Last updated: September 17, 2026
This policy covers Second, maintained by thedevdavid, including the website, connected service, native apps, browser extensions, CLI, and integrations. Contact contact@thedevdavid.com with privacy questions or requests.
We use information to provide capture, storage, search, organization, synchronization, AI features, account security, support, and service diagnostics. Your connected AI host and other services you choose have their own privacy policies.
Account data: your name, email address, and a hashed password when you create an account. If you use passkeys, the public key credential is stored with your account.
Content you save: URLs, titles, metadata, canonical Markdown, notes, retained original files, extracted text, content revisions, and source or handoff provenance. We also store PARA destinations, rules, Daily Focus items, preferences, and records needed for synchronization and organization history.
AI Profile: the optional, user-authored context sections you save for assistant personalization, along with immutable profile versions, activation state, and the compiled Markdown for each version. Imported Markdown is always saved as a draft and never activates itself.
Weekly-review activity: user-authored assistant prompts and bounded MCP tool metadata (tool name, success, result class/count, timestamp, and whether a client session id was supplied). These rows and generated review snapshots are retained for 35 days. That review-activity log does not store MCP arguments, search terms, URLs, notes, result bodies, or bearer credentials. Requested saves, conversations, handoffs, and operation records are stored separately as needed for those features.
Assistant history: your assistant conversations (your prompts and the assistant's answers) are stored so you can reload past chats on any device. You can delete any conversation at any time from the assistant's History menu or the API; deleting your account removes all of them.
Credentials: API tokens you create are stored as SHA-256 hashes. OAuth connections also retain client registration, consent, permission, session, and credential-generation records. Opaque access and refresh tokens are stored hashed; signed access tokens are verified against the account and current authorization. Revocation records prevent disconnected credentials from becoming valid again.
When you invoke a save command, the extension reads the selected page or link URL and title. On supported browsers it may also extract the page text as Markdown so saved pages remain readable. Saving a selection sends the text you select. Save-window commands read the URLs and titles of tabs in that window. Safari falls back to URL-only capture when its scripting API is unavailable. The extension does not continuously collect your browsing history.
Sign-in uses OAuth 2.1 with PKCE. Tokens are kept in your browser's sync storage and refreshed silently; browser sync storage may synchronize them through your browser account. They are sent to Second for authentication and token refresh.
If a save fails (for example, while offline), its URL, title, notes, destination, and any extracted or selected text are queued in local extension storage and retried automatically. Queued content is sent to Second when the retry succeeds. Pending captures are bound to their account, with recovery, export, and discard controls for records that cannot be delivered.
The Mac app keeps a local library with protected content encrypted at rest and can synchronize supported content with your Second account. The iPhone and iPad app accesses your connected library and keeps pending captures locally until they can sync. Connected search and AI features require a network connection. This is not end-to-end encryption: content synchronized to Second is processed by our servers.
iOS dictation and screenshot OCR run on-device. Native sign-in credentials use the system Keychain. When you enable an integration, the credentials needed for that integration are stored so its authorized sync can operate.
Your data is stored in Cloudflare D1 and served by Cloudflare Workers. Saved attachments and generated artifacts may also use Cloudflare R2, and content prepared for search is processed by Cloudflare AI Search.
Sentry receives technical error and crash diagnostics from the web app, browser extension, and native apps to help us fix failures. Performance tracing and session replay are disabled, and default personal information collection is disabled. Native events are scrubbed for user-derived content. Web or extension error messages can still contain contextual values such as item titles; capture bodies and credentials are not intentionally attached. We do not use advertising tracking.
If you use AI text features (filing suggestions, the assistant, managed agent turns, or weekly review), the relevant capture fields and user-authored prompts are sent to OpenAI GPT-5.6 Luna through Cloudflare AI Gateway for processing. When your AI Profile is active, its compiled Markdown is included as personalization context; profile text is not sent for assistant turns while the profile is off. AI Search embeddings/reranking and audio transcription use Cloudflare Workers AI. Weekly-review facts are computed deterministically; AI writes only the grounded narrative.
Providers may process information outside your country. Provider logs, retention, and international processing are governed by their service settings and policies; we do not promise that all processing remains in a single country.
