Privacy policy.
Private by default. Your provider, only when you choose it.
The short version
Silo Systems receives no data from Silo Bible.
No analytics, telemetry, Silo account, usage metrics, error beacons, advertising IDs, fingerprinting, or automatic crash reports. Your study database stays on your device. Optional cloud chat and pack downloads have the specific network boundaries described below.
Reading, plans, verse memory, notes, and installed voices work locally on your iPhone or Mac. Chat is on-device by default. Optional Bring Your Own Key cloud chat is off until you supply your key and confirm consent; selected chat requests then go directly to that provider under its privacy policy. Silo Systems operates no collection server, proxy, or relay for this app.
What we don't have, and therefore never see
The app does not send Silo Systems your identity, device identifiers, reading history, highlights, notes, questions, feature usage, or crash reports. Pack downloads go to GitHub, optional cloud chat goes to your selected provider, and external links open in your browser. These destinations handle their requests under their own policies.
Your study stays on the device
Highlights, margin notes, bookmarks, reading position, reading plans, completion history, and verse-memory cards and reviews stay in the local study database on that device. Silo Systems has no access to these files. Silo Bible has no account or sync service. Files you explicitly export or share remain under your control at the destination you choose.
AI chat runs on-device by default
On supported Apple Intelligence devices, Silo Bible's AI chat answers from installed translations with tappable verse citations, using the on-device model. With that model, your questions and the answers are processed entirely on the device, and nothing you ask is transmitted anywhere. Unsupported devices show an availability explanation rather than silently falling back to a cloud service. The only way chat leaves the device is the optional Bring Your Own Key mode described below, which you must enable and confirm yourself.
Outbound traffic you initiate
These are the app's network paths and related services. Download hosts and providers receive ordinary request metadata, including your source IP address; requests to a cloud provider also use your account credentials as described below.
- Translation, voice-pack, and lexicon downloads. When you choose to download a Bible translation (open-licensed and public-domain editions from the in-app public catalog), an offline voice pack, or the Strong's lexicon if its built-in copy is unavailable, the files are fetched from GitHub (github.com, which redirects to release-assets.githubusercontent.com), where Silo Systems publishes them as static release files. No Silo account or registration is required, and the request carries no study data, notes, or questions. GitHub receives ordinary HTTPS request metadata, including your IP address and the name of the file requested; Silo Systems sees only aggregate download counts from GitHub, never who downloaded. Once installed, the packs are used locally.
- App Store updates. When Apple ships a Silo Bible update, the App Store delivers it. This traffic is between your device and Apple's servers. Silo Bible is not involved.
- Links you tap. If you tap an external link inside the app, your browser handles the request. Silo Bible is not involved.
- Optional BYOK cloud chat. After you provide your key and confirm consent, chat requests go directly to your selected provider. Its privacy and data-retention policies apply.
Optional Bring Your Own Key (off by default)
Cloud chat is off by default and requires explicit consent. If you enable Cloud Inference in Settings and supply your own API key for Anthropic, OpenAI, Google Gemini, or OpenRouter, your questions and retrieved scripture passages, plus any Strong's lexicon entries matched to the question, are sent to the provider you selected, together with the answering instructions and model settings. Your API key is sent to that provider to authenticate the request. The provider's privacy policy and data-retention practices govern what you send; Silo Systems does not receive it.
Turning it on requires an explicit in-app confirmation, Silo Bible shows a persistent cloud badge whenever a cloud provider is active, and you can return to on-device processing at any time. These requests never go to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your device to the provider you configured. Your key is stored in the system Keychain on your device, not in the study database or logs. Optional local Ollama connects only to 127.0.0.1:11434 on the same device and does not send that request off the device.
Optional notifications
If you enable a daily reading reminder, Silo Bible schedules it locally. Lock-screen text is generic and contains no scripture, notes, plan title, or reading history. You can decline or revoke notification permission at any time without affecting reading plans or verse memory.
Third-party components
Silo Bible embeds no analytics, advertising, crash-reporting, or tracking SDKs. The open-licensed and public-domain scripture texts, open-source voices, and Strong's lexicon it downloads are static release files. GitHub, which hosts them, receives the download request metadata described above. Optional cloud providers receive the separately disclosed BYOK requests.
Children's privacy
Reading and study use the same on-device default at every age. Optional BYOK requires a separately configured provider account and explicit consent. That provider's terms and privacy policy govern the requests sent to it; this policy does not replace those terms.
Changes
If we ever materially change how Silo Bible handles data, we will update this policy and the release notes and explain any new optional data flow before enabling it. Silo Systems operates no collection server, proxy, or relay for this app.
Contact
Questions about this policy: ohms@duck.com