Search embeddings/reranking and audio transcription use Cloudflare Workers AI. Weekly-review facts are computed deterministically; AI writes only the grounded narrative.

Providers may process information outside your country. Provider logs, retention, and international processing are governed by their service settings and policies; we do not promise that all processing remains in a single country.

Transactional email and the optional weekly review are sent via Cloudflare Email Sending. Cloudflare D1 stores the bounded activity and generated review snapshots until the 35-day retention period expires.

Where billing is enabled for your account or platform, Apple processes App Store payments and RevenueCat processes App Store product and entitlement data. Stripe-hosted pages process direct Mac/web checkout and billing-portal actions. Second receives and stores account-bound billing metadata such as provider identifiers, product or price references, billing periods, entitlement state, and refund, cancellation, or revocation status; full card and bank details are handled by the payment provider and are not stored by Second.

Search sources and AI-generated Briefs

Start a chat and Create brief from Search process the complete canonical Markdown of every eligible matching Item through the configured Cloudflare AI Gateway. AI-generated Items are excluded unless you explicitly include them. We explain this before first use and remember your acknowledgement and last Brief Template across your account's devices.

Search-backed Chats and Briefs retain a frozen source manifest with exact revision identities, prepared source summaries, and generation provenance. Briefs contain a portable Markdown Sources section as well as structured provenance. Brief Generation continues on the server when you close the app; failed and cancelled generation records are retained for 30 days.

Opening a Search-backed Chat does not add it to conversation history until you send a message. Abandoned temporary context is cleaned up, with a 24-hour expiry as a safety net. Deleting a conversation removes its context and prepared summaries without deleting source Items.

Permanently deleting a source erases retained source content and source-dependent processing caches. Existing Briefs and conversation messages are not silently rewritten; their source references retain a Source deleted tombstone. You can edit or delete those outputs separately. Editing or archiving a source leaves its pinned historical revision available while the source exists.

Connected apps, permissions, and originals

When you connect an AI app through OAuth, Second records the access level and destinations you approve. Read access can disclose authorized content to that app; save and organize access add the corresponding actions. Legacy API tokens provide broader account access. Review the consent screen and connect only tools you trust.

Saved material may include supplied conversation turns, citations, omission records, original-file bytes and hashes, extraction results, save receipts, and organization proposals or history. Second can only receive what the host supplies; it does not automatically obtain every conversation, selected reply, or original file in that host.

Native original-file upload is separately consented. An original can be retained even if text extraction or search indexing is unsupported or incomplete. Incomplete upload sessions expire after 24 hours and are queued for cleanup; retained originals stay associated with their Items until removed.

You can inspect, narrow, or revoke connected-app access in Integrations. Disconnect stops future authorized access through that connection; it does not erase content already copied into another service. Delete those copies with the other provider. Integration credentials needed for ongoing Notion sync are retained by Second and are not protected by end-to-end encryption; a one-time import does not retain its supplied token.

Notion, Obsidian, and Apple Notes integrations do not propagate permanent deletions. Notion archive propagation is a separate opt-in setting. Deleting content in Second does not erase an external notebook or exported file.

Cookies, local storage, and retention

The website uses session cookies for sign-in and local storage for preferences such as appearance. Public integration icons are loaded from thesvg.org, which receives ordinary web request information such as your IP address when those images load. Native apps, the extension, CLI, and vault plugin keep local credentials, caches, or pending work appropriate to their function. These support the service rather than advertising tracking.

Saved content and account records are retained while needed to provide your workspace, until you remove them or delete the account. The shorter retention periods for review activity, temporary Search contexts, failed or cancelled Brief generation, and unfinished uploads are described above. Security revocation records and used invitation records may remain to prevent credential replay or code reuse. Resetting workspace data retains account access and billing records; it does not cancel a provider subscription.

Account deletion removes account links from billing records and invalidates associated access. Billing, usage, and audit records may remain for reconciliation and to prevent replay; deleting an account does not erase records held independently by a payment provider.

Removing content from the active service is not a promise of immediate removal from every provider recovery copy or diagnostic log. Copies you exported, saved to another service, or kept on a device require separate removal. Contact us for help with access, correction, deletion, or questions about retained information.

Your control

You can archive or delete individual items at any time. Settings → AI Profile lets you edit a new immutable draft, activate or deactivate personalization, restore an older version, delete non-active versions, and delete the complete profile history. Settings → Data exports a library ZIP with canonical Markdown, verified retained originals, file metadata, PARA data, Daily Focus, AI Profile versions, retained review activity, and generated snapshots. The export manifest reports unavailable or incomplete material; MCP session hashes are omitted. Deleting your account (Settings → Danger zone) removes the account and its workspace records and schedules cleanup of derived search data and retained objects, subject to the security and used-code retention described above. Cleanup may complete asynchronously. Account reset removes workspace data while retaining the account; archiving does not erase data.

Questions or requests: contact@thedevdavid.com.

Processor policies

Cloudflare · OpenAI business data · Sentry · Apple · RevenueCat · Stripe

OpenAI states that API inputs and outputs are not used to train its models by default. This is separate from the policies and settings of a ChatGPT, Claude, or other AI account you connect yourself.

We may update this policy as the service changes. The date above identifies this version. Privacy requests can be sent to contact@thedevdavid.com.