Privacy Policy — Sanctuary
Version 1.18 · Effective 1 October 2026 · Versions 1.0 (20 Aug 2026), 1.1 (25 Aug 2026), 1.2 (3 Sep 2026), 1.3 (4 Sep 2026), 1.4 (4 Sep 2026), 1.5 (5 Sep 2026), 1.6 (8 Sep 2026), 1.7 (8 Sep 2026), 1.8 (9 Sep 2026), 1.9 (10 Sep 2026), 1.10 (12 Sep 2026), 1.11 (16 Sep 2026), 1.12 (28 Sep 2026), 1.13 (28 Sep 2026), 1.14 (29 Sep 2026), 1.15 (30 Sep 2026), 1.16 (30 Sep 2026) and 1.17 (30 Sep 2026) in git history
0. The short version
Sanctuary is a macOS app that reads your Messages history on your Mac and builds a searchable library of the links inside it. The library file lives on your disk. We do not have a copy of it, cannot request one, and have not built the infrastructure to receive one.
| Question | Answer |
|---|---|
| Do you upload my messages or contacts? | No. They are read on-device and written to a local database only. Two opt-in features send bounded pieces to an AI enclave on your own key — see §5.3 and §5.6. |
| Do you collect analytics or telemetry? | Not from the app. Usage counters exist but stay on your Mac and are never transmitted. Our public website, linksanctuary.com, uses cookieless page analytics — see §4.6. |
| Do you sell or share my personal information? | No. Never have, and we commit to notice before that could change. |
| Does the app use AI? | Yes — see §5. By default a model that runs on your Mac. |
| Does anything leave my Mac? | Yes, a limited set — see §4. Mostly the websites you already have links to, plus sync to your own iPhone through your own iCloud (§4.9) and, only if you set up the Feed, short search queries to a web-search API on your own key — topic words, interest words, place names and your own search terms, never names or messages (§4.10). If you add your own Nyne key, one identifier per person you choose to look up (§4.13). If you use Build mode, your own Claude Code or Codex sends your requests and the code in the folder you chose to its own provider (§4.20). |
| Can I delete everything? | Yes — see §8. Deleting one folder removes the entire library. |
| Do you charge money? | Yes — US$29 a month or US$275 a year, after a 14-day trial that needs no card. Stripe takes the payment on its own page; your card never reaches us, and the app contains no payment code. See §10. |
We describe below not only what we do, but where in the source code each claim is enforced, so the claims can be checked rather than trusted (Appendix A).
1. Who we are and what this covers
Sanctuary is a product of Superscore AI, Inc. ("Superscore AI", "we", "us"). Where this policy says "we", it means that company.
Controller / publisher: Superscore AI, Inc., a Delaware corporation, 651 N Broad St, Suite 201, Middletown, DE 19709, United States. Contact: ravi@fulllist.ai.
This policy covers:
- the Sanctuary macOS desktop application ("the app"), distributed as a signed, notarized build;
- linksanctuary.com, the marketing website;
- the hosted web build at klipped.lovable.app, a read-only demonstration containing seeded sample data only.
It does not cover third-party websites you open from your library, the operating system's own handling of Messages and Contacts, or any AI provider you choose to configure with your own account.
A note on roles. For the data the app reads from your Mac, you are the party deciding what is processed and why; we never receive it, so we cannot access, disclose, or produce it — including in response to a subpoena or law-enforcement request, because we hold nothing to produce. For the limited web-build account data described in §4.6, we act as the controller in the sense of the GDPR and as a "business" in the sense of the CCPA/CPRA.
2. What the app reads on your Mac
To do its job, the app reads the following from your machine. Granting Full Disk Access in System Settings is what makes this possible; macOS asks you for it explicitly and you can revoke it at any time.
| Source | What is read | Why |
|---|---|---|
~/Library/Messages/chat.db | Message text, timestamps, sender/recipient handles, conversation identifiers, the URLs inside messages, and the "filtered/junk" flag | To find links and reconstruct the conversation around each one |
| macOS Contacts (AddressBook) | Names, phone numbers, email addresses | To turn handles like +1555… into the person who actually sent the link |
Apple Mail's index on this Mac (~/Library/Mail, its Envelope Index) | Sender, subject, date, read and flagged state, mailing-list id and Mail's one-line preview of each message — not a connection to your mail provider | So threads waiting on you show up beside your messages, and Ask can find an email; read-only, never uploaded |
The Mac's own Calendar (Calendar.sqlitedb) (§4.18) | Event titles, times, calendar names, locations, and attendees — kept as a name and, for a work address, the organisation, never the email address | So Today shows your day and Ask can answer "when am I seeing her"; read-only, nothing stored |
| LinkedIn messages you capture — only if you turn it on (§4.19) | The messages in a capture you hand to the app: who, when, and what was said | So a LinkedIn conversation counts like any other; turning it off deletes them |
| A ChatGPT or Claude export — only if you import one | The conversations in the export file you choose | So Ask can find something you worked out with an assistant; read from the file, never a login |
| Code folders you open in Build mode (§4.20) | The Markdown files in a folder you choose through the macOS file picker, and — when you ask it to — whatever your own coding agent reads there | So a project's own notes and roadmap sit in the app, and so you can work on it; nothing outside that folder |
| Pages you have links to | Title, description, author, publication date, favicon, and structured event data | To make each link recognizable instead of a bare URL |
The link previews inside Messages (payload_data) | The title, summary, site name and preview image Messages itself rendered for a link you were sent | So an Instagram, Facebook or Reddit link shows what it is instead of the site's name — with no visit to the site |
| Safari, Chrome and Arc history — only if you turn it on (§4.12) | Pages you visited and searches you made, with dates; copied from the browsers' own files | To answer "what was I researching", to show which links people sent you actually opened, and to seed the Feed; turning it off deletes everything it stored |
| Your Instagram data export — only if you turn it on (§4.14) | The saved posts in a file you downloaded yourself: link, caption, poster's handle, hashtags, save date, your collection names | To put what you bookmarked next to what people sent you; never a login, never a request to Instagram; turning it off deletes them |
| WhatsApp's own store on this Mac — only if you turn it on (§4.15) | Message text, timestamps, sender and group ids, chat names and WhatsApp's own link-preview titles, from ChatStorage.sqlite in the WhatsApp app's container | So links people sent you on WhatsApp sit beside the ones from Messages, with who sent them; read-only, never uploaded; turning it off deletes them |
| Your Obsidian vault — only if you turn it on (§4.16) | The Markdown notes in the folder you choose: title, body, tags, links between notes, and the links inside them | So your own notes and the links in them sit beside what people sent you; read from the folder on this Mac, never uploaded, never shared with connected chat apps; turning it off deletes them |
| Your Notion export — only if you turn it on (§4.16) | The pages in a Markdown & CSV export you download yourself: title, properties, body, links between pages, and the links inside them | Same as your vault: read from the file on this Mac, never a login, never a request to Notion; turning it off deletes them |
These reads are strictly read-only. The app never writes to, modifies, locks, or deletes your Messages database, your Contacts, or your browsers' history files.
Faces. A person's photo comes from your own Contacts card for them, and otherwise from the photo they chose to share with you through Messages' Name and Photo Sharing, which Messages keeps in its own cache on this Mac. Both are read from the Mac, shown inside Sanctuary, and never uploaded or sent to any connected app. Photos a sender marked sensitive are never shown.
What is derived and stored locally: a link record (original and canonical URL, domain, platform), who shared it and in which conversation, when, the message that carried it plus a short window of surrounding messages, an AI-generated category and summary, a person graph, your projects, favorites, archive and spam flags, and search indexes.
