top of page
Abstract Shapes

INSIDE

PUBLICATIONS

Reflect (Reflect Notes): end-to-end encrypted networked note-taking with an AI layer, scored 5.3 on the U365 CI-First Review

1 day ago
85 min read

Updated: 17 hours ago

Reflect: an end-to-end encrypted networked note-taking app with an AI layer, the vendor's own product card

Status: Active | Last tested: 2026-09-25 (Reflect as documented at reflect.app, reflect.academy and the 2026-07-14 Reflect Open announcement) | Re-check: trigger-based (max 6 months)


Active: the tool is current and recommended.


What Active means here. Active means current and recommended for the reader this review describes: one person keeping a private, connected notebook, who will do the linking and who decides before subscribing which of their notes are eligible to be sent to a model provider. It does not mean the AI layer is verified. No third party has published a measurement of the AI output's quality on this product, the vendor's own pages do not agree about which model provider receives the text you select, and the published independent review of the encryption design is from the second quarter of 2021 and covers the architecture rather than the client you install today. A reader who needs a measured guarantee of output quality, a single authoritative list of model providers, or a plan that can be cancelled monthly should treat those as not currently available and act accordingly.


For detailed explanations of the CI-First evaluation terms used in this review, including the Humics Protection Badge and the AI Imposture Risk levels, see the Glossary at the end of this post.


Summary: Reflect is a networked note-taking app whose note contents and attachments are encrypted on your device with a password the vendor states never leaves your machine, with an AI layer that reads what you select or what a search returns. The U365 CI-First Evaluation scores it 5.3 out of 10, CI-First Positive, with Humics-Neutral at -1 and AI Imposture Risk Medium overall with Skill Illusion High.


Primary institute alignment: UIT (Technology, AI, Data Science) high, for the encryption design, the append-only API the encryption forces and the local MCP server; UIB and UIC medium; UID low.


Reflect Review
Back to the TOC

In this Tool Review



Back to the TOC

Status and Re-check


Re-check triggers:


  • Any change to where AI processing happens, or to the list of model providers. The privacy policy says text you select is sent to OpenAI's API, Anthropic's API or Google's API. The security page names one provider for the same feature. Whichever list is correct at the time you read this, the list has already changed once without the security page being updated, and a further change is the single most important thing to re-check on this product.

  • A published price for the Reflect Open mobile app, or a change to the $10 per month single plan. The Mac app of Reflect Open is free and open source, and the vendor states that the mobile app is expected to become paid with pricing undecided. That decision, plus the fate of the existing subscription, decides what an existing subscriber is paying for.

  • A change to the end-to-end encryption claim, or a change to its scope. The claim currently covers note contents and attachments under a password that never leaves your device. It does not cover audio sent for transcription, text sent for AI processing, or the contact and company enrichment path. Any widening or narrowing of that boundary changes several sub-scores.

  • A second independent security review, or disclosure of a serious defect. The published audit is from the second quarter of 2021 and reviews the architecture and the cryptography, not the current client. The vendor states plainly that the client can change and that you have to trust it.

  • A first independent measurement of AI output quality on this product. No third party has published one. The Quality sub-score is capped on that absence rather than on measured weakness.

  • A change to the refund position. The public refund page promises a full refund with no questions asked. The terms make refunds discretionary and non-refundable except where the law requires. If the two are reconciled, this review's governance section should be read against the reconciled text.

  • Release of the MCP server from beta, or a change to what an agent may write. The MCP server currently lets a coding agent create notes, append to the daily note, and insert, replace or delete content anywhere in a note. That surface is the basis for the clause note in this review, and a narrowing or widening of it changes the Skill Illusion reasoning.

  • An Android app. There is none. Everything below that concerns mobile use concerns an iPhone or an iPad.


Back to the TOC

The Reflect naming, stated before the review begins


A reader who searches for Reflect meets a note-taking app, a software testing platform, an advertising software kit, and several unrelated products with similar names. This matters more than usual here, because the best-known review page carrying the name Reflect belongs to a different product and is widely cited as if it were this app's.


Name

What it actually is

Relationship to this review

Reflect Notes (reflect.app)

The product reviewed here: an end-to-end encrypted networked note-taking app with daily notes, backlinks, a graph, a web clipper, Kindle and calendar capture, voice transcription and an AI assistant over your own notes. Sold by Reflect App LLC, Austin, Texas

The subject of this review

Reflect (reflect.run, now smartbear.com/product/reflect)

An AI-powered, no-code web and mobile user-interface test automation platform, acquired by SmartBear. It carries a G2 listing of 4.7 out of 5 across 42 reviews, and a pricing page built around Premium, Advanced and Enterprise contact-sales tiers

Not related. This is the collision that matters most: the numeric review scores a reader finds first under the name Reflect belong to a software testing tool

Reflect (reflect.cloud)

A mobile advertising software kit with a developer console and usage-based pricing

Not related

Reflect CRM

A customer relationship management product listed on a software directory under the same one-word name

Not related

Reflection (reflection.ai)

A separate artificial intelligence company with its own privacy policy and legal pages

Not related

Reflct (reflct.co)

A daily-reflection wellbeing app with a changelog, not a knowledge tool

Not related

Reflection.app

A guided journaling app with a Premium subscription and a lifetime purchase option

Not related, and often confused with the subject because both are note-adjacent

Reflect (com.meetreflect.us)

A wellbeing companion app on the Google Play store

Not related, and it appears in mobile search results for the name

Reflecto (docs.reflecto.dev)

A developer notification API

Not related

Reflektive

A performance management platform with its own developer API documentation

Not related


Two consequences follow.


First, the naming collision is worse than for most tools because the collision is with a product that has real review volume. The G2 page at g2.com/products/reflect-reflect reports 4.7 out of 5 stars across 42 reviews, 88 per cent of them five star. Those reviews are about automated UI testing. None of them is evidence about the note-taking app, and a reader who takes them as evidence about the note-taking app has been measuring the wrong product.


Second, the vendor has a second product that a reader must not confuse with the first. In July 2026 Reflect announced Reflect Open, a separate, local-first, Markdown-based rebuild under the MIT licence, with a free Mac app and an iPhone beta. The original hosted Reflect continues. The two are different applications with different data models, different sync, and a different answer to the question of who holds your notes. Wherever this review says Reflect without qualification it means the hosted product at reflect.app that most current subscribers pay for. Reflect Open is treated as its own subject in Section 10, and it is the most important alternative to Reflect that exists, because it is made by the same company.


Back to the TOC

Tool Snapshot


Reflect Notes (Reflect App LLC)


Tagline: "Think better with Reflect. Never miss a note, idea or connection." (reflect.app, read 2026-09-25.)


Category: A networked note-taking application with an integrated AI layer. It is an LLM-flavoured productivity tool rather than a general assistant, and it is also an encrypted personal knowledge base. Five surfaces exist: a web app, a macOS desktop app, an iPhone app, an iPad beta app, and browser extensions for Chrome and Safari. Windows and Android users work through the browser.


Primary use cases:


  • Daily note-taking, journalling and meeting notes, in a keyboard-first editor that opens on today's note.

  • Connected thinking: typing two square brackets links one note to another, backlinks are created automatically, and the accumulated links form a browsable graph.

  • Capture from outside the app: web clipper for pages and saved passages, Kindle clipping sync, Readwise sync, Google Calendar and Outlook calendars, phone voice memos.

  • Retrieval over your own material: fast search, semantic search, and a chat function that answers questions over the notes a search returns.

  • Writing assistance inside a note: a prompt palette that summarises, lists action items, generates outlines, and rewrites prose, applied to text you select.

  • Private publishing: any note can be published at a long, unguessable address.


What it is not: not a team workspace, not a project manager, not a document store for shared files, and not a collaboration tool. It is single-player. There is no real multi-user editing, no shared workspace and no comments.


Platforms: Web, macOS (Apple silicon and Intel), iPhone, iPad (beta). No Android app, and no dedicated Windows app.


Data model: Notes and daily notes, linked with square-bracket wiki links, tagged with hash tags, organised into graphs. Notes are the database; export and an append-only API are the documented exits.


Encryption: Note contents and file attachments are encrypted on the client with XChaCha20-Poly1305 before they reach the vendor's servers, using a password the vendor states never leaves your machine. The published independent review of that design is from the second quarter of 2021 by Doyensec.


AI layer: A prompt palette bound to a keyboard shortcut, semantic search, a chat function over search results, voice transcription, link summaries, and an MCP server that lets external coding agents read and write your notes locally. The vendor names OpenAI GPT models, Anthropic Claude models and Google Gemini across its pages, and the vendor's transcription model for audio.


API: A REST API with OAuth 2 and PKCE support. All note endpoints are append-only, because the servers cannot read encrypted note bodies. The vendor points to a community-hosted endpoint listing and offers no official software development kits.


Pricing (as published on reflect.app, read 2026-09-25): "One plan one price." The published figure is $10 per month, billed annually, with a 14-day trial. There is no free plan on the vendor's own page. Third-party directories disagree about that, and the disagreement is recorded in Section 9 rather than resolved here.


Free tier: None. A 14-day trial, requiring a sign-up, and a published refund policy on the academy site.


Developer: Reflect App LLC, 222 West Ave Apt 1805, Austin, TX 78701, United States. Founder and chief executive Alex MacCaw, previously a co-founder of Clearbit.




Open-source component: The client-side encryption library is published at https://github.com/team-reflect/kiss-crypto. The separate Reflect Open application is published at https://github.com/team-reflect/reflect-open under the MIT licence.


At a Glance Dashboard


Question

Answer

What is it

An encrypted, backlink-first note-taking app with an AI assistant over your own notes

Who it is for

One person who thinks in connected notes and wants the notes encrypted at rest and in transit

Time to first result

Minutes. The app opens on today's note and the AI palette is one keyboard shortcut away

Time to competence

Two to four weeks of daily use before the graph is genuinely useful to you

Cost of the honest path

$120 per year, billed annually, after a 14-day trial, with no free tier

Strongest attribute

Speed of capture and retrieval, and an audited client-side encryption design

Weakest attribute

The AI layer's documentation, which describes the models and the processing locations differently on three of the vendor's own pages

Platforms

Web, macOS, iPhone, iPad beta. Browser on Windows and Android

Export

Documented and available, including a Markdown and text path

API

Yes, append-only by design, with OAuth 2 and PKCE

Encryption

Client-side, XChaCha20-Poly1305, password-derived, independently reviewed in 2021

Mainstream review evidence

Product Hunt 4.87 out of 5 across 96 reviews on the product page; Apple App Store 4.7 out of 5 across 87 ratings. The G2 score under this name belongs to a different product


Back to the TOC

The Problem


You already have more captured material than you can use. Notes accumulate in an app that stores them well and connects them badly, so the tenth note on a subject does not make the first nine easier to find. The material that would have been useful is in a browser bookmark, a saved passage from a book, a chat message to yourself, and a photograph of a whiteboard, in four places that do not know about each other.


The second problem is quieter and it is why this review exists at all. The tools that fix connection tend to fix it in the cloud, which means your private thinking, your meeting notes about people, your health notes, your drafts and your half-formed opinions sit readable on someone else's servers, indexed by someone else's search, and usable for whatever the terms of service permit. The tools that keep your notes private tend to leave you the assembly work: a folder of files, a plugin for links, a second plugin for search, a third for the AI you were told you needed.


The third problem is the new one. Every note app now advertises an AI assistant, and the assistant promises to read your notes. Read by whom, on whose servers, under what agreement, and with what model, are questions the marketing pages rarely answer in the same terms as the legal pages. A product can hold an encryption key on your device and still send the text you select to a third-party model provider, and both statements can be simultaneously true. The reader has to hold both at once, and most marketing pages make that as hard as possible.


Reflect positions itself on the first two problems: it is a connected notebook that ships assembled, and it is encrypted so the vendor cannot read it. It also advertises the AI layer prominently. The tension between those two positions, and how honestly the vendor states it, is the centre of this review.


Back to the TOC

The Outcome


What Reflect delivers, stated as plainly as the evidence permits.


A connected notebook that requires almost no assembly. The daily note opens on today. Typing two square brackets creates a link and the backlink appears on the other note automatically. Tags attach meaning to notes and the graph view shows the shape of the accumulated material. Search is fast and works offline. Published users describe the app repeatedly as fast, and speed is the attribute that appears in nearly every independent account.


Notes the vendor cannot read. Note contents and attachments are encrypted on your device with XChaCha20-Poly1305 before upload, keyed on a password the vendor states never leaves your machine. That design was reviewed independently in the second quarter of 2021, and the reviewer concluded that the cryptographic primitives and their use were sound. This is a serious and unusually specific privacy claim, and this review treats it as verified for the architectural design and unverified for the current client, which is exactly how the vendor describes it.


