Privacy Policy
For Sumi for iPhone · iPad · Last updated 29 August 2026
The short version
Sumi collects nothing. It has no account system, no analytics, no advertising, no third-party SDKs, and no networking code of any kind. Your notes are files on your device — or in your own iCloud Drive, if you turn that on. The developer has no access to them and no way to obtain them.
Who this policy is from
Sumi (“the app”) is developed and published by Shawn Chua, trading as Beem. In this policy “we” means that developer, and “you” means the person using the app. Questions about anything below can go to support@beem.im.
Information we collect
None. The app does not collect, transmit, sell, share or otherwise process any personal data. Specifically, it does not collect:
- your name, email address, phone number, or any other contact detail;
- account credentials — there are no accounts and no sign-in;
- the contents of your notes, their titles, or your search queries;
- usage or analytics data, session recordings, or crash reports;
- advertising or marketing identifiers, and it does not track you across apps or websites belonging to other companies;
- location, contacts, photos, calendars, health data, or your device's camera or microphone — the app never asks for these permissions.
On its App Store listing, Sumi is declared under Apple's privacy questionnaire as Data Not Collected.
What the app stores, and where
Your notes
Each note is a separate file, encrypted on your device with AES-256-GCM before it is written. By default these files live in the app's own Documents folder; one switch in Settings moves them to your own iCloud Drive instead. Their names are opaque identifiers and the titles are inside the encrypted contents, so the folder does not say what your notes are called.
Because they are encrypted, they are not files you can read by opening the folder. Export All Notes writes every one of them out as plain markdown whenever you want them, and Import Markdown brings files back in.
The key
A random 256-bit key, generated on your device the first time you open the app and kept in your Keychain. It is stored as a synchronizable item, which is how your other devices on the same Apple account get it. It is never transmitted to us; we operate no server that could receive it.
The search index
So that search can answer as you type, the app keeps a full-text index of your notes. Because that index contains every word of every note, it is held in memory while the app is open and written to disk only as a file encrypted with the same key as your notes. It contains the text of your notes and a small amount of bookkeeping — filenames, sizes, timestamps, your recent search queries, and whether you last had a note open for reading or for writing. It is created on your device, stays on your device, and is removed when the app is deleted.
Settings
Your preferences — appearance, whether the app lock is on, whether notes are stored in iCloud — are kept in the app's local settings store on the device.
iCloud Drive (optional)
Settings offers one switch: keep notes in the app's own folder, or in
iCloud Drive. If you turn iCloud on, your .md files are moved
into your iCloud Drive, in a folder named Sumi, under your own
Apple Account. Apple then syncs them between your devices in the ordinary
way, and Apple's handling of that data is governed by
Apple's Privacy
Policy rather than this one.
We are not a party to that sync. We operate no servers, hold no keys, and cannot read the contents of your iCloud Drive. The switch is reversible: turn it off and the files move back to the device. If iCloud is unavailable, the app falls back to local storage rather than losing notes.
Face ID and Touch ID (optional)
You can require Face ID or Touch ID to open the app. The biometric match is performed entirely by iOS in Apple's Secure Enclave. The app receives only a yes-or-no answer; it never receives, sees or stores your biometric data, and neither does anyone else.
When you share, print or export
Sharing a note (AirDrop, Mail, Messages, Save to Files, and so on), printing one, or exporting all of them sends that content wherever you direct it. A shared or exported note leaves as readable markdown — that is the point of it — so it is no longer encrypted once it is gone. Those destinations are outside the app, and what happens to your note there is governed by whichever service or app receives it. Nothing is ever sent anywhere without you initiating it.
Third parties
The app bundles no third-party analytics, advertising, attribution or crash reporting libraries. No data is shared with data brokers or advertisers. The only external system involved at all is Apple's iCloud, and only if you switch it on.
Retention and deletion
- We hold no data about you, so there is nothing for us to retain or delete.
- Emptying a note deletes its file. Deleting a note from the notes list deletes the file and removes it from the index.
- Settings → Privacy → Clear Search History erases the recent queries stored on the device.
- Deleting the app removes its local notes, its search index and its settings from that device.
- If you had iCloud storage turned on, the copies in iCloud Drive remain in your own iCloud until you delete them there. They stay encrypted, and without the key in your Keychain nothing can read them.
Your rights
Privacy laws such as the GDPR and the CCPA give you rights of access, correction, deletion, portability and objection over personal data a company holds about you. We hold none, so there is nothing to request — and no data of yours is ever sold or shared for advertising. Your notes are already portable: Export All Notes in Settings hands you every one of them as plain markdown, at any time and without asking us.
Children
Sumi is safe for users of any age. It collects no information from anyone, including children under 13, and contains no advertising, no in-app purchases, and no links out to user-generated content.
Security
Your notes are protected by the security of your device: iOS file protection, your passcode, and — if you enable it — the app's Face ID or Touch ID lock. Because nothing is transmitted to us, there is no server of ours that could be breached and no dataset of yours for us to lose.
Changes to this policy
If a future version of the app changes what it stores or does, this page will be updated before that version ships, and the date at the top will change with it. Material changes will also be noted in the App Store release notes.
Contact
Questions, corrections or privacy requests: support@beem.im. We aim to reply within a few business days.