Where it is stored: ~/Library/Application Support/Sanctuary/ (on Macs that ran an early build, ~/Library/Application Support/tanstack_start_ts/) — principally link-library.db, alongside local log files and, if you download it, the on-device AI model.
3. What we do _not_ do
We consider these commitments, not current defaults, and we will not change them silently (see §14):
- No telemetry. The app sends no usage, crash, or diagnostic data on its own initiative. There is no analytics SDK, no tracking pixel, no session recorder, no error-reporting service in the desktop app. (Our marketing website is a separate thing and does use page analytics — see §4.6. That code is disabled whenever it finds itself running inside the app.)
- No advertising, and no profiling for advertising. We do not run ads, embed ad networks, or build advertising profiles.
- No sale or sharing of personal information, as those terms are defined by the CCPA/CPRA and comparable state laws — including no "sharing" for cross-context behavioral advertising. We have not done so in the preceding 12 months.
- No training on your data. Nothing from your library is used to train, fine-tune, or evaluate any model of ours, and the optional cloud provider described in §5.2 represents that it does not train on or log inference inputs.
- No background upload of your library, in whole or in part, to us or anyone else.
- No account required to use the desktop app. There is no sign-in, no server-side profile, and no per-user records held by us.
We also keep usage counters — how many distinct days you have opened the app, how many searches you have run. These are written to your local database and are never transmitted. They exist so that if you choose to send us feedback, you can include them yourself (see §4.8).
4. What leaves your device
This is the complete list. Each item states what is sent, to whom, when, and whether you control it.
4.1 Requests to the websites you have links to
When the app enriches a link, it fetches that page directly from the site that hosts it, and requests the site's favicon. This is an ordinary web request from your Mac, so the destination website — and any CDN or analytics it runs — can see your IP address, the request headers your system sends, and the fact that the URL was fetched at that time.
- This is the single largest privacy consideration in the app and it is unavoidable for a product that describes what a link contains, so we state it plainly rather than bury it.
- We do not proxy these requests through our own servers, which means we do not see them either — the trade-off is that the destination site sees your IP instead of ours.
- If a page is behind a login or blocks the request, the link is simply left un-enriched.
- When a site offers no usable icon (some sites block these requests entirely), the app asks Google's public favicon service for that site's icon, once per site, at the same enrichment moment. Google receives the site's domain name only — never the full link, the message it came from, or who shared it — and the returned icon is stored locally like any other.
- Consider a VPN if the fact of a fetch is itself sensitive to you.
4.2 Update checks
The app periodically checks a public GitHub release manifest to see whether a newer version exists, and downloads the update if you accept it. GitHub therefore receives your IP address and the timing of the check as part of serving that file. No identifier of you or your library is attached.
4.3 Downloading the on-device AI model
If you choose to use on-device AI, the app downloads a model file (~2.5 GB) from Hugging Face. Hugging Face receives your IP address and which file was requested. This happens once, only when you start the download.
4.4 Cloud AI — off by default, opt-in, your own key
Packaged builds ship with cloud AI disabled and with no API key of any kind; our build tooling fails the release if a credential is found in the bundle. If — and only if — you turn cloud AI on and paste in your own provider API key, the app may send the payload described in §5.2 to that provider. Turning the setting off stops it immediately.
With cloud AI on, the Ask chat sends a second, distinct payload (DEC-014): the conversation you type into Ask, the results of the library tools the model calls while answering (shaped like the Ask payload — titles, domains, summaries; contact names and message-derived text only if you also enable message scanning), and — only when you choose to continue an imported ChatGPT/Claude conversation — a tail of that transcript. Chats are stored only on your Mac (local SQLite); an incognito chat is never written at all. With cloud AI off, Ask chat runs entirely on the local model and nothing leaves.
4.5 Web fonts — nothing is sent
The interface uses the IBM Plex typefaces, and they ship inside the app. Earlier versions loaded them from Google Fonts, which meant the desktop app contacted Google on every launch and disclosed your IP address for no product reason. That request is gone: the fonts are bundled (public/fonts/, src/fonts.css), so the interface renders offline and Google is not involved.
We mention a request we no longer make because the honest version of "nothing leaves your device" is a list of the things that used to.
4.6 Hosted web build and website
Website analytics. Our public website, linksanctuary.com, uses PostHog to count page views and clicks on the download button and the demo video. It runs cookieless: nothing is stored in your browser, there is no session recording, no cross-site tracking, and we do not identify visitors. PostHog receives your IP address with each request, as any web server does; the project is configured to discard it on receipt. Each event carries the page your visit landed on and the name of the site that sent you there (its hostname only, never the full address); both are kept in the page's memory for that visit and never stored. The website also loads Google Analytics for page views, which sets its own cookies and receives your IP address under Google's terms; a content blocker that blocks posthog.com and googletagmanager.com stops both and the site works identically. The same code ships inside the desktop app's bundle but does nothing there — it checks for the app environment and the site's hostname first — so the app itself still sends no analytics (§3).
Payments. Sanctuary is sold as a subscription on the website. There is no account to create: payment is taken by Stripe on Stripe's own checkout page, and your card number never reaches us. After paying, Stripe sends you to a download page whose address carries the checkout's identifier; that page asks Stripe whether the subscription is active and, if so, shows the download. We keep no record of the purchase ourselves — the identifier is stored in your browser so the page can find it again, and Stripe holds the customer, subscription, receipts and renewal dates. Stripe receives your email address and name for the receipt and renewal reminders it sends on our behalf, and processes your payment details under its own privacy policy. You can change or cancel the plan from the same download page; canceling stops the charges and, when the paid period ends, the download — it deletes nothing on your Mac. If you lose the download page, you can ask for it by email on the pricing page: we look the address up in Stripe and, if it has an active subscription, email the link to that address and nothing else; the request itself is not stored.
The demonstration build at klipped.lovable.app is a different thing from the app and holds no personal library. If you sign in there:
- Google sign-in returns your email address, display name, and avatar URL, which are stored in a
profilesrecord along with a plan flag. This is the only server-side personal record we hold about anyone; the subscription (above) is not linked to it. - Search queries typed into the hosted build are sent to a third-party embedding model to compute a vector, and to our hosted database to match against the sample data. Desktop search does not do this — it runs entirely on your Mac. Disclosure about the retired dataset. An earlier version of this product stored a personal Messages import in a hosted database whose access rules were, by misconfiguration, world-readable and world-writable. On 15 August 2026 we deleted every personal row, revoked all write access, and made the remaining tables read-only. What is left is seeded sample content, which is public by design and contains no user data. Do not treat the hosted build as private storage; it is a demo. We tell you this because a policy that omitted it would be less honest than the code, which records it.
4.7 Personal data archives you import (LinkedIn)
You can import your own LinkedIn data export (the ZIP LinkedIn lets you download) to add roles, companies, locations, and profile links to your People cards. The archive is read in memory on your Mac and never uploaded; nothing is extracted to disk, no request is made to LinkedIn or anyone else during the import, and Sanctuary never queries or scrapes LinkedIn. Only the parsed fields Sanctuary uses are stored, each tagged with its source and import date, and matching against people you already have is deliberately conservative (a name alone never merges two records). Settings → Data sources → LinkedIn → Remove imported data deletes every LinkedIn-sourced fact and the people that import alone created, leaving the rest of your library untouched.
4.8 Diagnostics you choose to send
The app can assemble a plain-text diagnostic report — counts and dates only: no message content, no URLs, no contact names, no keys. It is copied to your clipboard for you to read and send yourself. Nothing is transmitted automatically, and there is no channel for us to request it.