A real AI layer with a real boundary, stated by the vendor in plain words. Selecting text and pressing the palette shortcut sends that text to a model provider. Chatting with your notes sends the notes in the search results. Voice memos are uploaded as raw audio for transcription. Everything else stays encrypted. The vendor says this directly rather than burying it, and that candour is a genuine credit. The boundary is the outcome: you get AI over your notes, and you get it at the cost of the selected material leaving the encryption boundary.


A cost, and a real one. The honest user pays $120 per year up front after a two-week trial, with no free tier on the vendor's own page. There is no Android app. The AI layer is capped at 100,000 tokens a day on the paid plan, roughly 400,000 characters, unless you supply your own API key and a separate billing relationship with a model provider. And the encrypted design means the vendor's servers can never run search or indexing for you, which is why the API is append-only and why the heavy lifting happens on your devices.


A fork in the road the vendor itself created. In July 2026 the company released Reflect Open, a local-first rebuild in which your graph is a folder of Markdown files, the Mac app is free, the source is MIT-licensed, AI runs on your own provider key, and sync can run through iCloud or a Git remote. The vendor's own announcement describes the reason as the difficulty of evolving the encrypted, proprietary-format original. A reader considering Reflect today is choosing between the vendor's two answers to the same question, which is unusual and worth knowing before paying for either.


Back to the TOC

Who Should Use Reflect


Learner type

Difficulty

Typical ROI

Career path

Students (Bachelor, Master)

Beginner to Intermediate. Writing notes is not hard; keeping a link structure that is useful six months later is a practice

Moderate where the student writes every day. A linked notebook is a durable study artefact and the daily-note habit survives exam periods better than a folder of documents. Held back by the price against a student budget and by the absence of an Android app, which removes the most common student device

UIT. UIB for students keeping a running record of a project or a venture. UIC for students who write. Programme anchors are set out in the credential table below

Professionals (career upskilling)

Beginner to Intermediate to run it; Intermediate to get lasting value. The difficult part is a note-taking discipline, not the software

Strong for a solo knowledge worker whose notes are private and whose time is the constraint. Capture is fast enough that the habit holds, retrieval works offline, and the encryption claim covers the contents of the notes rather than only the transport. The cost is one year up front and a genuine single-player ceiling: nothing here supports a team

UIT for engineering, data and AI roles where the MCP server and the API are usable. UIB for consultants, founders and analysts who live in client and project notes. UIC for writers and communications professionals. UID for designers keeping reference libraries. Institute mapping is set out in the alignment section above

Everyone (lifelong learners)

Beginner

Moderate. This is one of the few tools in this series that a non-specialist can adopt for personal use at the same price a professional pays, and the daily note plus backlink pattern is a genuine lifelong-learning structure rather than a productivity costume. The AI layer is a smaller part of the value than the vendor's homepage implies

SL-OS daily routine, LIPS Collect and Review phases, and the EVA cycle, for a reader applying a life-management method to their own material. No credential anchor


Skill level required: Beginner to operate, Intermediate to benefit. Every important action has a keyboard shortcut and the app can be driven entirely from the keyboard, which the vendor documents. What the tool does not supply is the judgement about what to write down and what to link, and that is the part that decides whether the notebook is worth $120 a year.


Prerequisites: A Reflect account with a paid subscription or an active trial, which requires supplying a billing method. A password for the encryption, which the vendor warns you must not lose, because losing it means losing access to every note permanently. A model provider key if you want AI usage above the published daily cap. For the MCP server, a desktop installation and a coding agent such as Claude Code, Codex or Cursor.


Typical time to first result: Minutes. Sign up, choose a password, and the app opens on today's note with the graph empty and ready. The first backlink exists as soon as you type two square brackets around any phrase inside another note.


Typical time to competence: Two to four weeks of daily use. The first week teaches the mechanics. The second and third weeks are where the value appears or does not, because a graph of ten notes is a novelty and a graph of two hundred notes with consistent link names is an asset. The single most valuable habit is naming links the way you will search for them later, which the vendor's own documentation addresses directly and which almost nobody does at the start.


Back to the TOC

U365 Institutes Alignment


Confirmed by the University 365 Department of Academics as the academic owner, on the rule that no credential or programme claim is asserted without verification.


Institute

Relevance

Why, stated as the competency that remains

The limit that holds the row

UIT (Technology, AI, Data Science)

High (primary), confirmed

The competency is reading a system's data position and its interface shape as engineering facts. A Fellow who can state what an encryption boundary does and does not cover in an application that calls a hosted model, who can explain why an API is append-only because the servers cannot read the bodies, and who can write an agent instruction that names one note, one action and a read-back check, is exercising engineering judgement that survives the removal of the product. The review carries the cleanest worked example of the encryption-boundary question in the current tool market, and the boundary is stated by the vendor in its own legal document rather than being inferred.

The tool teaches no programming, cryptography or machine-learning competency of its own. It publishes an open-source encryption library and an independent review of the design from 2021, which is evidence a Fellow can read, and the client shipping today is not the client that was reviewed, which the vendor states. Nothing here is assessable as modelling, and the API is append-only by necessity rather than as a design a Fellow may choose.

UIB (Business Management, Entrepreneurship)

Medium, confirmed

Two competencies, and both are appraisal of a published record. Supplier-claim appraisal: the public refund page promises a full refund with no questions asked while the terms make refunds discretionary and non-refundable except where the law requires, and the homepage states that nobody else can read your notes while the privacy policy names the exceptions in its own opening summary. Deciding which document governs, and keeping the page and the correspondence if you rely on it, is a commercial judgement the Fellow makes. Build-versus-buy reading: the vendor replaced a proprietary format and a custom sync engine with plain files and published its reasoning, which is a sunk-cost and technology-investment case read from the vendor's own account rather than from outside reporting.

The tool teaches no management, finance, entrepreneurship or leadership content of its own, and neither competency has a published U365 assessment home. A term search across the descriptions of all 79 published programmes returned zero matches for procurement, vendor management, unit economics, total cost of ownership, build-versus-buy and sunk cost, so the vendor-appraisal competency is coursework and not a credential.

UIC (Digital Communication, Marketing)

Medium, confirmed, reason replaced

The competency is the publication boundary on your own writing: deciding what a note may say when it sits at a public address, confirming that a rendered page carries nothing you would not want indexed, and reading your own draft as a stranger would. The review's own first-session checklist puts that decision on the Fellow by name, and the decision survives the removal of the tool. The second competency is the disclosure question the AI layer raises: a reader who keeps private material in an encrypted notebook has to decide which of it is eligible to leave the encryption boundary, and has to state that rule rather than assume it.

The tool supplies the publish action and not the medium. There is no audience, no channel, no analytics, no version control and no editorial workflow, and the product produces no campaign and no audience-facing asset. Writing every day in a linked notebook is practice, and practice is not a competency, which is why the row does not rise above Medium. No published UIC programme assesses publishing-boundary judgement, synthetic-media or data-flow disclosure, so the competency is assessed in coursework rather than against a credential.

UID (Digital Design, UX/UI)

Low, confirmed, reason replaced

The competency is reading an information architecture and an interaction model as an object of critique: how the link-and-backlink loop frames what a note is for, how the graph represents adjacency rather than hierarchy, and whether a keyboard-first editor that opens on today removes a decision or hides one. A designer who keeps screenshots, briefs and research notes in it is using it as a reference library, which is a working habit rather than a taught discipline.

The tool produces no visual asset, supports no layout work, evaluates no design against a brief and specifies no design method. It builds no UID disciplinary competency, so the row stays at Low, and no credential chain is mapped. Praising the interface as worth looking at is not a competency claim, and the sentence is removed rather than left to carry the row.


Skill level and the honest caveat. The alignment above is written for a reader learning to work with an AI-assisted tool on their own material rather than for a reader learning a professional discipline from the product. UIT carries the highest rating because the encryption boundary, the interface shape of the API and the agent write surface are teachable engineering artefacts. No credential chain is mapped at UID, because the product produces no design output even though it holds design references well.


Back to the TOC

How Reflect Works


Inputs: Typed notes and daily notes, wiki links typed as two square brackets, hash tags, Markdown formatting, tasks with checkboxes and due dates, images and file attachments, web page clips and saved passages from the Chrome or Safari extension, Kindle clippings, Readwise clippings, calendar events from Google Calendar and Outlook, contacts, voice memos recorded on a phone or in the desktop app, and text selected inside a note for AI processing.


Processing, and this is where the review has to be precise:


  • Storage and sync. The client encrypts note contents and attachments with XChaCha20-Poly1305 before upload. The vendor states the password used as the key never leaves your machine. The servers hold an encrypted blob the vendor states it cannot read.

  • Search. Search works on the client, which is the direct consequence of the encryption model. Fast local search is the product's most consistently praised attribute, and it exists because the vendor cannot search for you.

  • AI palette. You select text and invoke the palette with a keyboard shortcut. The selected text is sent to a model provider's API. The vendor's artificial intelligence page states that the tool uses OpenAI's GPT and Anthropic's Claude for the assistant and Google's Gemini for AI chat, while the security page states that text selected and processed with the AI feature is sent to one provider's servers. The two pages do not name the same set.

  • AI chat over notes. The search surface has a chat mode. The vendor states that if you click chat and start chatting, your search results are shared with the model provider, and that only the notes listed in the search results are shared.

  • Voice transcription. Audio recordings are uploaded as raw audio to a transcription provider, and the vendor states the audio file is deleted once the transcription has been synced to the note.

  • Contact and company enrichment. The product scans notes tagged with a person or company tag, extracts an email address or domain name from the note, and requests enrichment data from a third-party provider. The vendor states no identifying information about the requester is sent.

  • MCP server. A local server on the desktop app exposes your notes to an external coding agent at a loopback address. The agent can search notes, read a note or the daily note, create notes, append to the daily note, insert, replace or delete content, rename notes, toggle checkboxes, and restyle blocks.


Outputs: The notebook itself, in the form of notes, links, backlinks, tags, a graph view, tasks and a daily record. Published notes at unguessable public addresses. Exported archives in a documented format. AI-generated text inserted into notes under your control. Transcripts of voice memos. And, through the MCP server, whatever an external coding agent writes into your notes on your instruction.


Technology, stated as far as the vendor states it: A client-side encryption layer using XChaCha20-Poly1305, published as an open-source library. A proprietary note format and sync engine in the hosted product. A local search index that can be rebuilt and, in the vendor's own words about the encrypted product, cannot be served by the vendor. Hosted model access to OpenAI, Anthropic and Google models depending on the feature. A dedicated speech recognition model for transcription. An OAuth 2 authorization server with PKCE support for third-party clients.


The architectural consequence a reader should hold on to. Because the servers cannot read your notes, they also cannot search your notes, index your notes, back up a readable copy of your notes, or answer a support request about the contents of your notes. That single constraint produces the append-only API, the client-side search, the local MCP server, and the reason the vendor rebuilt the product in 2026. It is the most important design fact in this review, and it is coherent rather than contradictory.


Back to the TOC

Getting Started with Reflect


A first-session checklist. It takes about fifteen minutes to reach the point where the tool is doing something useful rather than sitting open.


  • Create the account and set the encryption password. Reflect prompts for a password during sign-up and uses it as the encryption key. Use a generated password stored in a password manager. The vendor's own wording is that losing it means permanently losing access to your notes, and that is not a soft warning: there is no recovery from the vendor's side that does not depend on you still being logged in somewhere, or on a recovery kit downloaded at sign-up.

  • Download the recovery kit and put it where you keep credentials. The vendor generates it at sign-up and downloads it to the machine you signed up on, typically in your downloads folder under a file name beginning reflect-recovery-kit. Move it into your password manager's file store rather than leaving it as a file in a downloads folder.

  • Install the desktop app and the phone app, and sign in on both. Real-time sync is the product's main promise and it is worth confirming on day one rather than on the day you need it.

  • Write in today's daily note and do not organise anything yet. The app opens on today's note by design. Write the first three entries about your actual day, including one thing you would normally keep in a chat message to yourself.

  • Create the first link deliberately. In a note about a person, type two square brackets and the name of a project. Open the project note and look at the backlink. That loop, repeated, is the whole product.

  • Adopt one naming rule for links before the graph has two hundred notes in it. Pick the form you will search for later, for example a person's full name rather than initials, and use it every time. Inconsistent link names are the single most common reason a personal graph stops being useful, and the fix costs nothing on day one and a weekend after a year.

  • Connect the capture sources you actually use. The Chrome or Safari extension for web clips, the Kindle sync for saved passages, Readwise if you already use it, and Google Calendar or Outlook if meetings are a large part of your notes.

  • Configure the AI deliberately before you use it. Open preferences and choose the model. Read the artificial intelligence page on the vendor's academy site first, so that you know what leaves the encryption boundary before you select text and press the shortcut. Decide now, not later, whether the notes you keep in this app include material you would not send to a hosted model provider.

  • Add your own model provider key if you expect to exceed the daily cap. The published limit is 100,000 tokens a day on a paid plan, described as roughly 400,000 characters, counting the prompt and the response together. Supplying your own key removes the cap and moves the billing to the provider, which means a second account and a second billing relationship.

