Self-audit · September 8, 2026 · not indexed by search engines

Should you trust an app that reads your messages?

Fair question. Sanctuary reads years of your iMessage history to build a memory of the people in your life. That only works if the archive never leaves your Mac, so we built it that way and we check that it stays that way. This page says what we read, what leaves your computer, how we checked, what we found, and what we haven't done yet.

It is written for someone who is not an engineer. The privacy policy is the binding version and names the file in our code that enforces each promise.

The one-paragraph version

Your messages, contacts and mail are read on your Mac and written to one database file on your disk. We do not have a copy, cannot request one, and have not built anything that could receive one. There is no account, no sign-in, and no usage tracking inside the app. The AI runs on your Mac by default. A short list of things can leave your Mac, every one of them listed below, and the two that carry anything personal are off until you turn them on and use keys you own.

What the app reads, and what it never does

ReadsWhy
Your Messages databaseThe links, plans, and things people said, so you can ask about them
Your ContactsSo a phone number becomes a name
Apple Mail on this MacThreads where someone is waiting on you
Files you import yourselfA LinkedIn, ChatGPT or Claude export you drop in
Safari and Chrome historyOnly if you switch it on. Off by default. Turning it off deletes everything it stored.
NeverHow you can tell
Uploads your libraryTurn off Wi-Fi. Sanctuary still answers.
Sends usage or crash dataThere is no analytics code in the app, and a test fails the build if a key is found in it.
Trains on your dataNo copy of your data exists anywhere we could train on.
Needs an accountYou never sign in. There is nothing to sign in to.
Sends a message on your behalfEvery draft lands on your clipboard or in a Messages window for you to send.

Everything that can leave your Mac

This is the complete list. Each line is one function in the code, so widening any of them is a deliberate change we would have to write down.

WhatWhere it goesWhen
The address of a link someone sent, to fetch its titleThe website the link points toAlways, like a browser opening the page. Never the message around it.
A version checkGitHub, where releases are hostedOn launch and every few hours. No identifier is sent.
The on-device AI model downloadHugging Face, onceFirst run. Nothing about you is sent.
A link's title, address and one short excerpt, for better summariesA secure enclave your Mac verifies first, on your own keyOnly if you add a Tinfoil key. Off by default.
Recent message text, to find things you owe peopleThe same enclave, your keyA second, separate switch. Off by default.
Topic words for the Feed, never messages or namesParallel web search, your keyOnly if you add a Parallel key.
One identifier for a person you pick, to fetch their work profileNyne, your keyOnly when you press enrich on that person.
Your library, encrypted, to your own iPhoneYour iCloud, not oursOnly if you install the iPhone app on the same Apple ID.
Answers to questions a connected AI asksThe assistant you connected, such as ClaudeOnly if you connect one. Two switches decide whether it sees dates and names or the words of messages.
A setup report of counts and datesWherever you paste itOnly when you copy it yourself.

How we checked

On September 8, 2026 we ran the checks below against the shipping version. We will repeat them before each significant release and update this page.

CheckResult
Every third-party library, scanned for known vulnerabilities932 packages. None critical. The findings that reach the app are listed in the next section.
The app window cannot touch your files or network directlyConfirmed. The interface runs sandboxed and talks to the rest of the app through a small, checked bridge.
The app window cannot be steered to a foreign web pageFixed during this audit. Links now open in your browser, and the window refuses any other destination.
Your keys are stored encryptedConfirmed for the Tinfoil, Nyne and text-message keys. The web-search key was stored in plain text; fixed during this audit.
Your library file is readable only by your macOS userConfirmed. Permissions are set every time the app opens it.
No credential ships inside the appConfirmed by a check that fails the build if one is found.
Fetching a link's title cannot be tricked into reaching inside your networkConfirmed. Addresses are resolved and checked before every request, including redirects, in a separate process with no access to your library.
Nothing personal in any outbound requestConfirmed by an automated test that plants a sentinel and watches every request.
The app is signed and notarized by AppleConfirmed for every release. You can verify a download yourself with the command at the end.
Each privacy promise is pinned by a testConfirmed. The policy's appendix names the file for each one.

What we have not done yet

Honesty is the point of this page, so here is the other side.

GapWhat it means for you
No second layer of encryption on the library fileYour protection at rest is your macOS login and FileVault. If FileVault is off, anyone with your unlocked Mac or an unencrypted backup can read the file. Turning FileVault on is the single most effective step, and the app tells you if it is off.
This is a self-auditOne developer checked their own work. No outside firm has audited Sanctuary yet. That is planned once there is a company around it.
Some dependency warnings have no fixImage and archive libraries inside the on-device AI toolkit carry published advisories with no upstream patch. The app never feeds them untrusted input, so we accept them and watch them.
A single developerBus factor of one. The code is signed, the releases are public, and the policy names the enforcing files so someone else could verify them.
No bug bountyIf you find something, email the address below. We will credit you and fix it.

How to check for yourself

Turn off Wi-Fi. Open Sanctuary and ask it something. It answers, because everything it needs is on your Mac.

Watch the network. A tool like Little Snitch or LuLu shows every connection the app makes. You will see the websites your links point to, the release host, and, only if you turned them on, the enclave or search service on your own key.

Verify the download. In Terminal, with the app in your Applications folder, run spctl -a -t exec -vv /Applications/Sanctuary.app and look for "Notarized Developer ID".

Read the appendix. The privacy policy's Appendix A lists each promise next to the file that enforces it.

Report a problem

Email ravi@fulllist.ai. Security reports get a reply within two days, a fix as fast as we can ship one, and credit on this page if you want it.

Last checked September 8, 2026. This page is not listed in search engines on purpose; share the link with anyone who is deciding.