4.9 Sync to your iPhone — through your own iCloud
If you install the Sanctuary iOS app, your library syncs between your Mac and iPhone through your own iCloud Drive (the app's private iCloud container). What rides that channel: your links, the contacts-resolved people who shared them, projects, one excerpt of at most 280 characters per share, and — only if message scanning (§5.6) is on — your extracted tasks, each with a capped window of a few surrounding messages so the task is checkable on the phone.
Three things to be clear about: the data moves under your Apple ID, encrypted and stored by Apple under your iCloud terms; we operate no sync server and cannot read any of it; and full conversations never sync — the phone receives excerpts and task context windows, not your message history. Captures and dismissals made on the phone travel back the same way.
Moving to a new Mac is a bundle, not a sync: Profile → Move to a new Mac writes a copy of your library and a manifest into a folder on this Mac, and you carry that folder yourself. Nothing about it goes through iCloud or any server; restoring it on another Mac replaces that Mac's library and keeps the previous one beside it.
What the phone reads since 2026-09-19. The snapshot also carries: which app each link arrived from (Messages, WhatsApp, Mail, notes, LinkedIn, AI chats, Instagram) as a label, never the conversation; the composed Person card as the Mac shows it (a bio sentence or two, role, company, city, interests, what you share, what's recent and what's coming) for people the Mac has context on; the subject line and a short excerpt of Apple Mail threads waiting on you, so the phone's open loops match the Mac's; open page and loop proposals from the Mac's agents (title and a one-line reason, read-only); and pinned pages with their rows and cells. All of it is derived from records this policy already covers, stays inside your own iCloud container, and is replaced wholesale on the next sync. Marking a mail thread done on the phone updates the Mac's Mail status the same way the Mac's own Today does.
4.10 Feed and suggested links — web search on your own key
The Feed page, the "Add suggested links" option when generating a digest, and the project researcher agent (§5.7) find new pages for you with a web-search API, Parallel (api.parallel.ai). This is off until you paste your own Parallel key on the Feed page; the key is stored in your local library and never leaves your Mac except in the request header to Parallel itself.
What a request contains: a one-sentence objective and a handful of short search queries. Those are built from your topic names and keywords taken from titles of links you saved, or — for a digest or the project researcher — a project's name, your written brief, and recent link titles. What a request never contains: message text, names or handles of your contacts, the URLs of your saved links, or anything from a Person card. Parallel receives your IP address with the request, as any web service does, and returns page results; Sanctuary stores those results locally as feed items you can mark or dismiss.
Intent seeds (added 2026-09-05). Besides your library's topics, the Feed now searches for what Sanctuary can see you are about to need: a search you repeated over several days and never saved (browser history, only if that source is on), a gift for a birthday or anniversary in the next month, a trip with a place and a date ahead, an active project, or something a friend recommended that you never acted on. Those seeds are derived from your messages and history, so this is a wider use of the web-search exit than "topic names": each query carries interest words, place names, project words or your own search terms — never a person's name, a date, or message text. A guard drops any query containing a contact's name before it is sent, and the reason shown next to each item ("Nish's birthday is March 20 · cars, music production") stays on your Mac.
Pages and briefs with "Include the web" (added 2026-09-15). A page or brief searches the web only when you switch "Include the web" on for that page. The query is then the words of your own prompt for that page ("consumer AI investors in Chicago") — never message text, never a Person card, and the same guard drops the query entirely if it contains a contact's name or anything identifier-shaped, so nothing is sent. Results appear as rows or citations marked "from the web" with their URL; they are never merged with a person. Connected chat apps (§4.11) cannot reach this search. Turn the switch off and the next refresh uses your library alone.
4.11 Connected chat apps (MCP)
Sanctuary ships an MCP server so an assistant you already use — Claude Desktop or Claude Code, or an agent runtime such as OpenClaw or Hermes — can ask your library questions. You connect it yourself (a button in Profile → Connected chat apps writes Claude Desktop's or OpenClaw's config entry; Claude Code takes one command; for Hermes the app shows a snippet for you to paste); nothing is connected by default, and there is no sign-in: the assistant launches Sanctuary's server on your Mac. Agent runtimes can run unattended, so be deliberate about the two switches below when you connect one. ChatGPT's connectors only accept hosted servers, so ChatGPT is not supported. Its five link tools return titles, URLs, domains, categories, summaries, event dates, sender names, dates and counts, and never message text, conversation context, handles or phone numbers. That contract is pinned by tests and has not changed. The same server offers three prompts (recipes the assistant runs over these tools — "catch me up on", "before a meeting", "this week") and a few attachable resources: your recent links and a count of how far back each source goes, always; a person's card, your saved digests and your context pack only behind the switch below, through the same tools it gates. The context pack is six short files an assistant can read about you — who you are, key people, current projects, decisions, how you write, and your own goals and rules — generated from the library and dated; the "how you write" file carries lines from your own messages only behind the second (excerpts) switch, and the goals-and-rules file is the one you type yourself. Prompts and resources add no data the tools don't already return. You can also export the same six files as markdown from Profile → Context pack; from then on they are ordinary files on your Mac, outside Sanctuary's control.
A separate switch, Profile → Connected chat apps → Share what Sanctuary learned from messages, off by default, additionally exposes the app's own Ask tools: a person's card (relationship, preferences, interests, what they recommended, open loops between you), what people recommended, your open loops and mail loops, the working set, project context, message search, mail search (Apple Mail on your Mac: subject, sender name and domain, date, mailbox — never an address, never a body), the latest exchange with one person (when, who spoke last, how often you talk), people ranked by how often you talk (most active, gone quiet, tied to a city — names and dates only), and the context around one saved link (who shared it, when, in which chat, what it is filed under). Message search through a connected app answers who you talked to about something and when; the words of the messages themselves — and, for mail, Mail's one-line preview, and for the latest exchange and link context, the lines around them — are withheld unless you also turn on the second switch, "Also share the words of messages", which is off by default. Be clear about what the switches mean: those answers go to the connected app's model provider (Anthropic, OpenAI), not to the private enclave that runs the app's own AI, and that provider's terms apply. The switch is read on every call, so turning it off takes effect immediately. Connected apps can only read; no tool sends, posts, or changes anything.
4.12 Browser history — read here, kept here
Off by default. If you turn it on in Profile → Data sources, Sanctuary copies your Safari, Chrome and Arc history files on this Mac and reads new visits into its own local table: the page, its title, the search terms when the page was a search, and when. Nothing about it leaves the Mac: it is not part of any AI payload, and connected chat apps (§4.11) can never see it. It answers "what was I researching last week" and "did I ever open the link she sent" inside Ask. Turning the switch off deletes every stored visit immediately.
4.13 Work profiles from Nyne — on your own credits
Off unless you add your own Nyne API key and secret in Profile → Data sources, and even then nothing runs on its own: you enrich one person from their card, or press "Enrich next N" for the people you talk to most. For each person you choose, exactly one identifier leaves your Mac — their LinkedIn URL if the card has one, else an email address, else a phone number — together with the name on the card (kin words and emoji stripped). That goes to api.nyne.ai under Nyne's terms, and costs Nyne credits (6 per matched person; a person Nyne can't match costs nothing).
What comes back is filtered before anything is stored: the current company and title, a headline, location, schools, and the LinkedIn URL land as profile claims with nyne provenance (ranked below a LinkedIn export and your own edits), and the skills on their public profile as one "Skills" line under the card's details — never as interests, which come only from what the person said. Bulk enrichment only offers people who have no work profile on file. Nyne also returns things Sanctuary refuses to keep — salary estimates, gender, birthday, home address, personal emails, phone numbers, photos and a "possible matches" list — those are discarded in memory and never written. A person is not re-enriched within 90 days. Everything Nyne added can be removed like any other claim or chip.