  • Publish one note and read it as a stranger would. The publish action produces a long unguessable address. Confirm that the rendered note contains nothing you would not want indexed.

  • Export once, immediately, and open the result. Export is the exit path and its usefulness is a day-one question rather than a year-five question. The vendor's own history is the argument: a product built on a proprietary format and an encryption layer became expensive enough to evolve that the company rebuilt it around plain files.

  • Set a review date for the plan. Because there is no monthly option and billing is annual, the decision point is twelve months out. Put it in your calendar with the question you want to answer then: is this notebook earning the $120.


Verification checklist for the first session


  • The encryption password is stored in a password manager, and the recovery kit is stored with the credentials rather than in a downloads folder.

  • The desktop and phone apps both show the same note written minutes ago.

  • One backlink exists and resolves in both directions.

  • The link-naming rule is written down somewhere you will find it.

  • The AI model in preferences matches the vendor page you read, and you have decided which of your notes are eligible to be sent to it.

  • One exported archive has been opened and read, rather than only produced.

  • The annual renewal date is in your calendar.


Back to the TOC

Real Workflows


Three workflows, each with the prompt or the action, and each with a verification checklist. The verification steps are the point of the section: they are what turns a plausible output into a checked one.


Workflow 1: Turn a meeting into a linked record instead of a dead transcript


What you do. Before the meeting, open today's daily note and create a note for the meeting. Import the calendar event, which brings the attendees and the time. During the meeting, take plain notes, and every time a person or a project is mentioned for the first time, type two square brackets around the name instead of writing it plainly. After the meeting, select the notes and run the AI palette with the action-items prompt. Move the result into the meeting note under a heading, then go to each person's note and read the backlink that now exists.


What the AI does. It reads the selected text and returns a list of action items. It does not read the rest of your notebook, and it does not know anything about the people in the meeting beyond what the selected text contains. The backlinks are produced by the link syntax, not by the model.


Verification checklist:


  • Every action item the AI returned is traceable to a sentence you wrote. If an item cannot be traced to the selected text, delete it.

  • Every owner in the action list is a person who was in the meeting, or is explicitly marked as needing assignment.

  • Every person's name you linked resolves to a note, and a note that was created by the link contains at least one line saying who the person is.

  • You have read the text you selected before pressing the shortcut, and you are content with it having left the encryption boundary.

  • The daily note links to the meeting note, so the meeting is reachable from the day it happened.

  • No action item has been left in the note as the only record of a commitment. Anything with a date belongs on a task list outside the note.


Failure mode to expect. The palette will produce a tidy action list from messy notes, and tidy is not the same as correct. The most common error is attributing an item to the wrong person because a name appeared near a sentence rather than in it. The second is inventing an action from a discussion that ended without a decision.


Workflow 2: Ask your own notebook a question and check the answer against the sources


What you do. Open search, narrow it with a filter, for example a tag for a project or a client, and then use the chat function to ask a question over the filtered set. A useful first question is one whose answer you already know, so that you are testing the retrieval rather than testing the answer. Then read the notes the search returned and confirm the answer against them.


What the AI does. The vendor states that clicking chat shares the search results with the model provider, and that only the notes listed in the search results are shared. So the answer is bounded by the filter you set, which is a real control and worth using deliberately.


Verification checklist:


  • The answer cites or paraphrases only notes inside the filter you set. If it contains a fact from outside the filtered set, the retrieval is wrong and the answer should be discarded.

  • You have opened at least two of the notes in the result set and read the passages the answer draws on.

  • Where the answer summarises a disagreement between notes, the disagreement exists in the notes. A chat answer that flattens a genuine conflict into a single conclusion is the most expensive error in this workflow.

  • You have read the result set before clicking chat, because clicking chat is the act that sends it.

  • The question you asked for calibration is answered correctly. If a question whose answer you know comes back wrong, treat the whole surface as unreliable until you understand why.


Failure mode to expect. Semantic search will surface thematically adjacent notes that do not answer the question, and the chat layer will summarise them anyway. A confident answer assembled from adjacent material is the characteristic failure of this surface, and it is exactly the pattern the search filter limits.


Workflow 3: Let a coding agent maintain a project note, with the boundary written down first


What you do. Enable the MCP server in the desktop app, connect your coding agent to the local address the vendor documents, and give the agent a narrow, explicit instruction about one note. A worked example: ask it to append the deploy steps you have just completed to a named release note, and nothing else. The MCP server writes to your notes, so the instruction is the control surface.


What the AI does. The agent reads and writes your notes through a local server using credentials held on your machine. It can create notes, append to the daily note, insert, replace and delete content, rename notes, toggle checkboxes and restyle blocks. It is a genuine write capability, not a suggestion, and it is the strongest automation surface in the product.


Verification checklist:


  • The note the agent touched contains what you asked for and nothing else. Check the diff rather than trusting the agent's summary of it.

  • Nothing was appended to your daily note unless you asked for the daily note.

  • No note was created that you did not ask for. Check the note list sorted by creation date, rather than only the note you were watching.

  • No checkbox was toggled that represents a real commitment. An agent marking a release task complete is a claim about your project, not about the agent's run.

  • Deletions are read back before you move on. The MCP surface can delete a range of lines in one call, and there is no confirmation step inside the note.

  • The agent's instruction named one note and one action. If it named more than one, split the instruction, because a read-back verification of a multi-note change is work you will not do.

  • The note history shows what changed, which is the recovery path if the write was wrong.


Failure mode to expect. The agent will do exactly what it was asked and nothing more in the good case, and it will do exactly what it was asked and nothing more in the case you regret: an instruction that is one clause too broad, such as asking it to tidy a note, gives it a replace and delete capability over prose you wrote. Write the instruction as if you were briefing a competent contractor with write access to your private journal, because that is the arrangement.


Back to the TOC

Strengths, Limits, and AI Imposture Risk


Strengths


Speed is the strongest verified attribute, and it is structural rather than asserted. Independent accounts, review pages and community discussion all converge on the same word. Search is instant, the app opens on today's note, and the editor is keyboard-first with a documented shortcut set. This is not a marketing claim that requires a benchmark to check: it follows from the architecture, because search runs on the client and there is no server round trip and no network latency in the writing path.


The encryption design is specific, named and independently reviewed. Client-side XChaCha20-Poly1305, keyed on a password the vendor states never leaves your machine, applied to note contents and file attachments. The vendor publishes the client-side library used to do it, names the firm that reviewed it, and quotes the reviewer's conclusion that the cryptographic primitives and their usage were sound with no vulnerabilities or misconfigurations identified. A privacy claim with a named reviewer and published source code is a different class of claim from a privacy page.


The vendor states what leaves the encryption boundary, in its own words, on its own pages. The privacy policy sets out two exceptions in its opening summary rather than at the bottom of a long document: text you explicitly select and transform, or search results you explicitly select, is sent to a model provider's API, and audio recordings are uploaded for transcription. The artificial intelligence page repeats this feature by feature and answers the encryption impact question directly for both the palette and the chat surface. Most products in this category do not do this, and the review records it as a credit.


The architecture is coherent. Every awkward fact about the product traces back to one design decision. The API is append-only because the servers cannot read note bodies. Search is local because there is nothing readable to search server-side. The MCP server runs on loopback because the notes are already on your machine and already unreadable elsewhere. The 2026 rebuild exists because a proprietary encrypted format and a custom sync engine are expensive to evolve. A reader who holds that one fact can predict most of the product's behaviour, which is a sign of a genuinely thought-through design rather than an assembled feature list.


An exit path that is documented rather than incidental. A REST API, an export path, and an open-source client-side encryption library. In the hosted product the exit is partial, because the note format and the sync engine are proprietary. In the vendor's own 2026 replacement the exit is total, because the graph is a folder of Markdown files. Both facts are published by the vendor.


The daily-note and backlink pattern is a durable habit, not a feature. Users who describe using it for years describe the same thing: it replaced a general-purpose notes app because writing the day's note became automatic. A tool that survives two years of daily use in a crowded category is evidence of something that a feature table cannot show.


Limits


The AI layer's own documentation is inconsistent across the vendor's own pages, and the encryption promise and the AI feature pull in opposite directions. The privacy policy names three model providers for the AI feature. The security page names one. The artificial intelligence page names three but assigns them differently, with one vendor named for the assistant and another for chat. This is not a scandal and it does not mean the product is unsafe; it means the reader cannot determine from the vendor's pages alone which provider receives a given piece of text. Section 7c quotes the passages.


There is no free tier on the vendor's own pricing surface, and the plan is annual only. The published figure is $10 per month billed annually, which is $120 committed after a 14-day trial. Several third-party directories describe a free plan, and one states a figure the vendor does not publish. Those directories are wrong or out of date; the vendor's own page says one plan and one price. A two-week trial is enough to test the editor and not enough to test whether a graph is useful to you, because the graph's value appears in the third and fourth week.


No Android app, and no dedicated Windows app. The browser is the answer on both, which for a daily-note habit on a phone is a real limitation rather than a footnote.


The paid AI allowance is bounded and the boundary is not generous. 100,000 tokens a day on a paid plan, roughly 400,000 characters, counting prompt and response together, across whichever model you choose. Beyond that you supply your own key and take on a second provider relationship and bill.


Single-player by design. No shared workspace, no real multi-user editing, no team features. For a reader whose notes are a team asset, this is a disqualifying limit rather than a trade-off.


The security review is old and its scope is stated narrowly by the vendor. The published assessment is from the second quarter of 2021 and, by the reviewer's own summary as quoted by the vendor, it covers the system design, the cryptographic primitives and their use. The vendor states plainly that the client can be updated at any time and that you ultimately have to trust it, and describes that as a deliberate user-experience trade-off. That is honest, and it is also the correct frame for evaluating the claim: an audited design, reviewed five years ago, delivered by a client that changes.


A password you cannot lose, with recovery paths that depend on you. The vendor documents several recovery routes, all of which require you to still be signed in somewhere, or to hold the recovery kit, or to have stored the password in a browser or an operating system keychain. There is no institutional recovery. Losing the password loses the notes.


The refund position on the public page and in the contract do not say the same thing. The academy's refund page states that the policy is to offer a full refund with no questions asked. The terms state that paid subscription fees are non-refundable except where required by law, with requests considered case by case at the company's sole discretion. Section 7c records both passages verbatim.


Reflect: the vendor's own three pages describing the AI data flow, placed side by side, illustrating the documentation finding in Section 7c

A product family in transition, disclosed by the vendor as such. In July 2026 the company rebuilt the application around local Markdown files and released it as a separate free, MIT-licensed product, while keeping the existing hosted product running. That is a strong signal about the vendor's direction of travel and it is also a genuine planning question for anyone about to commit $120 to the hosted version.


AI Imposture Risk


Trap

Rating

Evidence

Time Illusion

Medium

The tool is genuinely fast at the thing it is designed for, and the saving is real: capture, linking and retrieval all work without prompting, and the daily note removes the decision about where to write. The trap is at the AI surface rather than in the editor. Producing an action-item list or a summary takes seconds, and then the verification cost lands: you have to read the selected text, read the output, trace each item back to a sentence, correct the attributions and remove the invented ones. On a one-paragraph selection the palette is a clear net saving. On a long meeting note it is roughly break-even against writing the list yourself, because you already know the content and the model does not. The vendor documents the daily token cap, which is an admission that the surface is metered rather than free, and the honest user's own key setup adds a second billing relationship to manage. Rated Medium rather than High because no part of the product is fast-looking-and-slow-in-fact: the speed claims are about the editor, and they hold

Quantity Illusion

Medium

The product does increase volume, and the mechanism is documented rather than asserted. A daily note plus link syntax means a reader captures more than they would in a document folder, and the capture sources bring in material from the web, Kindle, Readwise and calendars without a decision per item. The risk is specific and it is well known in this category: a notebook that grows faster than it is read is a notebook that is never read. The second risk is at the AI surface, where an action-item list or a summary is polished by construction and reads as finished. Rated Medium because the volume is real and usable and the polished-output risk is bounded by the fact that the user selected the source text and therefore knows what it should contain

Skill Illusion

High

This is the trap that applies most strongly, and two mechanisms support the rating. First, the product's own purpose is to hold the thinking for you: the vendor's language is that Reflect "builds you a second brain", and the daily-note-plus-backlink pattern means the linking work that would otherwise train note-taking judgement is performed automatically once the brackets are typed. A user can accumulate a rich connected graph without ever having decided how knowledge in their domain should be structured, and the graph's apparent richness is then evidence of the tool's linking rather than of the user's understanding. Second, and decisively, the AI output is inserted into the user's own durable notes. The palette writes text into a note under the user's authorship; the chat surface answers questions about the user's own knowledge base; and the MCP server lets an external agent create, rewrite and delete content in the notebook during use. Framework clause 5.2.3-a sets a Skill Illusion floor of no lower than Medium for a tool that writes procedural memory on the user's behalf, and sets the rating at High where the agent can revise that memory during use without a per-write human decision. That condition is met here: the MCP surface writes to the notebook while the user is working, the write is not gated by a per-write approval inside the note, and the durable artefact is the user's own knowledge base rather than the vendor's output. The full reasoning is in the clause note below


Overall AI Imposture Risk: Medium. One trap is High and two are Medium, with the High trap subject to real mitigations that the user controls: writing the agent instruction as a narrow, single-note instruction, reading the change back rather than the agent's summary of it, and keeping the AI palette to text you have read. Under framework Section 5.3 that is a Medium overall level. It is a Medium that requires disciplined use rather than a Medium that resolves itself.


