Kestrel

Privacy

What you write is yours. This page explains, in plain language, exactly what Kestrel does with it.

Last updated October 3, 2026

The short version

  • 1640, LLC, the people who make Kestrel, never receive anything you write, or anything about you.

  • Kestrel has no accounts, no servers of ours, no analytics, no advertising and no tracking.

  • Your books live in a folder on your device. They go somewhere else only if you choose to keep them in iCloud Drive or back them up to GitHub.

What stays on your device

Your library is an ordinary folder of files. It holds your books, chapters, notes and comments; Book Info (pitch, synopsis and query letters); and the history of your writing. On a Mac it’s in Documents › Kestrel Library unless you choose somewhere else. On iPhone and iPad it’s in On My iPhone (or iPad) › Kestrel › Kestrel Library, which you can see in the Files app. If you keep your books in iCloud Drive, they’re in iCloud Drive › Kestrel › Kestrel Library on every device instead.

The name and contact details you enter for a manuscript’s title page are kept apart from your library, in your Keychain. If you use iCloud Keychain, they sync to your other devices through it, end-to-end encrypted.

Kestrel also remembers your preferences on the device, such as font, zoom, page width and which book was open. And it gives each copy of the app a random code when it’s installed, so your history can say which kind of device made each change, “on your iPhone” or “on your other Mac”. It never uses your device’s name.

When you delete a book, Kestrel keeps it in a holding folder in its own storage on that device so you can bring it back. Empty Deleted Books… in Settings erases them from the device for good.

Taking your writing with you

Your writing is kept in ordinary files, so you can take all of it with you, and read it, without Kestrel.

  • Your library is a folder. Each book has a folder named for the book, holding a book.json file with the book’s title and the order of its chapters, and a chapters folder with one file per chapter, named and numbered in order, such as “01 The Ferry.html”. Notes are in a notes folder and the synopsis and query letter in an info folder, one file each, and a library.json file at the top keeps your shelves.

  • Chapters are web pages. Each one is a complete HTML file that opens in any web browser with its italics, centred lines, indents and scene breaks in place, and your comments shown in brackets after the words they’re about.

  • Your history is in the folder too, in Git’s standard format: a hidden .git folder, or, when your library is in iCloud Drive, a single file called “Kestrel History.bundle”. Any Git tool can turn either back into every version you’ve saved, from any copy of the folder.

  • Your backup holds the same files. If you back up to GitHub, you can open your repository on github.com, download it as a ZIP, or copy it, history and all, with any Git tool.

  • Your title-page details are kept in your Keychain, not in the library.

  • And you can export any book to Word, PDF or Markdown whenever you like.

If you keep your library in iCloud Drive

Your books are stored in your iCloud account by Apple, under Apple’s iCloud terms and privacy policy, in a Kestrel folder in iCloud Drive, and they stay in step between your devices through it. So that your other devices can read your history, Kestrel keeps a copy of it beside your books as one file, “Kestrel History.bundle”, and that history notes the kind of device behind each change and its random code. Your library also carries a random code of its own, so your devices know they’re looking at the same one. We have no access to your iCloud account or anything in it.

If you turn on backup to GitHub

Backup is off until you set it up. When it’s on, Kestrel sends copies of your library to a private place, a repository, in your own GitHub account, and brings in what you’ve written on your other devices from it. On a Mac you can sign in with GitHub and let Kestrel find or make that private place, or make it yourself on GitHub’s site and give Kestrel a token for it. Once it’s set up on one of your devices, your others use the same backup too, through the settings and token that travel with you (below).

Signing in with GitHub

  • Kestrel opens GitHub’s own sign-in page with a short code to enter. You approve Kestrel there, on GitHub, which shows you what it’s asking for.

  • GitHub’s sign-in lets Kestrel reach every repository in your account, public and private, because GitHub has no narrower permission that can write to one. Kestrel only ever uses the one private place it backs up to, and it won’t use a public one.

  • The sign-in lasts until you withdraw it on GitHub, in Settings › Applications › Authorized OAuth Apps. After that, backup simply stops.

  • If you’d rather Kestrel could reach just one repository, use a token instead. You create it on GitHub’s site and choose that one repository yourself.

Private, and checked

  • Before Kestrel uses a place, it asks GitHub whether it’s private, and refuses one that isn’t.