4.14 Instagram Saved — your own export, read here, kept here
Off by default, and not a connection to Instagram. If you turn it on in Profile → Data sources, Sanctuary reads the Saved section of the data export _you_ download from Instagram ("Download your information"): each saved post's link, its caption, who posted it, the hashtags, when you saved it, and the names of your own collections. The archive is read in memory on your Mac and never uploaded; nothing is extracted to disk. Sanctuary never signs in to Instagram, never uses your Instagram session or password, and never makes a request to Instagram during the import — it reads a file you already have.
Saved posts then live in your library like any other link, under a "Saved on Instagram" source with no person attached — the account that posted something is never turned into a contact. The caption is stored as the link's title and description, which means the one thing that leaves the Mac for a saved post is the same as for every other link (§5.3): the link and its stored title and description, to the enclave on your key, so it can be filed under a topic. The Feed never builds a search from a saved post's caption or from the poster's handle. Turning the switch off deletes every saved post immediately, along with the library rows they became — unless someone also sent you the same link in Messages, in which case that copy stays.
4.15 WhatsApp — read here, kept here
Off by default. If you turn it on in Profile → Data sources, Sanctuary reads the history the WhatsApp app itself keeps on this Mac (its ChatStorage.sqlite, covered by the same Full Disk Access grant as Messages) the way it reads Messages: read-only, never writing to or locking the file, and only while the app is linked to your phone. Message text stays in Sanctuary's local database so Ask can search it; links people sent you land in the library with who sent them and the lines around them. People are matched by phone number through your Contacts; WhatsApp's newer anonymous sender ids are kept as a display name only and never become a person on their own. Nothing about it leaves the Mac except what §4.1 already describes for any link. Photos and documents the WhatsApp app has already downloaded to this Mac are read the way iMessage attachments are — text recognized on this Mac, never uploaded. Turning the switch off deletes every WhatsApp line, link and file record immediately, keeping a link only if someone also sent it to you elsewhere.
4.16 Your notes (Obsidian, Notion) — read here, kept here
Off by default, one switch per source. If you turn Obsidian on in Profile → Data sources and choose your vault, Sanctuary reads the Markdown files in that folder — and only that folder — into its own local table; if you turn Notion on and pick the Markdown & CSV export you downloaded from Notion, it reads the pages in that file the same way (never a connection to Notion): each note's title, body, tags, links to other notes, and the web links inside it. Nothing is watched or synced; you choose when it reads again. Notes are your own writing, so Ask can search them, but a connected chat app (§4.11) never sees them. A link found in a note enters the same classification step as any other link (§4.1), with the few words around it from the note — never the whole note. Turning the switch off deletes every note and every link that only a note carried.
4.17 Map images — drawn by Apple's MapKit
The Places page shows a small map for each city and each place. Those images are drawn on your Mac by Apple's MapKit (the phone draws its map thumbnails the same way), which fetches map tiles from Apple's map servers exactly as the Maps app does. What Apple sees is the coordinates being drawn — never the place's name, who recommended it, or any message. The images are cached on your Mac and never re-requested for the same place. No other map service is used.
4.18 Your calendar — read here, from the Mac's own copy
macOS already keeps a copy of every calendar you have added to it (iCloud, Google, Workspace, Exchange) in a database on this Mac. Sanctuary reads that copy the way it reads Messages: read-only, covered by the same Full Disk Access grant, never writing to it, and with no connection to Google, Apple or any calendar service — there is no calendar sign-in and no calendar key. It stores nothing of its own: each time Today or Ask needs your schedule, it reads the file again.
What is read: each event's title, start and end time, calendar name, location, whether it is an online meeting, and its attendees. An attendee is kept only as a name and, when their address is a work address, the organisation in it (sam@example.co becomes "example.co"); the email address itself is used on this Mac to recognise people you already know and is then dropped. Attendees can include people you have never messaged.
Where it goes: Today's schedule and "Coming up", on this Mac. Ask can also look at your calendar while answering, and what it finds is then treated like any other Ask tool result — so if you have turned cloud AI on (§4.4), those calendar rows (title, time, calendar name, attendee names and organisations, location) are part of what Ask sends to the enclave, and if you have turned on "Share what Sanctuary learned from messages" for connected chat apps (§4.11), a connected app can read them too. With both of those off, your calendar never leaves the Mac. There is no separate switch: like Mail, your calendar is part of what Full Disk Access lets the app read, and it stores nothing to delete. Revoking Full Disk Access stops the read.
4.19 LinkedIn messages you capture — and the local door they can come in by
Off by default, and not a connection to LinkedIn: Sanctuary never signs in to LinkedIn, never uses your LinkedIn session, and never makes a request to LinkedIn. If you turn it on in Profile → Data sources, you can hand the app LinkedIn conversations you have captured yourself — for example, with an AI assistant working in your own browser — and it files each message under the person it is with, like a WhatsApp line. A capture arrives in one of three ways, all on this Mac: a command you run, a file you drop into a folder inside Sanctuary's own data folder, or a local endpoint.
The local endpoint is a separate switch, off by default. When it is on, the app listens on 127.0.0.1 — your own Mac only; nothing on your network or the internet can reach it — for one kind of request: a LinkedIn capture, accompanied by a secret token the app generates, stores encrypted in your Keychain, and shows you in Settings. It serves nothing back, has no other purpose, and stops listening the moment you turn it off. Anyone holding the token can add messages to your library, so treat it like a password; you can replace it from the same screen.
Every capture is checked field by field and stored as plain text: nothing in it is opened, fetched, run, or shown as a web page. The messages then behave like other messages (they can appear in Ask answers, open loops and Person cards, and leave the Mac only through the paths in §4.4 and §4.11). Turning the source off deletes every captured LinkedIn message; people it introduced stay, since you may have written about them since.
4.20 Build mode — your own coding agent, in a folder you choose
Build mode is for people who work on code. It appears only when a coding assistant it can drive is available, and it works only in folders you have picked through the macOS file picker — never a path the app chose for you — and in separate working copies of those folders that you ask it to make (below).
- Reading a project's notes. The Markdown files in a folder you pick are read into the app like your other notes. Nothing is uploaded.
- Asking a coding agent. When you ask something in Build mode, Sanctuary starts your own Claude Code or Codex on this Mac, in that folder, signed in with your own account for that tool. What you type, and whatever that agent reads in the folder to answer, go to that tool's provider (Anthropic for Claude Code, OpenAI for Codex) under your agreement with them — not to us, and not to the enclave in §5.2. Sanctuary adds nothing from your library to that request — unless you turn on the next item.
- Context from your library (off unless you turn it on). Settings → Build mode → "Give it context from your library" lets Claude Code, while it works, look things up in your library — people, decisions, open loops, links, who asked for something and why — through the same tools "Connected chat apps" (§4.11) offers. What it looks up goes to Anthropic under your Claude Code account, like everything else that session reads. It is a separate switch from Connected chat apps, because the recipient is different; turning it off stops the very next lookup. The words of your messages are never shared this way, and Codex never gets it. Each conversation shows, under "Why", every lookup and exactly what came back. Claude Code starts in a mode that can only read and propose; it can change files in the folder only after you switch that on for the session, and even then the only commands it can run are the project's own checks (its tests, type check and lint) and read-only git commands. Codex can only read. Each change it makes can be kept or undone from the conversation; undoing puts back exactly the text it replaced, or moves a file it created to the Trash.