Framework v1.2 clause note


Three clauses from framework v1.2 were checked against this tool. One applies, and two return a null. Each outcome is recorded with its reasoning, because a null reached without checking is worthless and an application recorded without its mechanism is not actionable.


Clause 5.2.3-a, agent-authored procedural memory: APPLIES, and Skill Illusion is recorded High. The clause sets a Skill Illusion floor of no lower than Medium for any tool that creates or revises the user's skills, memory stores or standing instructions on the user's behalf, and sets High where the agent can revise that memory during use without a per-write human decision, or where the user has no routine practice of reading what was written. Reflect meets the clause in a way that is different from the earlier applications in this series, and the difference matters. In the earlier cases the memory store was the tool's own record about the user, such as an automatic memory file or a skills file. Here the memory is the user's own knowledge base: the notebook is the durable artefact, the AI writes into it, and the MCP server lets an external coding agent create notes, append to the daily note, insert, replace and delete content, rename notes and toggle checkboxes while the user is working. Three facts establish the application rather than a mere proximity. First, the written artefact is durable and is reused in every later session, which is what makes the illusion outlive the task. Second, it is authored by an agent and presented as part of the user's own record, so the user holds a documented body of knowledge they did not write. Third, the write is not gated by a per-write human decision inside the notebook, which is the clause's own High condition. The counter-argument was examined and rejected: a note is a user artefact and the user chose to keep it, but the clause does not exempt a tool because the memory belongs to the user, and the risk it describes is sharper rather than weaker in that case, because a wrong line in the user's own notebook is a wrong line in the record the user will consult later and treat as their own thinking. The floor is therefore Medium and the recorded rating is High. The mitigation is stated in the workflows and in the guidance below, and the product supplies one of them itself: note history stores every change, so a wrong write is recoverable rather than permanent.


Clause 4.2-a, agent-mediated conversation: NULL. The clause concerns agent-authored text presented as a person's own voice in a human-facing channel, or the substitution of agent interaction for human contact. Reflect drafts no message to another person and sends none. The AI palette rewrites text inside your own note, the chat surface answers you, and the MCP server writes to your own notebook on your instruction. Nothing in the product composes communication in your name to a third party, and nothing substitutes agent interaction for human contact. The single feature that touches a human-facing channel is the publish action, and publishing a note is the user publishing their own writing at an address they chose. Social Authenticity is therefore scored neutral rather than eroded, and the reasoning is stated so that the null is not confused with a gap in the check.


Clause 7.5, team-level rooms: NULL. The clause addresses a shared channel in which a human coordinates with several named agents as peers, and requires a profile per agent in that case. Reflect's MCP server connects external coding agents to a personal notebook, but the notebook is single-player and it is not a shared room: the user addresses one coding agent they selected, in their own tool, under their own credentials, and no agent holds a conversation with the user in the notebook in its own name. The product is single-player by design, so the shared-channel condition cannot be met inside it. The consequence for the Collaboration Mode is none: the mode is derived from the Imposture Risk under framework Section 7.2 and is stated in Section 8.


Back to the TOC

Section 7c: Where the AI processing happens, and two of the vendor's own documents disagreeing about it, stated plainly


This section is not part of the CI-First score and changes no sub-score. It is here because the central security question for this product is not whether the encryption is real, which the vendor answers well, but how an end-to-end encrypted notes application can also run AI features over those notes. The answer is that it cannot do both everywhere, and the product's own pages describe the boundary differently from each other. A reader deciding whether to keep private material in this application needs the passages side by side rather than in the order a marketing funnel presents them. The framework measures benefit to the human, so nothing below moves the number, and saying so is deliberate: a reader who sees an unchanged score next to a documentation finding should not read the finding as discounted.


The passages, quoted verbatim, and they are all the vendor's own.


The privacy policy, last updated 20 March 2025, states in its opening summary:


"We never share your notes or read them. In fact the contents of your notes are end-to-end encrypted so no plaintext ever reaches our servers. The only exception to this is: 1. If you use the AI feature than we will send text you explicitly select and transform, or search results you explicitly select to OpenAI's API, Anthropic's API, or Google's API. This is also not associated with your account. 2. Audio recordings will also be uploaded to OpenAPIs API."


The same policy adds, in the section on in-app features, that it does not share user data with third-party tools including AI models except as outlined, and it points to two model providers' privacy policies by name.


The product homepage states:


"The contents of your notes are end-to-end encrypted. No one else can read them (not even us)."


The security page on the vendor's academy site covers audio and the AI feature in one paragraph. In the vendor's own words, voice recordings are processed through a provider's API, which the page states involves sending the raw audio to that provider, and the audio file on the vendor's side is deleted once the transcription has been synced to the note. The same paragraph then states:


"Similarly text selected and processed with our AI feature is also sent to OpenAPI's servers. OpenAPI's terms of service state they delete data after 30 days."


The artificial intelligence page on the same academy site states, answering what the product uses behind the scenes:


"We are using OpenAI's GPT and Anthropic's Claude API for the AI assistant and Google's Gemini for AI chat."


And, answering the encryption question for each of the two AI surfaces separately:


"If you do use this feature, only text that you explicitly ... will be sent to our (and the provider's) servers." "If you do click on the 'Chat' button and start chatting, then your search results will be shared with the model provider. Only the notes listed in the search results will be shared."


The finding, stated as a finding rather than as an allegation. Three of the vendor's own descriptions of the same feature do not agree about where the text goes. The privacy policy names three providers for the AI feature as a set. The artificial intelligence page names the same three but assigns one to the assistant and another to chat. The security page names one provider for the same feature and describes it as the destination for selected text. All three pages were live and current when this review read them. The most likely reading is that the security page has not been updated since the product added providers, and that the privacy policy and the artificial intelligence page are the accurate pair. That reading is a reconstruction and it is labelled as one. What a reader can establish from the vendor's own pages without reconstruction is narrower: the set of providers that can receive your selected text includes OpenAI, Anthropic and Google, and the security page's single-provider description is out of date or wrong.


Why this is the section a reader of this particular product needs. For most tools in this series, the data-flow question is one of several. Here it is the product's defining claim. The homepage sentence is absolute, and it is accurate about note contents at rest: the encryption is client-side, the key is derived from a password the vendor states never leaves your machine, and attachments are covered too. The same sentence is not accurate about what happens after you select text in a note and press the palette shortcut, or after you click chat on a search result set, or after you record a voice memo. The privacy policy is candid about all three exceptions and the homepage does not mention them. Both statements are the vendor's, both are current, and they answer different questions. Read together, the position is coherent and it is narrower than the homepage sentence taken alone: your notes are encrypted until you ask the product's AI to work on them, at which point the material you selected or the notes your search returned leave the encryption boundary in readable form.


The related passages a buyer should read together, quoted rather than summarised.


  • The public refund page states: "Our policy is to offer a full refund no questions asked. Email support@reflect.app". The terms, last updated 23 August 2023, state: "Except when required by law, paid Subscription fees are non-refundable. Certain refund requests for Subscriptions may be considered by the Company on a case-by-case basis and granted at the sole discretion of the Company." The public page is more generous than the contract, and only one of the two can govern a dispute. A reader relying on the refund page should keep the page and the correspondence.

  • The terms limit the company's total liability to "the amount actually paid by You through the Service or 100 USD if You haven't purchased anything through the Service", and exclude special, incidental, indirect and consequential damages. For a product whose stated value is the safety of your notes, the practical ceiling on the vendor's exposure is the amount you paid.

  • The terms permit the company to modify subscription fees in its sole discretion, effective at the end of the then-current period, with reasonable prior notice, and continued use constitutes agreement to the modified amount. Combined with annual-only billing, this means the price you can be charged next year is set by the vendor and acceptance is the default.

  • The privacy policy states: "We will never share your contacts or other plaintext data that we store on our servers (unless the US government forces us)." The vendor is a United States company with a stated Austin address, and the parenthetical is the operative part of the sentence for a reader outside the United States. It is honest and it is a jurisdictional fact rather than a promise.

  • The independent security review quoted on the academy's security page is from the second quarter of 2021 and its quoted summary covers design, primitives and their use: "At the design level, Doyensec found the system to be well architected. Cryptographic primitives and their usage is sound, with no vulnerabilities or misconfigurations identified." The same page states that the client can be changed at any time and that users ultimately have to trust it, and describes that as a deliberate trade-off. That is the correct scope for the claim: a design reviewed five years ago, delivered by a client that updates.

  • The contact and company enrichment path is a fourth data flow and the vendor describes it openly: the product scans notes tagged with a person or company tag, finds an email address or domain name in the note, and requests enrichment data from a third-party provider, while stating that no identifying information about who is making the request is sent.

  • The MCP server is a fifth flow and it is the one that changes over time rather than the one that leaks. It runs on the local machine at a loopback address, which keeps the notes off the network, and it hands write authority over the notebook to whatever agent you connect. The vendor documents that authority in a feature list that includes deleting content.


Reflect: what stays inside the end-to-end encryption boundary and what leaves it, illustrating Section 7c

What changed in July 2026, and why it belongs in this section. The vendor rebuilt the application around a different model and published the reasoning: the original was built with end-to-end encryption in the app and a proprietary note format and sync engine, and the vendor states that both decisions "created a great deal of complexity and made Reflect increasingly difficult to evolve". The replacement stores notes as ordinary Markdown files, uses the platform's file sync for sync and encryption, lets you mark specific notes as private so they are never sent to AI, and has no Reflect-hosted notes database. The consequence for this section is direct: the tension this section describes is a property of the hosted product's architecture, and the vendor's own answer to it is to change the architecture rather than to document the boundary more carefully. A reader who finds the tension unacceptable has a vendor-authored alternative from the same company, and should read the two products as two different data positions rather than as two editions of one.


What the section does not do. It does not assert that Reflect is unsafe, and it does not suggest that sending selected text to a model provider is improper, because it is disclosed in the privacy policy and it is the only way the feature can work. It does not treat the disagreement between the vendor's pages as deception, because the out-of-date page is the more restrictive one rather than the more flattering one, which is the reverse of how a misleading page usually reads. It does not advise against the tool, which would substitute a judgement for the reader's own. It states what the vendor published, quotes the passages that change an adoption decision, keeps the finding and the reconstruction distinct, and names the decision each of them puts in front of the reader: keep your most sensitive notes out of the AI surfaces rather than out of the app, decide before you select text rather than after, treat the refund page and the contract as two documents and keep the one you relied on, and read the vendor's two products as two different answers to the question of who holds your notes.


Back to the TOC

U365 Co-Intelligence Rating


CI-First Profile


Primary profile: Co-Worker and Assistant (level 2).


Secondary profile(s): Coach and Tutor (level 3), narrowly, for the reader who uses the daily-note and backlink pattern to learn how their own knowledge is structured. The vendor also publishes a free note-taking course at reflect.academy, including a principles of note-taking section and a linking section, which is teaching material rather than product documentation. Co-Creator and Thought Partner (level 1) is close to applying at the AI palette, because you select your own text and the model works on what you chose, and it is held at secondary-partial for one reason: the palette returns an answer rather than entering a dialogue with you over your note, so the human and the tool are not building on each other's thinking in the way level 1 requires.


Why level 2 and not level 1. Level 1 describes an ideation partnership in which the human and the tool alternate and each builds on the other's move. Reflect's design point is a fast personal notebook with an assistant you call on. You write, you link, you select, you ask, you read. The AI does not propose a direction for your notebook, does not challenge your structure, and does not know what is in it beyond what you selected or what a search returned. That is delegation with review, which the framework places at level 2, and the same reasoning placed Claude Opus 5.5, MiMo-V2.6-Pro, Rabbit OS3 and Klarent at level 2. It is recorded here so the series reads consistently.


What does not fit. Challenger and Devil's Advocate (level 5) does not apply: nothing in the product argues with your thinking, and the chat surface answers the question rather than questioning it. Analyst and Tester (level 4) is a partial fit at best: semantic search finds material you had forgotten, which is analysis of a kind, and it is retrieval rather than testing. The product has no hypothesis-checking, no coverage analysis and no counter-argument surface, so the profile is not claimed.


Collaboration Mode


Recommended mode: Centaur.


