Skip to content

Melanite Viewer Privacy

Melanite Viewer is an app for reading only — it opens a portable pack exported by Melanite on your phone or tablet.

This page covers Viewer alone. For Melanite on your computer, see Privacy.

What Viewer does not have

  • No account is required. There is no sign-up, no login, and no identifier for you
  • No usage data is collected. There is no analytics, telemetry, or crash reporting
  • No way to write anything. Importing, renaming, tagging, notes, deletion, and note editing simply do not exist. All you can do is look, and delete a pack you copied onto the device
  • No sync, no cloud. Nothing fetches a pack on its own, and Viewer never talks to the computer your library lives on
  • No way out. There is no share or export path for what a pack holds
  • No location. Viewer never asks for location permission

What it reads

Viewer reads only the copy of the pack you handed it, through the Files app or similar. Importing expands the contents into the app's own folder, and everything is read from that copy afterwards. It never opens the library folder on your computer.

Display settings (sort order, theme, and so on) are stored on the device. Deleting the app removes the imported packs and the settings along with it.

A sample pack ships inside the app. With nothing imported, choosing "Open the sample" shows its contents. It lives in the app itself, so nothing is imported and nothing is fetched — and you can delete it afterwards like any other pack.

The two times data leaves

Network requests happen in exactly two situations. In both, the system frameworks do the fetching — Viewer has no HTTP client of its own with which to call arbitrary URLs. In neither case is anything from the pack — file names, tags, note text, thumbnails — sent anywhere.

Situation Goes to What it reveals Default
Opening the Map tab Apple's map service (MapKit) the map area you are looking at on
Remote images in notes the server hosting the image that the image was loaded off

As with any web request, the server on the other end sees your IP address and the time of the request.

When you open the Map tab

To place items with coordinates on a map, the system's map framework fetches the background map. What this reveals is the area on screen — your pins and the contents of your items are not uploaded. If you never open the Map tab, none of this happens.

Your current location is never used, so the map has no notion of where you are.

Remote images in notes

If a note references an external image with ![](https://…), Viewer does not load it by default (the same treatment as on the desktop). This keeps merely opening a note from handing your IP address and reading time to someone else.

While an image is blocked, Viewer shows the URL it points at instead, so you can open it in a browser yourself if you want to see it. Turning loading on in the settings means that opening such a note fetches those images from the original server each time.

Getting a pack onto the device

You carry the pack across; Viewer never goes and gets it.

If you pass it through the cloud

Moving a pack through iCloud Drive or a similar service means entrusting that service with what the pack holds: your tags, the text of your notes, and thumbnails. A cable or AirDrop keeps the pack off the cloud entirely.

Contact