SYSANALEGAL / PRIVACY POLICYTRUST CENTER
LOCAL FIRST / TRANSPARENCY / CONTROL

PRIVACY
POLICY.

This policy explains what stays on your Mac, what Sysana receives when you choose an online feature, why information is processed, and the choices available to you.

EFFECTIVE
July 29, 2026
LAST UPDATED
August 13, 2026
VERSION
2.3
CONTENTS01Scope and operator02Local Mac processing03Information we receive04Sysana Intelligence05App Store purchases06Website and communications07Purposes and legal bases08Disclosures09Retention10Security11International processing12Your choices and rights13California notice14Children15Automated decisions16Changes and contact
PRIVACY AT A GLANCE

Sysana’s core diagnostics, storage scans, file metadata analysis, timelines, and recommendations run on your Mac. Granting folder or Full Disk Access does not upload those folders. In this App Store version, Sysana does not delete files, uninstall applications, or clear browser data. When you deliberately use Sysana Intelligence, the app sends your question, a short recent conversation window, an installation identifier, and a compact diagnostic summary to Sysana’s service and OpenAI. When you choose Send Feedback, Sysana sends only the report details shown in that form. These cloud summaries exclude file contents, photos, messages, passwords, browser history, visited domains, and complete file paths. App Store purchases are handled by Apple. We do not sell personal information or use it for targeted advertising.

01 / SCOPE & OPERATOR

Who this policy covers.

This Privacy Policy applies to information handled by UniVanta LLC, operator of Sysana (“Sysana,” “we,” “us,” or “our”), through the Sysana Mac application, Sysana Intelligence, sysana.app, and direct support or security communications.

UniVanta LLC is the controller for processing it determines. Apple, OpenAI, hosting providers, email providers, and websites you independently visit may act as processors or independent controllers under their own notices. This policy does not replace a just-in-time notice shown before a particular permission or cloud feature.

02 / LOCAL MAC PROCESSING

What Sysana analyzes without uploading it.

Subject to macOS permissions, Sysana can locally read system metrics, process and application names, resource values, battery and thermal signals, storage capacity, file and folder names, paths, sizes, dates, types, allocated size, duplicate hashes, application metadata, browser-profile storage totals, and other evidence needed for diagnostics and recommendations.

Storage access is permission-driven. A security-scoped folder selection, Photos permission, Automation permission, or Full Disk Access expands what macOS lets Sysana inspect. Those permissions do not themselves transmit data to us. In this App Store version, scans and duplicate verification are local and read-only: Sysana shows evidence and recommendations, but does not move items to Trash, permanently remove files, uninstall applications, or clear browser data. Bookmarks, preferences, reports, and local history may be stored on your Mac using Apple system storage.

You control permissions in macOS and can revoke them, remove approved folders, clear local learning history, or stop using the app. Revocation can make results partial or disable a feature.

03 / INFORMATION WE RECEIVE

Information that can leave your Mac.

A / SYSANA INTELLIGENCE

Your question, a short recent conversation window, app version, a random installation identifier, compact Mac metrics, verified diagnosis text, visible process names and resource values, storage category totals, maintenance totals, Deep Diagnosis category totals, website-data totals, and access-state notes.

B / IN-APP FEEDBACK

The category and message you write, app version, build, macOS version, and a one-way hash of a random installation identifier. You can choose whether to include a compact snapshot containing health score, CPU and memory percentages, free-storage total, thermal condition, and finding count. When you choose Report this answer, the selected question and answer are also included. The form does not send file contents, file paths, passwords, browser history, documents, or screenshots.

C / SUBSCRIPTION VERIFICATION

A signed App Store transaction representation can be sent to Sysana’s server so Apple’s transaction data can be verified and ongoing Intelligence access confirmed. It can contain Apple transaction identifiers, product identifier, purchase and expiration dates, environment, and revocation status.

D / WEBSITE REQUESTS AND COMMUNICATIONS

Hosting providers process ordinary website-request data. Direct support messages may contain your email address, message, signature, and attachments you voluntarily send.

Do not email passwords, payment-card data, private documents, or unnecessary sensitive diagnostic information.

04 / SYSANA INTELLIGENCE

A separate, user-initiated cloud boundary.

Core diagnostics do not require cloud Intelligence. Before first cloud use, Sysana provides an in-app notice and choice. When you press Send, the app transmits the information described above over HTTPS to the Sysana Intelligence endpoint hosted on our infrastructure. The service validates request size and format, enforces quotas, verifies subscription entitlement when supplied, and sends the question and compact context to OpenAI’s API.