Alternative mode: None recommended. Cyborg is not available here.


Mode rationale: Two independent grounds, and both belong on the record. Framework Section 7.2 assigns Centaur when the Imposture Risk is Medium or High, and it is Medium overall with one High trap. The second ground is specific to this tool. Cyborg describes a fast loop in which the human iterates with the model and applies a stopping criterion from inside the loop. Reflect's AI surfaces are single-shot: the palette takes a selection and returns text, and the chat takes a result set and returns an answer. There is no iteration loop to stop in, and the work that matters, deciding what to write down, what to link, and whether to keep the answer, happens outside the call. The boundary that makes Centaur real here is procedural rather than interactive: read the text before you select it, decide in advance which notes are eligible for AI, keep the agent instruction to one note and one action, and read back the change rather than the summary. The division of labour is the whole point. You own the notebook and what it means; the model owns a transform you asked for.


CI-First Benefit Score


Dimension

Score (0-10)

Rationale

Time

6

Clear savings in the parts of the product that are designed for speed, and the savings are structural rather than advertised: the app opens on today's note so there is no filing decision, link syntax creates a backlink without a second action, search runs locally so there is no round trip, and capture from the browser, Kindle, Readwise and calendars removes a per-item manual step. Held below 7 because the AI surface changes the arithmetic rather than improving it: producing an action list takes seconds and then costs a full read-back to trace each item to a sentence and remove the invented ones, so on long meeting notes the net saving against writing the list yourself is close to zero. The daily paid allowance of 100,000 tokens, with a separate key and a second billing relationship to exceed it, is overhead the honest user does pay

Quantity

6

Real increase, and the mechanism is the product rather than a claim. The daily note plus wiki-link pattern plus five capture sources means a reader accumulates connected material they would otherwise leave scattered, and the graph makes previously separate notes reachable from each other. Held below 7 because the framework scores verified and usable quantity, and the failure mode of every personal knowledge base is documented and applies here: a notebook that grows faster than it is reread stops being a knowledge base and becomes an archive. The AI surfaces add polished volume, and polished volume that has not been checked is the definition of the trap the framework's Quantity dimension names

Quality

5

Moderate. The notebook itself is high quality and the claim is checkable: local search is fast and reliable, the sync is described consistently by users as dependable, the encryption design has a named independent review and a published client library, and export and note history exist. The dimension is scored on the whole tool rather than on the editor, and it is capped at 5 for reasons that are evidence rather than opinion. There is no independent measurement of the AI layer's output quality on this product anywhere, from any third party. The vendor's own pages do not agree about which model provider receives the selected text or which model serves which feature, so a reader cannot establish from the vendor's documentation which model produced a given output. And the AI output lands in a durable private record, which raises the cost of a quality failure rather than lowering it. A quality claim without a measurement is not a quality benefit, and here there is not even a stable description of the model

Skill

4

Marginal to moderate, scored conservatively as the framework directs. There is a genuine learning surface: the vendor publishes a free note-taking course covering principles and linking, the daily-note habit builds a real discipline, and a reader who maintains a consistent link vocabulary does develop judgement about how knowledge in their domain connects. Against that, the product links for you as soon as you type the brackets, holds the structure for you, and writes AI-authored text into your own record. Clause 5.2.3-a applies with Skill Illusion recorded High, and that floor sits on the Skill Illusion rating rather than on this benefit score. The score is conservative on this dimension's own bands: the product links for you as soon as the brackets are typed, it holds the structure for you, and it writes AI-authored text into your own record. A reader gains speed and a maintained habit and does not necessarily gain the structural understanding the habit is supposed to build


CI-First Benefit Score: (6 + 6 + 5 + 4) / 4 = 5.3 / 10 (CI-First Positive)


Why this score is not higher, and why it is not lower


5.3 is CI-First Positive, and the band label matters: this is a recommendation for the reader it fits, with the limits stated rather than smoothed over.


The score is not higher because of the AI layer, and the reason is documentation rather than capability. The product's own pages describe the model set differently in three places, and two of them contradict the third about which provider receives text selected for AI processing. A reader cannot check which model produced an output, which means the quality of that output cannot be attributed, compared or monitored. Add to that the absence of any independent measurement of output quality on this product, and the Quality dimension cannot honestly go above 5. The same finding depresses nothing else: the notebook's own quality is not in doubt. A second reason is the skill question: the product's stated aim is to hold the thinking, and the framework's most conservative dimension exists precisely to catch a tool that substitutes for judgement while appearing to build it. Clause 5.2.3-a applies, and it is recorded as applying rather than argued away.


The score is not lower because the fundamentals are real, specific and independently checkable, which is unusual in this category. The encryption is client-side, named, applied to attachments as well as text, supported by a published client library, and reviewed by a named firm whose quoted conclusion is that the cryptographic primitives and their usage are sound. The vendor states the AI data flows in its privacy policy's opening summary rather than in the small print, and answers the encryption question separately for the palette and for chat. Speed, the third pillar, follows from the architecture and is corroborated by independent users rather than only asserted. There is a documented export path, a real REST API with OAuth 2 and PKCE, an open-source encryption library, and a documented recovery kit for the one failure that would otherwise be catastrophic. And the vendor has published a second product that removes the tension this review spends a section on, which is a rare thing for a vendor to do.


The two dimensions that cap the total are the two the review turns on. Quality is held at 5 because the model set is not consistently documented and no independent measurement exists. Skill is held at 4 because the tool holds the structure, links for you, and writes into your own record.


Humics Protection Badge


Dimension

Rating

Rationale

Creativity

Neutral (0)

The product neither originates your ideas nor prevents you from having them. Its contribution to creativity is structural: linking two notes you wrote separately can surface a connection you had not made, and the graph view shows adjacency you might not have noticed. That is a prompt rather than a substitute, and the AI palette rewrites text you already wrote rather than proposing what to write. The risk exists and is bounded: an outline generated from scattered thoughts can become the outline, and the vendor advertises exactly that use. Because the common case is a tool acting on the user's own material rather than producing the direction, the rating is neutral

Critical Thinking

Erodes (-1)

Three mechanisms, and each is documented. First, the product's own framing is that it builds you a second brain, which encourages a reader to treat the accumulated graph as a record rather than as a set of claims to be examined. Second, the chat surface answers questions over your own notes in fluent prose, and the characteristic failure of that surface is a confident synthesis of thematically adjacent notes that do not answer the question; independent accounts of this feature class converge on that failure, and the check requires opening the notes rather than reading the answer. Third, and most specific to this product, the vendor's own pages do not agree about where the material goes, so the reader cannot reason about the data flow from the vendor's documentation alone, and reasoning about it is exactly the critical-thinking exercise the product's privacy promise invites. The mitigation is available and cheap, which is why this is -1 and not more severe: set the search filter before you chat, read the result set, verify the answer against two source notes, and read the encryption exceptions on the privacy policy rather than the homepage sentence

Social Authenticity

Neutral (0)

The product drafts no message to another person and sends none. Its outputs are your own notes, your own published note at an address you chose, and AI text you chose to insert into your own record. Framework clause 4.2-a is explicit that agent-mediated composition is not erosion by itself and that erosion requires agent-authored text presented as the person's own voice in a human-facing channel, or the substitution of agent interaction for human contact. Neither condition is met: the publishing feature is you publishing your own writing, and the AI palette operates inside a private note. The null under clause 4.2-a is recorded in the clause note, and the neutral rating follows from it rather than from a gap in the check


Humics Protection Score: 0 + (-1) + 0 = -1 / +3 Badge: Humics-Neutral


This is the same badge as most of this series and it should be read with its reason attached. The erosion is in one place: an encrypted notebook whose AI answers arrive finished, and a vendor documentation set that requires the reader to reconcile it. Both have controls, and the controls are in the workflows above and in the guidance below. Humics-Neutral describes a tool that neither strengthens nor weakens you on its own, and the whole point of the Co-Intelligence framework is that you decide which of the two it becomes.


Superhuman Usage Guidance


When to invite this tool:


  • Daily note-taking and journalling where the habit is the point, because the app removes the filing decision that kills daily-note habits.

  • A private knowledge base that includes material you would not put in a cloud document: personal notes, health notes, client notes, draft thinking. This is the case the encryption is built for, and it is the honest reason to pay for this product rather than one of the free alternatives.

  • Connected thinking over material you already accumulated: the first three months of use on a Kindle library or a Readwise archive is where the backlink model earns its place.

  • Meeting notes where attendees, projects and organisations recur, because the link-and-backlink pattern turns a transcript into a durable map of who is involved in what.

  • Personal research or study where the same sources keep returning, with the caveat that the AI surfaces should be used on selections you have read.

  • A workflow where a coding agent should maintain a project note, provided the instruction names one note and one action and you read the change back. The MCP surface is genuinely useful for keeping a running project record without switching apps.


When to keep this tool out:


  • Any note that must be readable by a colleague, a manager or an auditor. The product is single-player, the servers cannot read the notes, and the sharing story is a public unguessable address rather than a permission model.

  • Any notebook that includes material you would not send to OpenAI, Anthropic or Google, unless you have decided to keep those notes out of the AI surfaces entirely and you trust yourself to do that consistently. Read the privacy policy's own exceptions before you decide this.

  • A team or an organisation that needs a shared workspace, comments, or role-based access. It is not that product and it does not pretend to be.

  • Anyone on Android, or anyone whose primary work device is Windows and who wants a native application rather than a browser tab.

  • Anyone who needs a free tier or a monthly option. There is neither on the vendor's own pricing surface.

  • Anyone who cannot keep a password and a recovery kit safe. The encryption protects you from the vendor and from a server breach, and it removes the vendor's ability to restore your notes if you lose the key. This is the single most common way this class of product causes a disaster.

  • Any workflow where the chat answer would be the record of a decision. A synthesised answer over adjacent notes is a plausible summary, not a verified one, and it should never be the thing you act on about a person, a contract or a number.


Over-delegation warning. The failure mode here is specific and it is quiet. Because the notes are yours, encrypted, private and well organised by the link structure, the notebook feels like your own thinking whether or not you thought it. An AI-generated action list moves into a note without visible provenance. A chat answer that resolves a contradiction between two notes into a single conclusion leaves the contradiction unexamined. An agent appends a project update to your daily note and you never read it. The graph grows, the app stays fast, and the record looks like a mind at work. What has actually happened is that the structural work, deciding what connects to what and what a note is for, was performed by the link syntax and the model rather than by you. The CI-First formula is unambiguous about the consequence: if the human intelligence drops because the user stopped doing the thinking, the Co-Intelligence score drops even though the tool is unchanged. The Superhuman becomes Sub-human. The control is cheap and it is the same control in every workflow above: read what the tool wrote before you accept that it is part of your record.


Back to the TOC

What Users Say


Reflect has a real user base and a real review presence, and it also has a naming collision that inflates what a search returns. Both facts are recorded here, and the platforms that have no entry are named as having none.


Aggregate Rating Table


Platform

Rating

Number of reviews

Link

Product Hunt

4.87 / 5 on the product page across 96 reviews. A second figure of 4.8 across 45 reviews appears elsewhere on the same platform, and the two counts do not reconcile, which is ordinary for a platform that counts reviews differently on different surfaces

96 on the product page

Apple App Store (iPhone)

4.7 / 5 across 87 ratings. A reviews sub-page on the same listing shows 4.8 across 84 ratings, and the two counts do not reconcile

87

G2

4.7 / 5, 88 per cent five star. This is SmartBear Reflect, the software testing platform, and it is not this product

42

Capterra

A page exists for the note-taking product. No rating is reported here, because no rating is published on it in a readable form

No rating published

GetApp

A listing exists describing Reflect as a note-taking platform with encrypted, backlinked notes. No rating is published on it.

No rating published

Trustpilot

No review page for reflect.app was located. Searches under the name return unrelated businesses with similar names

0

-

NoteApps.info

An independent feature-review site that catalogues 129 Reflect features across 18 groups. Its own review section states no reviews yet

0

Product Hunt awards

2022 Golden Kitty Awards. Ranked fourth product of the month for April 2022, first product of the week for 11 April 2022, and second bootstrapped product of the year for 2022

Not a rating

Reddit

No dedicated subreddit. Discussion appears in general productivity communities, most often about the absence of an Android app and about the annual-only price

Not a rating


Three honest notes on that table. First, the highest-profile numeric score attached to the name Reflect belongs to a different product, and a reader who takes it as evidence about the note-taking app has measured the wrong thing; the review records the collision rather than resolving it in the vendor's favour. Second, the two business-software directories publish no rating for this product and are therefore not counted either way. Third, the independent feature-catalogue site with the most systematic treatment of this product publishes zero user reviews, which is the same absence Section 9 reports for several tools in this series and is a fact about the category rather than about the product.


What Users Praise


The praise is consistent across platforms and it clusters on speed, the daily-note workflow, and the linking model.


