Privacy
Privacy Policy
The short version: we do not operate a cloud backend that receives your work. Processing is local, with named research and software-delivery requests described below.
In one sentence
Matter processing and generation run on your device. Named legal-data providers receive the searches you run; model and update providers receive software metadata requests, without matter documents or generated work.
We don't see or control your data
There is no Supra AI account, server, or cloud backend that receives your work. Your matter documents, prompts, embeddings, chats, and generated work product are created and stored on your Mac. We have no way to read, collect, or control any of it.
Everything runs on your device
Generation, document extraction and indexing, embeddings, semantic search, drafting, and timekeeping run locally on your machine. The app does not send matter content to Supra AI or to a cloud-generation service.
Your work is not sent for model training
Supra AI has no account or cloud-generation backend that receives prompts, documents, or generated work. Local models arrive pre-trained; model downloads request provider artifacts without attaching matter content.
Research requests you run
Legal-research and public-records searches send the query fields required by the named provider: CourtListener, official statutes and regulations sources, SEC EDGAR, the CFPB complaint database, or the NLRB. Application tests require these request builders to omit matter documents, prompts, and generated work.
Searches you can see and adjust
Research searches are sent as ordinary query terms — the words and connectors that make up the search — which you can review and adjust before and after you run them. You choose which connectors to enable; several need no key at all, and any API keys you add are stored in the macOS Keychain and sent only to the provider they belong to.
Local audit-log privacy
Raw legal query terms are omitted from local request logs by default and replaced with per-install keyed pseudonyms. You can opt in to raw local logging and can remove stored query markers from Diagnostics.
Protection at rest
Supra AI does not add application-level encryption to its SQLite database, managed document copies, model files, or exports. Protection at rest depends on macOS account controls, the permissions of destinations you choose, and FileVault when enabled.
Software downloads and updates
Model setup requests revision-bound metadata and model artifacts from named Hugging Face origins. When enabled, Sparkle checks the signed Supra AI update feed and may fetch its signed update. These clients do not attach matter content or legal-data credentials.
No application telemetry
The application contains no analytics or telemetry client and sends no prompt, document, legal query, or usage event to Supra AI.
This website
This site is static, hosted on GitHub Pages. It sets no cookies and runs no analytics or tracking. As host, GitHub may log ordinary technical request data such as IP addresses to operate the service.