Sanctuary

Privacy Policy — Sanctuary

Version 1.18 · Effective 1 October 2026 · Versions 1.0 (20 Aug 2026), 1.1 (25 Aug 2026), 1.2 (3 Sep 2026), 1.3 (4 Sep 2026), 1.4 (4 Sep 2026), 1.5 (5 Sep 2026), 1.6 (8 Sep 2026), 1.7 (8 Sep 2026), 1.8 (9 Sep 2026), 1.9 (10 Sep 2026), 1.10 (12 Sep 2026), 1.11 (16 Sep 2026), 1.12 (28 Sep 2026), 1.13 (28 Sep 2026), 1.14 (29 Sep 2026), 1.15 (30 Sep 2026), 1.16 (30 Sep 2026) and 1.17 (30 Sep 2026) in git history

0. The short version

Sanctuary is a macOS app that reads your Messages history on your Mac and builds a searchable library of the links inside it. The library file lives on your disk. We do not have a copy of it, cannot request one, and have not built the infrastructure to receive one.

QuestionAnswer
Do you upload my messages or contacts?No. They are read on-device and written to a local database only. Two opt-in features send bounded pieces to an AI enclave on your own key — see §5.3 and §5.6.
Do you collect analytics or telemetry?Not from the app. Usage counters exist but stay on your Mac and are never transmitted. Our public website, linksanctuary.com, uses cookieless page analytics — see §4.6.
Do you sell or share my personal information?No. Never have, and we commit to notice before that could change.
Does the app use AI?Yes — see §5. By default a model that runs on your Mac.
Does anything leave my Mac?Yes, a limited set — see §4. Mostly the websites you already have links to, plus sync to your own iPhone through your own iCloud (§4.9) and, only if you set up the Feed, short search queries to a web-search API on your own key — topic words, interest words, place names and your own search terms, never names or messages (§4.10). If you add your own Nyne key, one identifier per person you choose to look up (§4.13). If you use Build mode, your own Claude Code or Codex sends your requests and the code in the folder you chose to its own provider (§4.20).
Can I delete everything?Yes — see §8. Deleting one folder removes the entire library.
Do you charge money?Yes — US$29 a month or US$275 a year, after a 14-day trial that needs no card. Stripe takes the payment on its own page; your card never reaches us, and the app contains no payment code. See §10.

We describe below not only what we do, but where in the source code each claim is enforced, so the claims can be checked rather than trusted (Appendix A).

1. Who we are and what this covers

Sanctuary is a product of Superscore AI, Inc. ("Superscore AI", "we", "us"). Where this policy says "we", it means that company.

Controller / publisher: Superscore AI, Inc., a Delaware corporation, 651 N Broad St, Suite 201, Middletown, DE 19709, United States. Contact: ravi@fulllist.ai.

This policy covers:

It does not cover third-party websites you open from your library, the operating system's own handling of Messages and Contacts, or any AI provider you choose to configure with your own account.

A note on roles. For the data the app reads from your Mac, you are the party deciding what is processed and why; we never receive it, so we cannot access, disclose, or produce it — including in response to a subpoena or law-enforcement request, because we hold nothing to produce. For the limited web-build account data described in §4.6, we act as the controller in the sense of the GDPR and as a "business" in the sense of the CCPA/CPRA.

2. What the app reads on your Mac

To do its job, the app reads the following from your machine. Granting Full Disk Access in System Settings is what makes this possible; macOS asks you for it explicitly and you can revoke it at any time.

SourceWhat is readWhy
~/Library/Messages/chat.dbMessage text, timestamps, sender/recipient handles, conversation identifiers, the URLs inside messages, and the "filtered/junk" flagTo find links and reconstruct the conversation around each one
macOS Contacts (AddressBook)Names, phone numbers, email addressesTo turn handles like +1555… into the person who actually sent the link
Apple Mail's index on this Mac (~/Library/Mail, its Envelope Index)Sender, subject, date, read and flagged state, mailing-list id and Mail's one-line preview of each message — not a connection to your mail providerSo threads waiting on you show up beside your messages, and Ask can find an email; read-only, never uploaded
The Mac's own Calendar (Calendar.sqlitedb) (§4.18)Event titles, times, calendar names, locations, and attendees — kept as a name and, for a work address, the organisation, never the email addressSo Today shows your day and Ask can answer "when am I seeing her"; read-only, nothing stored
LinkedIn messages you capture — only if you turn it on (§4.19)The messages in a capture you hand to the app: who, when, and what was saidSo a LinkedIn conversation counts like any other; turning it off deletes them
A ChatGPT or Claude export — only if you import oneThe conversations in the export file you chooseSo Ask can find something you worked out with an assistant; read from the file, never a login
Code folders you open in Build mode (§4.20)The Markdown files in a folder you choose through the macOS file picker, and — when you ask it to — whatever your own coding agent reads thereSo a project's own notes and roadmap sit in the app, and so you can work on it; nothing outside that folder
Pages you have links toTitle, description, author, publication date, favicon, and structured event dataTo make each link recognizable instead of a bare URL
The link previews inside Messages (payload_data)The title, summary, site name and preview image Messages itself rendered for a link you were sentSo an Instagram, Facebook or Reddit link shows what it is instead of the site's name — with no visit to the site
Safari, Chrome and Arc history — only if you turn it on (§4.12)Pages you visited and searches you made, with dates; copied from the browsers' own filesTo answer "what was I researching", to show which links people sent you actually opened, and to seed the Feed; turning it off deletes everything it stored
Your Instagram data export — only if you turn it on (§4.14)The saved posts in a file you downloaded yourself: link, caption, poster's handle, hashtags, save date, your collection namesTo put what you bookmarked next to what people sent you; never a login, never a request to Instagram; turning it off deletes them
WhatsApp's own store on this Mac — only if you turn it on (§4.15)Message text, timestamps, sender and group ids, chat names and WhatsApp's own link-preview titles, from ChatStorage.sqlite in the WhatsApp app's containerSo links people sent you on WhatsApp sit beside the ones from Messages, with who sent them; read-only, never uploaded; turning it off deletes them
Your Obsidian vault — only if you turn it on (§4.16)The Markdown notes in the folder you choose: title, body, tags, links between notes, and the links inside themSo your own notes and the links in them sit beside what people sent you; read from the folder on this Mac, never uploaded, never shared with connected chat apps; turning it off deletes them
Your Notion export — only if you turn it on (§4.16)The pages in a Markdown & CSV export you download yourself: title, properties, body, links between pages, and the links inside themSame as your vault: read from the file on this Mac, never a login, never a request to Notion; turning it off deletes them