A Product Hunt summary of the product's reviews records that reviewers see Reflect as a fast, simple, well-executed note app that becomes part of daily work, especially for journalling, meeting notes and linked thinking, and that they repeatedly praise the clean editor, the backlinks, the daily notes, the strength of the search, and the privacy position. App Store reviews carry the same theme over a longer horizon: one long-term user describes having replaced a default notes app entirely and using Reflect daily for two straight years, and another describes it as well built with a solid AI implementation.


The most-quoted attribute is speed, and the second is the daily note. A recurring formulation in community discussion is that the app opens where you were going to write anyway. That is a design decision rather than a feature, and it is the one users describe as the reason the habit stuck.


What Users Complain About


The complaints are equally consistent, and they are the three limits this review names in Section 7.


Price and the absence of a free tier. The criticism that appears most often outside the vendor's own pages is that the product asks for a full year up front before the user has written anything, and that the trial is too short to test whether the structure suits you. The vendor's position is "one plan one price", and the review records the criticism without endorsing either side: a fourteen-day trial tests the editor, and it cannot test the graph, because the graph's value appears in the third and fourth weeks.


No Android app. This is the single complaint with the strongest evidence. A community thread on a productivity forum records a user who was considering the product and did not commit specifically because the mobile experience for Android users is poor. For a daily-note product, that is a real exclusion rather than a preference.


No sharing or collaboration. The product offers a publish action and a public address, and no permission model. Users who need to share a note with a colleague find that the only route is a public link, and several independent reviews list the absence of sharing as the practical limit.


The AI feature is not why most users stay. This is an observation rather than a quoted complaint, and it is supported by the praise pattern: the long reviews are about the editor, the links, the search and the encryption. The AI palette is described as useful and not as the reason to buy. That matters for a reader weighing the product, because the AI layer is the part whose documentation does not hold together and it is also the part users value least.


Sentiment Summary


Overall sentiment: Positive and stable, with the strongest sentiment attached to the parts of the product that do not involve the AI layer.


Key themes:


  • Speed and reliability are the attributes users agree on, and they are architectural rather than promotional.

  • The daily note is what creates the habit, and the habit is what creates the value.

  • The encryption claim is taken seriously by users and is the differentiator most often named against free alternatives.

  • No Android app is the most frequently cited concrete limitation, followed by price and the absence of sharing.

  • The AI layer is used and appreciated but is not the reason users describe staying.

  • The platform's own rating has drifted between reads, which is normal and is recorded rather than averaged.


U365 Editorial Note


The crowd and the framework agree here more than they do for most tools in this series, and the agreement is informative.


Where they agree: both put the product's value in the notebook rather than in the assistant. Users describe staying for the editor, the daily note, the links, the search and the encryption. The framework reaches the same place by a different route, scoring Time and Quantity on the structural features and capping Quality because the AI layer's own documentation does not establish which model produced an output. Neither the crowd nor the framework treats the AI feature as the reason to buy, and the vendor's homepage leads with it. That divergence between the vendor's framing and both the crowd's and the framework's assessment is the clearest finding in this section.


Where the crowd is more useful than the framework can be: the Android complaint and the price complaint are stated by users in terms the framework has no dimension for. The framework measures benefit to the human net of overhead, and it cannot tell you that a device you own has no native application. The community does, immediately.


Where the framework is more useful than the crowd: no review platform raises the question of what an end-to-end encrypted notebook means when its AI features send selected text to a model provider. It appears in the vendor's privacy policy, in the vendor's academy pages, and in independent privacy-focused commentary, and not in the review corpus at all. A user reading the ratings learns that the app is fast and private. A user reading the vendor's legal pages learns something more precise, and the precision is what a U365 reader needs, because the material a knowledge worker keeps in a private notebook is often the material that should not leave the encryption boundary.


The one point on which the crowd is more honest than the framework can be about this product: long-term users report that the AI features are secondary to their use. The framework scores the tool as a whole and cannot rank its parts by how much the user actually relies on them. A reader who takes the score as a description of what to expect day to day should weight the notebook heavily and the assistant lightly, and that is what the user evidence says.


Back to the TOC

Comparison and Alternatives


Alternative

"Choose the alternative if..."

"Choose Reflect if..."

You want to own the files outright and you are willing to assemble the system. Notes are plain Markdown in a folder you choose, the app itself is free for personal use, the library of community plugins is the largest in this category, and the data never depends on a vendor continuing to exist. The cost is assembly: links, search, sync and any AI layer are chosen and maintained by you, and your notes are not encrypted by default, so an AI plugin sends plaintext to whichever provider you configure

You want the connected notebook to arrive assembled and encrypted, you value speed of capture and retrieval over configurability, and you would rather pay $120 a year than spend the configuration time. The honest framing is that Obsidian gives you ownership and control and Reflect gives you a working system on the first day with the vendor unable to read your notes. Note also that the vendor's own Reflect Open is the closer answer if ownership is the deciding factor

Your work already lives in a shared workspace and you need pages, databases, tasks, permissions and collaboration in one place. Notion is a workspace platform with a note-taking surface, it is built for teams, it has an AI layer across the workspace, and its pricing starts far below Reflect's for an individual and scales by seat for a team. It is not end-to-end encrypted, and that is a design choice rather than an oversight: a workspace that several people and their AI can search cannot be encrypted with a key only you hold

Your notes are private rather than shared, single-player is the honest description of how you work, and the encryption claim is the reason you are choosing. Reflect is faster for writing and retrieval, it opens on the day's note rather than on a page hierarchy, and it is designed for one person. Choose Notion the moment a second person needs to read or edit the notes; choose Reflect the moment the notes are the thing you would least like indexed

You want the same vendor's thinking without the hosted data position. The graph is a folder of Markdown files, the Mac app is free and MIT licensed, sync runs through iCloud or a Git remote, AI runs on your own provider key, individual notes can be marked private so they are never sent to AI, and there is no Reflect-hosted notes database and no product analytics. The costs are real: at the time of writing it is a new application in beta, the mobile app is a TestFlight beta and the vendor states it is expected to become paid with pricing undecided, and the feature set is narrower than the hosted product

You want the assembled product the vendor currently supports at full strength, with a web app, a shipping iPhone app, published documentation and an API, and you accept the hosted data position set out in Section 7c. The two are made by the same company and they are two different data positions rather than two editions. Read both pages before choosing

You want the app to organise for you rather than with you. Mem's pitch is automatic organisation of captured material and an assistant over it, which suits a reader who will not maintain a link structure. The trade-off is the one this review's Section 7c exists to discuss: Mem's own position is that data is encrypted at rest rather than end to end, because a searchable assistant cannot run over notes it cannot read

You want to keep control of the structure and you want the encryption to be end-to-end rather than at rest. Reflect asks you to link and tag; that work is the reason the graph is useful and it is also the reason some users leave. If you will not do the linking, an automatic-organisation product will serve you better and this review says so

Logseq or Roam Research

You think in outlines and blocks rather than in pages and links, and you want the outliner model with a block-level graph. Logseq is local-first and open source with Markdown files; Roam is the product that defined the networked-thought pattern and it is sold as a subscription at a higher price than Reflect

You want a page-and-link model rather than a block outliner, and you want the encryption claim. Reflect's daily note and wiki-link model is closer to a notebook than to an outliner, and the choice between them is a choice about how you think rather than about features


Back to the TOC

Verdict and Next Steps


Verdict. Reflect is a good note-taking application with a genuinely strong privacy position and a weaker AI layer than its homepage implies. The notebook is fast, the daily-note-and-backlink pattern works, the encryption is client-side with a named independent review and a published client library, and the vendor states the exceptions to that encryption in its own privacy policy rather than hiding them. The AI layer is real, it is useful on selections you have read, and its documentation does not hold together across the vendor's own pages about which model provider receives your text.


At 5.3 out of 10 it is CI-First Positive. That is a recommendation with conditions rather than a caution, and the conditions are specific: pay for it if you want an encrypted personal notebook and you will do the linking; do not pay for it if you want a team workspace, a free tier, a monthly option, or an Android application; and decide before you subscribe which of your notes are eligible to be sent to a model provider, because that decision is yours and the product will not make it for you.


Next steps, in order.


  • Read the privacy policy's own summary before you read anything else. It names the exceptions in its first paragraph. If the exceptions are acceptable for the material you intend to keep in the app, the rest of the product is worth a trial. If they are not, read Section 10 and consider the vendor's own Reflect Open instead, which has a different answer to the same question.

  • Run the 14-day trial on the thing you will actually do. The trial tests the editor, the linking and the capture sources. Write the same kind of note every day for the trial, and at the end ask whether the graph is more useful than the folder you replaced.

  • Set the link-naming rule on day one. Pick the form you will search for in a year and use it every time. This costs nothing now and is expensive to fix later.

  • Decide the AI boundary explicitly. Choose the model in preferences, note which provider it belongs to, and decide which notes are eligible. Then hold to it, because a private notebook with selective AI use is only private to the extent you are consistent.

  • Supply your own model key only if the allowance blocks you. The paid allowance is a real limit, and adding a key adds a second billing relationship to manage. Measure your use for a month before you set it up.

  • Export once and open the result. Confirm the export is something you would be able to use if the product changed direction, and note that the vendor has already changed direction once, in July 2026, by building a different product.

  • Keep the encryption password and the recovery kit where you keep credentials. The vendor documents several recovery paths and all of them depend on you. This is the failure that ends the relationship with the product, and it is avoidable.

  • If you connect a coding agent, write the instruction as a single note and a single action, and read the change back. The MCP surface can delete content. It is a useful capability and it is the one place in this product where an agent writes to your record while you are working.

  • Re-check the plan at renewal. Billing is annual and the price can be modified by the vendor at the end of the period with notice, with continued use counting as agreement. Diary the decision rather than letting it renew by default.


Where this fits the U365 method stack


This is not a scored section and it makes no claim about U365's own tooling. It records where a reader applying U365 methods would place this class of tool.


  • LIPS, Collect and Review. A private, linked notebook is a natural Collect surface, and the backlink graph is a usable Review surface: opening a person's or a project's note and reading the backlinks is the manual version of the review step, performed by the tool rather than remembered by the reader.

  • EVA, Explore and Visualize. The graph view and the tag structure are Visualize surfaces. They show the shape of what has been collected without the reader having to reconstruct it.

  • CI-First discipline, and this is the one that matters. The framework places this tool at Co-Worker and Assistant with Centaur as the collaboration mode. Applied to the AI surfaces, that means the reader keeps the orchestrator seat: choose what to send, read what came back, and keep the record of decisions in the reader's own words rather than in a generated summary.

  • UP-Context prompting. The AI palette accepts saved custom prompts and the vendor exposes how each built-in prompt is written, including the placeholder that separates your selected text from the instruction. That makes it a usable surface for a reader practising structured prompting, with the caveat that the prompt and the selection both leave the encryption boundary when you run it.

  • UNOP. The daily note is a spaced rehearsal surface by construction: the same note type is opened every day, and the link structure brings earlier material back into view when it is relevant. Nothing in the product enforces retrieval practice, and the pattern supports it if the reader reads backlinks rather than only writing new notes.


UP-Context prompt pack


Three prompts a Fellow can save into the notebook's own prompt palette. Each states the boundary the prompt operates inside, because this product writes into a durable record and sends selected text outside an encryption boundary, and both facts belong in the prompt rather than only in the guidance above.


A check of what leaves the encryption boundary before you select anything


Context: I keep [kind of material] in an encrypted notebook, and the notebook's AI features send selected text to a hosted model provider. My policy is [your rule]. The note I am looking at is [note name], and it contains [what kind of information]. Role: AI as Analyst and Tester (Profile 4). You review the boundary question. I decide what stays in the notebook and what is eligible for AI processing. Task: read the material I paste below and return a classification of it against my policy. Constraints: do not rewrite my material, do not summarise it and do not offer advice on the subject matter. Work only from what I paste. Where a passage is borderline, say it is borderline rather than deciding for me. Do not tell me the vendor's encryption is strong or weak: the question is what my own policy says about this material. Output format: a table with the passage, the category you assign, and whether my stated policy puts it inside or outside the AI-eligible set. Then one heading: "I cannot classify this", for anything that needs a decision I have not written down. UP-Context verification: I read every passage you classified before I act on the table. I check two of your classifications against my own policy wording, including one where you called it borderline. I decide the borderline cases myself, and I write the resulting rule where I will find it next time rather than leaving it in this conversation. Nothing you said about the material is authoritative: I am the only party who can decide what my own notes may contain.


