Weave Privacy Policy

Effective date: September 16, 2026
Last updated: September 16, 2026

Weave is operated by Fernando Cervantes ("we," "us"). This policy explains what Weave collects, how it is used, who it is shared with, and the choices you have.

Weave is a personal, private library for videos you already have. It is not a social network, a publishing platform, or a content distribution service. Nothing you import is made public, shared with other users, or posted anywhere by us.


1. Summary


2. Content you import

Weave accepts video in two ways only:

  1. Import from your camera roll. You choose the files.
  2. The iOS share extension. You send a file to Weave from another app.

Weave does not download, scrape, stream, or fetch video from TikTok, Instagram, YouTube, or any other platform. It has no connection to those services and does not access your accounts on them. Every file in Weave arrives because you put it there.

Finding videos worth importing. If you grant photo library access, Weave checks your camera roll for videos added since it last looked and suggests the ones that look like short vertical videos, using properties such as shape, length, and date added. This check runs on your device. Nothing about the videos in your camera roll is transmitted to us, to our AI provider, or to anyone else, and no video enters your Weave library until you choose it. You can decline photo access, or grant access to selected videos only, and import through the share sheet instead.

You are responsible for the content you import. By importing a file you confirm you obtained it lawfully and have the right to keep a personal copy of it. See the Terms of Service for the full terms on this point.


3. What we collect

Content data. The video files you import, the compressed copies Weave creates, thumbnails, transcripts generated on your device, text read from video frames, and the titles, tags, topics, takeaways, and summaries generated from them. This is stored locally on your device. If you enable iCloud backup or sync, copies are stored in your own iCloud account under your Apple ID, which we cannot read.

Photo library data. If you grant photo library access, Weave reads properties of videos in your camera roll to identify candidates for import, and shows you thumbnails of them. This happens on your device, covers videos you have not imported, and is never transmitted, stored by us, or sent to our AI provider.

Your own writing. Notes you write on a video, and the moments you pull out of one, are stored on your device and in your own iCloud if you enable it. They are never transmitted to us or to any AI provider. See Section 4.

Search and usage input. Text and voice queries you enter, and the items you mark, save, or open. Voice queries are converted to text using Apple's speech recognition, which Weave requests on-device; we do not receive the audio. The resulting text is handled the same way as a typed query, which includes being sent for AI processing as described in Section 4.

Account data. Weave works without an account. If you choose to sign in with Apple, we receive an Apple user identifier and, if you allow it, the name and email address you choose to share. Your name and email address are stored only in the secure keychain on your device and are never transmitted to us. The Apple identifier is held by our backend provider so your account can be recognized across devices. We also store an Apple refresh token, which exists for one purpose: so that deleting your account can revoke Weave's access to your Apple ID.

Service metadata. Each time Weave performs an AI task for you, our backend records one row containing your account identifier, which task ran, how many tokens it cost, your plan tier, and the time. This is how usage limits are enforced and how the free tier is sized. These rows never contain any of your content: no query text, no transcript, no title, no note, nothing you wrote or said.

Diagnostics and product analytics. Through PostHog, our analytics provider, stored in its US cloud region. This covers device model, OS version, app version, app build, locale, timings such as how long an import took, failure reasons recorded as short category names rather than messages, and events describing how features are used, such as an import completing or a search being run. PostHog assigns a randomly generated identifier created on first launch, held in Weave's own storage, deleted when you delete the app, and never derived from your device hardware or joined to your account.

Weave does not collect crash logs. There is no crash reporting service in the app. Apple may provide us with anonymized crash reports for the App Store, which is Apple's collection and governed by Apple's policies.

Weave does not collect analytics in Europe. On devices set to a region in the European Economic Area, the United Kingdom, or Switzerland, product analytics is disabled entirely. No events are sent and no analytics identifier is created.

Weave instructs PostHog not to derive your location. Every event carries a flag that disables location lookup from your IP address, so no city, postal code, or coordinates are inferred or stored.

We do not send your video files, video frames, transcripts, extracted text, generated takeaways, notes, pulls, or search queries to PostHog. Where a query or note is counted at all, it travels only as a word count, and a note also as the color you chose.

Purchase data. Subscriptions are processed by Apple. Entitlement status is managed by RevenueCat, our subscription provider, which is given a randomly generated identifier not connected to your account. We never receive or store your payment card details.

Advertising attribution. Weave includes the TikTok Business SDK so we can tell which of our ad campaigns lead people to install and subscribe. It reports app installs, app launches, whether you return to the app, and subscription purchases to TikTok, along with device information such as model, OS version, and app version, and the IP address the request comes from. After you finish onboarding, iOS asks whether Weave may track you. Your device's advertising identifier is sent only if you allow it. If you do not, attribution relies on Apple's SKAdNetwork, which reports campaign results to advertisers without identifying you or your device. TikTok never receives your videos, frames, transcripts, extracted text, generated content, notes, pulls, search queries, or questions. This applies on every device, including those set to a region in Europe.

We do not collect your phone number, contacts, or precise or approximate location.


4. How AI processing works

This section describes the part of Weave that involves a third party, so it is worth reading closely.

On your device. Weave transcribes the audio of an imported video using Apple's speech recognition, which Weave requests on-device, and extracts visible on-screen text from individual frames using on-device optical character recognition. Audio is not transmitted to us or to our AI provider. Speech recognition is provided by Apple and governed by Apple's privacy policy.

