Skip to content
iPhone + iPad + Mac$8.99 one-time · no subscriptioniOS 18+ · iPadOS 18+ · macOS 14+
Privacy · SiloMeet · Effective 2026-09-23

Privacy policy.

The current policy is: nothing reaches Silo Systems.

The short version

Silo Systems operates no server and receives nothing from SiloMeet.

No analytics. No telemetry. No account. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. SiloMeet sends nothing about you, your device, or your content to Silo Systems. On the Mac, SiloMeet itself makes only two kinds of internet request, and both stay off until you turn them on: an optional speech model download from Hugging Face after you consent, and, if you enable Bring Your Own Key, requests that carry transcript text, the meeting title, and your chat questions directly to the provider you configured. Both are described below.

By default, everything SiloMeet does runs on your device through Apple Speech, Apple Foundation Models when available, and an always-available deterministic local engine. On the Mac you can also choose an optional local MLX speech model that is downloaded once with your consent and then runs entirely on-device. Silo Systems operates no server, hosted model, or SiloMeet account. The one exception is the optional Bring Your Own Key mode described below, which exists only in the macOS app, is off until you enable it, and sends data only to a provider you choose and pay for directly. The iOS app has no cloud option and makes no network requests at all.

What we don't have, and therefore never see

Because SiloMeet has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your content and anything derived from it; session timing, feature usage, or behavioural data; crash reports. The app never contacts Silo Systems on its own.

Meeting recording (explicit, never ambient)

SiloMeet records a meeting only when you start a session and stops the moment you end it. There is no ambient, continuous, or background capture — recording is always explicit and user-initiated. By default, everything about it stays on your device:

  • On-device by default. Capture, transcription, summaries, decisions, and action items all run locally on your device, and nothing recorded is transmitted anywhere — unless, on the Mac, you have turned on the optional Bring Your Own Key mode described below, which sends transcripts to the cloud provider you chose.
  • You start and stop it. A session begins when you tap record and ends when you tap stop. The app never listens outside a session you started.
  • Cited, never fabricated. Every action item and decision links back to the exact transcript line it came from, and a deterministic validator rejects anything not grounded in your transcript.
  • Stored locally. SiloMeet keeps transcripts and summaries inside the app's on-device container, protected at rest by the operating system. SiloMeet has no sync or cloud storage of its own.
  • Yours to delete. Erase any meeting, or all of them, at any time from inside the app.

If you never start a session, nothing is captured.

Outbound traffic you initiate

The only outbound network traffic, all user-initiated, and none of it to SiloMeet:

  1. App Store updates. When Apple ships a SiloMeet update, the App Store delivers it. This traffic is between your device and Apple's servers. SiloMeet is not involved.
  2. Links you click. If you click an external link inside the app, your default browser handles the request. SiloMeet is not involved.
  3. Optional local speech model download (Mac). If you choose the optional local MLX transcription engine on the Mac, SiloMeet downloads the model you pick once from a pinned, checksum-verified Hugging Face revision: Qwen3-ASR 0.6B (about 1 GB) by default, or Qwen3-ASR 1.7B (about 2.5 GB) if you choose Higher accuracy. SiloMeet first shows you the model, its download size, its license, and its source, and nothing is downloaded until you choose Download and use. No audio, transcript, or identifier is sent with the request, and each model can be removed in Settings at any time. If you keep Apple Speech, no download happens.
  4. Optional Bring Your Own Key requests (Mac). Only if you turn on cloud inference, confirm the consent dialog, and save your own API key, the Mac app sends summary and chat requests directly to the provider you configured, as described in the next section. A summary request carries the meeting's transcript lines with speaker labels and its title; a chat request carries your question and up to 12 matching transcript excerpts. The iOS app has no such requests.

Optional Bring Your Own Key (macOS only, off by default)

This is the one path by which your content can leave your Mac, and it stays closed until you open it. It exists only in the macOS app; SiloMeet for iOS has no cloud setting and no key entry. If you enable cloud inference in Settings and supply your own API key for a provider you choose, the content you process with that feature is sent over the internet to that provider, under your own account: the transcript lines of each meeting it summarizes (up to about 24,000 characters, with speaker labels) and that meeting's title, and each chat question that matches your transcripts, together with up to 12 of the matching transcript lines. Audio is never sent. What you send is then subject to that provider's privacy policy and data-retention practices, not ours.

Turning it on requires an explicit in-app confirmation, SiloMeet shows a persistent cloud badge whenever a cloud provider is active, and you can return to on-device processing at any time. Nothing is ever sent to Silo Systems. We never see your content or your key, and we run no server, proxy, or relay in this path — traffic goes directly from your Mac to the provider you configured. Your key is stored only in the macOS Keychain on this Mac, never in a file, a database, or a log. You can also point SiloMeet at Ollama running on your own machine, in which case nothing leaves your network at all.

Permissions we request, and why

  • Microphone. Record the meeting audio so it can be transcribed on-device.
  • Speech Recognition. Transcribe recorded audio on-device with Apple Speech.
  • Screen & System Audio (macOS). (optional) Capture meeting audio playing through your Mac (remote calls), so it can be transcribed alongside your mic.

If you turn on Name meetings from my calendar in Settings, SiloMeet also asks for Calendar access. It then reads, on your device, the events from one hour before to one hour after the time you started recording, and uses the title of the event in progress to name the meeting. On the Mac, if you have also turned on the optional Bring Your Own Key mode described above, that meeting title is sent with the transcript to the provider you configured. SiloMeet does not request Camera, Contacts, Location, or Full Disk Access. If you grant nothing, it can read nothing.

On-device data you create

Your content and everything derived from it live in SiloMeet's operating-system-protected app container. On Mac, that container is under ~/Library/Containers/com.silosystems.silomeet/Data/Library/Application Support/SiloMeet/; iPhone and iPad use the private app container managed by iOS or iPadOS. Files go elsewhere only when you explicitly export them. They are yours, and we do not have access to them.

During recording finalization, SiloMeet may stage a recovery copy inside the app container. After a successful save it deletes that copy or surfaces an explicit cleanup action if deletion fails. If finalization fails, you choose Retry or Discard; the app does not silently upload or abandon it.

Third-party components

SiloMeet uses these Apple frameworks on-device. They do not receive your meeting as a hosted SiloMeet service:

  • Apple Foundation Models — runs locally on-device.
  • Apple Speech — runs locally on-device.
  • Deterministic extractive engine — runs locally when Foundation Models are unavailable.

Children's privacy

SiloMeet is rated 4+. Because the app sends Silo Systems no personal data about any user, no special treatment is required for users under 13. The same policy applies regardless of age: the app sends us nothing.

Changes

If we ever materially change how SiloMeet handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing reaches Silo Systems.

Contact

Questions about this policy: admin@ohmslaw.net

For non-private inquiries you can also open an issue at github.com/flowmar47/silomeet/issues.

Contact
Last updated 2026-09-23 · v1.1