The short version
SiloApply collects no data. None.
No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. No data about you, your device, your résumé, or the jobs you apply to is collected by us, transmitted off your device, stored in our infrastructure, or shared with anyone.
Everything SiloApply does — reading an imported résumé or job description, assessing fit, tailoring your résumé, drafting an interview brief, validating source spans, and exporting files — runs on-device. Supported devices use Apple's Foundation Models; other devices use SiloApply's deterministic extractive engine. Silo Systems operates no cloud component, server, or SiloApply account. The one exception is the optional Bring Your Own Key mode described below, which is off until you enable it and sends data only to a provider you choose and pay for directly.
What we don't have, and therefore never see
Because SiloApply has no server-side component, the following do not exist anywhere in our infrastructure (and our infrastructure consists of: nothing):
- Your name, email, phone, or address.
- Your IP address, device identifier, advertising identifier, or any other hardware fingerprint.
- Your résumé, your master profile, your experience entries, the job descriptions you capture, or any résumé, brief, or file SiloApply generates or you export.
- The contents of your Photos, Files, or any document you import or scan.
- Session timing, feature usage, taps, or any other behavioural data.
- Crash reports. SiloApply does not implement a crash-reporting SDK.
We never see any of this because none of it is ever sent. SiloApply cannot phone home: it has no endpoint of ours to reach.
SiloApply makes no network connections of its own
With Bring Your Own Key off — its default state — SiloApply opens no network connections at all. The only connections it ever makes are the Bring Your Own Key requests described below, to a provider you chose and configured. Job descriptions you provide by camera scan, paste, file import, or the system share sheet are read on-device; a job-posting link you paste is stored only as a label and is never fetched by the app.
The current release also reads PDF, scanned PDF, image, RTF, and plain-text résumé files on-device. It does not support DOCX. Proposed facts must resolve to exact spans in the extracted source and require your approval before they become evidence.
On-device generation
Résumé tailoring and the interview brief use Apple's on-device Foundation Models where available, with a deterministic extractive engine as the always-local fallback. Both paths pass the same citation, numeric, and language checks. Unless you have enabled the optional Bring Your Own Key mode below, your profile and job description are never sent anywhere to produce output.
Optional Bring Your Own Key (off by default)
This is the one path by which your content can leave your device, and it stays closed until you open it. If you enable cloud inference in Settings and supply your own API key (Anthropic, OpenAI, Google Gemini, or OpenRouter), the content you process with that feature — your resume and job-application text — is sent over the internet to the provider you selected, under your own account. What you send is then subject to that provider's privacy policy and data-retention practices, not ours. This works the same way on Mac and on iPhone and iPad.
Turning it on requires an explicit in-app confirmation, SiloApply shows a persistent cloud badge whenever a cloud provider is active, and you can return to on-device processing at any time. Nothing is ever sent to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your device to the provider you configured. Your key is stored only in the Keychain on that device — the macOS Keychain on a Mac, the system Keychain on iPhone and iPad — never in a file, a database, or a log. You can also point SiloApply at Ollama running on your own machine, in which case nothing leaves your network at all.
Permissions we request, and why
SiloApply asks only for what a feature needs, and nothing it asks for sends anything off your device:
- Camera. Optional. Used only to photograph or scan a job description or résumé so it can be read on-device with Apple's Vision text recognition. Images are processed locally and are not transmitted.
- Microphone. Optional. Requested only when you start Speech practice, to record your spoken answers for on-device transcription. The audio never leaves your device.
On-device data you create
SiloApply stores the information needed to work for you locally; this is on-device storage, not collection by us. Your master profile, captured job descriptions, tailored résumés, briefs, and preferences live encrypted on your device under SiloApply's app container (bundle identifier com.silosystems.siloapply), plus any folder or file you explicitly choose to export to. They are yours. We do not have access to them. Deleting SiloApply removes the app and its on-device data.
Moving your profile between devices
To use your profile on both your iPhone and your Mac, SiloApply can export an encrypted copy that you move yourself — for example over AirDrop or through Files. The export is encrypted with a passphrase you choose; without it, the file cannot be read. SiloApply does not sync through any server and does not use iCloud for your profile.
Purchases
SiloApply's $24.99 unlock is a one-time universal purchase. The iPhone and Mac apps are available now. Payment is handled entirely by Apple under Apple's privacy policy. SiloApply never sees your payment details or receives personal information from the transaction. Entitlement is checked on-device via StoreKit.
Outbound traffic
With Bring Your Own Key off, there is none. The engine ladder has no model-download path: Apple provides Foundation Models as part of the operating system, and the deterministic extractive fallback is built into the app. App Store updates and external links you choose to open are handled by Apple and your browser; SiloApply does not fetch content from them. The only traffic SiloApply itself ever originates is a Bring Your Own Key request you have enabled, sent to the provider you configured.
Children's privacy
SiloApply is rated 4+. Because no personal data is collected from any user, no special treatment is required for users under 13. The same policy applies regardless of age: nothing collected.
Third-party services
SiloApply uses these Apple on-device frameworks. None of them receive any data about you from SiloApply, and none transmit your content off the device:
- Apple Foundation Models — on-device text generation.
- Vision — on-device text recognition for scanned job descriptions.
- Speech — on-device transcription for the Speech-practice feature (later update), with on-device recognition required.
- StoreKit — on-device purchase entitlement check.
Changes
If we ever materially change how SiloApply handles data — for example, if a future version ever begins to collect anything at all — we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The effective date at the top of this document reflects the current policy.
The current policy is: nothing is collected.
Contact
Questions about this policy: admin@ohmslaw.net