Transactional email and the optional weekly review are sent via Cloudflare Email Sending. Cloudflare D1 stores the bounded activity and generated review snapshots until the 35-day retention period expires.
Start a chat and Create brief from Search process the complete canonical Markdown of every eligible matching Item through the configured Cloudflare AI Gateway. AI-generated Items are excluded unless you explicitly include them. We explain this before first use and remember your acknowledgement and last Brief Template across your account's devices.
Search-backed Chats and Briefs retain a frozen source manifest with exact revision identities, prepared source summaries, and generation provenance. Briefs contain a portable Markdown Sources section as well as structured provenance. Brief Generation continues on the server when you close the app; failed and cancelled generation records are retained for 30 days.
Opening a Search-backed Chat does not add it to conversation history until you send a message. Abandoned temporary context is cleaned up, with a 24-hour expiry as a safety net. Deleting a conversation removes its context and prepared summaries without deleting source Items.
Permanently deleting a source erases retained source content and source-dependent processing caches. Existing Briefs and conversation messages are not silently rewritten; their source references retain a Source deleted tombstone. You can edit or delete those outputs separately. Editing or archiving a source leaves its pinned historical revision available while the source exists.
When you connect an AI app through OAuth, Second records the access level and destinations you approve. Read access can disclose authorized content to that app; save and organize access add the corresponding actions. Legacy API tokens provide broader account access. Review the consent screen and connect only tools you trust.
Saved material may include supplied conversation turns, citations, omission records, original-file bytes and hashes, extraction results, save receipts, and organization proposals or history. Second can only receive what the host supplies; it does not automatically obtain every conversation, selected reply, or original file in that host.
Native original-file upload is separately consented. An original can be retained even if text extraction or search indexing is unsupported or incomplete. Incomplete upload sessions expire after 24 hours and are queued for cleanup; retained originals stay associated with their Items until removed.
You can inspect, narrow, or revoke connected-app access in Integrations. Disconnect stops future authorized access through that connection; it does not erase content already copied into another service. Delete those copies with the other provider. Integration credentials needed for ongoing Notion sync are retained by Second and are not protected by end-to-end encryption; a one-time import does not retain its supplied token.
Notion, Obsidian, and Apple Notes integrations do not propagate permanent deletions. Notion archive propagation is a separate opt-in setting. Deleting content in Second does not erase an external notebook or exported file.
The website uses session cookies for sign-in and local storage for preferences such as appearance. Public integration icons are loaded from thesvg.org, which receives ordinary web request information such as your IP address when those images load. Native apps, the extension, CLI, and vault plugin keep local credentials, caches, or pending work appropriate to their function. These support the service rather than advertising tracking.
Saved content and account records are retained while needed to provide your workspace, until you remove them or delete the account. The shorter retention periods for review activity, temporary Search contexts, failed or cancelled Brief generation, and unfinished uploads are described above. Security revocation records may remain to prevent credential replay.
Removing content from the active service is not a promise of immediate removal from every provider recovery copy or diagnostic log. Copies you exported, saved to another service, or kept on a device require separate removal. Contact us for help with access, correction, deletion, or questions about retained information.
You can archive or delete individual items at any time. Settings → AI Profile lets you edit a new immutable draft, activate or deactivate personalization, restore an older version, delete non-active versions, and delete the complete profile history. Settings → Data exports a library ZIP with canonical Markdown, verified retained originals, file metadata, PARA data, Daily Focus, AI Profile versions, retained review activity, and generated snapshots. The export manifest reports unavailable or incomplete material; MCP session hashes are omitted. Deleting your account (Settings → Danger zone) removes the account and its associated application records and schedules cleanup of derived search data and retained objects. Cleanup may complete asynchronously. Account reset removes workspace data while retaining the account; archiving does not erase data.
Questions or requests: contact@thedevdavid.com.
Cloudflare · OpenAI business data · Sentry
OpenAI states that API inputs and outputs are not used to train its models by default. This is separate from the policies and settings of a ChatGPT, Claude, or other AI account you connect yourself.
We may update this policy as the service changes. The date above identifies this version. Privacy requests can be sent to contact@thedevdavid.com.