OpenAI generates the answer and may use web search restricted by our service to official Apple Support and Apple Developer domains. Search terms can be derived from your question. Sysana returns answer text and verified source links. We configure API requests with application-state storage disabled.

The cloud payload excludes document contents, photo contents, messages, passwords, browser history, visited domains, complete local file paths, and local learning-memory entries. Process names, app names, diagnosis labels, and category totals may still reveal information about how you use your Mac; review the cloud notice before sending. You can revoke cloud consent without disabling local features.

05 / APP STORE PURCHASES

Apple processes billing.

Sysana’s optional monthly and annual subscriptions are purchased through StoreKit and the App Store. Apple collects and controls payment credentials, billing details, tax information, purchase history, fraud signals, and Apple Account information under Apple’s privacy notice and terms. Sysana does not receive your full card number or CVC.

The app receives product information and verified entitlement status from StoreKit. To validate ongoing Intelligence access, the app may send Apple’s signed transaction representation to our server, where it is verified against Apple’s App Store Server services or libraries. Apple handles cancellation and refund requests.

06 / WEBSITE & COMMUNICATIONS

Public-site activity stays limited.

Our hosting and security infrastructure processes ordinary web requests to deliver sysana.app, prevent abuse, and diagnose failures. The website application code does not currently include advertising pixels, cross-site behavioral trackers, or optional analytics cookies. See the Cookie Policy.

If you contact us, we use your message to respond, investigate the request, protect users, and maintain a support record. Following an external link, including Apple’s subscription or refund pages, takes you to a service governed by its own notice.

07 / PURPOSES & LEGAL BASES

Why information is processed.

  • Provide the Service: answer requested questions, verify entitlements, deliver website pages, and provide support. The usual basis is contract performance or steps you request.
  • Secure and operate: enforce lifetime complimentary allowances and abuse-prevention limits, validate requests, prevent fraud, debug failures, and protect systems. The usual basis is legitimate interests.
  • Comply with law: respond to valid legal process and meet accounting, tax, consumer, and recordkeeping duties where applicable.
  • Consent-based features: where law or the interface requests consent, such as the optional cloud data flow, consent is the basis and can be withdrawn for future processing.

Where GDPR-style law applies, the exact basis depends on context. We do not use information for a materially incompatible purpose without appropriate notice and, where required, consent.

08 / DISCLOSURES

Who may process information.

  • Vercel and related hosting, network, security, and rate-limit infrastructure deliver sysana.app and the Sysana Intelligence endpoint.
  • OpenAI processes Intelligence questions and compact diagnostic context and may search allowlisted official Apple sources to generate answers.
  • Apple distributes the app, operates StoreKit and App Store billing, validates transactions, and provides platform services and documentation.
  • Email, support, legal, accounting, and security providers may process information necessary for a request or professional service.
  • Authorities or transaction participants may receive information when legally required, needed to protect rights or safety, or involved in a legitimate financing, merger, reorganization, or sale subject to confidentiality and notice.

We do not sell personal information, disclose it for cross-context behavioral advertising, or permit providers to use it for our targeted advertising.

09 / RETENTION

Information is kept only as needed.

  • Local app data: remains on your Mac until you clear it, remove access, uninstall the app, or macOS removes it, subject to backups and system behavior. The app’s temporary AI conversation cache expires after one hour and is limited to the most recent 40 messages.
  • Complimentary-credit balance: a one-way hash derived from the random installation identifier and a successful-answer count are retained for the lifetime of that installation to enforce the credit balance and prevent repeated resets. Credits are tied to the Sysana installation on a Mac, not to an Apple Account, so changing Apple Accounts does not create a new balance. The on-device installation identifier is stored in the macOS Keychain and may persist after an app reinstall for the same macOS user account. We do not use this hash to identify your Apple Account or inspect files.
  • Short-term rate limits: installation and network rate-limit records expire after approximately 65 seconds. The lifetime-credit record does not automatically expire.
  • Conversation requests: a short recent window accompanies an individual request; Sysana does not maintain a server-side conversation history or answer transcript for ordinary responses.
  • Usage telemetry and Vercel runtime logs: after a successful request, the service may record a truncated installation hash, subscription status, model name, token counts, web-search count, and request duration for quota enforcement, operations, abuse prevention, and cost monitoring. It does not record the question or diagnostic context in this telemetry event. Our current Vercel Hobby project retains runtime logs for 1 hour, after which Vercel removes them under its standard log-retention policy. We do not use a Vercel log drain or separate long-term log archive. If our Vercel plan or logging configuration changes, we will update this section before the new retention period applies.
  • OpenAI: Sysana sends Responses API requests with application-state storage disabled. OpenAI’s standard API data controls allow abuse-monitoring logs to be retained for up to 30 days; those logs may contain API prompts, responses, and related metadata, and may be retained longer when legally required. Sysana has not enabled a separate Zero Data Retention or Modified Abuse Monitoring arrangement.
  • Feedback reports: stored in a private operations inbox for up to 180 days so we can investigate, group, and resolve product issues. Reports use a hashed installation identifier rather than the identifier itself. You can request deletion by emailing us with the report date, category, and any reference shown by the app.
  • Entitlement and transaction evidence: retained only as needed to verify access, prevent fraud, resolve disputes, and meet legal obligations.
  • Support records: retained while a request is active and for a reasonable period afterward.