These reads are strictly read-only. The app never writes to, modifies, locks, or deletes your Messages database, your Contacts, or your browsers' history files.

Faces. A person's photo comes from your own Contacts card for them, and otherwise from the photo they chose to share with you through Messages' Name and Photo Sharing, which Messages keeps in its own cache on this Mac. Both are read from the Mac, shown inside Sanctuary, and never uploaded or sent to any connected app. Photos a sender marked sensitive are never shown.

What is derived and stored locally: a link record (original and canonical URL, domain, platform), who shared it and in which conversation, when, the message that carried it plus a short window of surrounding messages, an AI-generated category and summary, a person graph, your projects, favorites, archive and spam flags, and search indexes.

Where it is stored: ~/Library/Application Support/Sanctuary/ (on Macs that ran an early build, ~/Library/Application Support/tanstack_start_ts/) — principally link-library.db, alongside local log files and, if you download it, the on-device AI model.

3. What we do _not_ do

We consider these commitments, not current defaults, and we will not change them silently (see §14):

We also keep usage counters — how many distinct days you have opened the app, how many searches you have run. These are written to your local database and are never transmitted. They exist so that if you choose to send us feedback, you can include them yourself (see §4.8).

4. What leaves your device

This is the complete list. Each item states what is sent, to whom, when, and whether you control it.

When the app enriches a link, it fetches that page directly from the site that hosts it, and requests the site's favicon. This is an ordinary web request from your Mac, so the destination website — and any CDN or analytics it runs — can see your IP address, the request headers your system sends, and the fact that the URL was fetched at that time.

4.2 Update checks

The app periodically checks a public GitHub release manifest to see whether a newer version exists, and downloads the update if you accept it. GitHub therefore receives your IP address and the timing of the check as part of serving that file. No identifier of you or your library is attached.

4.3 Downloading the on-device AI model

If you choose to use on-device AI, the app downloads a model file (~2.5 GB) from Hugging Face. Hugging Face receives your IP address and which file was requested. This happens once, only when you start the download.

4.4 Cloud AI — off by default, opt-in, your own key

Packaged builds ship with cloud AI disabled and with no API key of any kind; our build tooling fails the release if a credential is found in the bundle. If — and only if — you turn cloud AI on and paste in your own provider API key, the app may send the payload described in §5.2 to that provider. Turning the setting off stops it immediately.

With cloud AI on, the Ask chat sends a second, distinct payload (DEC-014): the conversation you type into Ask, the results of the library tools the model calls while answering (shaped like the Ask payload — titles, domains, summaries; contact names and message-derived text only if you also enable message scanning), and — only when you choose to continue an imported ChatGPT/Claude conversation — a tail of that transcript. Chats are stored only on your Mac (local SQLite); an incognito chat is never written at all. With cloud AI off, Ask chat runs entirely on the local model and nothing leaves.

4.5 Web fonts — nothing is sent

The interface uses the IBM Plex typefaces, and they ship inside the app. Earlier versions loaded them from Google Fonts, which meant the desktop app contacted Google on every launch and disclosed your IP address for no product reason. That request is gone: the fonts are bundled (public/fonts/, src/fonts.css), so the interface renders offline and Google is not involved.

We mention a request we no longer make because the honest version of "nothing leaves your device" is a list of the things that used to.

4.6 Hosted web build and website

Website analytics. Our public website, linksanctuary.com, uses PostHog to count page views and clicks on the download button and the demo video. It runs cookieless: nothing is stored in your browser, there is no session recording, no cross-site tracking, and we do not identify visitors. PostHog receives your IP address with each request, as any web server does; the project is configured to discard it on receipt. Each event carries the page your visit landed on and the name of the site that sent you there (its hostname only, never the full address); both are kept in the page's memory for that visit and never stored. The website also loads Google Analytics for page views, which sets its own cookies and receives your IP address under Google's terms; a content blocker that blocks posthog.com and googletagmanager.com stops both and the site works identically. The same code ships inside the desktop app's bundle but does nothing there — it checks for the app environment and the site's hostname first — so the app itself still sends no analytics (§3).

Payments. Sanctuary is sold as a subscription on the website. There is no account to create: payment is taken by Stripe on Stripe's own checkout page, and your card number never reaches us. After paying, Stripe sends you to a download page whose address carries the checkout's identifier; that page asks Stripe whether the subscription is active and, if so, shows the download. We keep no record of the purchase ourselves — the identifier is stored in your browser so the page can find it again, and Stripe holds the customer, subscription, receipts and renewal dates. Stripe receives your email address and name for the receipt and renewal reminders it sends on our behalf, and processes your payment details under its own privacy policy. You can change or cancel the plan from the same download page; canceling stops the charges and, when the paid period ends, the download — it deletes nothing on your Mac. If you lose the download page, you can ask for it by email on the pricing page: we look the address up in Stripe and, if it has an active subscription, email the link to that address and nothing else; the request itself is not stored.

