Self-audit · September 8, 2026 · not indexed by search engines
Should you trust an app that reads your messages?
Fair question. Sanctuary reads years of your iMessage history to build a memory of the people in your life. That only works if the archive never leaves your Mac, so we built it that way and we check that it stays that way. This page says what we read, what leaves your computer, how we checked, what we found, and what we haven't done yet.
It is written for someone who is not an engineer. The privacy policy is the binding version and names the file in our code that enforces each promise.
The one-paragraph version
Your messages, contacts and mail are read on your Mac and written to one database file on your disk. We do not have a copy, cannot request one, and have not built anything that could receive one. There is no account, no sign-in, and no usage tracking inside the app. The AI runs on your Mac by default. A short list of things can leave your Mac, every one of them listed below, and the two that carry anything personal are off until you turn them on and use keys you own.
What the app reads, and what it never does
| Reads | Why |
|---|---|
| Your Messages database | The links, plans, and things people said, so you can ask about them |
| Your Contacts | So a phone number becomes a name |
| Apple Mail on this Mac | Threads where someone is waiting on you |
| Files you import yourself | A LinkedIn, ChatGPT or Claude export you drop in |
| Safari and Chrome history | Only if you switch it on. Off by default. Turning it off deletes everything it stored. |
| Never | How you can tell |
|---|---|
| Uploads your library | Turn off Wi-Fi. Sanctuary still answers. |
| Sends usage or crash data | There is no analytics code in the app, and a test fails the build if a key is found in it. |
| Trains on your data | No copy of your data exists anywhere we could train on. |
| Needs an account | You never sign in. There is nothing to sign in to. |
| Sends a message on your behalf | Every draft lands on your clipboard or in a Messages window for you to send. |
Everything that can leave your Mac
This is the complete list. Each line is one function in the code, so widening any of them is a deliberate change we would have to write down.
| What | Where it goes | When |
|---|---|---|
| The address of a link someone sent, to fetch its title | The website the link points to | Always, like a browser opening the page. Never the message around it. |
| A version check | GitHub, where releases are hosted | On launch and every few hours. No identifier is sent. |
| The on-device AI model download | Hugging Face, once | First run. Nothing about you is sent. |
| A link's title, address and one short excerpt, for better summaries | A secure enclave your Mac verifies first, on your own key | Only if you add a Tinfoil key. Off by default. |
| Recent message text, to find things you owe people | The same enclave, your key | A second, separate switch. Off by default. |
| Topic words for the Feed, never messages or names | Parallel web search, your key | Only if you add a Parallel key. |
| One identifier for a person you pick, to fetch their work profile | Nyne, your key | Only when you press enrich on that person. |
| Your library, encrypted, to your own iPhone | Your iCloud, not ours | Only if you install the iPhone app on the same Apple ID. |
| Answers to questions a connected AI asks | The assistant you connected, such as Claude | Only if you connect one. Two switches decide whether it sees dates and names or the words of messages. |
| A setup report of counts and dates | Wherever you paste it | Only when you copy it yourself. |
How we checked
On September 8, 2026 we ran the checks below against the shipping version. We will repeat them before each significant release and update this page.
| Check | Result |
|---|---|
| Every third-party library, scanned for known vulnerabilities | 932 packages. None critical. The findings that reach the app are listed in the next section. |
| The app window cannot touch your files or network directly | Confirmed. The interface runs sandboxed and talks to the rest of the app through a small, checked bridge. |
| The app window cannot be steered to a foreign web page | Fixed during this audit. Links now open in your browser, and the window refuses any other destination. |
| Your keys are stored encrypted | Confirmed for the Tinfoil, Nyne and text-message keys. The web-search key was stored in plain text; fixed during this audit. |
| Your library file is readable only by your macOS user | Confirmed. Permissions are set every time the app opens it. |
| No credential ships inside the app | Confirmed by a check that fails the build if one is found. |
| Fetching a link's title cannot be tricked into reaching inside your network | Confirmed. Addresses are resolved and checked before every request, including redirects, in a separate process with no access to your library. |
| Nothing personal in any outbound request | Confirmed by an automated test that plants a sentinel and watches every request. |
| The app is signed and notarized by Apple | Confirmed for every release. You can verify a download yourself with the command at the end. |
| Each privacy promise is pinned by a test | Confirmed. The policy's appendix names the file for each one. |
What we have not done yet
Honesty is the point of this page, so here is the other side.
| Gap | What it means for you |
|---|---|
| No second layer of encryption on the library file | Your protection at rest is your macOS login and FileVault. If FileVault is off, anyone with your unlocked Mac or an unencrypted backup can read the file. Turning FileVault on is the single most effective step, and the app tells you if it is off. |
| This is a self-audit | One developer checked their own work. No outside firm has audited Sanctuary yet. That is planned once there is a company around it. |
| Some dependency warnings have no fix | Image and archive libraries inside the on-device AI toolkit carry published advisories with no upstream patch. The app never feeds them untrusted input, so we accept them and watch them. |
| A single developer | Bus factor of one. The code is signed, the releases are public, and the policy names the enforcing files so someone else could verify them. |
| No bug bounty | If you find something, email the address below. We will credit you and fix it. |
How to check for yourself
Turn off Wi-Fi. Open Sanctuary and ask it something. It answers, because everything it needs is on your Mac.
Watch the network. A tool like Little Snitch or LuLu shows every connection the app makes. You will see the websites your links point to, the release host, and, only if you turned them on, the enclave or search service on your own key.
Verify the download. In Terminal, with the app in your Applications folder, run spctl -a -t exec -vv /Applications/Sanctuary.app and look for "Notarized Developer ID".
Read the appendix. The privacy policy's Appendix A lists each promise next to the file that enforces it.
Report a problem
Email ravi@fulllist.ai. Security reports get a reply within two days, a fix as fast as we can ship one, and credit on this page if you want it.
Last checked September 8, 2026. This page is not listed in search engines on purpose; share the link with anyone who is deciding.