Privacy Policy — Sovernity Chat
Version 1.0-beta.3 · Effective: 2026-08-21
Sovernity Chat is built so that this policy can be short: the app sends us nothing. Everything you do in it — every conversation, every file, every search — happens and stays on your Mac.
1. What we collect through the app
Nothing. Sovernity Chat has:
- no account or sign-in,
- no telemetry, analytics, or usage tracking,
- no crash reporting,
- no advertising or third-party SDKs that collect data,
- no ability — by design — to see your conversations, files, file names, search indexes, or activity logs.
We cannot hand over, sell, leak, or lose data we never receive.
2. The only times the app uses the network
Sovernity Chat makes exactly three kinds of network connection. Nothing else, ever, in any configuration — and none of them ever carries your content.
| Connection | When it happens | What the server can see | Who operates the server |
|---|---|---|---|
| 1. First-run model download | Once, during setup, when you click "Download and set up." Required — the AI model is several GB and downloading it once is how the app stays free of any cloud dependency afterwards. Resumes if interrupted. | Your IP address and which model files were requested. | Hugging Face (the public model repository and its CDN) — see §3. |
| 2. Update check | Only if you start one ("Check for Updates…" menu item) or switch on automatic weekly checks. Off by default. | Your IP address and the app/updater version (in the request's user-agent), i.e., "some Mac at this address runs version X." | Us (sovernity.com). |
| 3. Model-recommendation check | Same single opt-in switch as updates: a small signed file telling the app whether a better model is available for your hardware. Off by default. | Your IP address and the requested file. | Us (sovernity.com). |
Every request fetches a static, signed file. There are no query parameters derived from your data, no cookies, no identifiers. Connections 2 and 3 share one switch, set during onboarding (unchecked) and changeable anytime in Settings. In the app's default configuration, it performs zero automatic network activity after setup.
You don't have to take our word for it: the full product works in airplane mode after setup, and the app's network behavior can be verified by anyone with standard packet-capture tools. We will publish a step-by-step packet-capture walkthrough you can repeat.
3. Third party: Hugging Face
The first-run model download is served by Hugging Face's repository and CDN. Like any web server, Hugging Face can log the request (IP address, requested files, user-agent) under its own privacy policy (https://huggingface.co/privacy). We chose a download from the public source over running the traffic through ourselves so that we learn nothing — not even that you installed the app. We receive no information about your download.
4. Our servers (updates and model recommendations)
Today, these endpoints do not exist. As of this version, the update and model-recommendation endpoints are not live, and the app — by a built-in switch, independent of your settings — makes no request to them, manual or automatic, until they are. Before the first one goes live, we will update this policy with the concrete log-retention period for it. (Our website is a set of static pages served by a hosting service — see §6. It is not one of these endpoints, and the app never contacts it in any configuration.)
When connections 2 and 3 do go live and you use them, our server will see what any web server sees: IP address, request time, requested file, and user-agent (app version). We will use standard server logs solely to serve the files and protect the service from abuse.
- No analytics will be run on these logs, and they will never be sold, shared, or combined with anything else (there is nothing to combine them with — we have no user records).
Legal bases where GDPR applies: performance of your request and our legitimate interest in operating the service securely.
5. Your data on your device
All app data lives in the app's local container on your Mac — a SQLite store (chats, messages, file-activity log, folder-access records) and an attachments store — plus the downloaded model files. It is yours, under your control, protected by your Mac's own protections (we recommend turning on FileVault and using a strong login password).
Deleting data:
- Deleting a chat in the app permanently removes its messages, its attachments (when no other chat references them), and its file-activity entries, followed by a secure-delete pass on the database so the content isn't recoverable from database free space.
- Revoking a folder's access immediately deletes its search index.
- Settings → Data → "Delete All Data" removes, in one action, everything in the SQLite store and the attachments store — every chat and message, all attachments, the file-activity log, folder-access records, search indexes, undo history and Sovernity Trash copies — followed by the same secure-delete pass. It does not remove the model files. Those are the AI model itself: the same bytes for everyone on your model tier, containing nothing about you or anything you did, and keeping them means the app never has to download anything again as a result of your deleting your data. If you want them gone too, delete the app's container folder (see "Uninstalling" below).
- Uninstalling: delete the app and its container folder (
~/Library/Containers/com.sovernity.chat). Nothing remains anywhere else, because nothing was ever anywhere else.
Note: your own backups (e.g., Time Machine) may retain copies of app data under your control, like for any app.
6. Website
Our website, sovernity.com, is a set of static pages — a landing page and this policy — served by a static hosting service. It:
- runs no analytics and no tracking of any kind,
- sets no cookies,
- has no accounts, forms, or sign-ups — nothing on it asks for or accepts your data,
- and is never contacted by the app, in any configuration.
Like any web host, the hosting service that serves the pages can keep standard server logs (IP address, requested page, time, user-agent) under its own privacy policy in the course of delivering them. We add nothing on top: no analytics scripts, no fingerprinting, no identifiers — nothing on the site can tell us who you are.
App downloads are served from GitHub (github.com), which can likewise log the download request under GitHub's privacy policy (https://docs.github.com/privacy). We receive no information about your download.
7. Children
Sovernity Chat is a general-audience productivity tool, not directed at children, and collects no personal information from anyone — including children.
8. Your rights (GDPR, CCPA, and similar laws)
For everything you do in the app, we are not a data controller or processor — your data never reaches us, so rights of access, deletion, portability, and the rest are satisfied directly and instantly by you, on your device (see §5: the app gives you deletion and export, and there is nothing to request from us).
For the sliver of personal data processed around the edges — IP addresses in server logs (§2–4) and in the website host's delivery logs (§6) — you have whatever rights your local law provides (access, deletion, objection). In practice the logs are short-lived and not tied to any identity we could look you up by; contact us and we'll do what we can within those limits. We do not sell or share personal information as defined by the CCPA/CPRA, and we have no advertising relationships.
9. Changes
If this policy changes materially, the new version ships with the app update that occasions it, is published at sovernity.com, and the change is described plainly. Beyond that, we can't notify you individually — we don't know who you are.
10. Contact
Milo Shieber, doing business as Sovernity · milo.sovernity@shieber.com