The demonstration build at klipped.lovable.app is a different thing from the app and holds no personal library. If you sign in there:

4.7 Personal data archives you import (LinkedIn)

You can import your own LinkedIn data export (the ZIP LinkedIn lets you download) to add roles, companies, locations, and profile links to your People cards. The archive is read in memory on your Mac and never uploaded; nothing is extracted to disk, no request is made to LinkedIn or anyone else during the import, and Sanctuary never queries or scrapes LinkedIn. Only the parsed fields Sanctuary uses are stored, each tagged with its source and import date, and matching against people you already have is deliberately conservative (a name alone never merges two records). Settings → Data sources → LinkedIn → Remove imported data deletes every LinkedIn-sourced fact and the people that import alone created, leaving the rest of your library untouched.

4.8 Diagnostics you choose to send

The app can assemble a plain-text diagnostic report — counts and dates only: no message content, no URLs, no contact names, no keys. It is copied to your clipboard for you to read and send yourself. Nothing is transmitted automatically, and there is no channel for us to request it.

4.9 Sync to your iPhone — through your own iCloud

If you install the Sanctuary iOS app, your library syncs between your Mac and iPhone through your own iCloud Drive (the app's private iCloud container). What rides that channel: your links, the contacts-resolved people who shared them, projects, one excerpt of at most 280 characters per share, and — only if message scanning (§5.6) is on — your extracted tasks, each with a capped window of a few surrounding messages so the task is checkable on the phone.

Three things to be clear about: the data moves under your Apple ID, encrypted and stored by Apple under your iCloud terms; we operate no sync server and cannot read any of it; and full conversations never sync — the phone receives excerpts and task context windows, not your message history. Captures and dismissals made on the phone travel back the same way.

Moving to a new Mac is a bundle, not a sync: Profile → Move to a new Mac writes a copy of your library and a manifest into a folder on this Mac, and you carry that folder yourself. Nothing about it goes through iCloud or any server; restoring it on another Mac replaces that Mac's library and keeps the previous one beside it.

What the phone reads since 2026-09-19. The snapshot also carries: which app each link arrived from (Messages, WhatsApp, Mail, notes, LinkedIn, AI chats, Instagram) as a label, never the conversation; the composed Person card as the Mac shows it (a bio sentence or two, role, company, city, interests, what you share, what's recent and what's coming) for people the Mac has context on; the subject line and a short excerpt of Apple Mail threads waiting on you, so the phone's open loops match the Mac's; open page and loop proposals from the Mac's agents (title and a one-line reason, read-only); and pinned pages with their rows and cells. All of it is derived from records this policy already covers, stays inside your own iCloud container, and is replaced wholesale on the next sync. Marking a mail thread done on the phone updates the Mac's Mail status the same way the Mac's own Today does.

The Feed page, the "Add suggested links" option when generating a digest, and the project researcher agent (§5.7) find new pages for you with a web-search API, Parallel (api.parallel.ai). This is off until you paste your own Parallel key on the Feed page; the key is stored in your local library and never leaves your Mac except in the request header to Parallel itself.

What a request contains: a one-sentence objective and a handful of short search queries. Those are built from your topic names and keywords taken from titles of links you saved, or — for a digest or the project researcher — a project's name, your written brief, and recent link titles. What a request never contains: message text, names or handles of your contacts, the URLs of your saved links, or anything from a Person card. Parallel receives your IP address with the request, as any web service does, and returns page results; Sanctuary stores those results locally as feed items you can mark or dismiss.

Intent seeds (added 2026-09-05). Besides your library's topics, the Feed now searches for what Sanctuary can see you are about to need: a search you repeated over several days and never saved (browser history, only if that source is on), a gift for a birthday or anniversary in the next month, a trip with a place and a date ahead, an active project, or something a friend recommended that you never acted on. Those seeds are derived from your messages and history, so this is a wider use of the web-search exit than "topic names": each query carries interest words, place names, project words or your own search terms — never a person's name, a date, or message text. A guard drops any query containing a contact's name before it is sent, and the reason shown next to each item ("Nish's birthday is March 20 · cars, music production") stays on your Mac.

Pages and briefs with "Include the web" (added 2026-09-15). A page or brief searches the web only when you switch "Include the web" on for that page. The query is then the words of your own prompt for that page ("consumer AI investors in Chicago") — never message text, never a Person card, and the same guard drops the query entirely if it contains a contact's name or anything identifier-shaped, so nothing is sent. Results appear as rows or citations marked "from the web" with their URL; they are never merged with a person. Connected chat apps (§4.11) cannot reach this search. Turn the switch off and the next refresh uses your library alone.

4.11 Connected chat apps (MCP)

Sanctuary ships an MCP server so an assistant you already use — Claude Desktop or Claude Code, or an agent runtime such as OpenClaw or Hermes — can ask your library questions. You connect it yourself (a button in Profile → Connected chat apps writes Claude Desktop's or OpenClaw's config entry; Claude Code takes one command; for Hermes the app shows a snippet for you to paste); nothing is connected by default, and there is no sign-in: the assistant launches Sanctuary's server on your Mac. Agent runtimes can run unattended, so be deliberate about the two switches below when you connect one. ChatGPT's connectors only accept hosted servers, so ChatGPT is not supported. Its five link tools return titles, URLs, domains, categories, summaries, event dates, sender names, dates and counts, and never message text, conversation context, handles or phone numbers. That contract is pinned by tests and has not changed. The same server offers three prompts (recipes the assistant runs over these tools — "catch me up on", "before a meeting", "this week") and a few attachable resources: your recent links and a count of how far back each source goes, always; a person's card, your saved digests and your context pack only behind the switch below, through the same tools it gates. The context pack is six short files an assistant can read about you — who you are, key people, current projects, decisions, how you write, and your own goals and rules — generated from the library and dated; the "how you write" file carries lines from your own messages only behind the second (excerpts) switch, and the goals-and-rules file is the one you type yourself. Prompts and resources add no data the tools don't already return. You can also export the same six files as markdown from Profile → Context pack; from then on they are ordinary files on your Mac, outside Sanctuary's control.

