What actually leaves your device
Magicians are right to be careful about who they hand their library to. This page is the complete answer, in plain language, including the parts that are less flattering. If something here is unclear, ask and it will be made clearer.
Maven is a card catalog, not a cloud locker. You tell it what is on your shelf. It researches those titles on the open web and writes small text files that stay on your own device. Your books, videos and downloads are never uploaded, never read, and never copied. There is no Maven account and no database, so there is no pile of your material anywhere to be leaked or sold.
Where your library lives
On a computer running Chrome, Edge or Brave, you pick a folder and that folder is the library. Every entry is one small Markdown file in it, written for you rather than typed up by hand, which you can open in Notepad or TextEdit right now and read. That file is the whole of what Maven keeps about a book.
On a phone, a tablet, or a Mac running Safari, browsers do not hand out folders, so Maven keeps the same files in its own private storage on that device instead. You reach them through the app rather than through Finder, and Maven can save the whole library out as a single file whenever you want a copy. Which is which.
Either way there is no app database, no proprietary format, and no second copy on a server somewhere. Nothing about your library is uploaded, on any device.
If your downloads already live in a folder structure you like, including one inside Google Drive, Dropbox or iCloud, you keep it exactly as it is. Maven does not move, rename, reorganize or copy your files. It links to them where they already sit.
One consequence worth stating plainly, and it applies to the folder case: if you sync that folder with a cloud service, that service has whatever is in the folder, the same as any other folder you sync. That is between you and them, and it is the same arrangement you already have with the files themselves. A library kept inside the app is not synced anywhere by anybody, including us.
Everything that leaves your device
This is the whole list. Nothing happens in the background and nothing goes out while you are not using the app.
The title, and the author if you gave one. Nothing else. Maven researches that title on the open web the same way you would in a browser, and writes the result straight back to your own device.
Your question, plus the titles and tables of contents of the entries that look relevant. That is the same information printed on a book's cover and first few pages. Never the file, never a page of the book, never your folder listing.
The list of purchases shown on the page you are looking at, so it can be read into titles. Never your username, never your password, never your session. See below, because this is the one people ask about most.
The title being looked up, or a product URL you pasted. Images are proxied through the app so a store's hotlink block doesn't leave you with a broken cover.
If the app hits an error, or you press the bug-report button, a short diagnostic goes to the developer so it can be fixed: what broke, the page you were on, your browser, and the email on your licence. If cataloguing failed on something, the name of that item, so the reason can be found. Nothing else from your library.
The AI, precisely
People hear "AI" and "my library" in the same sentence and picture their collection being fed into a machine. That is not what happens, and the real mechanism is easy to describe.
Maven works from a catalog of titles and tables of contents, which it builds by researching each title on the public web: product pages, published indexes, reviews, publisher listings. The same pages you would find yourself. When you ask a question, the app first searches that catalog on your own machine, then sends your question along with the matching entries so the results can be understood and ranked properly.
So the AI sees what is printed on a cover and in a contents listing. It does not see inside your files, because the app never opens them for that purpose and there is no path by which a file could get there.
Being exact about this matters more than making it sound better than it is: the matching entries genuinely do transit, because the instructions that make Maven good at magic run on the server rather than in your browser. Those entries are titles and chapter lists. They are not stored, they are not logged, and they are not used to train anything.
Importing from Penguin, Vanishing Inc and other stores
This is the feature people are most suspicious of, and the suspicion is reasonable. Magic stores do not offer a "connect your account" button, so the natural assumption is that any app claiming to import your purchases must be asking for your username and password and logging in as you. Several people have assumed exactly that.
Maven does not do that, and could not, because it never asks for a login and has nowhere to keep one.
Here is the actual mechanism. You save a small bookmark to your browser bar. When you are on your own purchases page at the store, already signed in as yourself, you click it. It reads the list of titles on the page you are already looking at, and hands that list to Maven. It runs in your browser, on your click, on a page you opened.
