Skip to content
Mac$14.99 one-time · no subscriptionmacOS 14+
Privacy · Silo Tidy · Effective 2026-09-23

Privacy policy.

Silo Systems collects nothing. File content leaves your Mac only if you turn on Bring Your Own Key.

The short version

Silo Systems operates no server for Silo Tidy and receives nothing from it.

No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. No data about you, your device, or your content is ever collected by or sent to Silo Systems. Product data stays in the app's local container; the optional outbound paths are disclosed below.

By default, everything Silo Tidy does runs on your Mac using a bundled local runtime. Any optional model is stored and executed locally after consent. Silo Systems operates no remote processing service and there is no Silo Tidy account. The one exception is the optional Bring Your Own Key mode described below, which is off until you enable it and sends data only to a provider you choose and pay for directly.

What we don't have, and therefore never see

Because Silo Tidy has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. The app never contacts Silo Systems; its only outbound paths are the optional model downloads you approve, links you open, App Store traffic handled by Apple, and Bring Your Own Key requests sent directly to the provider you choose.

The local backend is not a network service

Silo Tidy runs a small local process to perform its on-device work. It binds strictly to the loopback interface (127.0.0.1:8767), never to a public or network-facing address. The SwiftUI host renders the UI in a WKWebViewloaded from that same loopback origin. This is on-device inter-process communication only — it accepts no external connections and is not reachable from your network or the internet.

Outbound traffic you initiate

Apart from the Bring Your Own Key requests described in the next section, the only outbound network traffic is listed below, and the app sends none of it to Silo Systems:

  1. Optional model downloads. No file content is included in a model request. You can choose the pinned Current Gemma 4 E2B snapshot at roughly 3.58 GB or the pinned Compact Ternary Bonsai 4B snapshot at roughly 1.14 GB. Before consent, Silo Tidy shows the exact Hugging Face host and immutable revision, license and NOTICE, storage requirement, integrity policy, and device-fit report. Filename rules remain available without either model.
  2. App Store updates. When Apple ships a Silo Tidy update, the App Store delivers it. This traffic is between your Mac and Apple's servers. Silo Tidy is not involved.
  3. Links you click. If you click an external link inside the app, your default browser handles the request. Silo Tidy is not involved.

Optional Bring Your Own Key (off by default)

This is the one path by which your content can leave your Mac, and it stays closed until you open it. If you enable cloud inference in Settings and supply your own API key (Anthropic, OpenAI, Google Gemini, or OpenRouter), the content you classify with that feature (each file name, type, size, and metadata such as archive entry names and Apple Vision image labels, up to 1,200 characters of extracted or OCR text, and your category names and descriptions) is sent over the internet to the provider you selected, under your own account. What you send is then subject to that provider's privacy policy and data-retention practices, not ours.

Turning it on requires an explicit in-app confirmation, Silo Tidy shows a Cloud badge in the Tidy workspace whenever a cloud provider is active, and you can return to on-device processing at any time. Nothing is ever sent to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your Mac to the provider you configured. Your key is stored only in the macOS Keychain on this Mac, never in a file, a database, or a log. You can also point Silo Tidy at Ollama running on your own machine, in which case nothing leaves your network at all.

Permissions we request, and why

  • Folders you choose. Read and write only the source and target folders you explicitly select through the macOS file picker. Remembered across launches with security-scoped bookmarks. Silo Tidy never touches a folder you didn't pick.

Silo Tidy does not request Camera, Contacts, Location, or Full Disk Access beyond what is listed above. If you grant nothing, it can read nothing.

On-device data you create

Categories live under ~/Library/Containers/com.silosystems.silotidy/Data/Library/Application Support/SiloTidy/. Local Workspace Audit snapshots, run history, reviewed decisions, and undo receipts live in that same container. Source files and organized outputs remain in folders you choose. They are yours. We do not have access to them. Deleting Silo Tidy removes the app; your work remains under its container until you delete it manually.

Version 1.11 component inventory

Silo Tidy uses these open-source components and public services. Local components do not transmit your content. Hugging Face receives an ordinary download request only when you approve a model download; a Bring Your Own Key provider receives only the content you explicitly process through that enabled mode, as described above.

  • mlx-lm — runs locally on-device.
  • gemma-4-e2b-it-4bit — runs locally on-device.
  • Apple Vision image classification and OCR — run locally on-device.
  • Gemma 4 E2B content and image-label classifier (Hugging Face) — optional, downloaded only after consent, and run locally.
  • Ternary Bonsai 4B compact classifier (Hugging Face) — optional, downloaded only after consent, and run locally.
  • FastAPI — the bundled local backend, bound to loopback only.
  • Hugging Face Hub — contacted only when you choose to download one of the optional pinned models.
  • OpenAI, Anthropic, Google Gemini, or OpenRouter — contacted only when you enable Bring Your Own Key, select that provider, and submit a request directly under your own account.

Children's privacy

Silo Tidy is rated 4+. Because Silo Systems collects no personal data from any user, no special treatment is required for users under 13. The same policy applies regardless of age: nothing is collected by us.

Changes

If we ever materially change how Silo Tidy handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: Silo Systems collects nothing.

Contact

Questions about this policy: admin@ohmslaw.net

For non-private inquiries you can also open an issue at github.com/flowmar47/silo-tidy/issues.

Contact
Last updated 2026-09-23 · v1.11