The short version
Silo Scan collects no data. None.
No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. No data of any kind is collected, stored, transmitted, or shared by Silo Scan about you, your device, or your content.
Everything Silo Scan does runs entirely on the Apple device where you use it, using its same-device local runtime. There is no cloud component or remote service, and no Silo Scan account.
What we don't have, and therefore never see
Because Silo Scan has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. The app does not phone home, ever.
The local backend is not a network service
Silo Scan runs an on-device local runtime to perform its work. It binds strictly to the loopback interface (127.0.0.1:8769), never to a public or network-facing address. The native app connects through that same-device loopback endpoint. This is on-device communication only — it accepts no external connections and is not reachable from your network or the internet.
Outbound traffic you initiate
The only outbound network traffic, all user-initiated, and none of it to Silo Scan:
- Model weight downloads. After onboarding, Silo Scan offers to download model weights from public open-weights repositories (the model source declared in the download consent screen). The download is anonymous by default; no token, account, or registration is required. Once the weights are on disk, Silo Scan works fully offline.
- App Store updates.When Apple ships a Silo Scan update, the App Store delivers it. This traffic is between your device and Apple's servers. Silo Scan is not involved.
- Links you click. If you click an external link inside the app, your default browser handles the request. Silo Scan is not involved.
Permissions we request, and why
- Camera. Scan physical paper documents, receipts, and invoices.
- Folders you choose. Save scanned PDF documents to your local storage.
Silo Scan does not request protected resources beyond those listed above. System permission controls remain in effect at all times.
On-device data you create
Your content and everything derived from it live inside the declared on-device data location ~/Library/Containers/com.silosystems.siloscan/Data/Library/Application Support/SiloScan/ and the app sandbox used by each platform. Files you explicitly choose to import are read only for that user-initiated workflow, and durable exports live in the folder or Files location you explicitly choose. They are yours; we do not have access to them. On iPhone or iPad, deleting Silo Scan (rather than offloading it) removes its app-sandbox data; on Mac, removing the app bundle may leave sandbox data in place, so use any in-app delete or purge controls first, then macOS storage controls. Durable exports in user-selected locations remain until you delete them explicitly.
Third-party components
Silo Scan uses the system frameworks, local model assets, or open-source components listed below. None receive any data about you from Silo Scan:
- gemma-4-e2b-it-4bit — runs locally on-device.
- vision-ocr — runs locally on-device.
- Local loopback runtime — the bundled or native on-device backend, bound only to same-device loopback.
- the model source declared in the download consent screen — contacted only when you choose to download model weights.
Children's privacy
Silo Scan is rated 4+. Because no personal data is collected from any user, no special treatment is required for users under 13. Same policy applies regardless of age: nothing collected.
Changes
If we ever materially change how Silo Scan handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing is collected.
Contact
Questions about this policy: admin@ohmslaw.net
For non-private inquiries you can also open an issue at github.com/flowmar47/silo-scan/issues.