A separate switch, Profile → Connected chat apps → Share what Sanctuary learned from messages, off by default, additionally exposes the app's own Ask tools: a person's card (relationship, preferences, interests, what they recommended, open loops between you), what people recommended, your open loops and mail loops, the working set, project context, message search, mail search (Apple Mail on your Mac: subject, sender name and domain, date, mailbox — never an address, never a body), the latest exchange with one person (when, who spoke last, how often you talk), people ranked by how often you talk (most active, gone quiet, tied to a city — names and dates only), and the context around one saved link (who shared it, when, in which chat, what it is filed under). Message search through a connected app answers who you talked to about something and when; the words of the messages themselves — and, for mail, Mail's one-line preview, and for the latest exchange and link context, the lines around them — are withheld unless you also turn on the second switch, "Also share the words of messages", which is off by default. Be clear about what the switches mean: those answers go to the connected app's model provider (Anthropic, OpenAI), not to the private enclave that runs the app's own AI, and that provider's terms apply. The switch is read on every call, so turning it off takes effect immediately. Connected apps can only read; no tool sends, posts, or changes anything.

4.12 Browser history — read here, kept here

Off by default. If you turn it on in Profile → Data sources, Sanctuary copies your Safari, Chrome and Arc history files on this Mac and reads new visits into its own local table: the page, its title, the search terms when the page was a search, and when. Nothing about it leaves the Mac: it is not part of any AI payload, and connected chat apps (§4.11) can never see it. It answers "what was I researching last week" and "did I ever open the link she sent" inside Ask. Turning the switch off deletes every stored visit immediately.

4.13 Work profiles from Nyne — on your own credits

Off unless you add your own Nyne API key and secret in Profile → Data sources, and even then nothing runs on its own: you enrich one person from their card, or press "Enrich next N" for the people you talk to most. For each person you choose, exactly one identifier leaves your Mac — their LinkedIn URL if the card has one, else an email address, else a phone number — together with the name on the card (kin words and emoji stripped). That goes to api.nyne.ai under Nyne's terms, and costs Nyne credits (6 per matched person; a person Nyne can't match costs nothing).

What comes back is filtered before anything is stored: the current company and title, a headline, location, schools, and the LinkedIn URL land as profile claims with nyne provenance (ranked below a LinkedIn export and your own edits), and the skills on their public profile as one "Skills" line under the card's details — never as interests, which come only from what the person said. Bulk enrichment only offers people who have no work profile on file. Nyne also returns things Sanctuary refuses to keep — salary estimates, gender, birthday, home address, personal emails, phone numbers, photos and a "possible matches" list — those are discarded in memory and never written. A person is not re-enriched within 90 days. Everything Nyne added can be removed like any other claim or chip.

4.14 Instagram Saved — your own export, read here, kept here

Off by default, and not a connection to Instagram. If you turn it on in Profile → Data sources, Sanctuary reads the Saved section of the data export _you_ download from Instagram ("Download your information"): each saved post's link, its caption, who posted it, the hashtags, when you saved it, and the names of your own collections. The archive is read in memory on your Mac and never uploaded; nothing is extracted to disk. Sanctuary never signs in to Instagram, never uses your Instagram session or password, and never makes a request to Instagram during the import — it reads a file you already have.

Saved posts then live in your library like any other link, under a "Saved on Instagram" source with no person attached — the account that posted something is never turned into a contact. The caption is stored as the link's title and description, which means the one thing that leaves the Mac for a saved post is the same as for every other link (§5.3): the link and its stored title and description, to the enclave on your key, so it can be filed under a topic. The Feed never builds a search from a saved post's caption or from the poster's handle. Turning the switch off deletes every saved post immediately, along with the library rows they became — unless someone also sent you the same link in Messages, in which case that copy stays.

4.15 WhatsApp — read here, kept here

Off by default. If you turn it on in Profile → Data sources, Sanctuary reads the history the WhatsApp app itself keeps on this Mac (its ChatStorage.sqlite, covered by the same Full Disk Access grant as Messages) the way it reads Messages: read-only, never writing to or locking the file, and only while the app is linked to your phone. Message text stays in Sanctuary's local database so Ask can search it; links people sent you land in the library with who sent them and the lines around them. People are matched by phone number through your Contacts; WhatsApp's newer anonymous sender ids are kept as a display name only and never become a person on their own. Nothing about it leaves the Mac except what §4.1 already describes for any link. Photos and documents the WhatsApp app has already downloaded to this Mac are read the way iMessage attachments are — text recognized on this Mac, never uploaded. Turning the switch off deletes every WhatsApp line, link and file record immediately, keeping a link only if someone also sent it to you elsewhere.

4.16 Your notes (Obsidian, Notion) — read here, kept here

Off by default, one switch per source. If you turn Obsidian on in Profile → Data sources and choose your vault, Sanctuary reads the Markdown files in that folder — and only that folder — into its own local table; if you turn Notion on and pick the Markdown & CSV export you downloaded from Notion, it reads the pages in that file the same way (never a connection to Notion): each note's title, body, tags, links to other notes, and the web links inside it. Nothing is watched or synced; you choose when it reads again. Notes are your own writing, so Ask can search them, but a connected chat app (§4.11) never sees them. A link found in a note enters the same classification step as any other link (§4.1), with the few words around it from the note — never the whole note. Turning the switch off deletes every note and every link that only a note carried.

4.17 Map images — drawn by Apple's MapKit

The Places page shows a small map for each city and each place. Those images are drawn on your Mac by Apple's MapKit (the phone draws its map thumbnails the same way), which fetches map tiles from Apple's map servers exactly as the Maps app does. What Apple sees is the coordinates being drawn — never the place's name, who recommended it, or any message. The images are cached on your Mac and never re-requested for the same place. No other map service is used.

