Skip to content

Legal

Corixa App Privacy Policy

Last updated: September 27, 2026

🔒 Local-First Storage - You Control Your Data
Privacy-First by Design
Corixa stores all your content locally on your Mac using Apple's SwiftData framework. Your saved pages, videos, notes, and categories remain entirely on your device. Summaries send a video's or page's link and its transcript through our proxy server, which does not store them. You stay in control of your data.

Overview

Corixa ("we", "our", or "us"), developed by Halldor Gislason, operates a macOS application for digital content management. This privacy policy explains our commitment to your privacy and how Corixa handles your information with a local-first approach.

Our Privacy Commitment

Corixa was created for users who value privacy and control over their digital content. We adhere to three core principles:

Local-First Storage: All content stored on your Mac with SwiftData
Minimal Data Collection: We only collect what's necessary for features you enable
Complete Transparency: Clear disclosure of every data connection

What Corixa Does NOT Do

To be absolutely clear, Corixa does not:

  • Store your content on our servers - Everything stays on your Mac
  • Sell your data - We have no data marketplace and share nothing for advertising
  • Track your browsing - Browser extensions only activate when you choose to save content
  • Log your content - AI processing happens through proxy without content storage
  • Require an account - No registration, no user profiles, no authentication (except for optional YouTube sync)
  • Use invasive analytics - No behavior tracking, no usage profiling

How Corixa Works

Local Data Storage

All your Corixa content is stored locally on your Mac using Apple's secure SwiftData framework:

  • Saved Items: Web pages, videos, documents stored in local database
  • Categories: Your organizational structure stored locally
  • Thumbnails & Images: Cached locally for offline access
  • AI Summaries: Generated summaries stored locally in database
  • Settings & Preferences: Stored in macOS UserDefaults
  • Backups: Optional local backups you control

Data location: ~/Library/Application Support/io.halldor.Corixa/

Browser Extensions

Corixa provides browser extensions for Safari and Chrome:

  • Safari Extension: Included with the app, communicates via App Groups (local only)
  • Chrome Extension: Available on Chrome Web Store, communicates via native messaging (local only)
  • Extensions only access page content when you explicitly click to save
  • No background tracking or data collection
  • Page metadata (title, URL, description) extracted locally
  • Content sent directly to your Mac app, never to external servers

YouTube Integration

When you choose to sync YouTube playlists and subscriptions:

  • You sign in on Google's own page (OAuth); Corixa never sees your Google password
  • OAuth tokens stored securely in macOS Keychain
  • Corixa requests read-only access to your YouTube data
  • Sign-in tokens are exchanged and refreshed through our proxy server, which holds Corixa's Google app credentials; some playlist requests also pass through it. The proxy does not store tokens or playlist data
  • Video metadata stored locally in your Corixa database
  • You can disconnect and delete all YouTube data at any time

What we access: Playlist names, video titles, thumbnails, descriptions, channel information
What we don't access: Your YouTube watch history, recommendations, or private viewing data beyond what you explicitly sync

AI-Powered Features

Corixa creates transcripts and summaries of the content you save:

How AI Processing Works

  • Secure Proxy: All AI requests routed through our proxy server at corixa.io
  • No Content Logging: Proxy server does not store your content; it keeps standard access logs (IP address, time, request path)
  • Temporary Processing: The video or page link goes to Supadata for the transcript, and the transcript to Anthropic (Claude) for the summary
  • HMAC Authentication: Requests authenticated but not associated with your identity
  • Immediate Return: Summaries returned to your Mac and stored locally
  • Automatic by default: New YouTube videos are analysed automatically when you save them: the video link goes to Supadata for the transcript and the transcript to Anthropic for the summary. Turn off automatic content analysis in Settings and summaries only run when you ask

Third-Party AI Providers: When you use AI features, content is processed by:

  • Anthropic (Claude): For high-quality content summaries (Privacy Policy)
  • Supadata: Fetches transcripts for the videos and pages you save (Privacy Policy)

Anthropic does not use content sent through its API to train its models.

Backup & Restore

Corixa's backup system:

  • Creates backup files (.clearday-backup) on your Mac, with checksums that detect damage
  • You choose where backups are saved (local folder, external drive, etc.)
  • No cloud backup service - you control all backup destinations
  • Automatic backup reminders available (weekly/biweekly/monthly)

What Information We Collect

Information You Provide

  • Content You Save: URLs, page content, notes, categories (stored locally)
  • YouTube Authentication: OAuth tokens (stored in your Keychain; passed through our proxy only to sign in and refresh, never stored there)

Automatically Collected Information

  • Crash and performance reports: Sent to Sentry (EU data region) with technical details such as app and macOS version, device model and what the app was doing, so we can fix problems. They are not used for advertising or profiling
  • Feature Usage (Minimal): Basic feature enable/disable state for UI optimization

Information We Do NOT Collect

  • Your personal identity or contact information
  • Your browsing history beyond what you explicitly save
  • Your library, apart from the links and transcripts sent for summaries
  • Your YouTube viewing habits or recommendations
  • Location data
  • Advertising identifiers or fingerprinting

Data Sharing and Third Parties

We do not sell or rent your personal data. The only external connections are:

  • YouTube API: When you choose to sync (OAuth authentication, read-only access)
  • Supadata and Anthropic: Links and transcripts for summaries — automatically for new YouTube videos unless you turn that off
  • Sentry: Crash and performance reports
  • RevenueCat: Corixa Pro purchases through the Mac App Store
  • Proxy Server: Our own server for secure API routing (no content logging)
  • Chrome Web Store: If you install the Chrome extension (standard browser extension installation)

Your Rights and Control

You have complete control over your data:

  • Access: All your data is in ~/Library/Application Support/io.halldor.Corixa/
  • Export: Export all data as JSON via File → Export
  • Delete: Delete individual items, categories, or the entire database
  • Disable Features: Turn off AI features, YouTube sync, or any optional functionality
  • Backup Control: Choose backup location and frequency
  • Uninstall: Completely remove app and data by deleting the app and Application Support folder

Security

We take security seriously:

  • All local data protected by macOS file system permissions
  • OAuth tokens stored in macOS Keychain (Apple's secure storage)
  • Proxy server uses HMAC authentication
  • HTTPS for all external communications
  • No AI provider API keys in the application
  • Regular security updates via App Store or direct download

Children's Privacy

Corixa does not knowingly collect personal information from children under 13. The app is designed for general productivity use and does not target children.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Significant changes will be communicated through the app or our website.

California Privacy Rights

California residents: Under CCPA, you have the right to know what personal information we collect, request deletion, and opt-out of any data "sales" (we don't sell data). Since Corixa stores your library locally and collects little information, most CCPA provisions don't apply, but we respect all privacy rights.

European Privacy Rights (GDPR)

EU residents: Corixa's local-first architecture means minimal personal data processing. For optional features (YouTube sync, AI processing), you have rights to access, rectification, erasure, and data portability. Contact us to exercise these rights.

Questions or Concerns?

If you have questions about this privacy policy or how Corixa handles your data, contact us:

Email: privacy@corixa.io
Website: https://corixa.io
Support: Corixa App Support