Refrain

Your library stays yours.

Refrain was built around a simple idea: it shouldn't need your data to work. Your Kindle highlights live on your devices. Your devices sync through your own iCloud. Refrain's intelligence runs locally.

There is no Refrain account. There is no Refrain cloud. And there is nothing on our side that can read your library.

The short version

Your Kindle

Amazon

Refrain

Your iPhone · iPad · Mac

Your iCloud

Your devices stay in sync

The important part

Your library never goes up to us. The intelligence runs where your library lives.

There is no Refrain cloud.

Most apps work by sending your data to a company's servers. Refrain doesn't. Your library is stored locally on your devices. iCloud syncs it between your own devices. Refrain doesn't operate a backend that receives, stores, indexes, or processes your reading.

That's not a privacy policy. It's the architecture.

Your password goes to Amazon. Not us.

When you connect Kindle, Refrain presents Amazon's own sign-in page inside the app. Your Amazon password is entered into Amazon's page. Refrain never sees it, stores it, or transmits it.

Once authenticated, Refrain reads your Kindle notebook and imports your passages directly onto your device. Older Kindles and sideloaded books can use My Clippings.txt instead.

Nothing from your library is uploaded to Refrain.

Your library lives on your devices.

Refrain uses Apple's native storage and sync technologies to keep your library available across iPhone, iPad, and Mac. Your passages, books, notes, insights, threads, and other Refrain data are stored in your private iCloud database when sync is enabled.

When you're offline, changes wait locally. When you're connected again, your devices catch up. The cloud here belongs to you.

Every model that reads your passages runs on your device.

Refrain's intelligence isn't a request to a remote model. Your passages are processed on your own hardware.

No passage. No note. No derivative. Nothing is sent away to be processed.

Built with Apple's stack.

Refrain is built almost entirely with technologies already on your Apple devices.

SwiftUI
One native interface across iPhone, iPad, and Mac.
SwiftData + CloudKit
Local library storage and iCloud sync.
Core ML
On-device passage embeddings and semantic matching, using the Neural Engine when available.
Natural Language
Linguistic analysis used to help name threads.
WebKit
Amazon's sign-in and notebook sync.
WidgetKit
The daily passage on your Home Screen.
StoreKit 2
The one-time unlock.

The only third-party code in the entire app is an HTML parser.

How rhymes actually work

Each passage is represented locally in a form that lets Refrain compare its meaning with other passages in your library. When two passages resonate, Refrain calls that a rhyme. A weaker match is a fainter rhyme.

The comparison happens on your device. Your library never needs to leave it.

For the curious: Refrain uses an on-device embedding model to represent passages and cosine similarity to rank their semantic proximity.

Threads are found, not written.

Refrain looks across your library for groups of passages that share a meaningful idea. Those groups become threads. Thread names are generated on-device from the passages themselves, using linguistic analysis and statistical signals. A thread might be “The cost of complexity”, or “Deciding without enough”.

The name isn't a claim about what you believe. It's Refrain describing what the passages have in common. The books speak. Refrain frames.

The library never goes up. The canon comes down.

Refrain downloads a collection of roughly 50,000 attributed quotations — once. Its vectors are already prepared. When Refrain looks for an echo, it compares your threads against that local collection. The result never requires uploading your library.

And Refrain has a quality bar: if there isn't a genuinely good echo, there isn't one. Silence beats an almost-match.

Insights: no intelligence required. Just you.

An insight is simply something you wrote about a passage or thread. It stays distinct from the book's words and from anything Refrain found. Its origin is permanent. Your insight is yours — Refrain doesn't rewrite it, summarize it, or pretend it came from somewhere else.

Refrain writes the brief. You decide who reads it.

Go deeper composes a plain-text research brief entirely on your device. It can include the original passage and attribution, your insight if you wrote one, up to three rhymes, the thread it belongs to, and focused research instructions.

Then Refrain hands that text to the standard iOS share sheet. You choose what happens next: ChatGPT, Claude, Notes, Mail, something else. Or just copy the prompt.

Refrain never makes the AI call. Once you hand the brief to another service, that service's privacy terms apply. That's your decision — not Refrain's.

Built for what's next

Refrain's intelligence already runs on your devices. As Apple expands what those devices can do, Refrain brings that capability in without changing the promise underneath: your reading stays yours.

Coming in Refrain 2.0 (October): Go deeper will read the passage for you. Tap it and a single brief — one passage, your note, up to three rhymes, the name of a thread, and the questions you've chosen — goes to Apple's Private Cloud Compute, Apple's servers running Apple's model, and a reading streams back beside the passage, where it stays. Not your library. One brief, when you tap, and never before; the reading comes back to your device, not to us. Apple's published design for Private Cloud Compute states that a request is used only to fulfill itself and is not stored or accessible afterwards — that's Apple's word, and we relay it rather than restate it as ours. The hand-off stays. Thread names will get a second opinion from Apple's on-device model, still on the device. And on iPhone Duo, Refrain will lay out as a spread — the passage on one page, what it connects to on the facing page, the fold as the gutter.

Readings in Refrain will need a current OS; the hand-off works everywhere. Better devices. Better Refrain. Same rule.

What does Refrain know about you?

Data / activityWho has it?
Your Amazon passwordRefrain never sees it
Your Kindle highlightsStored on your devices; never uploaded to Refrain
Your notes and insightsStored on your devices and your own iCloud
Your reading habitsNo tracking or analytics code
Which AI app you choose in go deeperRefrain doesn't know
The response you get from that serviceRefrain never sees it

What about Apple? iCloud is Apple's infrastructure, not Refrain's. Your iCloud data is protected by Apple's security model; Advanced Data Protection can provide end-to-end encryption for additional iCloud data when enabled.

Who does Refrain talk to?

Amazon
For the Kindle sync you initiate — your highlights and your books' cover art alike.
Apple
For iCloud, App Store services, and Apple's own optional diagnostics.
getrefrain.app
For two static downloads: configuration and the Echoes quotation pack.

That's it. There is no Refrain API. No AI endpoint. No analytics service. No tracking service. No user database.

And the app doesn't phone home.

Take it on a plane.

Once your library is imported, everything important works offline: read, return, search, search by meaning, find rhymes, explore threads, write insights, find echoes, go deeper.

The only things that need connectivity are the things that actually need somewhere else to go: Amazon sync, the one-time Echoes download, and iCloud propagation between devices.

Your library doesn't stop working because your Wi-Fi does.

The short version, again

Your books are yours. Your passages are yours. Your thoughts are yours. Refrain doesn't need to take possession of any of them to make them more interesting.

There is no Refrain cloud. There is no Refrain account. There is nothing for us to read.