  • It asks again each time it opens and whenever you turn backup back on. If the place has been made public, Kestrel pauses backup and tells you why.

  • Only a clear answer from GitHub that the place isn’t private pauses backup. If GitHub can’t be reached, backup carries on as it was.

What goes to GitHub

  • Everything in your library: books, chapters, notes, comments, Book Info, and the history of your changes. That includes books and chapters you later delete, which stay in that history.

  • A label on each saved change, with the time (including your time zone), the titles of the books and chapters it touched, and the kind of device that made it with its random code. Changes are signed “Kestrel”, not with your name or email.

What doesn’t

  • Your title-page name and contact details, which stay in your Keychain.

  • Your exported files, and books in the deleted-books holding folder.

  • If you used an early test version of Kestrel, the title-page details it backed up stay in that backup’s history. Starting a fresh private place, or deleting the old one on GitHub, removes them.

What comes back

  • Kestrel brings in what you wrote on your other devices from the same repository: when it opens, when you come back to it, every couple of minutes while it’s open, and, on iPhone and iPad, in the background and when you pull down on your shelf. It uses the same encrypted connection and the same token.

When

  • Within about twenty seconds of when you stop typing, at least every couple of minutes while you write, when you open Kestrel, and when you leave it.

Who can see it

  • You, and anyone you give access to that repository on GitHub.

  • GitHub keeps your copies under its own terms and privacy statement.

Your access token

  • Whether you sign in or create a token yourself, Kestrel keeps the token in your Keychain and syncs it through iCloud Keychain, so your other devices, iPhone and iPad included, can back up too.

  • It’s only ever sent to GitHub (github.com and GitHub’s API), over an encrypted connection.

Turning it off

  • You can pause backup at any time in Settings, which stops everything going to and coming from GitHub. iCloud Drive carries on if you use it. Or choose Stop Backing Up and forget the token.

  • If you signed in, you can also withdraw Kestrel’s access on GitHub at any time.

  • Stopping doesn’t delete the copies already on GitHub, and Kestrel never rewrites that history. To remove them, delete the repository on GitHub. Kestrel’s backup settings link straight to its page.

Settings that travel with you

If you’re signed in to iCloud, Kestrel shares three settings between your devices: where your GitHub backup is, whether backup is paused, and the name of your library’s folder in iCloud Drive (its name only, never its full location). Your access token and your title-page details travel through iCloud Keychain, end-to-end encrypted. Nothing from your books travels this way, and neither does your device’s random code.

What Kestrel never does

  • It never collects analytics, crash reports, advertising identifiers or anything that tracks you, and it includes no third-party code that does.

  • It never asks you to sign in to us. There’s no Kestrel account, and no server of ours for anything to go to.

  • It never opens files you didn’t choose. It reads your own library and the files you import. On iPhone and iPad it also looks in Kestrel’s own folder in iCloud Drive, to find the books your Mac keeps there. On a Mac, it also reads a library left by the NEO writing app, if you have one, so it can carry it over.

  • It never puts your comments in an export. Placeholders do stay in the text, and Kestrel warns you before a manuscript leaves with one. Word and PDF exports include the title and byline you entered.

What Apple shares with us

Kestrel is delivered through the App Store. If you’ve chosen to share analytics with app developers in your device’s settings, Apple may send us anonymous crash reports and usage numbers, such as how many people use the app. These come from Apple’s system, not from Kestrel, and contain none of your writing. You can turn this off in Settings › Privacy & Security › Analytics & Improvements.

Children

Kestrel isn’t directed at children, and it collects no personal information from anyone.

Changes to this policy

If what Kestrel does with your information ever changes, we’ll update this page, and the date at the top, before the app changes.

Contact

Questions? Email matt@1640.io.

Kestrel is made by 1640.

© 2026 1640, LLC. Apple, the Apple logo, Mac, iPhone, iPad and App Store are trademarks of Apple Inc., registered in the U.S. and other countries.

Kestrel is made by 1640.

© 2026 1640, LLC. Apple, the Apple logo, Mac, iPhone, iPad and App Store are trademarks of Apple Inc., registered in the U.S. and other countries.

Kestrel is made by 1640.

© 2026 1640, LLC. Apple, the Apple logo, Mac, iPhone, iPad and App Store are trademarks of Apple Inc., registered in the U.S. and other countries.