offloadSign in

Last updated 14 September 2026

Privacy

offload only works if you put real material into it, and you should only do that if you know where it goes. This page says where it goes.

The short version

This section is not a legal document. It is our attempt to summarise this page to make it more readable. Where the two disagree, the sections below are the ones that count.

  • What you upload is yours. We do not sell it, rent it, trade it or hand it to advertisers. If offload is ever bought, the buyer is bound by this page as it stands, and section 8 says what that means.
  • We do not train AI on what you upload. That stays off unless you explicitly allow us to improve the product with your content, and you can withdraw that at any time.
  • Delete anything, whenever you want. A single upload, a thread, or the whole account. It leaves our live systems immediately and our backups within 30 days. One exception: what you put into a thread you share stops being yours alone. Section 10 explains why.
  • Your photos, screenshots and voice notes are encrypted before we store them, with a key our storage provider never receives. The text in offload is not. We plan to encrypt that too.
  • No ad trackers and no cookie banner. Nothing on our site follows you anywhere else.
  • A few companies help us run offload. All of them are named below, none of them may use what you upload for their own purposes, and we do not add one quietly. We may also be obliged by a court to hand over your content, and section 7 describes how we handle that.
  • We only look at your content to fix problems. Someone here may read it when you ask us for help, or when we are chasing a bug that needs it. Not otherwise.
  • You can take it all with you. One export, readable without offload.

1. Who we are

offload is run by [legal name], a [state] corporation at [registered address]. We decide what happens to the information described here, which makes us the controller of it under European and UK data protection law, and a business under the California Consumer Privacy Act.

Write to us about anything on this page at hello@offload.club. A person reads it.

To fill in before this is published: our EU and UK representative under Article 27, once we have users in either place. [representative, or a note that we have none yet]

2. What this covers

The offload apps for iOS and Android, the offload web app, and this website. It does not cover anything a link from here takes you to, including the companies listed in section 6, who each have their own policy.

3. What we hold

What you give us

  • Your email address, which comes from Apple or Google when you sign in. There is no password, so we never hold one.
  • Your name. Either the one Apple or Google passes along when you first sign in, or the one you type, and you can change it at any time in Settings.
  • Everything you upload. Notes, links, screenshots, photos, voice notes, and what you say to offload in the composer. This is the product, so we keep it.

What offload makes from it

  • The threads what you upload is sorted into, and the tags, dates and amounts pulled out of it.
  • Transcripts of your voice notes, and text read out of screenshots.
  • Notes, which are short sentences about a thread: something that is true about it, or how you want it handled. You write some of them and offload writes others from what you dumped, and they are what lets it be useful without your whole history in front of it. Plus the numeric representations that make search work.

The same advice first run gives you: we do not recommend sharing passwords, card numbers or government IDs in any AI tool. Nothing in offload is built to handle them, and no assistant is the right place to keep them.

What comes from an app you connect

If you connect an email account, a calendar or a browser, offload reads what is there, keeps what it describes, and throws the rest away. We store that plus a reference we can use to fetch the original again on demand. We do not keep the raw message, the raw event or the raw page. What you upload is something you chose to hand us. A connected inbox is not, and we treat the two differently on purpose.

A connected calendar is the one that also goes the other way. You can ask offload to add, change or delete an event, and it writes to your calendar to do it. It never writes anywhere else: not your mail, not your files. When a change would reach somebody else, because the event has guests or the calendar is one you share, offload asks you first and tells you who will find out. When it reaches nobody but you, it just does it and you have a few seconds to undo.

An event brings other people with it. If somebody is invited to an event on your calendar, offload keeps their name and whether they accepted, so it can tell you who you are seeing. It keeps their email address only for an event offload itself created with guests, because changing that event later means telling those guests again. Everyone else’s address is dropped before anything is stored. These details are kept for as long as the event is, which is until you delete it. We keep what a calendar describes and none of the event’s own description text.