- Separate working copies. If you start a conversation "in a worktree", Sanctuary asks git on this Mac to make a second working copy of your folder, on a new branch, inside the app's own data folder. It is used exactly like the folder you picked, and removed when you close that conversation (never while it holds changes you have not committed). Nothing is uploaded.
- Running your project. If you press Run, Sanctuary starts your project's own
npm run devon this Mac, in that folder, and can open the page it serves in a separate window that shows only that local address. Whatever your project's code does when it runs — including any network requests it makes — is your project's behaviour, the same as running it in a terminal. Capture saves a picture of that window on this Mac so you can attach it to your next message. - Commit and push. If you choose files and press "Commit and push", Sanctuary runs git on this Mac to commit them and push to the remote your folder is already set up with (for example GitHub). Only the files you ticked are included, and nothing is pushed unless you press that button. On the folder's main branch it asks first, and offers to move the change to a new branch.
- Ship. The Ship tab reads your open pull requests and recent CI runs from GitHub through your own GitHub CLI login, and, when you press Refresh, fetches your remote's latest branches with git. It only reads; it never merges, pushes or publishes.
4.21 License check — one identifier to our website
The app is sold as a subscription (§10). Once a day, and when you paste your license key, the app sends that key alone — the identifier of the Stripe checkout you paid with — to linksanctuary.com, our website, which asks Stripe whether the subscription is active and answers yes or no. Nothing else travels with it: no library, no names, no usage, no machine identifier. The key is stored encrypted on your Mac. If the site can't be reached, the last answer stands for two weeks; an install without a key runs for a fourteen-day trial. The code is electron/services/license.cjs; the endpoint is src/routes/api/license.ts, which keeps no record of the request.
4.22 Sanctuary in Slack — your own Slack app, answers posted to your workspace
Off until you set it up in Profile → Slack. You create a Slack app in your own workspace from a manifest the app gives you, and paste its two tokens; they are stored encrypted on your Mac. Your Mac then keeps one outbound connection open to Slack (Socket Mode). There is no Sanctuary server in between, nothing listens on your Mac, and we never see the tokens or the conversation.
- What it reads. Only direct messages sent to the Sanctuary app, and it answers only you: a six-digit code shown in the app pairs your Slack account, and anyone else who messages the app gets no reply at all. It is never added to channels and cannot read them.
- What leaves your Mac. The answer to each question you ask, posted back to your direct message with the app. That text is then stored by Slack under your workspace's retention and export settings, which your workspace's admins control and can read — on a work workspace, treat an answer the way you would treat pasting it there yourself. The question and the tool results go to the model you have chosen for Ask (§5.2), exactly as when you ask on your Mac.
- What an answer may use. One setting, What Slack answers can use, with four levels. Each level includes the ones before it. The default is the first. 1. Links only: link titles, URLs, senders, topics, dates and counts. This is the same baseline as connected chat apps (§4.11). 2. What Sanctuary learned: adds people cards, open loops, projects, mail and your calendar. 3. Message words: adds the matching lines of your messages, which an answer can quote into Slack. 4. Full Ask: everything Ask does on your Mac. That includes your browser history, notes, imported AI chats and Instagram saves, and it can add an open loop, turn skills on or off, or make a digest. At this level, anything in your library may end up in an answer posted to Slack.
Web search is never used from Slack. At Full Ask you can also type commands to list and run your skills and to accept or dismiss suggestions. Accepting a reply draft shows the draft in Slack; it is never sent.
- Build from Slack. This is a separate switch, off by default. When it is on, typed commands can:
- start Claude Code in a repo you granted in Build (read-only until you confirm edit mode in the thread);
- read the dev loop's tasks and move one to ready after its scope is shown;
- run a task, and show a task's diff;
- run a release as a dry run.
The code, diffs and run output these produce are posted to Slack. Publishing a release, committing and pushing are not possible from Slack. Anyone who can use your Slack account can use these commands, so turn the switch on only if your Slack account is secured like your Mac.
- Limits. It answers only while Sanctuary is open. Messages sent while the Mac is asleep may not be answered. Answers are capped at 200 a day. A follow-up remembers the last few turns for 30 minutes, in memory only. Slack conversations are not saved as Ask chats.
- Turning it off. Disconnect deletes both tokens, the pairing and the settings from your Mac. To remove the app from Slack as well, uninstall it at api.slack.com/apps; answers already posted stay in Slack until you or your workspace delete them.
If your Slack app has token rotation on (Slack won't let an app turn it off once it is on), its tokens expire every few hours. Sanctuary then also stores each token's refresh token and the app's Client ID and Client Secret, encrypted like the tokens, and renews them itself by calling Slack's oauth.v2.access — the only extra network call, and it goes to Slack alone.
The code is electron/services/slack.cjs and slack-tokens.cjs. Reading your own Slack conversations into the library is a separate feature with its own token and switch: §4.23.
4.23 Slack as a source — your own conversations, read into your library
Off until you connect it in Profile → Slack → Read my Slack conversations and turn reading on. It uses a second token from the same Slack app — a user token (it starts xoxp-) that Slack only issues after the app's manifest asks for read-only user scopes and you reinstall it. The token is stored encrypted on your Mac, like the bot's.
- What it reads. Your direct messages and group direct messages. Channels you are a member of are read only if you also turn on Include channels I'm in. The first pass reads the last 14 days; after that, only what is new, about every 15 minutes while Sanctuary is open. It reads Slack's names and email addresses for the people in those conversations, so a coworker can be matched to your contact card.
- What it writes. Nothing to Slack. It cannot post, react, edit, or mark anything read: the token's scopes are read-only (
*:history,*:read,users:read.email), and a test pins that. - Where the lines go. Into your library on this Mac, as imported lines, beside your WhatsApp and LinkedIn messages. From there they are treated exactly like your iMessages: open loops are extracted from them, people cards and cadence use them, and Ask can search them. Any feature that sends message text to cloud AI sends these lines too, when you have turned cloud AI on (§5); with cloud AI off, the on-device model does that work and nothing leaves your Mac.
- Your workspace's rules still apply. Slack keeps these messages under your workspace's retention settings whatever Sanctuary does. Reading them into a personal library on your own Mac may be covered by your employer's policies; check before connecting a work workspace.
- Stopping. Turning reading off stops new reads. Disconnect removes the token. Lines already read stay in your library until you delete them, as with any import.
The code is electron/services/slack-history.cjs.
5. Artificial intelligence
The app uses AI, and this section says exactly how. We disclose it here because you deserve to know when a machine-generated inference is being written into your library, and to know what text was used to produce it.
5.1 What the AI does
It assigns each link a category, writes a short summary of what the page is, and decides which of your own projects a link belongs to. It answers the questions you type into Ask (§4.4), looking things up in your library to do so. Only behind the separate switches in §5.6 and §5.7 does it read conversations to find tasks and facts about people, or draft suggestions. It does not act on your behalf, does not send messages, and does not make decisions with legal or similarly significant effects. There is no automated decision-making within the meaning of Article 22 GDPR.
5.2 Where the model runs
- On-device, by default. A ~2.5 GB model runs locally on your Mac. Nothing leaves the machine.
- Optional cloud AI. If you enable it and supply your own API key, requests go to Tinfoil (
inference.tinfoil.sh). Tinfoil represents that inference runs inside attested secure enclaves and that prompts are neither logged nor used for training; we rely on that representation and on their terms, and note that the app currently reaches the enclave over ordinary HTTPS without performing the client-side attestation check their SDK offers. You are billed by that provider, on your own account, per token.
