Skip to content
Privacy · Coil · Effective 2026-08-11

Privacy policy.

The current policy is: nothing is collected.

The short version

Coil collects no data. None.

No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. No data of any kind is collected by Silo Systems or transmitted or shared off-device by Coil about you, your device, or your content. Coil stores only the local content and history you create and control on your Mac.

By default, everything Coil does runs entirely on your Mac, on-device, using a bundled local runtime and locally-stored open-weights models. Silo Systems operates no cloud component, no server, and no Coil account — and never will. The one exception is the optional Bring Your Own Key mode described below, which is off until you enable it and sends data only to a provider you choose and pay for directly.

What we don't have, and therefore never see

Because Coil has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. The app does not phone home, ever.

Outbound traffic you initiate

The only outbound network traffic, all user-initiated, and none of it to Coil:

  1. Model weight downloads. After onboarding, Coil offers to download model weights from public open-weights repositories (Hugging Face). The download is anonymous by default; no token, account, or registration is required. Once the weights are on disk, Coil works fully offline.
  2. App Store updates.When Apple ships a Coil update, the App Store delivers it. This traffic is between your Mac and Apple's servers. Coil is not involved.
  3. Links you click. If you click an external link inside the app, your default browser handles the request. Coil is not involved.

Optional Bring Your Own Key (off by default)

This is the one path by which your content can leave your Mac, and it stays closed until you open it.If you enable cloud inference in Settings and supply your own API key (Anthropic, OpenAI, Google Gemini, or OpenRouter), the content you process with that feature — your prompts and workspace context — is sent over the internet to the provider you selected, under your own account. What you send is then subject to that provider's privacy policy and data-retention practices, not ours.

Turning it on requires an explicit in-app confirmation, Coil shows a persistent cloud badge whenever a cloud provider is active, and you can return to on-device processing at any time. Nothing is ever sent to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your Mac to the provider you configured. Your key is stored only in the macOS Keychain on this Mac, never in a file, a database, or a log. You can also point Coil at Ollama running on your own machine, in which case nothing leaves your network at all.

Permissions we request, and why

Coil does not request Camera, Contacts, Location, or Full Disk Access beyond what is listed above. If you grant nothing, it can read nothing.

On-device data you create

Your content and everything derived from it live on your disk under ~/Library/Containers/com.silosystems.coil/Data/Library/Application Support/Coil/ (plus any folder you explicitly choose to export to). They are yours. We do not have access to them. Deleting Coil removes the app; your work remains under its container until you delete it manually.

Workspace tools remain scoped to one folder you select, use a per-run policy and explicit approvals, and export a trace receipt only when you choose a destination. Durable workspace traces omit selected file text, diffs, shell output, and graph result bodies. Coil does not transmit previews or receipts.

The planned version 1.9.0 update—not included in the current 1.8.0 download—adds a route preview that does not start generation, run a tool, or change transcript or memory. Depending on what Coil logged locally, a route-audit JSONL export may include turn text alongside the proposed route, your selection, and the result. Coil writes an export only to the destination you choose and does not transmit it automatically. Exported files remain wherever you save them until you delete them.

Third-party components

Coil uses these open-source components and public services. None of them receive any data about you from Coil:

Children's privacy

Coil is rated 4+. Because no personal data is collected from any user, no special treatment is required for users under 13. Same policy applies regardless of age: nothing collected.

Changes

If we ever materially change how Coil handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing is collected.

Contact

Questions about this policy: admin@ohmslaw.net

For non-private inquiries you can also open an issue at github.com/flowmar47/coil/issues.

Contact
Last updated 2026-08-11 · v1.1