Last updated: August 24, 2026
The short version: your books, your audio, your reading activity, and your AI conversations stay on your Mac. We collect the minimum needed to run accounts, subscriptions, and crash reporting - never the contents of what you read. We do not sell data, show ads, or train AI models on anything of yours.
Unknown is built so that the private parts of reading cannot leave your machine, because there is nowhere for them to go - the app processes documents entirely on-device and no Unknown server exists that receives them.
A few narrow things do involve a network, and we list all of them here.
If you sign in (Sign in with Apple or Google), we receive your name and email address through Firebase Authentication. This exists so your subscription can be restored across devices. We use it for nothing else - no marketing emails, no profiling.
Subscriptions are processed by RevenueCat and Stripe. They handle payment details; we never see or store your card number. We receive your subscription status linked to a pseudonymous identifier.
If the app crashes, a crash report (stack trace, app version, macOS version, device model) is sent to Sentry so we can fix it. If you file a bug report from inside the app, the app log you choose to attach is included; logs are designed to describe what the app did, not what your documents say.
We record which features are used (for example, that a narration was started or a mind map was created) via PostHog, with app version and device model. These events never include document contents, document names, page text, voice audio, or chat messages.
The app periodically checks unknown.ac for updates (via Sparkle). This is a standard web request and involves no account or personal data beyond your IP address, which is not logged by us.
Connecting a calendar is optional. If you connect Google Calendar so Unknown can schedule listening sessions around your meetings:
Calendars connected through macOS (Apple Calendar via EventKit) are read with the system permission you grant and are handled entirely on-device.
unknown.ac uses Google Analytics and Ahrefs Analytics to measure aggregate traffic (pages viewed, approximate region, download clicks). No account is needed to browse or download, and website analytics are never linked to your in-app identity.
Local data (books, audio, chats, reading progress) lives on your Mac and is yours to delete; uninstalling the app removes it. Crash reports and analytics events are kept only as long as needed to maintain the app. To delete your account and everything tied to it (authentication record, subscription linkage, diagnostics), email support@unknown.ac and we will complete the deletion within 30 days.
The few network calls the app makes use TLS. Calendar tokens live in the macOS Keychain. Locked books require Touch ID. Because documents are processed on-device, there is no server-side copy of your library to breach.
Unknown is not directed at children under 13, and we do not knowingly collect personal information from them.
If this policy changes, the latest version will always be at this page with an updated date. We will not weaken the commitments in section 1 and section 5 without asking for your consent in the app.
Questions or requests? Reach us at support@unknown.ac.
← Back to Unknown