SideNote Pro for organisations
Security & privacy, clearly documented.
SideNote Pro sends AI requests to the provider you choose. Application data, credentials and local folder search stay on your own Windows device. For organisations evaluating SideNote Pro, BediniLabs can also provide technical and procurement documentation on request.
Privacy by design
SideNote Pro is a native Windows application and a client for AI services you choose and configure. BediniLabs does not operate an AI backend for it, and there is no SideNote Pro account, cloud profile or hosted conversation service.
When a request is submitted, it goes from the application to the AI provider configured in its settings. BediniLabs is not in that path, and does not receive prompts or responses as part of AI generation.
With a local provider such as Ollama or LM Studio running on the same machine, the request goes to localhost and processing can remain on that machine. What SideNote Pro controls is where a request is sent; it does not supply the local model.
The Privacy Policy sets all of this out in full, and BYOK and privacy explains what bringing your own key does and does not change.
The AI provider you configure does receive the requests submitted to it, and handles them under its own privacy, retention and usage policies. BediniLabs does not control those practices, so review them as part of choosing a provider.
Local data and credentials
Application data is stored on the device, under the Windows user’s Local App Data location. It is not uploaded to BediniLabs and is not synchronised between devices.
Provider credentials
Each provider profile’s API key is kept in its own file, protected with the Windows Data Protection API (DPAPI) for the current Windows account, and never written into the settings file. It is sent only to the provider endpoint it authenticates, and never to BediniLabs.
Conversation history
Threads are stored locally when history is enabled, and history can be turned off. Encrypting the archive with DPAPI is optional and covers attached images and extracted document text. History can be deleted in the application or pruned automatically after a set number of days.
Documents
Attached documents are read and extracted on the device, and the original file is never uploaded. Only the extracted text is sent, and only as part of a request that is submitted.
Local folder indexes
Indexing, search and ranking run on the device, with no embeddings, vector database or hosted search service, and the index is protected with DPAPI. A request carries only the excerpts local search selected.
No filesystem crawling
A folder is only ever one a user added. SideNote Pro does not discover folders, crawl drives, inspect recent files or run background filesystem watchers.
Explicit actions only
Screenshots, pasted images and selected text are read only after an explicit action: starting a capture, pasting, or pressing an action shortcut. There is no passive screen, clipboard, microphone or camera monitoring.
What a request contains
Nothing is sent to the provider until a request is submitted. A request then carries what it needs: the message and the system prompt, relevant earlier messages from the same conversation within the configured context window, and anything attached or captured for it, such as images, text extracted from documents, text from a selected-text action, or the excerpts local search selected from an indexed folder. A request that is only typed text sends only typed text.
One request is easy to overlook: when a long conversation is compacted, the summary is produced by the configured provider, so older messages are sent to it for that purpose.
A clear service boundary
Three separate parties can be involved when SideNote Pro is in use, and they see very different data. The application makes network requests to two destinations, and they are entirely separate: the AI endpoint configured in its settings, and the BediniLabs licensing service.
SideNote Pro, on your Windows device
- Holds
- Settings, conversation history, attachments and extracted document text, folder indexes, the usage ledger, provider credentials, licensing state, and the device key used to sign licensing requests.
- Connects to
- The AI endpoint you configured, and the BediniLabs licensing service.
The AI provider you configure
- Receives
- The requests submitted to it, and the API key that authenticates them.
- Governed by
- The provider’s own terms and its privacy, retention and usage policies. BediniLabs does not control or audit those practices, and billing for API usage is between you and the provider.
The BediniLabs licensing service
- Handles
- Trial authorization, activation, entitlement refresh and device deactivation. For those it processes licensing and device information: the licence, its registered devices, trial and entitlement dates, and the purchase email. Trial authorization also sends an identifier derived from the Windows installation, and only that derived value is transmitted.
- Never receives
- Prompts, responses, attachments, screenshots, filenames, folder contents, usage figures or AI provider API keys. AI requests do not pass through it, and it is not a proxy for any provider.
Buying a licence online also involves Stripe, which processes the payment, and Brevo, which delivers the licence email. Neither receives conversations or AI provider credentials. Purchase and licensing data in the Privacy Policy sets out what each one handles.
No application telemetry
The SideNote Pro application does not contain telemetry, product analytics, advertising identifiers or marketing SDKs. It does not report usage, feature interaction, crash statistics or device information to BediniLabs.
The usage figures the application shows are recorded in a ledger on the device: daily token counts and local cost estimates by provider and model. The ledger holds no prompts, responses, filenames, document contents, images or API keys, and it is not sent to BediniLabs.
Documentation for your review
Organisations evaluating SideNote Pro for Business or Enterprise use can ask BediniLabs for the material a security, IT or procurement review needs. Tell us what your process requires, and we will confirm what we can provide.
Security & privacy documentation
A written account of how the application handles data, credentials and network connections, consistent with the published Privacy Policy.
Architecture and data-flow information
What runs on the device, which endpoints the application contacts, and what each connection carries.
Software Bill of Materials (SBOM)
SBOM available on request for organisational evaluations.
Technical product documentation
System requirements, provider configuration and licensing behaviour, building on the public setup and usage guides.
Security questionnaire support
Answers to your organisation’s security or vendor questionnaire, based on the documented architecture.
Procurement & vendor review support
Vendor information for supplier onboarding, and quotation and invoicing for Enterprise purchases.
DPA or data-processing documentation where applicable
Whether a DPA is relevant depends on the deployment. What BediniLabs handles is licensing and purchase information, not conversation content.
Deployment & environment requirements
The Windows version the application requires, how it is distributed, and the network destinations it needs to reach.
To request documentation, email [email protected] with your organisation’s name and what your review needs.
This material is prepared by BediniLabs and describes how SideNote Pro is built and how it handles data. Documentation is provided for customer review and does not represent a third-party certification or independent audit.
Need something specific?
Organisational deployments can have requirements that do not apply to individual customers. Business and Enterprise deployments can be discussed directly with BediniLabs. Where a requirement falls outside the standard product, we can evaluate it and scope the work separately.
Examples of requirements to raise:
- Provider and model defaults
- Deployment configuration
- Organisational settings
- Integration with internal workflows
- Custom licensing requirements
- Other product modifications, scoped individually
These are examples to discuss, not features included with a licence.