Desk Trials

ARCHIVE / Research & notes

Reflect keeps notes encrypted until you ask the assistant something

Reflect's marketing page names one AI provider; its privacy policy discloses three, plus a training-data caveat.

Preserved retrospective record

Historical source and event dates are not site publication dates. Product plans, policies and availability may have changed since retrieval.

Visual for this record: Reflect keeps notes encrypted until you ask the assistant something
Visual published by site.reflect.app, shown for identification of the record. Credit: site.reflect.appPreserved source visual · owner review pending

The setup

Reflect is a daily-notes tool built around backlinks between entries, with a chat-style assistant layered on top rather than a separate app to switch to. Reflect's homepage lists 'End-to-end encryption — Only you can access your notes' among its core networked-notes features, and separately markets 'Reflect AI,' stating it 'uses GPT-4 and Whisper from OpenAI to improve your writing, organize your thoughts, and act as your intellectual thought partner.' Turning that assistant on requires no separate setup beyond an account; the feature sits inside the same editor as the encrypted notes it describes elsewhere on the same page.

What the documents show

Reflect's privacy policy, last updated by the company on 20 March 2025 and read here on 16 September 2026, is more specific than the marketing page about where data goes: 'the contents of your notes are end-to-end encrypted so no plaintext ever reaches our servers,' with one stated exception — 'if you use the AI feature then we will send text you explicitly select and transform, or search results you explicitly select to OpenAI's API, Anthropic's API, or Google's API.' It adds that voice recordings are 'uploaded' for transcription and then deleted once the transcript syncs to the note. The homepage's mention of only 'GPT-4 and Whisper from OpenAI' is narrower than the three providers the privacy policy names.

The friction

The policy states plainly that 'OpenAI and Anthropic may use prompts we send them as training data,' a disclosed risk that applies specifically to whatever text a user selects for the AI feature, not to the rest of an encrypted note. The document also states there is 'no way' for the AI provider to associate that selected text with a user's account, which limits but does not eliminate the exposure the policy describes. A reader relying only on the homepage's 'end-to-end encryption' framing would not learn about the OpenAI, Anthropic, or Google exception without opening the separate privacy policy.

What changed in the work

Per the vendor's own documents, encryption is the default state of a Reflect note, and the AI assistant only sees the specific text a user explicitly selects and sends to it, not the whole note graph in the background. That is a narrower, opt-in exposure than an assistant with standing access to everything written, which is what the policy's language supports; it is not a claim that no note content ever leaves the encrypted store, since any text run through the AI feature does.

  • Does the marketing page name every AI provider the privacy policy actually discloses?
  • Is the assistant reading only the text you selected, or does it have standing access to more?
  • Could the vendor's AI partner use what you send as training data, and does the policy say so directly?

End-to-end encryption and an AI assistant are not automatically in tension, but only if the exception is scoped as narrowly as Reflect's own policy states, and confirming that scope means reading the privacy page, not just the feature description.

Sources & verification

Preserved from the earlier archive. These sources have not all been freshly rechecked for this expansion.

  1. Reflect homepageSource date: not stated · Retrieved: 2026-09-16

    States the end-to-end encryption feature and the Reflect AI marketing description, as read on 16 September 2026.

  2. Reflect Privacy PolicySource date: not stated · Retrieved: 2026-09-16

    Discloses which providers receive selected AI text, the training-data caveat, and the voice-memo upload and deletion process.

Continue the workflow

  1. Turn a research question into an evidence table that survives disagreement

    A reproducible way for a solo operator or small team to collect evidence, compare conflicting sources, and hand the work to another reader without losing provenance.

  2. Check PDF extraction before you trust the summary

    A quick, repeatable quality check for deciding whether PDF text, tables, and OCR output are reliable enough to feed into notes or summaries.

  3. Hand off a citation library without handing over a puzzle

    A practical Zotero handoff method that preserves attachments and meaning while making the collection understandable to a teammate.

  4. Tana split into two products and its notes tool got a new address

    The structured-notes app once called Tana is now Tana Outliner at a separate site, with AI features metered by shared credits.