5.3 Exactly what a link-enrichment request contains
When cloud AI is enabled, the link-enrichment payload is deliberately narrow and defined in one place in the code so it cannot drift feature by feature:
- the link's URL, canonical URL, domain, platform, and object type;
- whether you sent or received it;
- an excerpt of at most 280 characters of the message that carried the link;
- for project grouping: page title, domain, AI summary, and a short context string.
Not sent by link enrichment: names, phone numbers, email addresses, conversation history beyond that excerpt, your contact list, your other links, or any identifier of you. (Message scanning, §5.6, is a separate feature with a deliberately broader payload and its own switch — nothing described there happens under the cloud-AI setting alone.)
Before an excerpt is sent, a local redaction pass strips recognized contact names, email addresses, and phone-shaped strings. We describe this as defense in depth, not as anonymization: an excerpt is free-form text a human wrote, and no automated filter can guarantee it contains nothing identifying. The primary protection is that excerpts are only sent when the page itself yields no usable metadata, and that the whole path is off unless you turn it on.
5.4 Other people's words
An excerpt of a message may contain something another person wrote to you. Enabling cloud AI is therefore a decision that touches people who are not using this app and did not agree to anything. We have designed the default — on-device, no network — so this never happens unless you deliberately choose it. If you handle other people's messages under a professional duty of confidence (legal, medical, journalistic, or similar), we recommend leaving cloud AI off. Everything in this section applies with greater force to message scanning (§5.6), which reads conversations rather than link excerpts.
5.5 Limits you should know about
AI summaries and categories are inferences and can be wrong. They are stored in columns separate from the raw facts, so an incorrect summary never overwrites what was actually said or sent, and you can recategorize or re-run enrichment at any time. The app is not a crisis, medical, legal, or financial service, and its AI is not designed or tested to respond helpfully to messages describing distress or self-harm — it classifies links, and does not read for that purpose. If you or someone you know needs help, contact local emergency services or a crisis line (in the US and Canada, call or text 988).
5.6 Message scanning — a second, separate opt-in
Sanctuary can surface commitments, deadlines, and unanswered questions from your recent messages ("From your messages" on Home). Because this reads conversations — not just the excerpt that carried a link — it sits behind its own consent, separate from cloud AI: a labeled checkbox during onboarding, and a toggle on the Profile page afterward. It is off by default, does nothing without both cloud AI and this switch on, and turning it off stops every path described below immediately.
When it is on, and only then:
- Extraction sends recent message text to Tinfoil (the same enclave provider, on your own key), batched one conversation at a time, up to 500 characters per message, with sender names included — attribution is the point of the feature, so the redaction pass described in §5.3 does not apply to this path.
- Person context (the "Context" section of a Person card) sends recent messages from your one-to-one conversations with your most-contacted people, one person at a time and in the same bounded batches, to extract evidence-backed items about them: relationship, interests, stated preferences, places and things they recommended, current life context, dates, and shared history. Every item stores the exact messages it came from, and you can confirm, edit, mark outdated, or delete any of them. The extraction is instructed, and the app additionally filters, so that health, religion, politics, sexuality, ethnicity, immigration, and finances are never stored.
- Auditing periodically re-checks each surfaced task against the conversation, sending the task, its anchor message, and surrounding messages (including the most recent ones) so stale or superseded tasks resolve themselves.
- Reply drafting, if you ask for a draft, sends the task and the few messages around it so the suggestion fits the conversation. Drafts are suggestions in an editable field; the app never sends a message on your behalf — you always send from Messages yourself.
- What is stored: the extracted tasks live in your local library, each with a provenance excerpt; if you use the iPhone app, tasks and a capped context window sync through your own iCloud (§4.9).
Message text is processed by the enclave to answer the request and is not retained by us — we have no server in this path at all. But be clear-eyed about what the switch means: your conversations contain other people's words, and those people did not opt into anything. That is why this is the only feature in the app with two consent gates in front of it, and why the honest default is off.
5.7 Agents — suggestions, never actions
Since version 0.2.53 Sanctuary runs a small set of agents after each sync: meeting prep, follow-up drafter, project researcher, intro finder, weekly digest, and context confirmer. Each is a switch in Profile → Agents, and each only ever writes a suggestion into your local library — a prep sheet before a dated plan, a reply draft, a few new reads, people already in your graph who fit a project, a digest, or items on a Person card worth confirming. Nothing is sent, posted, or changed until you accept a suggestion, and accepting is a bounded local action: a draft is pasted into Messages for you to read and send yourself; a card item is marked confirmed; a digest opens.
Agents use only the paths this policy already describes and inherit their consent gates: the follow-up drafter uses reply drafting (§5.6) and so requires both cloud AI and message scanning to be on; the project researcher and "suggested links" use the web search in §4.10 and so require your Parallel key; the weekly digest composes with cloud AI (§4.4) and is off by default; meeting prep, intro finder and the context confirmer read your local library and make no network request at all. Docs (added 2026-09-19) gathers everything about one thing you name — a trip, a project — from your chats, mail, notes, links, places, decisions and loops, on this Mac, with no model; sharing a doc writes a standalone page or PDF to a folder you choose, containing only the sections you tick, and uploads nothing. Groups (added 2026-09-18) shows a page per group chat built the same way — who is in it, what is being planned, what was decided, the links and places that came up — recomputed from your library each time you open it, with a notes box that only you write in; nothing leaves the Mac. Suggested pages (added 2026-09-18) reads the last 45 days of your group chats on this Mac for planning words and dates — a trip, a birthday, a wedding — and proposes a page listing who is in that chat and what each of them said; it uses no model and no network, reads only what is already on this Mac, and builds nothing until you click. Agents never contact the people they mention. Notifications about a suggestion are local macOS notifications and contain only the suggestion's title.
5.8 The wiki — written pages about the people, projects and topics in your library
Since 30 September 2026 the Library can show a wiki: a written page for each person, project and topic your library knows well, where every paragraph cites numbered facts. Nothing is written until you press Build the wiki, which first tells you how many pages that is and where they will be written.
- What the model is given. Only the page's numbered facts — never message text. For a person: their name, the relationship you have confirmed or Sanctuary inferred, their job title, company, location and education where known, the items on their Person card (interests, preferences, places, recommendations, life context, dates, shared history — each a short label and one sentence), up to five open loops with them, and the titles and summaries of up to ten links shared with them. For a project: its name, the description you wrote, its link count and dates, and up to ten link titles and summaries. For a topic: the same, for links in that category.
- Where it is written. On your Mac by the on-device model, unless cloud AI is on, in which case on Tinfoil on your own key (§4.4, §5.2). Person pages on the cloud path also require message scanning (§5.6) — the switch their facts were extracted under. With cloud AI on and message scanning off, only project and topic pages are written, and the facts naming who shared each link are left out (a name can still appear where you or a page put it — a project you named after someone, a link's own title).
- What is kept. The pages, their facts and what changed at each rewrite, in your local library. The model's text passes the same filter as Person cards: a paragraph touching health, religion, politics, sexuality, ethnicity, immigration or money is dropped, as is one that cites no fact. Opening a fact's messages shows excerpts from your library on this Mac; nothing is fetched.
- Keeping it current. After your first build, Sanctuary rewrites pages whose facts changed — at most twelve pages every six hours, and none whose facts are unchanged. Stop keeping it current (the ⋯ menu) ends that; the pages stay. Marking a fact Not right marks that item outdated on the Person card, as the card itself does, and rewrites that page.
