← Sistine

Privacy Policy

Last updated: August 2026

Sistine is built so that the honest answer to "what do you do with my data?" is: almost nothing, because almost nothing reaches us. This policy says plainly what stays on your Mac, what can leave it and when, and what we never do.

The short version

  • The app's AI runs on your Mac. Your conversations, email, messages, documents, statements and browsing are processed locally by default and stored only on your Mac.
  • We do not operate accounts, conversation servers, analytics, or trackers. We cannot read your conversations because they are never sent to us.
  • Some optional features send specific data to specific services, described below; each is off by default or clearly yours to enable.

What stays on your Mac

Chat history, memory ("what your ghost remembers"), imported documents, email and Telegram content, statements, study material, routines and browsing content are stored locally in your user account. Sensitive stores (such as the email cache) are encrypted at rest with a key held in your macOS Keychain. Deleting the app's data or the app itself removes them.

What can leave your Mac, and when

  • Hosted AI (paid plans, optional): if you enable a hosted model, the messages you choose to send it (and the context needed to answer) are transmitted to our AI infrastructure provider to generate a response. Per-module "private mode" settings (on by default for email, Telegram, statements, study material and browsing) pin that content to the local model in code, so it is not sent even when hosted AI is enabled elsewhere.
  • Web search (optional): your search query is sent through our search proxy to the search provider. We do not log queries; the proxy exists so you don't need your own API key.
  • Web browsing and modules that fetch public data: when you open a web page, check weather, quotes, or news, those requests go to the relevant services like any browser's would.
  • Wallet verification (optional, for Sistine holders): when you connect a wallet, your wallet signs a message in your browser and our verification service checks token ownership on-chain. We receive your public wallet address and token list, never keys. A signed entitlement and chat token are stored on your Mac.
  • Holders' chat (optional): messages you post in the holders' room are stored on our chat database and visible to other verified holders.
  • Points, invites and the scoreboard (optional): if you use FriendZone or open an invite link, the app sends a device identifier and, if you have one, your public wallet address to our points service, plus a note that the app was used that day and any invite code you arrived with. The device identifier is a salted one-way hash derived from your Mac's hardware id: the hardware id itself is never stored or transmitted, and the hash is specific to this app, so it cannot be used to recognise you anywhere else. We use it to award invite credit once per machine and to stop the scoreboard being farmed, not to profile you. No message, file or browsing content is involved.
  • Crash reports (optional): if you enable them, crash logs (technical stack data, no conversation content) are sent to us.
  • Software updates: the app checks our update feed for new versions; this is a standard HTTPS request with no personal data attached.

Purchases

Subscriptions are sold by Paddle, our merchant of record. Paddle collects and processes your payment details, billing address and email under Paddle's privacy policy; we receive subscription status, not your payment details.

What we never do

  • No selling or sharing of personal data. No advertising, no ad identifiers.
  • No analytics or telemetry in the app or on this site, with one narrow exception we'd rather name than bury: if you use the points and invite features, the app records that it was used on a given day (see above). It records no content, no page views, no feature usage, and nothing at all if you don't use those features.
  • No training AI models on your content.

Third-party services you may enable

If you connect your own accounts (email via IMAP, Telegram) the app talks directly to those services with credentials stored in your macOS Keychain. If you add your own API keys (search, market data), requests go directly to those providers under their terms.

Data retention and deletion

We retain nothing about your app usage beyond the points records described above (device identifier, wallet address if connected, points, invite credit), which you can have deleted by emailing us. The holders' chat retains posted messages until deleted by you or a moderator. To delete local data, use the in-app options or remove the app and its Application Support folders.

Children

The app is not directed at children under 13 and we do not knowingly collect their information.

Changes and contact

If this policy changes materially, the updated version ships with the app update and is posted here. Questions: support@sistine.ai.

Terms · Privacy · Refunds · Hosting