4.18 Your calendar — read here, from the Mac's own copy

macOS already keeps a copy of every calendar you have added to it (iCloud, Google, Workspace, Exchange) in a database on this Mac. Sanctuary reads that copy the way it reads Messages: read-only, covered by the same Full Disk Access grant, never writing to it, and with no connection to Google, Apple or any calendar service — there is no calendar sign-in and no calendar key. It stores nothing of its own: each time Today or Ask needs your schedule, it reads the file again.

What is read: each event's title, start and end time, calendar name, location, whether it is an online meeting, and its attendees. An attendee is kept only as a name and, when their address is a work address, the organisation in it (sam@example.co becomes "example.co"); the email address itself is used on this Mac to recognise people you already know and is then dropped. Attendees can include people you have never messaged.

Where it goes: Today's schedule and "Coming up", on this Mac. Ask can also look at your calendar while answering, and what it finds is then treated like any other Ask tool result — so if you have turned cloud AI on (§4.4), those calendar rows (title, time, calendar name, attendee names and organisations, location) are part of what Ask sends to the enclave, and if you have turned on "Share what Sanctuary learned from messages" for connected chat apps (§4.11), a connected app can read them too. With both of those off, your calendar never leaves the Mac. There is no separate switch: like Mail, your calendar is part of what Full Disk Access lets the app read, and it stores nothing to delete. Revoking Full Disk Access stops the read.

4.19 LinkedIn messages you capture — and the local door they can come in by

Off by default, and not a connection to LinkedIn: Sanctuary never signs in to LinkedIn, never uses your LinkedIn session, and never makes a request to LinkedIn. If you turn it on in Profile → Data sources, you can hand the app LinkedIn conversations you have captured yourself — for example, with an AI assistant working in your own browser — and it files each message under the person it is with, like a WhatsApp line. A capture arrives in one of three ways, all on this Mac: a command you run, a file you drop into a folder inside Sanctuary's own data folder, or a local endpoint.

The local endpoint is a separate switch, off by default. When it is on, the app listens on 127.0.0.1 — your own Mac only; nothing on your network or the internet can reach it — for one kind of request: a LinkedIn capture, accompanied by a secret token the app generates, stores encrypted in your Keychain, and shows you in Settings. It serves nothing back, has no other purpose, and stops listening the moment you turn it off. Anyone holding the token can add messages to your library, so treat it like a password; you can replace it from the same screen.

Every capture is checked field by field and stored as plain text: nothing in it is opened, fetched, run, or shown as a web page. The messages then behave like other messages (they can appear in Ask answers, open loops and Person cards, and leave the Mac only through the paths in §4.4 and §4.11). Turning the source off deletes every captured LinkedIn message; people it introduced stay, since you may have written about them since.

4.20 Build mode — your own coding agent, in a folder you choose

Build mode is for people who work on code. It appears only when a coding assistant it can drive is available, and it works only in folders you have picked through the macOS file picker — never a path the app chose for you — and in separate working copies of those folders that you ask it to make (below).

4.21 License check — one identifier to our website

The app is sold as a subscription (§10). Once a day, and when you paste your license key, the app sends that key alone — the identifier of the Stripe checkout you paid with — to linksanctuary.com, our website, which asks Stripe whether the subscription is active and answers yes or no. Nothing else travels with it: no library, no names, no usage, no machine identifier. The key is stored encrypted on your Mac. If the site can't be reached, the last answer stands for two weeks; an install without a key runs for a fourteen-day trial. The code is electron/services/license.cjs; the endpoint is src/routes/api/license.ts, which keeps no record of the request.

4.22 Sanctuary in Slack — your own Slack app, answers posted to your workspace

Off until you set it up in Profile → Slack. You create a Slack app in your own workspace from a manifest the app gives you, and paste its two tokens; they are stored encrypted on your Mac. Your Mac then keeps one outbound connection open to Slack (Socket Mode). There is no Sanctuary server in between, nothing listens on your Mac, and we never see the tokens or the conversation.

Web search is never used from Slack. At Full Ask you can also type commands to list and run your skills and to accept or dismiss suggestions. Accepting a reply draft shows the draft in Slack; it is never sent.

The code, diffs and run output these produce are posted to Slack. Publishing a release, committing and pushing are not possible from Slack. Anyone who can use your Slack account can use these commands, so turn the switch on only if your Slack account is secured like your Mac.

If your Slack app has token rotation on (Slack won't let an app turn it off once it is on), its tokens expire every few hours. Sanctuary then also stores each token's refresh token and the app's Client ID and Client Secret, encrypted like the tokens, and renews them itself by calling Slack's oauth.v2.access — the only extra network call, and it goes to Slack alone.

The code is electron/services/slack.cjs and slack-tokens.cjs. Reading your own Slack conversations into the library is a separate feature with its own token and switch: §4.23.

4.23 Slack as a source — your own conversations, read into your library

Off until you connect it in Profile → Slack → Read my Slack conversations and turn reading on. It uses a second token from the same Slack app — a user token (it starts xoxp-) that Slack only issues after the app's manifest asks for read-only user scopes and you reinstall it. The token is stored encrypted on your Mac, like the bot's.

The code is electron/services/slack-history.cjs.

5. Artificial intelligence

The app uses AI, and this section says exactly how. We disclose it here because you deserve to know when a machine-generated inference is being written into your library, and to know what text was used to produce it.

5.1 What the AI does

It assigns each link a category, writes a short summary of what the page is, and decides which of your own projects a link belongs to. It answers the questions you type into Ask (§4.4), looking things up in your library to do so. Only behind the separate switches in §5.6 and §5.7 does it read conversations to find tasks and facts about people, or draft suggestions. It does not act on your behalf, does not send messages, and does not make decisions with legal or similarly significant effects. There is no automated decision-making within the meaning of Article 22 GDPR.