Turn a meeting note into a linked record whose action items are traceable


Context: meeting notes for [meeting], written [when]. Attendees: [names]. The project is [project]. The notes are [paste or note name]. I will link every person and project named. Role: AI as Co-Worker and Assistant (Profile 2). You transform text I have written and read. I own the record, the links and the decision about what is a commitment. Task: from the notes only, return the action items and the decisions, keeping each item traceable to the sentence it came from. Constraints: no item may appear that you cannot tie to a sentence in the notes. Do not assign an owner who was not in the meeting, and mark an item as needing an owner rather than guessing one. Do not resolve an open question into a decision. Do not add an item because it would be reasonable to do so. State the exact sentence for every item you return. Output format: a table with item, type (action or decision), owner if stated in the notes, and the sentence you relied on. Then one heading: "Mentioned but not decided", for discussion the notes record without a conclusion. UP-Context verification: I check every returned item against the sentence you cited, and I delete any item whose sentence does not support it. I set the owners myself and I put anything with a date on a task list outside the notebook. I choose the link names for the people and the project, and I read the backlinks afterwards to confirm they resolved. If I cannot trace an item in one move, it does not become part of my record.


A bounded agent instruction for one note, with the read-back written in


Context: [project] note called [note name]. The change I want is [one action]. The current content is [paste]. The agent connecting to my notebook can create notes, append, insert, replace, delete, rename and toggle checkboxes. Role: AI as Co-Worker and Assistant (Profile 2) with write authority limited to one note. I authorised this one action, and I read the change back before it stands. Task: perform this single action on this single note: [action]. Nothing else. Constraints: do not touch any other note, and do not append to the daily note. Do not create a note I did not ask for. Do not delete any line unless deleting is the action I named, and if deleting is the action, return the lines first and wait for my confirmation. Do not restyle anything. Do not toggle a checkbox, because a checkbox in my notebook is a claim about my project rather than about your run. Output format: before the write, the exact lines you intend to change and the exact replacement. After the write, the note name, the line range changed, and the resulting content of that range. Then one heading: "What I did not verify". UP-Context verification: I read the changed range rather than your summary of it, I confirm the note list has no note I did not ask for, and I check that nothing was appended to the daily note. I confirm no checkbox moved. If the note history does not show the change you described, I treat the write as unverified. I keep the instruction to one note and one action, because a read-back check of a multi-note change is work I will not do.


Where U.Copilot should route Fellows to Reflect


Route to Reflect when the Fellow needs to:


  • Keep private working material in one connected place: client notes, personal notes, health notes, draft thinking, and material they would not put in a cloud document

  • Turn recurring people and projects into a durable map, where the value comes from reading backlinks rather than from searching

  • Capture continuously from a browser, a Kindle, Readwise and a calendar, and read it back offline

  • Practise a knowledge habit with a structure the software maintains, at the point where the Fellow will actually keep it

  • Work with a coding agent on a project record, provided the instruction names one note and one action and the Fellow reads the change back


Where U.Copilot should route Fellows away


Route away when the Fellow:


  • Needs a shared workspace, comments, permissions or role-based access. The product is single-player by design; the only sharing route is a public address with no permission model.

  • Needs a team deliverable or an auditable artefact produced from the notebook. The vendor cannot read the notes, so nobody at the vendor can recover or verify their contents.

  • Is on Android or works primarily on Windows and wants a native application rather than a browser tab.

  • Needs a free tier or a monthly option. Neither exists on the vendor's own pricing surface.

  • Intends to keep material in the notebook that must not reach a hosted model provider. The AI features send selected text outside the encryption boundary, and the decision about which notes are eligible is the Fellow's and not the product's.

  • Wants the AI answer itself to be the record of a decision about a person, a contract or a number. A fluent synthesis over adjacent notes is a plausible summary, not a verified one.

  • Cannot keep an encryption password and a recovery kit safe. Loss of the key is loss of the notes, and there is no institutional recovery.


The guardrails that must not be softened


  • State the score beside the risk. 5.3 out of 10, CI-First Positive, with Medium AI Imposture Risk, and name Skill Illusion High rather than only the overall Medium.

  • Require the disclosure rule before the first AI use. A Fellow must be able to state which of their notes are eligible to leave the encryption boundary, and that rule has to be written down rather than assumed.

  • Require the read-back on every agent write. The MCP surface can delete content in a call, and there is no confirmation step inside the note.

  • Require the privacy policy to be read before the homepage. The policy names the exceptions to the encryption claim in its opening summary; the homepage states the absolute version.

  • Never present the notebook's speed as evidence about the AI layer's quality. Users praise the editor, the search, the links and the encryption. The AI layer is the part whose documentation does not hold together and the part users describe as secondary.

  • Never read Quality 5 as a statement that the notebook is mediocre. The cap is driven by measured absence: no third party has published an output-quality measurement for this AI layer, and the vendor's pages do not agree on which provider receives selected text, so an output cannot be attributed to a model.

  • Keep the Section 7c finding beside the adoption decision, and state that it moves no sub-score. A reader who sees an unchanged score next to a documentation finding must not read the finding as discounted.


SL-OS placement and the LIPS record


Reflect fits SL-OS as a capture and linking surface for the ULM domains, and it does not replace planning, review or judgement. One LIPS record per substantive engagement, under the relevant Project or under the ULM domain it serves:


  • The objective in the Fellow's own words, and the question the notebook is meant to answer

  • The link-naming rule in force, and the date it was adopted

  • The AI boundary rule: which notes are eligible to leave the encryption boundary, and the date it was written

  • Which model is selected in preferences, and which provider it belongs to, as stated on the vendor's own page

  • Every agent write, with the note, the action, the line range and the date the Fellow read the change back

  • The export path used and the date the exported copy was opened and read

  • The decision log: what stayed in the notebook and what was moved out to a shared workspace instead

  • The renewal date and the price in force, because billing is annual and the price can change at the end of a period


EVA placement. Collect is the notebook itself. Explore is search and the graph over material already captured. Visualize is the graph and the tag structure. Action Plan is the link-naming rule and the AI boundary rule, both written before the graph grows. Review is reading backlinks rather than writing new notes, which is the step the product supports and does not enforce.


Cadence. Five to fifteen minutes daily for the note itself. One weekly review of backlinks opened, not written. One monthly check of the AI boundary rule against what was actually sent. One annual decision at renewal rather than a default renewal.


Microsoft 365. There is no native integration and none is needed. Keep the notebook for private thinking and keep shared work in SharePoint and Teams, because the product cannot do both. Export to OneDrive when material becomes a deliverable, and never place credentials, keys or unredacted secret-bearing material in a note, because the encryption claim protects against a server breach and not against a shared screen or an agent with write authority.


Tool to Skill to Credential


Confirmed and corrected by the University 365 Department of Academics as the academic owner. No credential claim is asserted here without verification, and every programme named below was read from the published catalogue on 2026-09-25, where each programme page was opened and its description and module list read.


No published U365 credential assesses any of the six competencies this tool exercises. That is the finding, and it is not a catalogue defect: it is a statement about what the tool does. It removes a note-taking and linking burden rather than teaching note-taking judgement, and U365 credentials assess what a Fellow can do rather than what a tool can do for them. The Skill sub-score of 4 records the same thing from the scoring side.


Every row therefore does two things. It names the nearest published programme a Fellow could enrol in, and it states what that programme does not publish. An adjacent anchor is useful to a Fellow who wants the neighbouring skill. An adjacent anchor is not a credential claim.


Tool skill

U365 competency

Credential, and what it does not publish

Institute

Reading a client-side encryption design, its boundary and its exceptions, and reconciling a privacy policy against a security page

Reasoning about where data lives and what an encryption boundary does not cover

IT Security Specialist (60 days), published, carries Core Concepts, Operating System Security, Network Security, SSL/TLS, Vulnerability Management, Threat Modeling and AI for Cybersecurity, and it is the only programme in the catalogue whose description mentions cryptography or threat modelling at all. It publishes no module on user-facing encryption boundaries, no privacy-policy reading and no application data flow, so the competency in this row is not asserted as credential-recognised.

Reading an API as a design statement rather than a feature list, and understanding what a server cannot do for you

Integration engineering and interface reading against a published specification

Full-Stack Web Developer (60 days), published, carries REST APIs, Node.js, SQL and NoSQL, Git Essential and DevOps Foundations, and it is the only programme in the catalogue whose description mentions an API at all. It publishes no module on authorisation design, no append-only or event-sourced interface pattern, and no case in which an interface's shape is forced by a data-protection decision, so this competency is not asserted as credential-recognised.

Writing an agent instruction that names one note and one action, keeping a read-back check, and knowing which parts of a private record an agent may write to

Delegating to an agent with write authority, and designing the boundary and the read-back that make it safe

MCP Server from Zero to Deployed (2 days, certificate) publishes building MCP servers from scratch, elicitation and sampling, security and authorisation, and remote deployment, and it publishes a Micro-Credential for your Career of 1 US academic credit and 1.5 ECTS. AI Agents and Workflows Automation with n8n (2 days, same credit) publishes building advanced agents and custom MCP servers for multi-agent tool use. Neither publishes an outcome in agent write authority over a personal record, in instruction scoping or in read-back verification, so the competency is taught rather than assessed.

Reading the vendor's own published record for a purchase decision: a refund page against its terms, and a published rebuild explained as a sunk engineering cost

Supplier-claim appraisal and technology-investment reading

Entrepreneur (25 days) publishes a Business Law module, raising capital and income tax, and Business Analysis Professional (60 days) publishes benefits realisation and business process modelling, and Project Manager Mastery (25 days) publishes budgets and stakeholder communication. The catalogue description search returns zero matches for contract, licence, procurement, vendor management, unit economics, total cost of ownership and sunk cost, so this competency is not asserted as credential-recognised.

Keeping a daily linked notebook and a link vocabulary that still works after a year, with the capture habit that makes the graph worth having

Personal knowledge management as a practice: capture discipline, link naming and structure that survives

Superhuman Expert with AI (30 days, diploma) is the one programme whose published description uses the digital second brain framing and teaches LIPS and CARE as the execution system, and Administrative Professional (30 days) publishes an explicit Effective Note-Taking module, and Microsoft 365 Expert (46 days) publishes OneNote for Windows. None of the three publishes a linking method, a graph or backlink model, or a module on naming structure, and the catalogue search returns zero matches for knowledge management, backlink and capture discipline, so the practice is supported rather than assessed.

UIT, UIB and UIC

Deciding what a note may say at a public address, and deciding which of your material is eligible to leave the encryption boundary for AI processing

Publication-boundary judgement and data-flow disclosure on your own writing

Content Marketing Specialist (30 days) publishes Content Strategy, Content Writing and SEO, and Social Media Marketing Manager (30 days) publishes Copywriting for Social Media and Content Creation Strategy. Both publish audience-facing writing for a channel. Neither publishes a disclosure rule, a synthetic or AI-assisted content policy, or a decision about third-party processing of source material, and the catalogue search returns zero matches for publication, editorial, disclosure and media literacy, so the rule is assessed in coursework rather than against a credential.


Six rows, and a seventh competency deliberately left off the table. The reading of an information architecture as an object of critique is the design-institute row in the alignment above, and no credential is mapped for it, because the nearest published programme, UX Designer Expert (25 days), assesses the making of a design rather than the critique of someone else's. Mapping it would inflate the claim. No design-institute credential chain is asserted, which matches the statement made in the alignment above.


Curriculum gaps recorded


Four competencies this tool exercises have no assessment home in the published catalogue. They are recorded as gaps rather than filling them with a plausible programme name.


  • The user-facing encryption boundary and the reading of a privacy policy against a security page. The catalogue carries system security, network security and threat modelling, and it carries nothing on the boundary a privacy claim actually has, on reading two vendor documents against each other, or on reasoning about an application's data flow from its legal pages.

  • Agent write authority over a personal record. The MCP certificates teach how to build and secure a server. No programme publishes an outcome on deciding what an agent may write into a record the Fellow owns, on scoping the instruction, or on the read-back step that makes the write safe.

  • Publication-boundary judgement on your own material. Content and social programmes publish audience-facing writing for a channel. No programme publishes the rule for what may sit at a public address with no audience, or the decision about which material is eligible to leave a private boundary for third-party processing.

  • Reading a vendor's own published record as a commercial appraisal. The catalogue carries financial statement analysis and benefits realisation. It carries nothing on supplier-claim appraisal, on reading a public promise against the contract that governs, or on a published build-versus-buy decision.


What is not claimed. None of the four is a current programme and none is presented as one. They are named so that a curriculum conversation starts from the evidence rather than from a placeholder, and so that a reader is not told a credential exists where none does.


Access levels, stated plainly. University 365 has three academic access levels: DISCOVERY, INSIDER and SUPERHUMAN. Specialised diplomas and certificates carry Basic, Foundation and Expert levels: DISCOVERY Fellows can enrol in Basic-level programmes only, INSIDER Fellows in Basic and Foundation programmes, and SUPERHUMAN Fellows in all of them. University degree programmes carry a single Expert level and are open to SUPERHUMAN Fellows only. No degree chain is asserted for any row above, and no micro-credential component title is asserted anywhere: every anchor is a programme a Fellow can find and enrol in.


