Skip to content
iPhone + iPad + Mac$9.99 one-time · no subscriptioniOS 18+ · iPadOS 18+ · macOS 14+
Privacy · Silo Sweep · Effective 2026-09-23

Privacy policy.

The current policy is: nothing is collected.

The short version

Silo Sweep collects no data. None.

No analytics. No telemetry. No account. No personal data. No usage metrics. No error beacons. No advertising IDs. No fingerprinting. No crash reports. Silo Sweep never sends anything about you, your device, or your content to Silo Systems, and it never uploads your photos or anything derived from them.

Everything Silo Sweep does runs on your iPhone, iPad or Mac, using Apple's own on-device frameworks. The cleanup makes no network requests on any device, and Silo Sweep never downloads an original from iCloud, so the whole scan, review and delete flow works with the network turned off. Silo Systems operates no server and receives nothing, and there is no Silo Sweep account. The one optional exception is on the Mac: in Silo Sweep 1.7.1 for Mac, the Semantic image pilot in Settings can download a 5.65 GB vision model from Hugging Face (huggingface.co and its download servers), and only after you tap Download. It is a download only: nothing from your photo library is sent, and the model then answers questions about a photo you choose entirely on your Mac. Silo Sweep for iPad and iPhone has no such download.

What we don't have, and therefore never see

Because Silo Sweep has no server-side component, none of the following exists anywhere in our infrastructure (which consists of: nothing): your name, email, phone, or address; your IP address, device identifier, or any hardware fingerprint; your photos and anything derived from them; session timing, feature usage, or behavioural data; crash reports. The app never contacts Silo Systems.

Outbound traffic you initiate

The only outbound network traffic, all user-initiated, and none of it to Silo Sweep:

  1. App Store updates. When Apple ships a Silo Sweep update, the App Store delivers it. This traffic is between your device and Apple's servers. Silo Sweep is not involved.
  2. Links you click. If you click an external link inside the app, your default browser handles the request. Silo Sweep is not involved.
  3. Optional photo-question model (Silo Sweep 1.7.1 for Mac only). If you open Settings, choose the semantic image pilot, and click Download, the app downloads a pinned 5.65 GB open-source vision model (Apache-2.0) from Hugging Face (huggingface.co and its download servers). The requests carry only the model name, its pinned revision, and file names, plus the connection details any download reveals, such as your IP address. No photo, question, answer, or device identifier is sent. The model is stored in the app container and runs offline afterward, so questions you ask about a photo are answered on your Mac. Silo Sweep for iPhone and iPad never downloads it, and the cleanup never needs it.

Permissions we request, and why

  • Your photo library. Read your photos to find duplicates, near-duplicates, bursts, blurry shots and screenshots, and to move the items you confirm into Recently Deleted. Requested only when you start a Photos scan, never at launch. Limited Library mode is fully supported.
  • Files you choose (Mac only). When you scan a Lightroom Classic or Capture One catalog: the catalog you pick in an Open panel, and each folder that catalog keeps photos in, which Silo Sweep offers in its own panel for you to allow or skip. The catalog is only read, never written. Files you toss go to the Trash.

Silo Sweep does not request Camera, Microphone, Screen Recording, Contacts, Location, or Full Disk Access. If you grant nothing, it can read nothing, and the built-in sample library still shows how a review works.

What happens when you remove something

Silo Sweep cannot delete anything on its own. Every Photos removal goes through Apple's own confirmation and then stays in Recently Deleted, where it is recoverable for 30 days. Space is reported as pending until Recently Deleted clears, never as already freed. On the Mac, files you toss after a catalog scan move to the Trash when you confirm and stay there until you empty it. The catalog is not changed, so it lists those files as missing until you remove them in the catalog's own app.

On-device data you create

Silo Sweep keeps a local index of what each scan measured (item identifiers, sizes, dates, fingerprints, digests, sharpness scores and face counts, never copies of your photos) plus the record of each sweep, in its own app container. On the Mac that is ~/Library/Containers/com.silosystems.silosweep/Data/Library/Application Support/SiloSweep/ (plus any location you explicitly choose when you export a CSV record). It is yours. We do not have access to it. On iPhone and iPad, deleting the app deletes this data with it. On the Mac, it stays in the container until you delete that folder yourself.

Third-party components

Silo Sweep uses these Apple system frameworks, all running entirely on-device. None of them receive any data about you from Silo Sweep, and none require a network connection:

  • Photos (PhotoKit) reads your library and carries out the removals you confirm.
  • Vision computes feature prints for near-match checks, counts how many faces a photo contains (it does not recognise or identify anyone), and labels documents, receipts and whiteboards.
  • Core Graphics reduces each image to the small grayscale grid behind the perceptual hash and the sharpness score.
  • CryptoKit computes the SHA-256 digest behind every exact-duplicate call.
  • ImageIO and SQLite read a Lightroom Classic or Capture One catalog and the photos it lists when you scan one on the Mac.
  • Optional vision model (Mac app only, Apple silicon): not an Apple framework. An openly licensed model (Apache-2.0), downloaded from Hugging Face only after you click Download, then run locally with MLX. The photo and question you give it stay on your Mac, and it needs no network connection once installed.

The local index is stored with GRDB, an open-source SQLite library compiled into the app. It runs on your device and sends nothing anywhere.

Children's privacy

Because no personal data is collected from any user, no special treatment is required for users under 13. Same policy applies regardless of age: nothing collected.

Changes

If we ever materially change how Silo Sweep handles data, we will publish an updated version of this page, announce the change prominently in the release notes, and require explicit consent in-app before any new collection begins. The current policy is: nothing is collected.

Contact

Questions about this policy: admin@ohmslaw.net

Help and short answers are on the support page at ohmslaw.net/apps/silosweep/support.

Contact
Last updated 2026-09-23