The short version
Silo Redact collects no data. None.
No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. No data of any kind is collected, stored, transmitted, or shared by Silo Redact about you, your device, or your content.
Everything Silo Redact does runs on your Mac using a bundled local runtime. Any optional model is stored and executed locally after consent. There is no remote processing service and no Silo Redact account.
What we don't have, and therefore never see
Because Silo Redact has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. The app never phones home to Silo Systems; its only direct outbound request is the optional model download you approve.
The local backend is not a network service
Silo Redact runs a small local process to perform its on-device work. It binds strictly to the loopback interface, never to a public or network-facing address. Version 1.3.0, which is in preparation and not in the current App Store build, moves that service to a fresh authenticated port on every launch. The SwiftUI host renders the UI in a WKWebViewloaded from that same loopback origin. This is on-device inter-process communication only — it accepts no external connections and is not reachable from your network or the internet.
Outbound traffic you initiate
The only outbound network traffic, all user-initiated, and none of it to Silo Redact:
- Optional model download. No document content is included in a model request. Version 1.3.0, which is in preparation and not in the current App Store build, standardizes this as one pinned Gemma 4 E2B 4-bit snapshot from disclosed Hugging Face hosts and adds the roughly 3.58 GB size, Gemma license, storage location, integrity policy, and device-fit report before consent.
- App Store updates.When Apple ships a Silo Redact update, the App Store delivers it. This traffic is between your Mac and Apple's servers. Silo Redact is not involved.
- Links you click. If you click an external link inside the app, your default browser handles the request. Silo Redact is not involved.
Permissions we request, and why
- Files and folders you choose. The current build uses macOS sandboxed picker access. Version 1.3.0 changes this to temporary access: the host reads selected PDF bytes into the authenticated local session and does not remember security-scoped bookmarks.
- Loopback client and server. Required for authenticated same-device communication between the app interface and bundled backend. It accepts no external connections.
- External model download. (optional) Used only after consent for the pinned contextual model from disclosed Hugging Face hosts. Document content is never sent.
Silo Redact does not request Camera, Contacts, Location, or Full Disk Access beyond what is listed above. If you grant nothing, it can read nothing.
On-device data you create
Your content and everything derived from it live on your disk under ~/Library/Containers/com.silosystems.siloredact/Data/Library/Application Support/SiloRedact/ (plus any folder you explicitly choose to export to). They are yours. We do not have access to them. Deleting Silo Redact removes the app; your work remains under its container until you delete it manually.
Third-party components
Silo Redact uses these open-source components and public services. None of them receive any data about you from Silo Redact:
- presidio — runs locally on-device.
- spacy — runs locally on-device.
- mlx-lm — runs locally on-device.
- gemma-4-e2b-it-4bit — runs locally on-device.
- vision-ocr — runs locally on-device.
- naturallanguage — runs locally on-device.
- Gemma 4 E2B contextual model (mlx-lm) (Hugging Face) — downloaded on demand, runs locally.
- FastAPI — the bundled local backend, bound to loopback only.
- Hugging Face Hub — contacted only when you choose to download the optional pinned model.
Children's privacy
Silo Redact is rated 4+. Because no personal data is collected from any user, no special treatment is required for users under 13. Same policy applies regardless of age: nothing collected.
Changes
If we ever materially change how Silo Redact handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing is collected.
Contact
Questions about this policy: admin@ohmslaw.net
For non-private inquiries you can also open an issue at github.com/flowmar47/SiloRedact/issues.