5.2 Where the model runs

When cloud AI is enabled, the link-enrichment payload is deliberately narrow and defined in one place in the code so it cannot drift feature by feature:

Not sent by link enrichment: names, phone numbers, email addresses, conversation history beyond that excerpt, your contact list, your other links, or any identifier of you. (Message scanning, §5.6, is a separate feature with a deliberately broader payload and its own switch — nothing described there happens under the cloud-AI setting alone.)

Before an excerpt is sent, a local redaction pass strips recognized contact names, email addresses, and phone-shaped strings. We describe this as defense in depth, not as anonymization: an excerpt is free-form text a human wrote, and no automated filter can guarantee it contains nothing identifying. The primary protection is that excerpts are only sent when the page itself yields no usable metadata, and that the whole path is off unless you turn it on.

5.4 Other people's words

An excerpt of a message may contain something another person wrote to you. Enabling cloud AI is therefore a decision that touches people who are not using this app and did not agree to anything. We have designed the default — on-device, no network — so this never happens unless you deliberately choose it. If you handle other people's messages under a professional duty of confidence (legal, medical, journalistic, or similar), we recommend leaving cloud AI off. Everything in this section applies with greater force to message scanning (§5.6), which reads conversations rather than link excerpts.

5.5 Limits you should know about

AI summaries and categories are inferences and can be wrong. They are stored in columns separate from the raw facts, so an incorrect summary never overwrites what was actually said or sent, and you can recategorize or re-run enrichment at any time. The app is not a crisis, medical, legal, or financial service, and its AI is not designed or tested to respond helpfully to messages describing distress or self-harm — it classifies links, and does not read for that purpose. If you or someone you know needs help, contact local emergency services or a crisis line (in the US and Canada, call or text 988).

5.6 Message scanning — a second, separate opt-in

Sanctuary can surface commitments, deadlines, and unanswered questions from your recent messages ("From your messages" on Home). Because this reads conversations — not just the excerpt that carried a link — it sits behind its own consent, separate from cloud AI: a labeled checkbox during onboarding, and a toggle on the Profile page afterward. It is off by default, does nothing without both cloud AI and this switch on, and turning it off stops every path described below immediately.

When it is on, and only then:

Message text is processed by the enclave to answer the request and is not retained by us — we have no server in this path at all. But be clear-eyed about what the switch means: your conversations contain other people's words, and those people did not opt into anything. That is why this is the only feature in the app with two consent gates in front of it, and why the honest default is off.

5.7 Agents — suggestions, never actions

Since version 0.2.53 Sanctuary runs a small set of agents after each sync: meeting prep, follow-up drafter, project researcher, intro finder, weekly digest, and context confirmer. Each is a switch in Profile → Agents, and each only ever writes a suggestion into your local library — a prep sheet before a dated plan, a reply draft, a few new reads, people already in your graph who fit a project, a digest, or items on a Person card worth confirming. Nothing is sent, posted, or changed until you accept a suggestion, and accepting is a bounded local action: a draft is pasted into Messages for you to read and send yourself; a card item is marked confirmed; a digest opens.

Agents use only the paths this policy already describes and inherit their consent gates: the follow-up drafter uses reply drafting (§5.6) and so requires both cloud AI and message scanning to be on; the project researcher and "suggested links" use the web search in §4.10 and so require your Parallel key; the weekly digest composes with cloud AI (§4.4) and is off by default; meeting prep, intro finder and the context confirmer read your local library and make no network request at all. Docs (added 2026-09-19) gathers everything about one thing you name — a trip, a project — from your chats, mail, notes, links, places, decisions and loops, on this Mac, with no model; sharing a doc writes a standalone page or PDF to a folder you choose, containing only the sections you tick, and uploads nothing. Groups (added 2026-09-18) shows a page per group chat built the same way — who is in it, what is being planned, what was decided, the links and places that came up — recomputed from your library each time you open it, with a notes box that only you write in; nothing leaves the Mac. Suggested pages (added 2026-09-18) reads the last 45 days of your group chats on this Mac for planning words and dates — a trip, a birthday, a wedding — and proposes a page listing who is in that chat and what each of them said; it uses no model and no network, reads only what is already on this Mac, and builds nothing until you click. Agents never contact the people they mention. Notifications about a suggestion are local macOS notifications and contain only the suggestion's title.

5.8 The wiki — written pages about the people, projects and topics in your library

Since 30 September 2026 the Library can show a wiki: a written page for each person, project and topic your library knows well, where every paragraph cites numbered facts. Nothing is written until you press Build the wiki, which first tells you how many pages that is and where they will be written.

The wiki has no switch of its own beyond not building it: it uses cloud AI and message scanning exactly as described above, and turning either off stops the corresponding pages from being written or rewritten. Pages are deleted with your library (§8); a page whose subject no longer qualifies is removed on the next pass.

6. Third parties who may receive data

The complete list. No one else receives anything.