What we collect because software has to run

  • Your IP address and a description of your browser or device, stored against your sign-in sessions so we can show you where you are signed in and end a session that should not be there.
  • Server logs. Which request, how long it took, whether it worked. Never what was in it.
  • Product events, such as joining the waitlist or finishing first run. These carry a random identifier for your account rather than your account id or your address. Deleting your account destroys the mapping, after which every event we have already recorded is permanently unattributable to you.

4. Why we hold it, and on what basis

If you are in the UK or the European Economic Area, the law asks us to name a legal basis for each purpose. These are ours.

WhyWhatBasis
To give you offload at allYour account and everything you uploadPerformance of our contract with you
To keep you signed in and keep others outSessions, IP address, device description, rate limitsOur legitimate interest in a secure service
To email you about your accountYour email addressPerformance of our contract with you
To find out whether offload worksPseudonymous product events and server logs, never contentOur legitimate interest in improving the product
To hold the private material people inevitably uploadHealth, money, and anything else personal that lands in a threadYour explicit consent, given on the last screen of first run
To improve offload using your own contentWhat you upload, only if you switch this onYour consent, and off until you give it
To answer a lawful request or defend a claimWhatever is strictly relevantLegal obligation, or our legitimate interest

Where the basis is our legitimate interest, you can object, and section 14 says how. Where it is consent, you can withdraw it at any time without losing anything else.

The consent on the private material row is the one that matters most, and it is why first run ends with two tick boxes rather than a button. Some of what people upload will be health, money, beliefs or relationships, because those are the subjects worth not forgetting, and European law asks for consent that is explicit and specific before anyone holds them. That is the tick. It is separate from acknowledging this page, and if you withdraw it we can no longer run offload for you, so withdrawing it means closing the account and taking your export with you.

5. AI, and what it does with what you upload

Sorting an upload into a thread, pulling a date out of a sentence, transcribing a voice note and answering you in the composer are all done by AI models we call on your behalf. To do that, the relevant part of your content is sent to the companies in the table below.

  • They do not train on it. Every company in the table below publishes terms that rule out using what an API sends them to train or improve their own models, and not publishing such a term disqualifies a company from this list. We rely on those published terms rather than on separately negotiated ones, which is worth knowing because a published term can be changed by the company that published it. We check them, and section 17 says what happens when something material moves.
  • Only what the task needs goes out. Not your account, not your history, not your other threads.
  • Our own monitoring never sees content. The tooling we use to watch cost and reliability receives identifiers, model names, token counts, timings and outcomes. No prompts, no responses, nothing you wrote.
  • We do not train models on your content either, and there is nothing in offload today that does. If that ever changes it will be a switch that starts off, described here first, and yours to leave alone.

Looking things up. Some of what you dump needs a fact offload does not hold: what day a holiday falls on, what the weather will be, what a link you pasted actually is. When that happens, two things leave.

  • A search carries words you wrote. It is built only from the words of the thing you just dumped, never from your other threads, your notes, or anything anyone else put in a thread with you. It goes to Anthropic, who run the search, and from there to a search index.
  • A link you paste is opened. The site you linked to receives a request from us. It is not a company you picked, and it can see that somebody asked for that page, along with anything already in the address you pasted.
  • offload only opens links you gave it. Not one it thought of, not one that appeared inside a page it read, and not one someone else wrote into a thread you share.
  • What comes back is not kept. What is stored is the answer it needed, such as a date, and the address it came from. The page itself is not stored anywhere.
  • A search may carry your approximate location. Today that is a country: the one in Settings, or the one you pick when offload asks which country a question is about, because a thread of yours says you are somewhere else. It goes in the question so a date or a forecast is the one where you are. It is two letters and nothing else about where you live: not your address, not your town, and never taken from your IP or your phone. Leave it unset and offload tells itself it does not know, which is why an answer that needs a country is sometimes "Not sure." rather than a guess.
  • A link can bring its picture, and the picture comes from the site. When offload reads a link you pasted, it keeps the address of the image the page publishes about itself, so the row shows the photo instead of a symbol. We do not store the image. Your device loads it from that site each time the row is on screen, which means the site can see your IP address and when you looked, the same as if you had opened the page. In a thread you share, that applies to each person who sees the row. Turn off Read links I paste in Settings and no new link keeps one.
  • Both of these are switches, in Settings, and either can be off. With both off, nothing about what you dump reaches a search or a site.
  • We record that a lookup happened, and not what it was. What kind of thing was looked up, whether it helped, and what it cost. Never the words you searched with and never a link tied to your account.

