AnnotateIt

Privacy Policy

Last updated: 2026-09-19

Cloud upload is not required for manual annotation or local AI tools. Optional external connections send the content needed for the requests you choose to make.

This policy covers AnnotateIt for Web, Windows, macOS and the native iOS/iPadOS app, as well as the AnnotateIt website. Available connections differ by platform. Local project storage, optional external processing and infrastructure requests are described separately below.

Privacy by Platform

Local annotation and optional OpenAI or Anthropic connections
VersionLocal processingOptional external AI
WebProjects and supported local AI tools run in your browser.OpenAI API or Claude API using your own provider key. Codex and Claude Code CLI connections are not available in the web app.
WindowsProjects and local AI tools run on your PC.OpenAI API or Claude API using your own provider key, or ChatGPT / Claude Code through the corresponding separately installed CLI that you choose to connect.
macOSProjects and local AI tools run on your Mac.OpenAI API or Claude API using your own provider key, or ChatGPT / Claude Code through the corresponding separately installed CLI that you choose to connect.
Native iOS/iPadOSProjects and the local AI tools supported by the app run on your iPhone or iPad.No AI Assistant API-key or desktop CLI connection is available.

The web app opened in a browser on an iPhone or iPad follows the Web row, not the native iOS/iPadOS row. Optional connections are not needed to use manual annotation or local AI tools.

For the shared macOS and iOS/iPadOS App Store record, see the App Store privacy explanation, which describes the differences between the Mac and native iPhone/iPad apps.

Your Project Content

Projects, imported or camera-captured images and videos, dataset archives, labels, annotations, settings and exports are stored on your device or in browser-managed local storage. Camera video is recorded without microphone audio. The current production product does not provide cloud accounts, project sync or hosted dataset storage, and it does not upload project content to an AnnotateIt backend.

You control the lifecycle of this content. It remains until you delete the project, clear the application's storage, uninstall the application or otherwise remove it from your device. Browser and operating-system backup behaviour is controlled by your platform settings.

Local AI and Model Delivery

Local AI-assisted annotation runs on your device. Native apps include built-in model files; additional models may be downloaded where supported. The web app downloads the application, model files and runtimes needed for its local tools. Model delivery may use models.annotateit.ai on Cloudflare R2/CDN or the source shown for the selected model, such as Hugging Face. These downloads create ordinary request metadata, including the requested file, IP address, headers and timestamps. They do not upload your images, local-tool prompts, labels or annotations. A downloaded model still runs locally.

Optional OpenAI and Anthropic Connections / Ask AI

Ask AI is an optional online integration, separate from local AI tools. On Web it uses your own OpenAI or Anthropic API key. On Windows and macOS you may use your own API key or connect ChatGPT / Claude Code through the corresponding separately installed CLI. Using a plugin, external executable or your own account does not make these requests local: the selected content is sent to the selected provider (OpenAI or Anthropic) to answer your request. The native iOS/iPadOS app does not provide this integration.

API requests are sent from your browser or desktop app to the selected provider (OpenAI or Anthropic). Desktop account requests pass through the selected Codex executable to OpenAI, or through Claude Code to Anthropic. These requests are not routed through an AnnotateIt project-processing server. The selected provider receives the submitted content and ordinary connection metadata. Its processing, retention and data controls depend on the service and account you use; see the OpenAI Privacy Policy or the Anthropic Privacy Policy, and the terms and settings of the provider and API or CLI account you select. This policy does not promise that all accounts have the same retention or model-training settings.

What is sent

Chat requests include your messages, conversation context needed for the request, and requested project information. That information can include project names, labels, annotations and results of application tools used to answer your request.

When you send a message with the image attachment enabled, the request also includes a JPEG preview of the current image or paused video frame, up to 1600 pixels on its longest side, its original dimensions, project labels and annotation context. A single-image request does not send the entire video or dataset. In external-assistant annotation mode, the image is attached by default; moving to another image or frame enables the attachment for that new media. Opening the panel alone does not send image pixels.

Starting Auto-annotate with ChatGPT or Claude sends each eligible still image in the scope you select, together with your instructions and project labels, through the connection you selected. The app sends JPEG previews up to 1600 pixels on the longest side with their original dimensions. A batch can therefore send multiple images. Opening the batch dialog alone does not upload them. Returned annotations remain local Pending AI Review drafts until accepted.

Your controls and credentials

You choose whether to configure and use an external connection. Before sending, review the attached image and, for batch work, the selected scope. You can disable the image attachment, stop an ongoing request or batch, remove the saved API key, or sign out of the connected CLI account. Disabling an attachment still allows your text and requested project context to be sent. Stopping a request prevents further work where possible; it does not recall content already transmitted.