RecipientWhat they receiveWhenBasis
Websites you have links toYour IP address and the requestWhenever a link is enrichedNecessary to perform the service
Tinfoil (AI inference)The payload in §5.3Only if you enable cloud AIYour consent
Hugging FaceYour IP addressOnly if you download the on-device modelYour consent
GitHubYour IP addressUpdate checks and downloadsLegitimate interest in secure software delivery
Yahoo FinanceTicker symbols of holdings you track (never amounts or account data)Only if you use Net WorthYour consent
Open-MeteoThe city name you configure (geocoded once), then rounded coordinates; a city named in a places question when nothing is saved under it (geocoded once, cached); the town name of a saved place whose address names a town but carries no coordinates, so "near" questions can rank it (the town name only — never the place, the sender, or the message)Weather widget, a places question about a city with nothing saved, or a saved place with a town and no coordinatesLegitimate interest — a town name is not personal data
Apple Maps (MapKit, through macOS / iOS)The coordinates of the saved places being drawn — the same request the Maps app makes to show a map; never a name, a sender or a messageDrawing the map images on the Places page (Mac) and the map thumbnails on the phoneLegitimate interest — a map of your own places, from the platform's own map service
Supabase / Lovable (hosting)Web-build account data and search queriesHosted web build onlyContract
Google sign-inYour email, name, avatar URLHosted web build onlyYour consent
PostHog (website analytics)Page views, download/demo clicks, browser and country; IP discarded on receipt; no cookieslinksanctuary.com only, never the appLegitimate interest in knowing whether the website works
A chat app or agent runtime you connect over MCP (Claude Desktop, Claude Code, OpenClaw, Hermes) and its model providerLink metadata (§4.11) whenever you connect one; message-derived Ask context, including calendar rows (§4.18), only while the Profile switch is onOnly if you connect an app yourselfYour consent
Anthropic or OpenAI, through your own Claude Code or CodexWhat you type in Build mode and what that agent reads in the folder you chose (§4.20)Only when you use Build mode, under your own account with that providerYour agreement with that provider
Your git host (e.g. GitHub)The files you tick, as a commit, pushed to the remote your folder already uses (§4.20)Only when you press "Commit and push"Your instruction
Parallel (web search)Your IP address and the search objective and queries in §4.10 (topic names, title keywords, a project's name and brief — never message text or contacts)Only if you add your own Parallel key for the Feed, suggested links, or the project researcherYour consent
Nyne (people data)Your IP address and, per person you choose to enrich, one identifier (LinkedIn URL, else email, else phone) plus their name (§4.13)Only if you add your own Nyne key and press enrichYour consent

We may also disclose information we actually hold — which, for desktop users, is nothing — where legally compelled, or to protect rights and safety. We will contest overbroad demands where we can, and will notify affected users unless prohibited by law.

If we are ever party to a merger, acquisition, or asset sale, any personal information we hold would transfer as an asset. We commit to giving notice before such a transfer changes how information is handled, and to honoring this policy for information collected under it.

7. Security

8. Retention and deletion

Your library is kept until you delete it. We do not impose a retention period on data we cannot see, and there is nothing on our side to expire.

You are always in control:

To do thisDo this
Delete a single linkDelete it in the app; its project associations are removed with it
Clear AI results and start overReset enrichment from the app
Stop the wiki being rewrittenLibrary → Wiki → ⋯ → Stop keeping it current (pages are removed with the library)
Stop all outbound AI requestsTurn off cloud AI in settings
Remove your saved API keyClear it in settings
Revoke the app's access to MessagesSystem Settings → Privacy & Security → Full Disk Access
Delete everythingQuit the app, then delete ~/Library/Application Support/Sanctuary/ (and ~/Library/Application Support/tanstack_start_ts/ if it exists) and drag the app to the Trash. Nothing of yours remains, on your machine or ours.

Spam is flagged, never deleted — junk-filtered messages are marked so they stay out of your way, but the record is preserved so nothing disappears without your say-so.

Hosted web build. To delete the profiles record created by signing in there, email ravi@fulllist.ai and we will delete it within 30 days. Because the retired tables are read-only and hold only sample data, there is nothing else associated with your account to delete.

9. Your rights

Everyone. Because your library is a file on your own disk, you can exercise the substance of every data-protection right yourself and immediately: access it (open the app), export or copy it (copy the database file), correct it (edit categories and people in the app), and erase it (delete the folder). No request to us, and no waiting period, is involved.

If you are in the EU, EEA, UK, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent at any time (withdrawal does not affect processing already carried out) and the right to lodge a complaint with your national supervisory authority. Our lawful bases are set out in §6; in short: performance of the service for enrichment, your consent for cloud AI and the model download, and legitimate interests for update checks.

If you are in California, you have the rights to know, delete, correct, and to opt out of sale or sharing — the last of which is moot, because we do not sell or share personal information, and do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. We do not discriminate against anyone for exercising a right. We honor Global Privacy Control signals on our websites. Categories of personal information collected in the last 12 months, for the hosted web build only: identifiers (email, name, avatar URL) and internet activity (search queries), collected from you, used to operate the demo, disclosed only to our hosting and embedding providers for that purpose.

Other US state privacy laws (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others) grant comparable rights; we extend the rights above to all users regardless of residence.

To exercise a right, email ravi@fulllist.ai. We respond within 30 days (45 where an extension is permitted). Because we hold almost nothing, most requests are answered by pointing you to the local control that does what you want — we will say so plainly rather than open a ticket. We verify requests by confirming control of the email address on the account; where we hold no record of you at all, we will tell you that instead of demanding identification we do not need. You may use an authorized agent, with written permission.

Do Not Track. Browsers send inconsistent DNT signals and there is no agreed standard, so we do not respond to DNT specifically. It makes no practical difference here: we run no cross-site tracking to disable.

10. Payments, subscriptions, and cancellation

Sanctuary is sold as a subscription on the website — US$29 a month or US$275 a year, after a fourteen-day trial that needs no card (§4.21) — and the payment is handled by Stripe, a PCI-compliant processor, on Stripe's own checkout page. Card numbers, billing addresses and other financial details go to Stripe and never touch our systems; the app itself contains no payment code and never asks for payment information.

We hold no record of the purchase on our side. The download page's address carries the checkout's identifier (also kept in your browser), and each visit asks Stripe whether that subscription is active. Stripe holds the customer record, payment history, receipts and renewal dates and shows them to you in its billing portal, reachable from the download page.

In line with the FTC's Negative Option Rule and state auto-renewal laws:

11. Children

Sanctuary is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal information from children. Because the desktop app collects nothing about anyone, the practical scope of this is the hosted web build's sign-in; if we learn that we hold information from a child under 13 (or under 16 in the EEA/UK), we will delete it promptly. Note that a Mac's Messages history may contain messages from minors — that data stays on your device under your control, and we never receive it.

