The short version
Silo Systems receives no data from Silo Scanner.
No analytics. No telemetry. No account. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. Silo Scanner stores your profile and scan history only on your device. When you start a scan, it sends only the needed name and location terms directly to selected public broker sites. Those sites also receive ordinary web-request metadata, including your source IP address and Silo Scanner's honest user-agent string. The traffic never passes through Silo.
Profile storage, scan orchestration, result classification, letter generation, and exports run on your Mac, using its same-device local runtime. User-initiated scans send only the public broker lookups disclosed below directly to the selected broker sites. Silo provides no cloud component or remote service, and there is no Silo Scanner account.
What we don't have, and therefore never see
Silo Scanner has no Silo server-side component, so Silo's infrastructure receives none of your profile, scan, usage, diagnostics, or generated-artifact data. User-initiated scan requests go from your device directly to selected public broker sites, which receive the disclosed search terms and ordinary web-request metadata. See Outbound traffic below.
The local backend is not a network service
Silo Scanner runs an on-device local runtime to perform its work. It binds strictly to the loopback interface (macOS: 127.0.0.1 on a locally selected per-launch port, authenticated by a fresh per-launch token), never to a public or network-facing address. The native app connects through that same-device loopback endpoint. This is on-device communication only — it accepts no external connections and is not reachable from your network or the internet.
Outbound traffic you initiate
The only outbound network traffic, all user-initiated, and none of it to Silo Scanner:
- Public broker lookups. When you start a scan, Silo Scanner sends the needed name and location terms directly to the selected data brokers' public search pages. Those sites also receive ordinary web-request metadata, including your source IP address and Silo Scanner's honest user-agent string. The requests go to those broker sites, not to Silo, and the app does not send your saved email, phone number, or generated artifacts with a scan.
- App Store updates. When Apple ships a Silo Scanner update, the App Store delivers it. This traffic is between your device and Apple's servers. Silo Scanner is not involved.
- Links you click. If you click an external link inside the app, your default browser handles the request. Silo Scanner is not involved.
Permissions we request, and why
- Files you choose. Save the opt-out letters and scan reports you generate only to the locations you pick in the macOS file panel.
Silo Scanner does not request protected resources beyond those listed above. System permission controls remain in effect at all times.
On-device data you create
Your content and everything derived from it live inside the macOS app container at ~/Library/Containers/com.silosystems.siloscanner/Data/Library/Application Support/FootprintScanner/. Durable exports live in the folder or Files location you explicitly choose. They are yours; we do not have access to them. Removing the Silo Scanner app bundle may leave its macOS sandbox data in place; use any in-app delete or purge controls first, then macOS storage controls for remaining container data. Files in user-selected locations remain until you explicitly delete them.
Third-party components
Silo Scanner bundles a local loopback runtime. It runs on your device and does not receive or transmit data as a remote service:
- Local loopback runtime — the bundled or native on-device backend, bound only to same-device loopback.
Children's privacy
Silo Scanner is rated 4+. Silo receives no personal data from any user. The same policy applies regardless of age; user-initiated public broker lookups are disclosed above.
Changes
If we ever materially change how Silo Scanner handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new Silo collection begins. The current policy is: Silo receives no data, and only the user-initiated direct traffic disclosed above leaves your device.
Contact
Questions about this policy: admin@ohmslaw.net