- Export. Export to a folder… writes the pages as Markdown files into a folder you choose: the written text, the cited facts, and record references (
sanctuary://claim/…) — no message excerpts. Those files are yours and outside the app; if the folder is synced (iCloud Drive, Dropbox, an Obsidian vault in the cloud) its provider receives them. Re-exporting rewrites only changed files and never deletes a file you have edited.
The wiki has no switch of its own beyond not building it: it uses cloud AI and message scanning exactly as described above, and turning either off stops the corresponding pages from being written or rewritten. Pages are deleted with your library (§8); a page whose subject no longer qualifies is removed on the next pass.
6. Third parties who may receive data
The complete list. No one else receives anything.
| Recipient | What they receive | When | Basis |
|---|---|---|---|
| Websites you have links to | Your IP address and the request | Whenever a link is enriched | Necessary to perform the service |
| Tinfoil (AI inference) | The payload in §5.3 | Only if you enable cloud AI | Your consent |
| Hugging Face | Your IP address | Only if you download the on-device model | Your consent |
| GitHub | Your IP address | Update checks and downloads | Legitimate interest in secure software delivery |
| Yahoo Finance | Ticker symbols of holdings you track (never amounts or account data) | Only if you use Net Worth | Your consent |
| Open-Meteo | The city name you configure (geocoded once), then rounded coordinates; a city named in a places question when nothing is saved under it (geocoded once, cached); the town name of a saved place whose address names a town but carries no coordinates, so "near" questions can rank it (the town name only — never the place, the sender, or the message) | Weather widget, a places question about a city with nothing saved, or a saved place with a town and no coordinates | Legitimate interest — a town name is not personal data |
| Apple Maps (MapKit, through macOS / iOS) | The coordinates of the saved places being drawn — the same request the Maps app makes to show a map; never a name, a sender or a message | Drawing the map images on the Places page (Mac) and the map thumbnails on the phone | Legitimate interest — a map of your own places, from the platform's own map service |
| Supabase / Lovable (hosting) | Web-build account data and search queries | Hosted web build only | Contract |
| Google sign-in | Your email, name, avatar URL | Hosted web build only | Your consent |
| PostHog (website analytics) | Page views, download/demo clicks, browser and country; IP discarded on receipt; no cookies | linksanctuary.com only, never the app | Legitimate interest in knowing whether the website works |
| A chat app or agent runtime you connect over MCP (Claude Desktop, Claude Code, OpenClaw, Hermes) and its model provider | Link metadata (§4.11) whenever you connect one; message-derived Ask context, including calendar rows (§4.18), only while the Profile switch is on | Only if you connect an app yourself | Your consent |
| Anthropic or OpenAI, through your own Claude Code or Codex | What you type in Build mode and what that agent reads in the folder you chose (§4.20) | Only when you use Build mode, under your own account with that provider | Your agreement with that provider |
| Your git host (e.g. GitHub) | The files you tick, as a commit, pushed to the remote your folder already uses (§4.20) | Only when you press "Commit and push" | Your instruction |
| Parallel (web search) | Your IP address and the search objective and queries in §4.10 (topic names, title keywords, a project's name and brief — never message text or contacts) | Only if you add your own Parallel key for the Feed, suggested links, or the project researcher | Your consent |
| Nyne (people data) | Your IP address and, per person you choose to enrich, one identifier (LinkedIn URL, else email, else phone) plus their name (§4.13) | Only if you add your own Nyne key and press enrich | Your consent |
We may also disclose information we actually hold — which, for desktop users, is nothing — where legally compelled, or to protect rights and safety. We will contest overbroad demands where we can, and will notify affected users unless prohibited by law.
If we are ever party to a merger, acquisition, or asset sale, any personal information we hold would transfer as an asset. We commit to giving notice before such a transfer changes how information is handled, and to honoring this policy for information collected under it.
7. Security
- The app's window runs sandboxed with context isolation on, with no direct filesystem or network access from the interface layer; every privileged operation goes through a small, validated, parameterized bridge.
- Every key you provide — cloud AI (Tinfoil), web search (Parallel), work profiles (Nyne), and any other integration — is encrypted with Electron's
safeStorage, backed by the macOS Keychain. Earlier plaintext keys are migrated to encrypted storage automatically. - The app's windows can only show Sanctuary's own pages; any web link opens in your browser, so a foreign page can never run inside the app with the app's abilities.
- A plain-language version of how we check these claims, what we found, and what we have not done yet is at linksanctuary.com/security.
- Builds are code-signed and notarized by Apple, and release checks fail if any credential or environment file is detected in the bundle.
- Your library database is protected by your macOS user account and whatever full-disk encryption (FileVault) you have enabled. The app does not add a second layer of encryption at rest, so anyone with access to your unlocked Mac or an unencrypted backup can read it. Turning on FileVault is the most effective single thing you can do to protect your library.
- No system is perfectly secure. If we become aware of a breach affecting personal information we hold, we will notify affected users and the relevant supervisory authority as required by law — under the GDPR, within 72 hours of becoming aware where the standard is met.
8. Retention and deletion
Your library is kept until you delete it. We do not impose a retention period on data we cannot see, and there is nothing on our side to expire.
You are always in control:
| To do this | Do this |
|---|---|
| Delete a single link | Delete it in the app; its project associations are removed with it |
| Clear AI results and start over | Reset enrichment from the app |
| Stop the wiki being rewritten | Library → Wiki → ⋯ → Stop keeping it current (pages are removed with the library) |
| Stop all outbound AI requests | Turn off cloud AI in settings |
| Remove your saved API key | Clear it in settings |
| Revoke the app's access to Messages | System Settings → Privacy & Security → Full Disk Access |
| Delete everything | Quit the app, then delete ~/Library/Application Support/Sanctuary/ (and ~/Library/Application Support/tanstack_start_ts/ if it exists) and drag the app to the Trash. Nothing of yours remains, on your machine or ours. |
Spam is flagged, never deleted — junk-filtered messages are marked so they stay out of your way, but the record is preserved so nothing disappears without your say-so.
Hosted web build. To delete the profiles record created by signing in there, email ravi@fulllist.ai and we will delete it within 30 days. Because the retired tables are read-only and hold only sample data, there is nothing else associated with your account to delete.
9. Your rights
Everyone. Because your library is a file on your own disk, you can exercise the substance of every data-protection right yourself and immediately: access it (open the app), export or copy it (copy the database file), correct it (edit categories and people in the app), and erase it (delete the folder). No request to us, and no waiting period, is involved.
If you are in the EU, EEA, UK, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent at any time (withdrawal does not affect processing already carried out) and the right to lodge a complaint with your national supervisory authority. Our lawful bases are set out in §6; in short: performance of the service for enrichment, your consent for cloud AI and the model download, and legitimate interests for update checks.
If you are in California, you have the rights to know, delete, correct, and to opt out of sale or sharing — the last of which is moot, because we do not sell or share personal information, and do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. We do not discriminate against anyone for exercising a right. We honor Global Privacy Control signals on our websites. Categories of personal information collected in the last 12 months, for the hosted web build only: identifiers (email, name, avatar URL) and internet activity (search queries), collected from you, used to operate the demo, disclosed only to our hosting and embedding providers for that purpose.
Other US state privacy laws (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others) grant comparable rights; we extend the rights above to all users regardless of residence.
To exercise a right, email ravi@fulllist.ai. We respond within 30 days (45 where an extension is permitted). Because we hold almost nothing, most requests are answered by pointing you to the local control that does what you want — we will say so plainly rather than open a ticket. We verify requests by confirming control of the email address on the account; where we hold no record of you at all, we will tell you that instead of demanding identification we do not need. You may use an authorized agent, with written permission.
