Sysana minimizes collection. Core Mac diagnostics run locally. When you choose Ask Sysana in the App Store edition, the app sends your question and a compact diagnostic summary to Sysana Intelligence; it does not send document contents, photos, messages, passwords, or complete file paths. The public website has no advertising or behavioral-tracking system in its application code. Payments are completed on Stripe’s hosted checkout. Sysana does not sell personal information.
Who this policy covers.
This Privacy Policy applies to personal information handled by Sysana through the public website at sysana.app, the Sysana Mac application, Sysana Intelligence, subscription checkout initiated from the website, official download links, and direct communications with us. In this policy, “Sysana,” “we,” “us,” and “our” refer to the operator of the Sysana service.
For applicable data-protection law, Sysana is the controller of personal information for the purposes described here, except where another company independently determines how and why it processes information—for example, Stripe acting under its own privacy policy.
This policy does not apply to third-party websites, services, or applications that publish their own privacy notices. It also does not replace a just-in-time notice shown for a particular feature.
Information we may receive.
IP address, browser and device type, operating system, requested page, referring page where provided, request date and time, language, approximate region derived from IP, and security or error information. Hosting and security providers may generate this data automatically when delivering the site.
Subscription plan, price, currency, transaction and checkout-session identifiers, payment status, renewal status, timestamps, and limited customer or billing details returned by Stripe. Full card numbers and CVCs are entered into Stripe’s hosted checkout and are not received by Sysana’s website server.
Your email address, name or signature if included, message contents, attachments you choose to send, and related support correspondence when you contact hello@sysana.app or security@sysana.app.
A request for the download route and the ordinary technical request data described above. The configured download host may separately receive your IP address, browser information, and download request under its own or our instructions.
When you submit an Ask Sysana question, we receive the question, a random installation identifier stored in your Mac’s Keychain, app version, and compact system facts such as processor and memory percentages, available storage, verified diagnostic findings, top visible process names and resource values, and category-level storage or cleanup totals. We do not request document contents, photos, messages, passwords, or complete file paths.
We may also receive information from service providers that help us prevent fraud, secure the service, process payments, or respond to requests. We do not intentionally infer sensitive traits from website activity.
Information we do not seek.
The public website does not ask you to upload documents, photos, messages, Mac files, passwords, government identifiers, health information, or precise geolocation. Do not send this information by email.
Sysana’s website does not receive or store your full payment-card number or CVC. The website’s application code does not currently include advertising pixels, cross-site behavioral trackers, or optional analytics cookies. See our Cookie Policy for the current inventory and browser controls.
Website demonstrations display illustrative Mac system information. Interacting with a demonstration changes what appears in your browser; it does not scan your Mac or transmit real diagnostic data from your device.
How we use information.
- Provide requested services. Load pages, answer Ask Sysana questions from supplied diagnostic summaries, redirect to official downloads, initiate secure checkout, confirm subscription events, and deliver purchased access.
- Administer subscriptions. Reconcile payments, identify plans, manage renewals or cancellations, respond to billing questions, and maintain transaction records.
- Communicate. Answer support, privacy, download, billing, and security inquiries and send service-related messages.
- Protect the service. Enforce daily discussion limits, authenticate Stripe webhooks, identify malicious traffic, prevent abuse and fraud, debug failures, and maintain availability.
- Comply and enforce. Meet tax, accounting, legal, regulatory, and recordkeeping duties; establish or defend legal claims; and enforce applicable agreements.
- Improve responsibly. Diagnose aggregate reliability and performance issues using information proportionate to that purpose. We do not use website activity for targeted advertising.
We will not use personal information for a materially incompatible purpose without providing appropriate notice and, where required, obtaining consent.
Why processing is permitted.
Where we rely on legitimate interests, those interests are operating a safe, reliable, commercially sustainable service, preventing fraud, and responding to users. We consider the necessity and privacy impact of the processing before relying on this basis.
When information is shared.
We disclose personal information only as needed for the purposes above, subject to appropriate obligations. Recipient categories may include:
- Hosting, network, security, and rate-limit providers that deliver and protect sysana.app and Sysana Intelligence.