Back to the TOC

Migration Path


Not applicable. Reflect is Active and this section is required only for a tool that is Retired, Deprecated or Risky. The heading is carried so the section inventory is complete, and it states plainly that no migration plan is built here.


One adjacent fact belongs on the record, because it is the product's own news rather than a finding about its health: in July 2026 the vendor released Reflect Open, a separate free and MIT-licensed application built on local Markdown files, while keeping the hosted product running. That is a second product rather than a successor, the vendor states that existing subscriptions transfer, and no migration is required or recommended on the evidence available at the time of writing. A reader who chooses to move between the vendor's two products is making a data-position decision, and the comparison section sets out how to make it.


A smaller decision is available to a reader who wants to reduce dependence rather than leave: keep your exports somewhere you control, read one exported archive end to end, and keep private notes marked as such. The three re-check triggers at the top of this review are the conditions under which this section would stop being empty.


Back to the TOC

U365's Recommendations to Learn More


Every link below was checked before it was included, and the four video identifiers were resolved through the platform's own metadata endpoint rather than copied from a page.


Official learning resources



Video tutorials and channels


Four identifiers were resolved through the video platform's own metadata endpoint before inclusion. One is the vendor's own walkthrough; the other three are independent reviews.






Watch the vendor demonstration for what the interface does, and the independent reviews for what daily use looks like. None of the four measures the two claims that matter most in this review, which are the encryption boundary during AI use and the reliability of the AI output.


Written tutorials and deep-dive articles



Community and social


Dedicated Reflect channels



Resources on Reflect


The independent usability and feature material worth reading beyond the two official surfaces above.


Independent long-form review material about Reflect, the kind of account that describes daily use rather than features

Resources on X


Dedicated X channels


The account to add first is the vendor's own, because a change to the pricing model, the licence over your content or the model line would be announced there before it reached a documentation page. For this category the accounts worth following alongside it are the practitioner and analyst accounts that publish comparative work, and the competitor accounts named in the comparison section, so that any capability claim in this review can be checked against a measurement rather than against a marketing page.


The Reflect account on X, the vendor's own social card, which is the image the account and the academy site serve for the product, read 2026-09-25

Back to the TOC

CI-First Evaluation Summary Card


Field

Value

Tool

Reflect (Reflect Notes, reflect.app)

Vendor

Reflect App LLC, Austin, Texas, United States

Category

Applied AI / LLM-flavoured productivity tool: end-to-end encrypted networked note-taking with an AI layer

Status

Active

Last tested

2026-09-25

CI-First Benefit Score

5.3 / 10 (CI-First Positive)

Time benefit

6

Quantity benefit

6

Quality benefit

5

Skill benefit

4

CI-First Profile

Primary: Co-Worker and Assistant (level 2). Secondary: Coach and Tutor (level 3), narrowly

Collaboration Mode

Centaur

Humics Protection

0 / -1 / 0, total -1 of +3. Humics-Neutral

AI Imposture Risk

Medium overall. Time Illusion Medium, Quantity Illusion Medium, Skill Illusion High

Framework v1.2 clauses

5.2.3-a APPLIES, Skill Illusion recorded High. 4.2-a null. 7.5 null

Encryption

Client-side, XChaCha20-Poly1305, password-derived, attachments covered, independently reviewed in the second quarter of 2021

Key exception to the encryption

Text you select for AI processing, chat over search results, and audio for transcription leave the encryption boundary, as the vendor states in its own privacy policy

Pricing

One plan, $10 per month billed annually, 14-day trial, no free tier published by the vendor

Platforms

Web, macOS, iPhone, iPad beta. Browser on Windows and Android

API

REST, OAuth 2 with PKCE, append-only by design

Primary reader

One person keeping a private, connected notebook and willing to do the linking

Main reason to hesitate

The AI layer's documentation does not agree across the vendor's own pages, and no independent measurement of its output quality exists

Section 7c

Included: where AI processing happens, quoted against the vendor's own privacy policy, security page and product pages, plus the refund page against the terms


Back to the TOC

Glossary


CI-First Benefit Score


The average of four dimensions scored from 0 to 10 for the honest user, net of the overhead of using the tool: Time, Quantity, Quality and Skill. Bands are 0 to 2.0 CI-First Negative, 2.1 to 4.0 CI-First Neutral, 4.1 to 6.0 CI-First Positive, 6.1 to 8.0 CI-First Strong, and 8.1 to 10 CI-First Transformative. Reflect scores 5.3, which is CI-First Positive.


CI-First Profile


The classification of the role the tool plays for the user, from five profiles: Co-Creator and Thought Partner, Co-Worker and Assistant, Coach and Tutor, Analyst and Tester, and Challenger and Devil's Advocate. Reflect is classified primarily as Co-Worker and Assistant.


Collaboration Mode


How the human and the tool divide the work. Centaur mode separates the work into stages and the human reviews at the boundary. Cyborg mode interleaves the human and the model in one fast loop with a stopping criterion the human applies. Centaur is the safer mode and framework Section 7.2 assigns it whenever the Imposture Risk is Medium or High. Reflect's recommended mode is Centaur.


Humics Protection Badge


The sum of three ratings at +1, 0 or -1 for Creativity, Critical Thinking and Social Authenticity. Plus two to plus three is Humics-Friendly, minus one to plus one is Humics-Neutral, and minus two to minus three is Humics-Risky. Reflect scores -1, which is Humics-Neutral.


AI Imposture Risk


The likelihood that the tool traps the user in one of three usage illusions: the Time Illusion, the Quantity Illusion and the Skill Illusion. Overall levels are Low, Medium and High. Reflect is Medium overall, with Skill Illusion High.


User Sentiment


What the public says about the product across review platforms, community forums and repository activity. It is reported separately from the CI-First score, because crowd sentiment can contradict a scored evaluation. Where the two agree the finding is stronger, and where they diverge the divergence is worth explaining. Reflect's sentiment is positive and attached to the notebook rather than to the AI layer, which is the opposite of what the vendor's homepage leads with.


Skill Illusion


The illusion of demonstrating a skill when the user is not developing it, or is losing it. Framework clause 5.2.3-a sets a floor of no lower than Medium for a tool that writes procedural memory on the user's behalf, and High where the agent can revise that memory during use without a per-write human decision. Reflect meets that second condition through its AI writing surfaces and its MCP server.


End-to-end encryption


Encryption applied on the user's device, with the key held by the user, so that the service provider stores material it cannot read. Reflect applies it to note contents and attachments with XChaCha20-Poly1305 under a password-derived key.


Encryption boundary


The line at which material stops being protected by end-to-end encryption. For Reflect, everything inside the app is inside the boundary except the material you select for AI processing, the search results you send to chat, and the audio you record for transcription.


Review Status


The status vocabulary used across this series: Active means current and recommended. Changed means a material change is pending re-evaluation. Risky means significant unresolved issues, or clearly surpassed by newer alternatives. Deprecated means superseded by the vendor's own successor product. Retired means withdrawn or no longer maintained. Reflect is Active.


Back to the TOC

Sources


Vendor primary sources



Independent sources



Review platforms and ratings



Community and social



Media



Framework and method


  • The U365 CI-First Evaluation Framework, version 1.2, which is the scoring method used here. It sets the benefit dimensions, the Humics protection rating, the AI Imposture risk assessment and the collaboration modes applied in this review: https://www.university-365.com/ci-first

  • The U365 INSIDE Tools review template, which sets the structure of this post: https://www.university-365.com/tools

  • Published U365 INSIDE Tools reviews, read as comparisons and linked where they are named in this post: Klarent, MiMo-V2.6-Flash, MiMo-V2.6-Pro, Rabbit OS3, Claude Opus 5.5 and ElevenLabs: https://www.university-365.com/tools


Faculty Note on Evidence Quality


Five claims from this release did not survive checking, and the pattern across them is worth stating before the list. This is a vendor whose product pages and whose documentation pages are written to different standards, and whose legal pages are more precise than either.


First, the vendor's own pages disagree about which model providers receive your text. The privacy policy names OpenAI's API, Anthropic's API and Google's API for the AI feature as a set. The artificial intelligence page names the same three and then assigns OpenAI and Anthropic to the assistant and Google to chat. The security page names one provider for the same feature. All three were current when read. The claim to discount is not that the product uses a particular model; it is that no single page of the vendor's own documentation tells you which provider receives the text you select. The out-of-date page is the more restrictive of the three, which is the reverse of how a misleading page usually reads, and that is recorded as a point in the vendor's favour rather than against it.


Second, the price a reader will find depends on whether they believe the vendor or the directories. The vendor publishes one plan at $10 per month billed annually with a 14-day trial, and no free tier on its own pricing surface. Directory pages describe a free plan, a "freemium" model, an annual-only tier called Standard, a Personal plan at a figure expressed as per year when the vendor quotes per month, and a median contract value from a purchase sample. These are not readings of the same source. The vendor's own page is the operative one, and a reader budgeting from a directory page is budgeting from a description of the product that the vendor does not publish.


Third, the refund position on the public page and in the contract do not say the same thing. The refund page states a full refund with no questions asked. The terms state that paid subscription fees are non-refundable except where required by law, with requests considered at the company's sole discretion. The public page is more generous than the contract that governs. Both are quoted in Section 7c and this review's recommendation is to keep the page and the correspondence if you rely on it.


Fourth, the encryption claim is absolute on the homepage and conditional in the policy. The homepage states that nobody else can read the notes, adding that this includes the vendor. The policy states the same and then names two exceptions in its own opening summary. The security page names a third and a fourth, in the enrichment path and in the audio path. Every statement is accurate within its own scope, and the scope narrows as the reader moves from marketing to documentation to contract. That progression is normal, and it is the reason this review's Section 7c exists: the sentence a reader remembers is the absolute one, and the paragraph that governs is the conditional one.


Fifth, the independent security review is quoted with a scope that is narrower than a reader will assume. The quoted conclusion covers the system design, the cryptographic primitives and their use, and it is from the second quarter of 2021. The vendor states elsewhere on the same page that the client can be updated at any time and that users ultimately have to trust it. That is a fair and unusual disclosure, and it also means the audit is evidence about a design rather than about the client you install today. The claim to discount is that the product as currently shipped is audited; the claim that survives is that its encryption architecture was reviewed and found sound.


What the vendor got right, stated with the same emphasis, and it is a longer list than this section usually carries. It states the exceptions to its own encryption claim in the opening summary of a legal document rather than in a footnote, and it answers the encryption-impact question separately for each of its two AI surfaces. It publishes the client-side library that performs the encryption, so that anyone who wants to can read it. It names the firm that reviewed the design and quotes the reviewer's conclusion rather than paraphrasing it into something stronger. It explains, in its own words, why the encryption and the AI feature pull in opposite directions, and it does so feature by feature. It documents the daily token allowance and the route to exceeding it with your own key, rather than describing the AI feature as unlimited. It publishes a refund page more generous than its contract. It documents the recovery paths for a lost encryption password honestly, including the routes that depend on the user. It states plainly that the product is single-player and describes the publish action as a public unguessable address rather than as secure sharing. And in July 2026 it published a rebuild in which the tension this review spends a section on does not exist, with the reasoning stated: the encrypted proprietary format and the custom sync engine had become too expensive to evolve. A vendor that changes its architecture when it cannot reconcile a promise with a feature has answered the question the review was going to ask.


The pattern is consistent. Where this vendor is describing a mechanism, it is precise, it is often arguing against its own marketing, and it is unusually willing to state a limit. Where it is describing a benefit, the emphasis varies between pages and the absolute version is the one that gets the headline. A reader of this review should take the mechanism statements as the evidence, treat the homepage absolutes as a summary of the best case, and read the privacy policy before deciding what to keep in the notebook.


Review conducted by URC under the CI-First Evaluation Framework, version 1.2. Scoring date 2026-09-25. Product reviewed: Reflect (Reflect Notes, reflect.app) by Reflect App LLC, as documented at reflect.app, reflect.academy and the 2026-07-14 Reflect Open announcement. Framework version applied: 1.2. Framework clauses checked: 5.2.3-a applies, with Skill Illusion recorded High, because the AI palette writes into the user's own durable note record and the MCP server lets an external coding agent create, rewrite and delete content in that record without a per-write human decision inside the notebook; 4.2-a returns a null, because the product drafts and sends nothing in the user's name to another person and the publish action is the user publishing their own writing; 7.5 returns a null, because the notebook is single-player and the user addresses one coding agent of their own choosing in their own tool rather than coordinating with several named agents in a shared room.


Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
Image by Erik  Lucatero

Become Superhuman

Master AI to stay irreplaceable in every field.

 

 

 

​

​

Apply for Admission Today.
Select Your Initial Access Level.


Become a DISCOVERY, INSIDER, or SUPERHUMAN Fellow.

Image by Milad Fakurian

Master Your Life with a Digital Second Brain

Turn overwhelm into clarity with LIPS + CARE
U365’s unique framework to organize your goals, projects, and knowledge into a superhuman system for success

bottom of page