Sent off device for processing. The following is transmitted over an encrypted connection to our backend, which forwards it to our AI provider, currently OpenAI:

Never sent off device. Your video files, your audio, your thumbnails, individual video frames, the notes you write, and the moments you pull out of a video. A note and a pull are your own words rather than something the video said, and they are deliberately excluded from every request.

Because transcripts and on-screen text are records of the video itself, anything spoken or displayed in a video you import may be included in what is sent for processing. If a video contains personal, private, medical, financial, or otherwise sensitive information, that information will be part of what reaches our AI provider. Do not import content you are not comfortable processing this way.

OpenAI processes this data as our service provider under its API terms. Data submitted through the OpenAI API is not used to train its models, and is retained by OpenAI for a limited period for abuse monitoring before deletion. OpenAI's practices are governed by its own policies, available at openai.com. We may change or add AI providers, and will update this policy if we do.


5. AI generated content

Titles, tags, topics, takeaways, summaries, connections, and search answers in Weave are generated by an artificial intelligence system. They are automated interpretations of content you supplied. They are not written or reviewed by a person.

AI output can be inaccurate, incomplete, or misleading, and can misrepresent the source video. It is not professional advice of any kind, including medical, mental health, legal, financial, or safety advice. Verify anything you intend to rely on against the original source.


6. Sensitive content

Weave has no control over what you import. If you import content covering sensitive subjects, that content will still be transcribed, read, and processed as described above, and the generated output may reflect the subject matter of the source.

Weave does not screen your content. We do not review or moderate what you import. Our AI provider applies its own usage policies to what it receives and may decline to process an item. When that happens, Weave tells you the item could not be processed. We do not receive an explanation of what the provider objected to, and the outcome is not a judgment we make about you or your content.

Weave is a personal recall tool. It is not a source of guidance, diagnosis, or crisis support. If you are dealing with a mental health or safety situation, contact a qualified professional or an appropriate emergency service.

We do not intentionally collect special categories of personal data. Any such data reaching us is data you chose to import.


7. Where data is stored

Your library lives on your device. If you enable backup or sync, copies are stored in your own iCloud account so they survive a reinstall or a device change. That storage is governed by Apple's terms and privacy policy and is under your control. We have no access to it.

We operate a backend, and it holds no content. Our backend runs on Supabase and does three things: it gives each installation an identity so AI requests can be authorized, it enforces usage limits, and it holds the AI provider's credentials so they never have to ship inside the app. What it stores is described under "Account data" and "Service metadata" in Section 3. It does not store your videos, transcripts, notes, pulls, search queries, or generated content, and it keeps no copy of your library.

Text sent for AI processing passes through our backend in the moment the request is made. We do not store or retain it, including in our logs.


8. Sharing

We share data only in these cases:

We do not sell personal information for money. Sending install and purchase events and, with your permission, your advertising identifier to TikTok to measure our ads may count as "sharing" for cross-context behavioral advertising under some US state laws. You can stop it as described in Section 10. We do not use your content to train any model of ours.


9. Retention and deletion

Your content. It stays in Weave until you delete it. Deleting an item removes it and its generated data from your device. If iCloud sync is on, the deletion propagates to your other devices. Deleting the app removes local data, and your analytics identifier goes with it.

Your account. You can delete your account from within Weave, under Settings. Doing so revokes Weave's access to your Apple ID, and deletes your user record from our backend along with its service metadata rows and the stored Apple token, by cascade. If Apple cannot be reached at that moment, the deletion still completes and the revocation is logged as incomplete.

Text sent for AI processing is retained by OpenAI under its own retention schedule and is outside our control once processed.

Analytics data is retained by PostHog for one year.

Attribution data is retained by TikTok under its own retention schedule and is outside our control once sent.

Service metadata is retained for as long as your account exists, and is deleted with it.


10. Your choices and your rights

You can turn off product analytics at any time, under Settings, with no effect on how the app works. Nothing is sent from that point on, including anything already queued. On devices set to a region in the EEA, the UK, or Switzerland, analytics is off and cannot be enabled.

You can refuse or withdraw tracking permission at any time, in iOS Settings under Privacy & Security, then Tracking. Once it is off, your advertising identifier is no longer sent to TikTok.

You can use Weave without an account. Signing in is only needed for backup, sync, and using Weave on more than one device.

Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of your personal information, and to appeal a denial of those rights. Because your library is stored on your device rather than on our servers, you can exercise most of these rights directly in the app.

For requests we can act on, contact us at hello@formalabs.app. We will respond within the time required by applicable law. We will not discriminate against you for exercising these rights.

If you are in the EEA or the UK, our legal basis for processing is performance of our contract with you. Product analytics is not collected from your device at all. Advertising attribution is, and its legal basis is our legitimate interest in measuring our advertising, with your advertising identifier sent only on your consent. You have the right to lodge a complaint with your local supervisory authority.


11. Children

Weave is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us at hello@formalabs.app and we will delete it.


12. Security

We use encrypted transmission for everything sent off your device, and rely on iOS platform protections, including the secure keychain, for data stored on it. Our AI provider's credentials are held by our backend and never ship inside the app. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.


13. Changes

We may update this policy as Weave changes. When we do, we publish the revised policy at this address and revise the date at the top. Anything that needs your permission, such as tracking, is asked for in the app through iOS before it happens, and you can say no. Continued use after an update means you accept the revised policy.


14. Contact

Fernando Cervantes
16200 Bridgeland High School Dr APT 6106
hello@formalabs.app