Local-only processing

How we keep your data on your device

The claim is simple: your documents are never transmitted. Here is what that means in practice, and how you can check it for yourself.

The work happens on your laptop

After activation, the app installs everything it needs directly onto your device and then does the whole job there, using your own hardware. Your documents are never sent away to be processed.

The risk report stays on your device

The residual-risk report, which tells you what was found and what may still need a look, is shown in the app only. It is never logged, synced, or reported back to our servers.

The boundary is enforced, not just promised

The part of the app that handles your content is deliberately kept apart from the parts that talk to the network. That separation is checked automatically every time we build the app: if the two were ever connected, the build would fail rather than ship.

You can verify this yourself

You do not have to take our word for it, and you cannot read our source — the application is proprietary. What you can do is observe its behaviour. Once the app is activated and set up, disconnect from the network entirely, turn off Wi-Fi or pull the cable, and anonymize a document. It works, because nothing in that path needs a server.

You can also watch the app with a network monitor such as Little Snitch, Wireshark, or your own firewall logs, and compare what you observe against the list below. If you see anything that is not on it, we want to hear about it.

What goes over the network

Only account and subscription metadata:

  • Email address, for sign-in and subscription management
  • Device ID and app version, for license activation
  • Your licence, issued by our server and checked on your device
  • The app itself and its updates, downloaded once your subscription is confirmed
  • Optional crash reports, which are off by default and content-free when enabled

See the full security and delivery model