Privacy policy.
None of your content reaches Silo Systems. It leaves your Mac only if you turn on Bring Your Own Key.
The short version
Coil collects nothing about you, and none of your content reaches Silo Systems. Your content leaves your Mac only if you turn on Bring Your Own Key, and then it goes directly to the provider you configure.
No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. Your prompts, files, workspace context, transcripts, memory, and everything derived from them are never collected by Silo Systems. They leave your Mac only while Bring Your Own Key is active, and then only to the provider you configure. Switching it off takes effect the next time Coil launches. Coil stores only the local content and history you create and control on your Mac.
By default, everything Coil does runs entirely on your Mac, on-device, using a bundled local runtime and locally-stored open-weights models. There is no Coil account and no cloud service that holds your work. Beyond the model weight downloads listed below, two optional paths can reach the network, and both are off until you turn them on: the optional Bring Your Own Key mode, which sends data only to a provider you choose and pay for directly, and the optional model-catalog check, which downloads a metadata file and sends none of your content anywhere. Both are described below.
What we don't have, and therefore never see
Coil has no server-side component that receives your work, so none of the following reaches us: your name, email, phone, or address; your device identifier or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. With the optional features below switched off, the app makes no requests to Silo Systems at all.
Outbound traffic you initiate
Outbound network traffic with the optional features off, none of it carrying your content:
- Model weight downloads. Coil downloads model weights from public open-weights repositories on Hugging Face: the chat models you choose, after you consent at first run or when you pull one in the Models pane, and an on-device embedding model the first time Coil starts after setup, whichever engine you use. The download is anonymous by default; no token, account, or registration is required. Once the weights are on disk, on-device Coil works fully offline.
- App Store updates. When Apple ships a Coil update, the App Store delivers it. This traffic is between your Mac and Apple's servers. Coil is not involved.
- Links you click. If you click an external link inside the app, your default browser handles the request. Coil is not involved.
Optional “check for new models” (off by default)
Coil can offer to tell you when a newer build of a local model is available. This check is off by default and never runs until you turn it on. Once enabled, Coil periodically downloads a small, cryptographically signed model-catalog file from ohmslaw.net — a site operated by Silo Systems and hosted on Vercel. The catalog is metadata about model builds. Nothing is uploaded: the check is a one-way download.
No prompt, file, workspace path, transcript, memory, licence, or account identifier is part of the request — there is no account to identify you with. The request exposes only what any HTTPS request to any website unavoidably exposes: your IP address and a user-agent string. Coil writes no log of the check. The hosting infrastructure may keep standard web access logs, as any web host does; we do not use them to profile you or link them to anything you do in the app.
Turning the setting off stops the checks. Coil verifies the catalog's signature before using it, so a missing, expired, or unverifiable catalog simply leaves Coil on the model list it already knows about.
Some models the catalog offers may be marked unvalidated (“experimental”). That label means exactly what it says: the model has not been tested on Silo Systems hardware, and the memory and disk requirements shown for it are estimated, not measured — calculated from the model's published size and format rather than from a real run on a real machine. Coil shows you the basis for that estimate before anything is downloaded. An unvalidated model is never chosen for you and never installed automatically: it is never a default at any memory tier, and installing one takes an explicit extra confirmation beyond the normal model-download consent. It may need more memory than estimated, or run poorly, on your Mac.
Optional Bring Your Own Key (off by default)
This is the one path by which your content can leave your Mac, and it stays closed until you open it. If you turn on cloud inference, at first run or in Settings, and supply your own API key for a provider you choose, that provider generates Coil's replies, memory updates, and wiki drafts. Each request goes over the internet directly to the provider you configured, under your own account. A reply request carries your message plus the context Coil builds for it: its instructions, any room brief you set, short verbatim excerpts of the last few messages in the conversation, your core and retrieved memories with one-line summaries of related ones, matching skill notes, and any workspace hints. A memory update carries your message and your most similar existing memories. A wiki draft carries the topic you enter and the names of your existing wiki pages. What you send is then subject to that provider's privacy policy and data-retention practices, not ours.
Turning it on requires an explicit in-app confirmation, Coil shows a persistent cloud badge whenever a cloud provider is active, and you can turn it off at any time; Coil returns to on-device processing the next time it launches. None of it is ever sent to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your Mac to the provider you configured. Your key is stored only in the macOS Keychain on this Mac, never in a file, a database, or a log. You can also point Coil at Ollama running on your own machine, in which case these requests never leave your network.
Permissions we request, and why
- Folders you choose. Standard sandboxed file access. Coil reads only folders you explicitly select, such as a workspace or a folder to map, and writes or edits files there only after you approve the change. Exports go only to the destination you pick.
Coil does not request Camera, Contacts, Location, or Full Disk Access beyond what is listed above. If you grant nothing, it can read nothing.
On-device data you create
Your content and everything derived from it live on your disk under ~/Library/Containers/com.silosystems.coil/Data/.config/coil/ (plus any folder you explicitly choose to export to). They are yours. We do not have access to them. Deleting Coil removes the app; your work remains under its container until you delete it manually.
Workspace tools remain scoped to one folder you select, use a per-run policy and explicit approvals, and export a trace receipt only when you choose a destination. Durable workspace traces omit selected file text, diffs, shell output, and graph result bodies. Coil does not transmit previews or receipts.
Coil's route preview does not start generation, run a tool, or change transcript or memory. Depending on what Coil logged locally, a route-audit JSON export may include turn text alongside the proposed route, your selection, and the result. Coil writes an export only to the destination you choose and does not transmit it automatically. Exported files remain wherever you save them until you delete them.
Third-party components
Coil uses these open-source components and public services. None of them receive your content from Coil; the hosted ones receive only the ordinary request metadata any HTTPS request carries, and only for the downloads described above:
- mlx-swift-lm — runs locally on-device.
- qwen3.5 — runs locally on-device.
- qwen3-embedding — runs locally on-device.
- Qwen chat, router, and embedding models (MLX) (Hugging Face) — downloaded on demand, runs locally.
- Hugging Face Hub — contacted to download model weights: the chat models you choose, and the on-device embedding model the first time Coil starts after setup.
- ohmslaw.net (Silo Systems, hosted on Vercel) — contacted only if you turn on the optional model-catalog check, and only to download that signed metadata file.
Children's privacy
Coil is rated 4+. Because no personal data is collected from any user, no special treatment is required for users under 13. The same policy applies regardless of age.
Changes
If we ever materially change how Coil handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing about you is collected, none of your content reaches Silo Systems, and your content leaves your Mac only if you turn on Bring Your Own Key.
Contact
Questions about this policy: admin@ohmslaw.net