← SecureOffline.ai
Trust & verification
Privacy products usually ask you to trust a policy. Ours asks you to check the architecture. This page explains what SecureOffline does technically — and how to verify every claim yourself.
The claims
- No server. AI answers are generated by an open model running on your Mac’s own processor. There is no SecureOffline backend that sees your questions — one doesn’t exist.
- No account. The app never asks you to sign in. Your license is verified by cryptographic signature on your machine, offline.
- No telemetry. No analytics, no crash reporting, no usage pings. The app makes network requests only when you ask it to download or update an AI model or voice pack.
- Your files stay put. Attached PDFs are read locally; conversations are stored as plain files on your Mac that you can open, copy, or delete anytime.
Verify it yourself (10 minutes)
- The router test: download a model, then turn off Wi-Fi entirely. Use the app — chat, attach a PDF, use voice. Everything works, because nothing depended on a connection.
- The packet test: run a network monitor (Little Snitch, LuLu — free) while you use the app. During normal use you’ll observe zero outbound traffic from SecureOffline.
- The Apple test: macOS itself verifies our identity. Run
spctl --assess -vv /Applications/SecureOffline.app in Terminal: you’ll see accepted · Notarized Developer ID. Every copy is signed by our Apple-verified developer identity and scanned by Apple before it ever reaches you.
What we do collect (the honest list)
- If you buy: your email and payment record, processed by Stripe — used to deliver your license and honor the 30-day guarantee.
- If you join the newsletter: your email, used for the newsletter. Unsubscribe anytime.
- This website: no analytics profiles and no cross-site trackers. The one third-party tag is Google’s ads-measurement tag, used only to count whether visits came from our own ads — and not loaded at all if your browser sends the Global Privacy Control signal. Model downloads are served from our own content network; standard server logs (IP, file requested) exist there as with any download server and are not linked to any identity.
That’s the complete list. If it ever changes, this page changes first.
For compliance & procurement reviews
If you're evaluating SecureOffline for professional use on confidential material, the review is unusually short — because the sensitive data path doesn't exist:
- Your client data: never received, transmitted, or stored by us. We never act as a data processor, service provider, or business associate for your app content — there is nothing shared with us for such an agreement to cover (confirm your own obligations with counsel). Full analysis: Data Processing Statement.
- Our commerce data (your purchase email, license, consent records): processed in the U.S. by a small subprocessor set (Stripe, Apple, Resend, Zoho, Cloudflare, Railway) with DPA-grade commitments — retention schedule, 72-hour incident notification, deletion rights — documented in the same statement.
- Verification instead of attestation: your own IT staff can confirm the zero-transmission claim in minutes with the tests above — no questionnaire answer of ours is load-bearing.
- Paperwork: executed copies of the Data Processing Statement and completed security questionnaires are available on request.
Report a security issue
Found a vulnerability in the app, this site, or our license service? Write to [email protected] with the details and “SECURITY” in the subject line. We read every report, respond promptly, and will credit you (with your permission) when a fix ships. Good-faith research conducted without harming other users' data will not be met with legal action.
Who we are
SecureOffline.ai is a DBA of OnyxLinc LLC, a United States company, sold under Apple team ID RY3H96AKGP. Legal documents: Terms · Privacy · Data Processing Statement. Questions, security reports, or audit inquiries: [email protected].