Automated decisions. Filing is automatic, which is the whole point of offload, but it produces no legal or similarly significant effect on anyone. Every decision it makes is visible to you and reversible by you, and anything filed in the wrong place can be moved afterwards. We do not profile you to decide anything about you.

6. The companies that help us run offload

CompanyWhat they doWhat they receive
RailwayRuns our servers and our databaseEverything, because it is where offload runs
Cloudflare R2Stores files and our nightly backupYour photos, screenshots and voice notes, encrypted, and never a key
AnthropicClaude, which does the sorting and the conversation, and which runs the searches and opens the links described in section 5The part of your content a given task needs, the words of a search when offload looks something up, and your country when you have set one
The site a link points toShows the picture that page publishes about itself, on the row, when offload read the linkNothing we send. Your device asks that site for the image, so it sees your IP address and the time, the same as opening the page
Voyage AIMakes what offload holds searchable, including its own replies to youThe text being indexed
AssemblyAITranscribes voice notesThe audio of a voice note
LangfuseTells us what our AI calls cost and whether they workedIdentifiers, timings and counts. No content, by rule
ResendSends the handful of emails we sendYour email address and the email itself
Google CalendarOnly if you connect one: reads your calendars, and writes the changes you ask forThe events in the calendars you turn on, and the events offload writes for you. A separate connection from signing in, which you can end at any time
Apple and GoogleSign you inThey tell us your verified email address and your name. We tell them nothing about what you upload

Each of them is under a contract that lets them process this only to provide their service to us, and never for themselves. We do not add a company that will hold your content without updating this page and telling account holders before the change takes effect.

7. If someone else asks for your content

The companies in section 6 are not the only way something could leave offload. A court, a regulator or the police can compel disclosure, and no privacy policy can promise otherwise. Here is what we do.

  • We give what the law requires, not more. A request for an account gets that account. It does not get a thread other people are also in, and it does not get an adjacent account because it would be convenient.
  • We check that a request is valid before we answer it. A demand without the paperwork behind it gets refused, and we push back on one that is overbroad rather than treating any letterhead as an order.
  • We tell you, unless we are forbidden from telling you. If we can say that your content has been asked for, we will, before we hand anything over if there is time and afterwards if there is not. Where a gag order applies we say nothing, because that is what a gag order is, and we tell you the moment it lifts.
  • We cannot hand over a key we do not have. That cuts both ways: your photos, screenshots and voice notes are encrypted, and your text is not. Section 12 is precise about which is which.

8. If offload is bought or merges

Companies get bought, merge and occasionally wind up, and personal information usually moves with the rest of the business when they do. Our commitment:

  • A buyer inherits this page as it stands. If offload is acquired, merges, or its assets are sold, whoever ends up holding your content is bound by the policy you are reading, not by whatever policy they already had.
  • Anything weaker needs your agreement first. A new owner who wants to do something this page does not allow, including anything that would count as selling your information, has to ask you and get a yes. Not a notice, not a banner, not continued use of the app. A yes.
  • You get told before it completes, and you can leave with everything you put in. We email account holders ahead of a change of ownership, with enough time to export everything and delete the account first if that is what you want.

9. Where it is kept

offload runs in the United States, in [region]. If you are in the UK or the European Economic Area, that means your information is transferred out of it. We rely on the European Commission's standard contractual clauses, and the UK addendum to them, for those transfers, and we hold the same terms with each company in section 6.