12. International transfers

Superscore AI, Inc. is a United States company, and any information we hold is processed in the United States.

For desktop users there is no transfer at all — your library does not leave your machine, so there is nothing to transfer to any country.

Two narrow paths do involve US processing: the hosted web demo, and optional cloud AI if you turn it on. Both run on third-party infrastructure whose own published transfer terms and supplementary measures apply — for the AI path, enclave-based inference with no logging. We are a small company in beta and have not negotiated bespoke transfer agreements of our own; if the legal basis for a transfer matters to you, write to us at ravi@fulllist.ai before enabling cloud AI or signing in to the web demo, and we will tell you exactly what is in place.

13. Accessibility of this policy

We aim to keep this policy readable. Where a plain-language summary in §0 and the detailed text below could be read differently, the detailed text governs, but tell us — if the summary misleads, the summary is the thing that is wrong.

14. Changes to this policy

We will post any revision here with an updated version and date, and keep prior versions available in the project's public git history so changes are diffable rather than announced.

For any change that materially expands what leaves your device — a new recipient, a wider AI payload, telemetry of any kind, or a new category of collection — we will give notice in the app before the change takes effect, and where the change relies on your consent, we will ask for it rather than assume it from continued use. Silence is not consent to a materially different policy.

15. Contact

ravi@fulllist.ai

Superscore AI, Inc., a Delaware corporation 651 N Broad St, Suite 201 Middletown, DE 19709 United States

[If a EU/UK representative or DPO is required, name them here.]

Appendix A — where each claim is enforced

This product's privacy properties are enforced in code, and this table exists so a technically inclined reader can verify them rather than take our word.

ClaimWhere
Messages/Contacts are read strictly read-onlyelectron/services/chatdb.cjs, contacts.cjs
The outbound AI payload has exactly one definitionqueries.enrichmentContextOf() in electron/services/queries.cjs
Excerpts are capped at 280 characterssame function
Contact names, emails, and phone numbers are stripped from excerptselectron/services/redact.cjs
Cloud AI is off by default in packaged buildscloudAiEnabled() in electron/services/cloud-ai.cjs
No API key ships in the bundlescripts/secret-guard.mjs, which fails packaging and signing
Website analytics never run inside the appsiteAnalyticsEnabled() in src/lib/site-analytics.ts — requires the public hostname and no desktop bridge
Your key is encrypted via the macOS KeychaincloudAiKey() / decryptKey() in cloud-ai.cjs
Nyne receives one identifier per chosen person; salary, gender, birthday, address, emails, phones never storedidentifiersFor() / mapResult() in electron/services/nyne.cjs, pinned by nyne.test.cjs
Desktop search runs locally, sending no query anywheresrc/hooks/use-semantic-results.ts
The desktop app does not call the hosted backendisDesktop() in src/lib/desktop.ts
Diagnostics contain counts and dates onlyelectron/services/diagnostics.cjs
"Add to Calendar" uses a local file, not a calendar accountelectron/services/calendar.cjs
Personal rows were deleted from the hosted databasesupabase/migrations/20260815120000_retire_web_plane_personal_data.sql
Logs are local, rotated, and never transmittedelectron/services/log.cjs
Fonts are bundled, so no request goes to Googlesrc/fonts.css, public/fonts/, scripts/fetch-fonts.mjs
Message scanning is off by default and separately gatedmessageScanEnabled() in electron/services/cloud-ai.cjs; checked in maybeExtractCommitments() and revalidateCommitments() in commitments.cjs
Task context windows synced to the phone are capped and consent-gatedcommitmentChatMeta() in electron/services/mobile-export.cjs
The "test as new user" profile can never publish to iCloudpublishSnapshot() in electron/services/mobile-export.cjs
Web search runs only with a key you entered, and its payload is topic names, title keywords, or a project's name/brief/link titlesKEY_STATE and the request body in electron/services/feed.cjs and digest-suggest.cjs
The MCP server's link tools never carry message text; message-derived tools answer only while the switch is onshapeLink() and contextToolHandler() / shareEnabled() in scripts/mcp-server.mjs; the mcp tier on each tool in electron/services/chat-tools.cjs
Agents only write suggestions; accepting one runs a bounded local actionpropose() and resolveSuggestion() in electron/services/agents.cjs — the only writers
Agents inherit consent gates: drafts need cloud AI (and exist only under message scanning), research needs your Parallel key, the weekly digest is off by defaultrunFollowUp(), runProjectResearch(), runDigestAutopilot() and AGENTS[...].defaultOn in agents.cjs
The calendar is read read-only and attendee email addresses never leave the readerreadEvents() in electron/services/calendar-read.cjs
Calendar rows reach cloud Ask and connected apps only through the events tool's context tierevents in electron/services/chat-tools.cjs
The LinkedIn capture endpoint listens on 127.0.0.1 only, is off by default, and needs a Keychain-held tokenelectron/services/ingest-server.cjs; every capture validated by linkedin-payload.cjs
Turning LinkedIn messages off deletes thempurge() in electron/services/linkedin.cjs
Build mode runs only in folders you granted (or worktrees it made of them), read-only by default, with no shell beyond the project's checkselectron/services/claude-code.cjs, codex-cli.cjs, build-worktrees.cjs
Commit and push runs a fixed git sequence on files you picked, never a shell, never a force pushelectron/services/repo-git.cjs
Wiki person pages go to the cloud only with message scanning on; project and topic pages then carry no nameswikiLane() (namesAllowed) and candidates() / projectFacts() / topicFacts() in electron/services/wiki.cjs
Wiki prose must cite a fact and passes the never-inferred filter; exports carry no message excerptsgroundParagraphs() and pageMarkdown() in electron/services/wiki.cjs, pinned by wiki.test.cjs
This policy is published from this exact filesrc/routes/privacy.tsx