- OpenAI processes the question and compact diagnostic summary to generate an Ask Sysana answer. We configure Responses API requests not to store application state. OpenAI states that API data is not used to train its models unless the customer opts in; default abuse-monitoring logs may be retained for up to 30 days.
- Stripe and payment participants that process checkout, payment methods, fraud signals, refunds, disputes, tax-related data, and recurring billing.
- Download or storage providers that host the official application installer.
- Professional advisers and vendors such as legal, accounting, security, and customer-support providers, when engaged.
- Authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or respond to valid legal process.
- Transaction participants in a financing, merger, acquisition, reorganization, or asset transfer, subject to appropriate confidentiality and lawful notice.
We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising. We do not permit service providers to use information on our behalf for their own targeted advertising.
Checkout is handled by Stripe.
When you continue to payment, your browser is redirected to Stripe’s hosted checkout. Stripe directly collects payment credentials, billing details, device and network information, fraud-prevention signals, and other information needed to process the transaction. Stripe may act as our processor for some activities and as an independent controller for others required by law or its financial-services role.
Sysana receives limited checkout and subscription information needed to confirm and administer the transaction. Our current webhook verifies that an event genuinely came from Stripe and records the checkout-session identifier for a completed session. We do not rely solely on the browser’s success page as proof of payment.
Review Stripe’s Privacy Policy ↗ and Cookie Policy ↗. Your bank, card network, wallet provider, or other payment participant may also process information under its own notice.
Public-site activity stays limited.
Our infrastructure necessarily processes web requests to deliver pages and protect the site. We may use logs to investigate errors, abusive activity, or security incidents. We do not currently use the public website’s application code to create user profiles, track people across unrelated websites, or measure advertising conversions.
The download button passes your browser through a Sysana route that validates the configured destination and allows redirects only to an HTTPS address. If no official installer is configured, you are sent to a local status page. If the installer is hosted by another provider, that provider will receive the technical data needed to deliver the file.
Local-first product boundaries.
Core system sampling, storage analysis, maintenance scanning, and rule-based diagnostics run locally. Meaningful actions remain under user control. Sysana Intelligence is a separate, user-initiated feature: when you press Send, the App Store edition transmits the question and compact diagnostic summary described in Section 2 over HTTPS.
The summary can include system percentages, category totals, diagnostic explanations, and top visible process names with resource values. It excludes document contents, photos, messages, passwords, complete file paths, and the Mac’s locally stored learning history. A random installation identifier held in Keychain is used to enforce three successful answers per UTC day. Failed model requests are rolled back and do not consume the allowance.
The App Store interface displays this cloud boundary before use. Sysana Pro may offer different intelligence and maintenance controls, which will be described in its release-specific notice and settings.
Product screenshots and interactive website demonstrations use sample content; they do not access a visitor’s real Mac diagnostics.
We keep information only as needed.
Retention depends on the information, purpose, sensitivity, legal requirements, and whether deletion is technically and commercially reasonable:
- Sysana Intelligence quota: a one-way hash derived from the random installation identifier and a daily count are kept until shortly after the UTC day ends. Sysana does not create a server-side conversation history for the App Store allowance.
- OpenAI API processing: Responses API application-state storage is disabled for these requests. OpenAI may retain default abuse-monitoring logs containing prompts and responses for up to 30 days unless a different approved data-control setting applies.
- Security and request logs: generally retained for a limited operational period determined by the relevant infrastructure configuration, then deleted or aggregated unless needed for an incident.
- Subscription and transaction records: retained while the subscription is active and afterward for accounting, tax, dispute, fraud-prevention, and legal-record requirements.
- Support and privacy correspondence: retained while the request is active and for a reasonable period afterward to document the response, identify recurring issues, or meet legal duties.
- Stripe data: retained by Stripe according to its policies and financial-services obligations.
- Backups: may persist for a limited cycle before being overwritten and ordinarily are isolated from routine use.
When information is no longer needed, we delete, de-identify, aggregate, or securely isolate it, unless law requires longer retention. A legal hold, dispute, security incident, or fraud investigation may extend an otherwise applicable period.
Protection without impossible promises.