10. How long we keep it

  • What you upload: for as long as your account exists. offload does not age your uploads out or thin them down over time. Being able to find something from three years ago is the product, so nothing expires on a clock. This covers what you put in: your dumps, the conversations they arrived in, and your photos, screenshots and voice notes.
  • What offload works out about you: for as long as it is still true. The short notes it keeps on a thread are its picture of that thread, not a record of what you said, and it revises them. Once a day it goes over them: it merges two that say the same thing, it combines ones that belong together, it drops what has stopped being true, and it adds what it learned from your conversations that day. Notes it wrote itself it can also remove. A note you typed it can set aside, so it stops acting on it, and it cannot delete your words. All of it is on the thread, in front of you, yours to correct, and yours to delete where you wrote it: in a thread you share, the rule below holds here too, and nobody deletes what somebody else wrote.
  • Anything you delete: immediately, then 30 days. It goes from the live database and from file storage as soon as you ask. Our backups, which exist so a bad day is recoverable, roll over within 30 days, and after that it is gone from those too.
  • Product events: kept, but detached. Deleting your account destroys the identifier that connects them to you.

Deleting your account, and shared threads

Deleting your account removes what you kept privately, including your notes, and your membership of every thread you were in. There is one deliberate exception: what you put into a thread you shared with other people stays in that thread, and that includes the notes you added to it. Understand this before you share anything, so here is the reasoning behind it.

Sharing is a deliberate act, on one thread, with one person you already know. offload has no public links and nothing is shared by default. You pick a thread and you pick a connection, someone you and they have both agreed to be connected to, and you do it again for the next thread. Nothing arrives in a shared thread by accident.

What you put in a shared thread becomes part of a shared record. The moment you add something to a thread with other people in it, it stops being only your information and becomes theirs as well: their record of a trip you are planning together, their copy of the answer to a question they asked, the context for everything they added after it. Taking your part back out later would not return the thread to some earlier state. It would leave the other members with a conversation full of holes and no way to know what used to be there, and it would delete information about them, on your instruction, without their agreement.

So nobody owns a shared thread, including us. A thread has members and no owner. There is no role that can throw someone out, take it over, or empty it, and being the person who created it grants nothing beyond having been the first one in it. Nobody, including you, can delete what somebody else wrote while that person is still in the thread. That symmetry is the point: the protection you give up over your own contribution is exactly the protection you get over everybody else's. When somebody leaves a thread, or deletes their account, what they left in it becomes the thread's. Anyone still there can edit or remove it. We think that is the right way round: the protection exists so a thread cannot become a place where someone else destroys your work, and once you have gone there is no work of yours left to protect, only a thread other people still use carrying things none of them can tidy.

What you keep is the right to leave, and the thread ends with its last member. You can take yourself out of a shared thread at any time. Your membership and your access go, and the other members' view is untouched. When the last member leaves, the thread and everything in it is deleted, which is the only moment at which nobody is left who could read it. Nothing is kept forever against everyone's wishes. It is kept for as long as somebody in it still wants it.

We tell you all of this at the moment you share a thread, not afterwards, so the trade is one you make on purpose. If you would rather keep something entirely yours, keep it in a thread you have not shared, where deleting it deletes it.

11. Other people

  • You can share a thread with a connection, which is someone you have both agreed to be connected to. Everyone in a thread can read everything in it and add to it, and nobody can delete what they did not write themselves.
  • Everyone in a shared thread sees your name and the initials taken from it, next to what you add. Changing your name in Settings changes what they see.
  • There are no public links. Nothing in offload can be handed to someone who is not in the thread, and nothing is visible to anyone you have not connected to.
  • Leaving a shared thread takes you and your access out of it. The other members' view is untouched.

12. Security, described exactly

We would rather make a narrow claim that is true than a broad one that sounds better. Precisely:

What is encrypted by us

Your photos, your screenshots and the audio of your voice notes are encrypted by offload before they are stored, each under its own key, and our storage provider never receives a key. They hold ciphertext and nothing else.