Your credentials are never involved because they are never needed. The store never sees Maven and Maven never sees the store. Nobody logs in as you, no session is captured, and there is nothing stored afterward. The list of titles goes through the same reading step as a shelf photo so it can be turned into catalog entries, and then you review it before a single item is added.
If you would rather not use the bookmark at all, you can copy your list and paste it in. Same result.
Bringing your own AI key, if you want to
The AI is included in the purchase, so there is nothing to sign up for and no key to make. Searching your library is unlimited, and cataloging draws on an allowance that comes with it. Those requests run on our account rather than yours, and they carry exactly what is described above: your question and the matching titles and chapter lists, nothing else.
You can also supply a key from your own OpenAI account, in which case the research and the searching happen under your name and at your cost, and nothing is counted against your purchase. It is entirely optional, and most people will never touch it.
If you do use your own key, it is stored in your browser on that device. Where your library is a real folder, a copy also goes into a small private file inside it, so the key survives clearing your browser data and travels with the folder. It is not stored on our servers. It rides along with each request only so that request can be made, and then it is gone.
Two consequences, depending on which of those you have. Where a copy sits in your library folder, anyone with access to that folder can read it, including a cloud service you sync it to: a deliberate trade for not losing your key every time you clear a cache. Where the library is kept inside the app instead, nothing else can reach the key, but clearing that browser's data removes it along with everything else. You can remove the key in Settings at any time and it is cleared from wherever it was.
Reading, watching and casting
Maven can open your PDFs and play your videos so you are not juggling apps. Every one of those files is read from your own machine, by your own browser. Nothing is streamed from us, because we do not have it.
The same is true when you send a lesson to another device on your home network. That connection is device to device, across your own network. Your files do not pass through our servers, not even in transit, and not even briefly.
Your bookmarks, notes and where you left off in a video are written into your library folder alongside everything else.
Your licence, and what a bug report contains
Maven is a one-time purchase, so the app checks that your licence key is valid. That check goes to the store that handled your purchase, and the result is remembered so it does not need re-checking constantly. The app also keeps working offline for a good while, on purpose, so a bad connection never locks you out of your own library.
If the app crashes, or if you press the bug-report button, a short diagnostic is sent so the problem can actually be fixed. That includes what went wrong, the page you were on, your browser and version, and the email address on your licence, so you can be contacted if a fix needs testing. It also includes a short list of the actions you had just taken, like "opened search" or "added item", so a crash can be reproduced.
If cataloguing fails on something, the report names the item it failed on, so the reason can be found and fixed. That is the one piece of your library that a report carries, it is only ever an item that failed, and it is never the rest of your shelf.
Those action labels are otherwise deliberately free of library content. Nothing is sent unless the app errors or you press the button, and nothing is collected while things are working normally. There is no analytics service, no tracking pixel, and no third party watching your session.
What never leaves, at all
- Your PDFs, ebooks, audio or video. There is no upload path for them and no server that could hold them.
- The contents of any file, at any point, for any reason.
- A listing of your folders, drives or filenames beyond the ones you deliberately link to an entry.
- Any password, for our app or anyone else's. There is no Maven account to have a password for.
- Anything sold, brokered, or shared with an advertiser. There is no data to sell, which is the only version of that promise worth anything.
Check it yourself
You should not have to take any of this on faith. Three things you can verify in about a minute:
Your library still opens, still browses, still plays your files. Only the asking needs the internet, because only the asking involves anyone else.
Everything Maven knows is plain text. If it is a folder, open it and read it right now. If it is kept inside the app, save it out in one click and open that. Either way you can read it, edit it, take it somewhere else, and it stays readable with or without this app.
If you are the sort of person who would, open your browser's developer tools and watch what goes out while you use the app. You will find the list above and nothing else. If you find something that is not on this list, that is a bug and it will be fixed.
Still not sure?
That is fair, and it is a better instinct than the opposite one. Ask a direct question and you will get a direct answer, including "yes, that part does leave your device" where it is true.
Ask a question →