Do Not Track. Browsers send inconsistent DNT signals and there is no agreed standard, so we do not respond to DNT specifically. It makes no practical difference here: we run no cross-site tracking to disable.
10. Payments, subscriptions, and cancellation
Sanctuary is sold as a subscription on the website — US$29 a month or US$275 a year, after a fourteen-day trial that needs no card (§4.21) — and the payment is handled by Stripe, a PCI-compliant processor, on Stripe's own checkout page. Card numbers, billing addresses and other financial details go to Stripe and never touch our systems; the app itself contains no payment code and never asks for payment information.
We hold no record of the purchase on our side. The download page's address carries the checkout's identifier (also kept in your browser), and each visit asks Stripe whether that subscription is active. Stripe holds the customer record, payment history, receipts and renewal dates and shows them to you in its billing portal, reachable from the download page.
In line with the FTC's Negative Option Rule and state auto-renewal laws:
- the price, billing interval and renewal terms are shown before you are charged, and the plan renews automatically only because you agreed to that on the checkout page;
- Stripe sends a reminder before each renewal with the amount and date, and a receipt after every charge;
- cancellation is at least as easy as signing up: one click from the download page into Stripe's billing portal, no retention flow, no email or call required. You keep access until the end of the period you have paid for;
- canceling deletes nothing — the app on your Mac and everything it built are yours (§7).
11. Children
Sanctuary is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal information from children. Because the desktop app collects nothing about anyone, the practical scope of this is the hosted web build's sign-in; if we learn that we hold information from a child under 13 (or under 16 in the EEA/UK), we will delete it promptly. Note that a Mac's Messages history may contain messages from minors — that data stays on your device under your control, and we never receive it.
12. International transfers
Superscore AI, Inc. is a United States company, and any information we hold is processed in the United States.
For desktop users there is no transfer at all — your library does not leave your machine, so there is nothing to transfer to any country.
Two narrow paths do involve US processing: the hosted web demo, and optional cloud AI if you turn it on. Both run on third-party infrastructure whose own published transfer terms and supplementary measures apply — for the AI path, enclave-based inference with no logging. We are a small company in beta and have not negotiated bespoke transfer agreements of our own; if the legal basis for a transfer matters to you, write to us at ravi@fulllist.ai before enabling cloud AI or signing in to the web demo, and we will tell you exactly what is in place.
13. Accessibility of this policy
We aim to keep this policy readable. Where a plain-language summary in §0 and the detailed text below could be read differently, the detailed text governs, but tell us — if the summary misleads, the summary is the thing that is wrong.
14. Changes to this policy
We will post any revision here with an updated version and date, and keep prior versions available in the project's public git history so changes are diffable rather than announced.
For any change that materially expands what leaves your device — a new recipient, a wider AI payload, telemetry of any kind, or a new category of collection — we will give notice in the app before the change takes effect, and where the change relies on your consent, we will ask for it rather than assume it from continued use. Silence is not consent to a materially different policy.
15. Contact
ravi@fulllist.ai
Superscore AI, Inc., a Delaware corporation 651 N Broad St, Suite 201 Middletown, DE 19709 United States
[If a EU/UK representative or DPO is required, name them here.]
Appendix A — where each claim is enforced
This product's privacy properties are enforced in code, and this table exists so a technically inclined reader can verify them rather than take our word.
| Claim | Where |
|---|---|
| Messages/Contacts are read strictly read-only | electron/services/chatdb.cjs, contacts.cjs |
| The outbound AI payload has exactly one definition | queries.enrichmentContextOf() in electron/services/queries.cjs |
| Excerpts are capped at 280 characters | same function |
| Contact names, emails, and phone numbers are stripped from excerpts | electron/services/redact.cjs |
| Cloud AI is off by default in packaged builds | cloudAiEnabled() in electron/services/cloud-ai.cjs |
| No API key ships in the bundle | scripts/secret-guard.mjs, which fails packaging and signing |
| Website analytics never run inside the app | siteAnalyticsEnabled() in src/lib/site-analytics.ts — requires the public hostname and no desktop bridge |
| Your key is encrypted via the macOS Keychain | cloudAiKey() / decryptKey() in cloud-ai.cjs |
| Nyne receives one identifier per chosen person; salary, gender, birthday, address, emails, phones never stored | identifiersFor() / mapResult() in electron/services/nyne.cjs, pinned by nyne.test.cjs |
| Desktop search runs locally, sending no query anywhere | src/hooks/use-semantic-results.ts |
| The desktop app does not call the hosted backend | isDesktop() in src/lib/desktop.ts |
| Diagnostics contain counts and dates only | electron/services/diagnostics.cjs |
| "Add to Calendar" uses a local file, not a calendar account | electron/services/calendar.cjs |
| Personal rows were deleted from the hosted database | supabase/migrations/20260815120000_retire_web_plane_personal_data.sql |
| Logs are local, rotated, and never transmitted | electron/services/log.cjs |
| Fonts are bundled, so no request goes to Google | src/fonts.css, public/fonts/, scripts/fetch-fonts.mjs |
| Message scanning is off by default and separately gated | messageScanEnabled() in electron/services/cloud-ai.cjs; checked in maybeExtractCommitments() and revalidateCommitments() in commitments.cjs |
| Task context windows synced to the phone are capped and consent-gated | commitmentChatMeta() in electron/services/mobile-export.cjs |
| The "test as new user" profile can never publish to iCloud | publishSnapshot() in electron/services/mobile-export.cjs |
| Web search runs only with a key you entered, and its payload is topic names, title keywords, or a project's name/brief/link titles | KEY_STATE and the request body in electron/services/feed.cjs and digest-suggest.cjs |
| The MCP server's link tools never carry message text; message-derived tools answer only while the switch is on | shapeLink() and contextToolHandler() / shareEnabled() in scripts/mcp-server.mjs; the mcp tier on each tool in electron/services/chat-tools.cjs |
| Agents only write suggestions; accepting one runs a bounded local action | propose() and resolveSuggestion() in electron/services/agents.cjs — the only writers |
| Agents inherit consent gates: drafts need cloud AI (and exist only under message scanning), research needs your Parallel key, the weekly digest is off by default | runFollowUp(), runProjectResearch(), runDigestAutopilot() and AGENTS[...].defaultOn in agents.cjs |
| The calendar is read read-only and attendee email addresses never leave the reader | readEvents() in electron/services/calendar-read.cjs |
Calendar rows reach cloud Ask and connected apps only through the events tool's context tier | events in electron/services/chat-tools.cjs |
| The LinkedIn capture endpoint listens on 127.0.0.1 only, is off by default, and needs a Keychain-held token | electron/services/ingest-server.cjs; every capture validated by linkedin-payload.cjs |
| Turning LinkedIn messages off deletes them | purge() in electron/services/linkedin.cjs |
| Build mode runs only in folders you granted (or worktrees it made of them), read-only by default, with no shell beyond the project's checks | electron/services/claude-code.cjs, codex-cli.cjs, build-worktrees.cjs |
| Commit and push runs a fixed git sequence on files you picked, never a shell, never a force push | electron/services/repo-git.cjs |
| Wiki person pages go to the cloud only with message scanning on; project and topic pages then carry no names | wikiLane() (namesAllowed) and candidates() / projectFacts() / topicFacts() in electron/services/wiki.cjs |
| Wiki prose must cite a fact and passes the never-inferred filter; exports carry no message excerpts | groundParagraphs() and pageMarkdown() in electron/services/wiki.cjs, pinned by wiki.test.cjs |
| This policy is published from this exact file | src/routes/privacy.tsx |