We use administrative, technical, and organizational measures intended to protect personal information in light of its nature and risk. Current measures include HTTPS transport, server-only AI credentials, non-stored API responses, hashed quota identifiers, request-size and shape validation, server-enforced daily limits, hosted Stripe checkout, verification of signed Stripe webhooks, restricted download redirects, and limited collection.
No internet transmission, storage system, or security control is guaranteed to be completely secure. If you believe information associated with Sysana has been exposed or misused, contact security@sysana.app. Do not send passwords, full card details, or private files in the report.
Information may cross borders.
Sysana and its providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use an approved transfer mechanism—such as adequacy regulations, standard contractual clauses, or another lawful safeguard—and apply supplementary protections appropriate to the risk.
Contact us if you are entitled to information about the safeguard used for a specific transfer. Some details may be redacted to protect confidential or security-sensitive terms.
Access, correction, deletion, and control.
Depending on where you live and subject to legal exceptions, you may have rights to:
Confirm processing and receive a copy of eligible personal information.
Correct inaccurate or incomplete personal information.
Request deletion when information no longer needs to be kept.
Ask us to limit processing in qualifying circumstances.
Receive certain information in a structured, commonly used format.
Object to processing based on legitimate interests or to direct marketing.
Withdraw consent for future processing when consent is the basis.
Contact your local data-protection or consumer-protection authority.
To submit a request, email hello@sysana.app with the subject “Privacy Request.” Describe the right you want to exercise and the relevant interaction with Sysana. We may request information reasonably necessary to verify identity and authority. We will use verification information only for that purpose.
You may use an authorized agent where law permits. We may require proof of authorization and, where allowed, direct identity confirmation. We will not discriminate against you for exercising a privacy right. If we deny a request, we will explain the basis and available appeal or complaint options when required.
Additional information for California residents.
For purposes of the California Consumer Privacy Act, the categories of personal information we may have collected in the preceding 12 months are: identifiers; customer-record and commercial information; internet or other electronic-network activity; approximate location derived from IP; and correspondence-related inferences limited to understanding and responding to a request. Sources are you, your browser or device, Stripe and payment participants, and infrastructure or security providers.
We use and disclose these categories for the business purposes described in Sections 4 and 6. The recipient categories are service providers, contractors, payment participants, professional advisers, authorities, and transaction participants as applicable. We do not knowingly collect sensitive personal information through the public website for purposes requiring a right to limit its use.
Sysana has not sold personal information or shared it for cross-context behavioral advertising during the preceding 12 months and does not have actual knowledge that it has sold or shared personal information of anyone under 16. Therefore, the website does not display a “Do Not Sell or Share My Personal Information” link. If those practices change, we will provide required notices and opt-out mechanisms and recognize applicable opt-out preference signals such as Global Privacy Control.
California residents may request to know, access, correct, or delete covered information and may exercise applicable opt-out or limitation rights without discriminatory treatment. Use the request process in Section 13.
Not directed to children.
Sysana’s website and subscription offering are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the website. If local law sets a higher age for valid consent, we do not knowingly rely on a child’s consent below that age. If you believe a child provided personal information, contact us so we can investigate and delete it where required.
No solely automated legal decisions.
Sysana does not use personal information collected through the public website to make decisions based solely on automated processing that produce legal or similarly significant effects. Automated security tools may flag suspicious requests or payment risk, but payment providers may independently apply their own fraud systems and notices. Contact us if you believe an automated measure incorrectly affected your access to a Sysana-controlled service.
External services have their own terms.
The website links to Stripe and may redirect to an external download host. It may also link to email software or other external destinations selected by you. We do not control third-party privacy or security practices. Review their notices before providing information. A link does not mean Sysana endorses every practice of the linked service.
How to reach us.
We may update this policy to reflect changes in the service, providers, law, or data practices. We will update the date above and provide additional notice before a material change when required. If a change requires consent, it will apply only after valid consent is obtained.
SYSANA PRIVACYhello@sysana.appsecurity@sysana.appWebsite: sysana.appFor regulatory complaints, you may also contact the privacy or data-protection authority where you live. Please do not include passwords, full payment-card details, private documents, or unnecessary diagnostic data in an email.