The short version
Citebound runs no analytics, no tracking, and no servers of its own. The only data associated with you is your own workspace content, stored in your private iCloud (CloudKit) container for optional sync — that is what the App Store privacy label (“User Content, linked to you”) reflects. Silo Systems cannot read it.
No third-party analytics. No telemetry SDKs. No usage beacons. No advertising identifiers. No crash-reporting trackers. No external AI API or third-party document processing service receives your questionnaires or compliance evidence — unless you turn on the optional Bring Your Own Key mode described below and point Citebound at a provider of your choosing.
All document parsing, text extraction, token indexing, passage citation, and answer matching run locally on your Mac.
CloudKit Architecture & Sync
Citebound uses your private Apple iCloud account for optional multi-device workspace synchronization:
- Apple-hosted Private Database: Sync records are stored exclusively in your personal Apple CloudKit private container (
iCloud.com.silosystems.citebound). - No Custom Backend: Silo Systems operates no server, database, or proxy for Citebound. We cannot view, access, or restore your CloudKit records.
- Encryption in Transit and at Rest: All CloudKit traffic and storage are encrypted by Apple in accordance with Apple's iCloud security standards.
Document Processing & AI Privacy
Imported vendor security questionnaires and evidence documents (PDFs, text files, Markdown, CSVs) are untrusted input data. They are parsed deterministically on-device inside your macOS application container.
On supported Apple Silicon Macs running compatible macOS versions, local Apple Foundation Models may assist in drafting suggestions using retrieved passages. Text sent to on-device models never leaves your hardware and is never transmitted to a cloud LLM provider.
Optional Bring Your Own Key (off by default)
This is the one path by which your content can leave your Mac, and it stays closed until you open it. If you enable cloud inference in Settings and supply your own API key (Anthropic, OpenAI, Google Gemini, or OpenRouter), the content you process with that feature — your questions and document excerpts — is sent over the internet to the provider you selected, under your own account. What you send is then subject to that provider's privacy policy and data-retention practices, not ours.
Turning it on requires an explicit in-app confirmation, Citebound shows a persistent cloud badge whenever a cloud provider is active, and you can return to on-device processing at any time. Nothing is ever sent to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your Mac to the provider you configured. Your key is stored only in the macOS Keychain on this Mac, never in a file, a database, or a log. You can also point Citebound at Ollama running on your own machine, in which case nothing leaves your network at all.
Monetization & StoreKit
Citebound offers a free single-questionnaire evaluation mode and optional Citebound Pro subscriptions ($29.99/month or $299.99/year). Purchases, receipt validation, and subscription management are handled entirely through Apple's StoreKit framework. Payment details are processed by Apple; Silo Systems receives no credit card or financial info.
File System & Sandbox Access
Citebound operates inside the standard macOS App Sandbox. It accesses only:
- Files you select: Questionnaire CSVs and evidence files explicitly selected via standard macOS file open/save dialogs or drag-and-drop.
- Application Support: Local workspace state stored at
~/Library/Containers/com.silosystems.citebound/Data/Library/Application Support/Citebound/.
Exporting a completed questionnaire always prompts you to save a separate copy. Citebound never overwrites or modifies your imported original CSV files.
Data Control & Deletion
You remain in full control of all evidence and questionnaire data. Removing a workspace or document inside Citebound purges its extracted text and index locally and from your private CloudKit container. Uninstalling the application removes its container.
Children's Privacy
Citebound is a professional software workspace rated 4+. Because no personal data is collected or transmitted to any server, no personal data from minors is ever gathered.
Changes & Contact
If material changes are ever made to how Citebound handles data, this policy will be updated with an explicit version note.
For privacy inquiries or technical questions regarding this policy, contact us at: admin@ohmslaw.net