Privacy policy.
The current policy is: nothing is collected.
The short version
Silo Redact collects no data. None.
No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. Silo Redact sends nothing to Silo Systems and never uploads your documents or anything derived from them.
Everything Silo Redact does runs on your Mac using a bundled local runtime. Any optional model is stored and executed locally after consent. There is no remote processing service and no Silo Redact account.
What we don't have, and therefore never see
Because Silo Redact has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. The app never phones home to Silo Systems; its only direct outbound request is the optional model download you approve.
The local backend is not a network service
Silo Redact runs a small local process to perform its on-device work. It binds strictly to the loopback interface, never to a public or network-facing address. It uses a fresh authenticated port on every launch. The SwiftUI host renders the UI in a WKWebViewloaded from that same loopback origin. This is on-device inter-process communication only — it accepts no external connections and is not reachable from your network or the internet.
Outbound traffic you initiate
The only outbound network traffic, all user-initiated, and none of it to Silo Redact:
- Optional model download. No document content is included in a model request. After you accept the consent card, which first shows the exact download size (3,583,086,498 bytes, roughly 3.58 GB), Gemma license, storage location, integrity policy, and device-fit report, Silo Redact fetches one pinned Gemma 4 E2B 4-bit snapshot from huggingface.co, which may redirect to these Hugging Face download hosts: cdn-lfs.huggingface.co, cdn-lfs-us-1.huggingface.co, cdn-lfs.hf.co, cdn-lfs-us-1.hf.co, us.aws.cdn.hf.co, cas-bridge.xethub.hf.co, cas-server.xethub.hf.co, and transfer.xethub.hf.co. Those requests contain no account or device identifier; Hugging Face sees the pinned model repository, revision, and file names, a fixed app user agent, and your IP address, as with any download.
- App Store updates. When Apple ships a Silo Redact update, the App Store delivers it. This traffic is between your Mac and Apple's servers. Silo Redact is not involved.
- Links you click. If you click an external link inside the app, your default browser handles the request. Silo Redact is not involved.
Versions 1.5.1 and 1.5.2 also made one request you did not start: the first time name detection checked the domain of an email address, the bundled helper downloaded the public list of internet domain suffixes from publicsuffix.org, or from raw.githubusercontent.com if that failed. The request carried no document content; those hosts saw your IP address, as with any download. From version 1.5.3 that list is built into the app, and analyzing a document makes no network connection.
Permissions we request, and why
- Files and folders you choose. Silo Redact uses temporary access: it reads only the PDFs you pick or drop in, the PDFs inside a folder you pick for Batch, and the JPEG or PNG images you drop in for Clean & Verify, into the authenticated local session. It does not remember security-scoped bookmarks.
- Loopback client and server. Required for authenticated same-device communication between the app interface and bundled backend. It accepts no external connections.
- External model download. (optional) Used only after consent for the pinned contextual model from disclosed Hugging Face hosts. Document content is never sent.
Silo Redact does not request Camera, Contacts, Location, or Full Disk Access beyond what is listed above. If you grant nothing, it can read nothing.
On-device data you create
Your content and everything derived from it live on your disk under ~/Library/Containers/com.silosystems.siloredact/Data/Library/Application Support/SiloRedact/ (plus any folder you explicitly choose to export to). They are yours. We do not have access to them. Deleting Silo Redact removes the app; your work remains under its container until you delete it manually.
Third-party components
Silo Redact uses these components and one public service. Your documents, and anything derived from them, never leave your Mac: the components below run on-device and send nothing anywhere. The one public service is Hugging Face, contacted only if you choose the optional model. It receives the download requests described above, which carry your IP address and no document content:
- presidio — runs locally on-device.
- spacy — runs locally on-device.
- mlx-lm — runs locally on-device.
- gemma-4-e2b-it-4bit — runs locally on-device.
- vision-ocr — runs locally on-device.
- naturallanguage — runs locally on-device.
- Gemma 4 E2B contextual model (mlx-lm) (Hugging Face) — downloaded on demand, runs locally.
- FastAPI — the bundled local backend, bound to loopback only.
- Hugging Face Hub — contacted only when you choose to download the optional pinned model.
Children's privacy
Silo Redact is rated 4+. Because no personal data is collected from any user, no special treatment is required for users under 13. Same policy applies regardless of age: nothing collected.
Changes
If we ever materially change how Silo Redact handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing is collected.
Contact
Questions about this policy: admin@ohmslaw.net