What is not, and what that means

The text in offload is not encrypted by us. Titles, bodies, transcripts, notes and search indexes sit in our database as ordinary text, protected by our provider's own disk encryption and by access control, the way most software works. Three consequences follow from that:

  • Someone who obtained a copy of our database would be able to read text content in it.
  • What a file says is not protected even where the file is. A voice note's audio is encrypted while its transcript is ordinary text, and the same is true of the words read out of a screenshot.
  • None of this defends against a compromise of the running service itself.

We plan to encrypt text as well. This section changes when that ships, and section 17 says how we tell you.

The rest of it

  • Every request is authorised on the server, per row, against the account that owns it. A client is never trusted to decide what it may see.
  • Content never leaves in a log, an error report, an analytics event or an AI trace. Those carry identifiers, counts and outcomes only, and that rule is enforced in the code rather than remembered.
  • Only a small number of people can reach production, and they read your content when you have asked for help or when a specific fault requires it. Not to look around.
  • Backups run nightly and are encrypted. We can restore to a point in time if something goes badly wrong.

13. What you can change

offload is an invite-only beta as of 14 September 2026, and none of the controls below is built yet. Email us and we will do any of it by hand, usually the same day. Nothing here is on unless the text says so.

  • Improve offload with my data. Off. Nothing you upload is used to train anything unless you turn this on yourself.
  • Let offload notice patterns. On. This is what lets it work out that the brackets belong to the bookshelf. It stays inside your own account.
  • Crash and usage reports. Counts and failures, never content.
  • Export everything. One file, readable without offload.
  • Delete. A single upload, a thread, or your whole account.

14. Your rights

Wherever you live, you can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it, and we will not treat you differently for asking. Write to hello@offload.club. We answer within 30 days and usually much sooner. We may need to confirm you are who you say you are before we act, which for most requests means asking from the address you signed in with.

If you are in the UK or the European Economic Area

You have the right to access your information, to have it corrected, to have it erased, to restrict what we do with it, to object to processing we base on a legitimate interest, to take your information elsewhere in a portable form, and to withdraw any consent you have given without that affecting what came before it.

One limit on erasure, and it is the one in section 10. We will delete everything of yours that is yours alone, on request, without asking why. We will not delete what you put into a thread you shared with other people, because that is also their information and erasing it would be erasing theirs at your request. We will always remove you from the thread, which takes away your membership and your access, and the thread and its contents are deleted when the last member leaves it. If you think that balance is wrong in your particular case, tell us and a person will look at it rather than a policy.

You also have the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority for the country you live in. We would rather you came to us first, but it is your call.

If you are in California

You have the right to know what we collect and why, to a copy of it, to have it deleted, to have it corrected, and not to be discriminated against for exercising any of that. You may use an authorised agent.

We do not sell your personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act, and we have not in the twelve months before the date at the top of this page. There is therefore nothing to opt out of, and no "do not sell" link, because there is no sale.

Some of what you upload may count as sensitive personal information. We use it only to give you offload, which is a purpose the Act permits without a separate right to limit, and never to infer anything about you for anyone else.

If you are elsewhere in the United States

Several other states now give their residents broadly the same rights. Rather than checking which state you are in, we apply the list above to everyone.

15. Cookies

offload sets what it needs to keep you signed in and to stop the sign-in and waitlist being abused. That is the entire list. There is no advertising cookie, no third-party analytics running in your browser and nothing that follows you to another site, which is why this page is not interrupted by a banner asking you to accept something.

16. Age

offload is for people aged 18 and over. We do not knowingly hold information about anyone younger, and if we find out that an account belongs to someone under 18 we delete it. If you think that has happened, tell us at hello@offload.club and we will deal with it.

17. Changes to this page

When we change this we change the date at the top. If a change actually matters, meaning it affects what we do with your content rather than how a sentence is worded, we email account holders before it takes effect rather than relying on you to notice.

18. Contact

hello@offload.club, or [postal address].