On Web, your API key is saved in local storage in that browser until you remove it or clear that site's storage. On Windows it is held in Windows Credential Manager; on macOS it is held in Keychain. The desktop app requests operating-system credential storage for its Codex connection. OpenAI and Anthropic API keys are stored separately. Claude Code uses its existing CLI authentication on this machine; signing out through AnnotateIt also signs that CLI out. Connection settings such as the provider, model and executable path are stored locally; the connected account's email and plan may be displayed in the app. Signing out or removing a key does not itself delete content already held by the external provider; use that provider's account controls or privacy-request process for those records.

Manual annotation and local AI tools remain available without these connections. See the Ask AI guide for setup and review controls.

Optional Connected ML Runner

In versions that include ML Pipelines, starting a supported training or inference job sends the selected dataset bundle to the runner you configure. Training bundles contain selected media and annotations. A runner on your machine processes them there; a remote runner receives those bytes and operates under its own retention and access controls. This optional transfer is separate from local annotation and Ask AI. Review the destination and selected dataset before starting a job. The runner token is held in app memory for the session and is not included in a backup.

Optional Network Cameras — Windows and macOS

When you add an IP camera source in the desktop app, AnnotateIt connects directly to the camera address you enter and decodes its stream on your machine. The camera password is held in memory for the session and sent to the camera when authentication is needed; it is not persisted or included in backups. The stream is not relayed through an AnnotateIt service.

Web Infrastructure Data

The web application is delivered through Cloudflare Pages, and model files are delivered through Cloudflare R2/CDN. The separate marketing website at annotateit.ai is also hosted on Cloudflare Pages. Like other Internet infrastructure providers, these services may process IP addresses, requested URLs, request headers, browser or device information, timestamps, and security or operational logs needed to deliver and protect the services.

The current production application does not enable advertising trackers, cross-site tracking or cloud product telemetry, beyond the cookieless measurement described below.

Website and Web Application Analytics

The marketing website at annotateit.ai and the web application at app.annotateit.ai use Cloudflare Web Analytics. It is cookieless: it sets no cookies, stores nothing in your browser, does not create a persistent identifier and does not track you across other sites. It records aggregated page views and route changes, the referring site, the requested path, country, browser and device class, and Web Vitals performance measurements. The marketing website (annotateit.ai) additionally records first-party, cookieless interaction events — which call-to-action or link was clicked, as a non-personal label, together with the page path — recorded through a first-party endpoint and stored in Cloudflare Workers Analytics Engine. These events set no cookie, create no persistent identifier, and never include your project content, form input or email address.

This measurement is not present in the desktop or mobile applications, which contain no analytics component of any kind. It is also not sent when the web application is used offline, because the measurement script is loaded from the network. Your project content — images, video, labels, annotations and exports — is never part of these measurements.

Support and Security Communications

If you email support, privacy or security contacts, we process the email address, message, headers and attachments you intentionally provide. Do not send private datasets or personal data unless they are necessary and an approved transfer method has been agreed.

Support requests are retained for up to 24 months after the last correspondence. Security reports may be retained for up to five years to document remediation and protect the service. Records may be kept longer where required by law or necessary to establish, exercise or defend legal claims.

Purposes and Legal Bases

  • Delivering the application and model files: performance of the service you request and legitimate interests in operating the product.
  • Running an optional external AI request or ML job: carrying out the operation you request through your selected connection. Where consent is required for a transfer, it must be given before that transfer. The receiving service's own purposes and legal bases are described in its policy.
  • Security and abuse prevention: legitimate interests in protecting users, infrastructure and the service.
  • Measuring website and web application usage: legitimate interests in understanding aggregate traffic and page performance to improve the product, using cookieless measurement that does not identify you.
  • Responding to support, privacy and security messages: taking steps at your request, providing support and legitimate interests in maintaining the product.
  • Compliance records: compliance with legal obligations and establishment, exercise or defence of legal claims.

Infrastructure Providers and International Processing

Cloudflare, model-delivery hosts and email providers may process request or communication data outside your country. If you choose an external AI connection or a remote ML runner, its operator may also process the content you send outside your country under the terms and safeguards applicable to that service. See Providers and external connections for destinations and policy links. User-selected services are distinguished there from infrastructure operated for AnnotateIt; they are not all described as AnnotateIt subprocessors.

Your Choices and Rights

You can delete project content directly in the application or by clearing its local storage. Depending on applicable law, you may also request access, correction, deletion, restriction, portability or objection for personal data processed through support or infrastructure records. You may lodge a complaint with your local data-protection authority.

Children

AnnotateIt is designed for professional, educational and research workflows and is not directed to children. We do not knowingly request personal data from children.

Changes

We update this policy when supported platforms, data flows or providers change, including before introducing new transfers of project content. The date on this page identifies the policy revision.

Contact