Clasp privacy policy
Effective 8 October 2026. Clasp is provided by Kihyuk Hong. Contact hominot@gmail.com about privacy or this policy.
Your account and local files
Clasp requires an account to use Personal and shared workspaces. The desktop app saves preferences and downloaded workspace content on your Mac so that synchronized content can be opened and edited offline. Files and folders you choose to import are copied into the selected cloud workspace; Clasp does not automatically upload unrelated local folders. Exported files and original imported files remain under your control.
Clasp Cloud
Cloud uses Google Firebase Authentication, Google Cloud Run, and private Google Cloud Storage in the United States. Authentication processes your email address, password, account identifier, and verification state. Clasp does not write your password to its own application logs or library files.
Cloud sync processes the content you choose to store in cloud workspaces: PDFs, Markdown notes, highlights, attachments and images, folders, metadata, document history, recovery versions, and related identifiers. A generated device identifier and synchronization timestamps support delivery and conflict recovery. Account identifiers, email addresses, and any available display name support workspace membership and author attribution.
Sharing
Workspace members can access content according to their permissions. Live collaboration exchanges document changes and presence information with authorized members. A workspace owner controls membership and ownership. Choose carefully what to put in a shared workspace.
If you explicitly enable Anyone with the link on a page, people with its public web link can read its saved content and linked attachments without an account. Sharing starts restricted. You can revoke the link in Share; copies or downloads a visitor already made cannot be recalled. Public reads recheck the publisher’s account and workspace access.
Sign-in on your Mac
Sign-in credentials are held for the current app session by default. If you choose Keep me signed in using macOS Keychain, Clasp stores encrypted sign-in tokens on your Mac using macOS protection. You can remove saved sign-in in Settings. Account library caches remain locally available after sign-out unless you delete them.
Sign-in in your browser
When Stay signed in is off, browser sign-in tokens are held in session storage. Stay signed in stores them in that browser’s local storage until you sign out. Documents, PDFs, highlights, and attachments load when requested and are not cached persistently in browser storage. Browser reads and saves require a connection. The previous document cache is removed when the web app opens. The web interface at kihyukh.github.io/clasp/app/ is hosted by GitHub Pages; private workspace data is accessed through the authenticated Clasp cloud service. Live editing uses short-lived, single-use connection tickets there and a Secure, HttpOnly cookie on the cloud-origin frontend. Clasp never includes sign-in tokens in shared page links.
Optional ChatGPT assistance
If you connect ChatGPT in the desktop app, Clasp opens OpenAI’s sign-in page and keeps the resulting connection tokens encrypted on your Mac, separately for each Clasp account. When you send a message, the desktop app sends that message, the conversation needed to answer it, your selected source content, and any files you explicitly attached directly to OpenAI. Source content can include selected note passages or blocks, whole selected notes, and selected papers. A paper source includes available extracted PDF text, readable paper notes and highlights, and paper metadata; it does not send the original PDF or its images unless you attach that PDF. A separate research note beside the paper is included only when its own source chip is selected. Attached PDFs and supported images are sent as file contents; supported text and code files are sent as bounded text. These attachments stay in the assistant window and are not added to your library or cloud sync by attaching them. Clasp Cloud does not proxy those AI requests or store your ChatGPT tokens. OpenAI handles those requests according to your OpenAI account settings and its policies, including the OpenAI privacy policy. You can review plan usage and connected access in ChatGPT settings.
The assistant conversation is held in the Clasp window. Answers are added to your library only when you choose Save as note, Insert in open note, or Apply on a reviewed writing suggestion. Apply replaces the selected note content, which is saved and synchronized through the normal note-editing workflow. Saved answers and applied edits then follow your workspace’s normal sharing and retention settings. Disconnect ChatGPT to clear its local tokens and request revocation. If the network is unavailable, you can also revoke access in ChatGPT settings.
Clasp plugin connections
If you connect Clasp as a plugin in ChatGPT, you explicitly choose which cloud workspaces it can access and whether it may create or edit notes. Tool results send requested note content and paper information to ChatGPT on your behalf. Existing account and workspace permissions continue to apply. The service stores OAuth consent, workspace selections, scopes, expiration times, account identifiers, and token digests to verify and revoke the connection; it does not store plaintext MCP access or refresh tokens in those records. Disconnecting and revoking access blocks future calls but does not recall content already shared with ChatGPT. Expired or revoked connection records may remain for security and operational purposes.
Network requests and diagnostics
Paper lookup and import send the requested paper identifiers or URLs to the corresponding metadata or download providers. Links you open use your browser and the destination site's privacy policy. GitHub Pages and cloud infrastructure process connection information such as IP addresses, request paths, timestamps, and service errors to operate and protect the service. Clasp has no advertising or cross-app tracking. Operational endpoint metrics record predefined route names, HTTP method, status, duration, and completion outcome without account identifiers, request bodies, raw URLs, or IP addresses in these custom metrics. Hosting providers’ ordinary connection logs may still include IP addresses and request paths.
Optional website analytics
The Clasp desktop and web apps do not collect GA4 usage analytics and have no analytics opt-in prompt or menu. The public website asks before sending optional visit and download analytics to Google Analytics. You can allow or decline there, or change your choice using Analytics preferences in the website footer. Declining does not affect the service. Only your consent choice is saved on this device or browser. If you allow analytics, a random temporary identifier and session identifier measure website visits, download clicks and operating system. These identifiers stay in memory, rotate on restart or page reload and after 30 minutes of inactivity, and are separate from your account and sync identifiers. Old persisted analytics identifiers are removed.
Analytics never includes your IP address, location, account IDs, email addresses, note or paper contents, titles, search text, file paths, or credentials. The relay does not inspect or forward connection addresses or forwarded headers to Google. Advertising personalization and advertising data use are disabled. No third-party analytics script runs inside the note editor. Google processes analytics under its privacy policy. Hosting providers’ ordinary connection logs may still include IP addresses and request paths; those operational logs are separate from optional analytics.
Turning analytics off clears the temporary identifiers and pending events and stops future collection. Already delivered events are not recalled. Analytics is not tied to your account, so account deletion cannot identify previously delivered analytics events. Analytics retention is set by the property administrator; Clasp’s setup specifies a two-month event-data retention period. Operational monitoring remains separate and supports service reliability.
Deletion and retention
You can initiate account deletion inside Settings → Account. Workspace owners must transfer their workspaces first. Deletion removes your authentication account, personal cloud library, and membership profile. Shared documents and contributions remain part of the shared workspace under its owner's control, including document history; deleting an account does not delete another owner's workspace. Copies already downloaded by you or collaborators are not remotely erased.
Cloud Storage retains deleted objects in protected backups for seven days before expiration. Operational logs and a hashed identifier used to block stale sessions may remain for security and service integrity. If deletion is interrupted, the app blocks new cloud changes and lets you retry. Original local folders are never deleted as part of account deletion.
Your choices
Choose what to import into your workspace, manage workspace access, export your documents, remove saved sign-in, or delete your account. Contact the support address for access, correction, deletion, or other privacy requests. We do not sell personal information or use it for advertising.
Policy changes
This page will be updated when Clasp's handling of information changes. The effective date identifies the current policy.