Legal

Privacy

Last updated: 29 September 2026

Tipto is a desktop application that runs on your own computer. It is designed so that your reading library never has to leave that computer. This page describes what the application does with your data, what this website collects, and the choices you have.

What stays on your device

Everything in your library is stored locally, in an application database and file storage inside your operating system's application data directory:

  • Feed subscriptions, folders, read and starred state
  • Article text, saved pages, captured pages, PDFs, EPUBs and images
  • Highlights, tags, notes and reading progress
  • Generated summaries and digests, and their run history
  • Search indexes and document embeddings
  • AI provider credentials and any website sign-ins you save for sources

There is no Tipto account, and the application does not upload your library to a server we operate.

What is sent to third parties you choose

Your AI provider

Tipto works with the AI provider you configure — any service exposing an OpenAI-compatible chat completions endpoint. When you generate a summary or a digest, or ask a question about your library, the relevant text from your content is sent to that provider's endpoint together with your API key. Nothing is sent until you trigger one of those actions or schedule a digest that performs them.

That provider's own privacy policy and data-retention terms apply to those requests. Your API key is stored on the device, is not returned to the application interface, and is excluded from backups.

Sources you subscribe to

Refreshing a feed, loading a web source or capturing a page makes a normal network request to that website, which will see your IP address and user agent just as a browser would. If you save a sign-in for a source, those session cookies stay on the device.

Update checks

The application periodically checks a release metadata file on our distribution host to see whether a newer version exists. That request reveals your IP address and the version you are running. No library content is involved.

Diagnostics and telemetry

Remote diagnostics are disabled by default. The application keeps bounded local logs and traces on your device for troubleshooting. You can export a redacted diagnostic bundle, inspect it, and decide whether to share it.

Sharing diagnostics with a remote collector is opt-in under Settings → Privacy, and requires configuring a collector endpoint. When enabled, the exported data excludes credentials and private content by default. You can turn it off again at any time.

The Chrome extension

The browser extension pairs with the desktop application on your machine and captures a page only when you click to capture it. Captured content is sent to the desktop application over that local pairing, not to a server we run.

This website

tipto.ai is a static site hosted on Cloudflare Pages. It sets no advertising or tracking cookies and runs no third-party analytics. Cloudflare processes standard request data such as IP address and user agent in order to serve the site and protect it from abuse, as described in Cloudflare's own privacy documentation. Fonts are loaded from Google Fonts, which receives the request data needed to serve those font files.

Application downloads are served from Cloudflare R2 storage, which likewise sees the request data needed to deliver the file.

Your choices

  • Use Tipto entirely without AI by not configuring a provider key.
  • Leave diagnostic sharing off, which is the default.
  • Export your subscriptions as OPML and back up your library at any time from within the application.
  • Delete everything by removing the application and its application data directory. There is no server-side copy to request the deletion of.

Changes

Planned cloud features — optional accounts, hosted AI and cross-device sync — are not available today. If and when they ship, this page will be updated before they are enabled, and they will remain opt-in.

Contact

Questions about this policy: hello@tipto.ai.