← Sistine
Privacy Policy
Last updated: August 2026
Sistine is built so that the honest answer to "what do you do with my data?" is: almost nothing, because almost nothing reaches us. This policy says plainly what stays on your Mac, what can leave it and when, and what we never do.
The short version
- The app's AI runs on your Mac. Your conversations, email, messages, documents, statements and browsing are processed locally by default and stored only on your Mac.
- We do not operate accounts, analytics, or trackers.
- On the free tier and any local model, your conversations never reach us at all. If you turn on a hosted model (a paid plan), the messages you send it pass through our server to reach the AI provider — so for those messages we are in the path, and we say so rather than claiming otherwise. We do not store their content (see Retention).
- Some optional features send specific data to specific services, described below; each is off by default or clearly yours to enable.
What stays on your Mac
Chat history, memory ("what your ghost remembers"), imported documents, email and Telegram content, statements, study material, routines and browsing content are stored locally in your user account. Sensitive stores (such as the email cache) are encrypted at rest with a key held in your macOS Keychain. To remove them, delete the app's data from within the app, or remove its Application Support folder — dragging the app icon to the Trash removes the app but, like most Mac apps, leaves that data folder behind.
What can leave your Mac, and when
- Hosted AI (paid plans, optional): if you enable a hosted model, the messages you choose to send it (and the context needed to answer) are transmitted to our AI infrastructure provider to generate a response. Per-module "private mode" settings (on by default for email, Telegram, statements, study material and browsing) pin that content to the local model in code, so it is not sent even when hosted AI is enabled elsewhere.
- Web search (optional): your search query is sent through our search proxy to the search provider. We do not log queries; the proxy exists so you don't need your own API key.
- Web browsing and modules that fetch public data: when you open a web page, check weather, quotes, or news, those requests go to the relevant services like any browser's would.
- Wallet verification (optional, for Sistine holders): when you connect a wallet, your wallet signs a message in your browser and our verification service checks token ownership on-chain. We receive your public wallet address and token list, never keys. A signed entitlement and chat token are stored on your Mac.
- Holders' chat (optional): messages you post in the holders' room are stored on our chat database and visible to other verified holders.
- Points, invites and the scoreboard (optional): if you use Points (the scoreboard) or open an invite link, the app sends a device identifier and, if you have one, your public wallet address to our points service, plus a note that the app was used that day and any invite code you arrived with. The device identifier is a salted one-way hash derived from your Mac's hardware id: the hardware id itself is never stored or transmitted, and the hash is specific to this app, so it cannot be used to recognise you anywhere else. We use it to award invite credit once per machine and to stop the scoreboard being farmed, not to profile you. No message, file or browsing content is involved.
- Your plan and billing status: requests to our hosted AI service carry the same salted device identifier described above, so we can tell which plan an install is on and meter its allowance. This applies whenever you use a hosted model, start a checkout, or cancel a subscription — not only to Points.
- The ghost mint and its artwork (optional): if you claim a Sistine Ghost, the app sends the device identifier and the wallet address you type to our mint service, which records that this install and that wallet each claimed once, and mints the token on Robinhood Chain. The claim, the wallet address and the token number are written to a public blockchain and are permanent and world-readable — that is what minting is. Ghost artwork is fetched from our art and drop services, which see only which images you asked for.
- Feedback (optional): if you send feedback from the app, the message you write and a device identifier reach our feedback service.
- Website publishing (optional): if you publish a site from the Code module, the files you publish are stored on our hosting infrastructure and served publicly at the address you chose — that is the product. Alongside them we keep: messages visitors submit through your site's contact form (held for you alone, newest 200, deleted with the site), a daily count of visits to your front page (a number only, kept 35 days), and abuse reports visitors file against a site. Deleting your site deletes its files, its inbox, and its counters.
- Launch mailing list (optional): if you enter your email on sistine.ai to be notified at launch, we store that address for exactly that one mailing. Unsubscribe or email us and it's deleted.
- Crash reports (optional): if you enable them, crash logs (technical stack data, no conversation content) are sent to us.
- Software updates: the app checks our update feed for new versions; this is a standard HTTPS request with no personal data attached.
Who we are
Sistine is made by Looks Labs LLC, which is the data controller for the processing described here. Contact us at support@sistine.ai about anything on this page.
Your rights over your data
Email support@sistine.ai and we will act within 30 days. You can ask us to give you a copy of what we hold, correct it, or delete it; object to or restrict a particular use; and, where a law such as the GDPR or the CCPA applies to you, complain to your data protection authority. We do not sell or share personal information, so there is nothing to opt out of on that front. Because most of what the app holds never leaves your Mac, the fastest way to delete the bulk of it is to delete it locally.
One honest limit: a mint recorded on a public blockchain cannot be erased by us or by anyone. If that matters to you, do not mint.
Purchases
Subscriptions are sold by Paddle, our merchant of record. Paddle collects and processes your payment details, billing address and email under Paddle's privacy policy; we receive subscription status, not your payment details.
What we never do
- No selling or sharing of personal data. No advertising, no ad identifiers.
- No analytics or telemetry in the app or on this site, with one narrow exception we'd rather name than bury: if you use the points and invite features, the app records that it was used on a given day (see above). It records no content, no page views, no feature usage, and nothing at all if you don't use those features.
- No training AI models on your content.
Third-party services you may enable
If you connect your own accounts (email via IMAP, Telegram) the app talks directly to those services with credentials stored in your macOS Keychain. If you add your own API keys (search, market data), requests go directly to those providers under their terms.
Data retention and deletion
What we keep, and for how long:
- Points and invites: device identifier, wallet address if connected, points and invite credit, kept while the record exists. Deleted on request.
- Plan and usage: device identifier, current plan, and counts of hosted requests used in the current period — the meter that enforces your allowance. Message content is not stored.
- Mint claims: device identifier, wallet address, token number and transaction hash, kept permanently. These record a one-per-person free mint and cannot be deleted without making the collection forgeable; the same facts are on a public blockchain regardless.
- Holders' chat: posted messages, until deleted by you or a moderator.
- Published sites: your files and contact-form inbox, until you delete the site; front-page view counts, 35 days; abuse reports, until resolved.
- Launch mailing list: your email address, until the launch mailing is sent or you ask for removal.
- Feedback and crash reports: what you submitted, kept until acted on.
- Search queries: not logged.
To delete local data, use the in-app options or remove the app and its Application Support folders.
Children
The app is not directed at children under 13 and we do not knowingly collect their information.
Changes and contact
If this policy changes materially, the updated version ships with the app update and is posted here. Questions: support@sistine.ai.
Terms · Privacy ·
Refunds · Hosting ·
@sistineai