Legal holds, security incidents, fraud investigations, or mandatory records can extend retention. When information is no longer needed, we delete, de-identify, aggregate, or securely isolate it.

10 / SECURITY

Protection without impossible promises.

Measures include HTTPS, server-only API credentials, non-stored response configuration, hashed quota identifiers, request validation, transaction verification, restricted source domains, local permission boundaries, and user confirmation for meaningful actions. No transmission or storage system is completely secure. Report concerns to security@sysana.app without sending secrets or private files.

11 / INTERNATIONAL PROCESSING

Information may cross borders.

We and our providers may process information in countries different from yours. Where required, we use adequacy decisions, standard contractual clauses, or another lawful transfer mechanism with safeguards appropriate to the risk. Contact us for information about an applicable transfer safeguard.

12 / CHOICES & RIGHTS

Access, correction, deletion, and control.

You can deny or revoke macOS permissions, remove approved folders, disable launch at login, turn off notifications, revoke Sysana Intelligence cloud consent, avoid sending questions, cancel an App Store subscription, and clear available local history in the app. Clearing local history does not automatically remove server-side quota, entitlement, or security records.

Depending on your location and legal exceptions, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or an appeal, and may complain to a privacy authority. Email hello@sysana.app with “Privacy Request,” the right requested, and enough context to locate the interaction. We will acknowledge a request and generally respond within 30 days where GDPR applies, or within the period required by applicable California law. We may verify identity and authority, may retain information required for legal, fraud-prevention, security, or transaction-record purposes, and will not discriminate for exercising a right.

13 / CALIFORNIA NOTICE

Additional California information.

Categories potentially processed in the prior 12 months include identifiers, commercial information, internet or electronic-network activity, approximate location derived from IP, and support correspondence. Sources include you, your app or browser, Apple, and infrastructure providers. Purposes and recipient categories are described above.

Sysana has not sold personal information or shared it for cross-context behavioral advertising, including for monetary or targeted-advertising purposes, and does not knowingly sell or share information of anyone under 16. California residents may request to know, access, correct, delete, or appeal a decision using Section 12. We do not currently offer a separate authorized-agent portal; an agent may submit a request with proof of authorization, and we may verify the request as required by law.

14 / CHILDREN

Not directed to children.

Sysana is not directed to children under 13 and we do not knowingly collect their personal information. Where a higher age applies for consent, we do not knowingly rely on consent below that age. Contact us if you believe a child submitted information so we can investigate and delete it where required.

15 / AUTOMATED DECISIONS

No solely automated legal decisions.

Sysana’s health scores, diagnoses, maintenance rankings, and AI answers are informational and do not produce legal or similarly significant effects. Automated security or quota systems may limit a request. Contact support if you believe a Sysana-controlled automated measure incorrectly affected access.

16 / CHANGES & CONTACT

Material changes receive appropriate notice.

We may update this policy for product, provider, legal, or security changes. The current date and version will appear here. The app may require renewed acknowledgment or cloud consent when a material change affects its data flow.

UNIVANTA LLC / SYSANA PRIVACYhello@sysana.appsecurity@sysana.appWebsite: sysana.app

You may also contact the privacy or consumer authority where you live. Do not include passwords, payment credentials, private documents, or unnecessary diagnostic details.

HOMETERMSCOOKIESAPP STORE REFUNDS© 2026 UNIVANTA LLC