1. Scope and operator
This Policy covers the Supra desktop application, its local backend, the website and account portal at supra.silviaai.dev, authentication, entitlement and authorized-computer controls, protected downloads, optional cloud sync, update checks, configured Silvia relay features, and support communications. “Silvia AI,” “we,” or “us” means the operator of Supra. Supra is currently a pre-commercial beta. The operator has not yet published a complete contracting-entity name and postal address. For that reason, Supra must not be used for commercial, regulated, production, or safety-critical work until the operator identity and any legally required representative details are published and reviewed. Contact: hello@silviaai.dev.
This Policy does not govern independent third parties such as Anthropic, OpenAI, GitHub, Vercel, component suppliers, or sites you open. Their notices and your direct contracts govern their processing.
2. Data categories and where they come from
| Category | Examples | Default location |
|---|---|---|
| Project and engineering content | Prompts, requirements, conversations, parameters, sketches, CAD source, STEP/mesh files, drawings, photos/scans, renders, simulations, BOMs, firmware, tool calls, measurements, checks, failures, verdicts, revisions, and provenance. | Local application-data directory and user-selected export locations. Selected context is transmitted when an AI or remote feature is invoked. |
| Account and entitlement data | Email address, display and company name, date of birth (used only to confirm you are 18 or older, and not shown on your profile), account identifier, email-verification state, plan, subscription state, access dates, enabled features, and password-authentication records. Silvia AI does not receive your plaintext password. | Supabase Auth and the dedicated Supra account database. Password reset and verification messages are delivered through configured email infrastructure. |
| Authorized-computer data | A one-way device hash, computer label, operating system, app version, activation and last-seen times, revocation state, device limit, and security events. | Supra account database. The hardware inputs used to derive the hash remain on the device. |
| Optional cloud projects | Project name, owner, version number, content hash, encrypted transport, object path, size, timestamps, and project payload. | Not uploaded by default. Stored in a private object bucket only after you explicitly enable cloud sync for that project. |
| Credentials and configuration | Anthropic/OpenAI API keys, relay tokens and URLs, model selection, repository path, preferences, acceptance version, and update state. | Local settings.json and browser local storage. Keys are not sent to Silvia AI when you connect directly to your chosen provider, but are sent to that provider for authentication. |
| Operational records | Local logs, errors, job state, token/cost estimates, latencies, artifact hashes, build and verifier metadata. | Local files/database. Information you intentionally attach to a support email is received by Silvia AI and its email provider. |
| Website and download metadata | IP-derived keyed hash, approximate region inferred by infrastructure, user agent, requested platform/build, account identifier, artifact hash, timestamp, referrer, security and delivery logs. | Processed by Vercel and Supabase for the website, protected release delivery, and abuse prevention. We do not currently add first-party ad trackers. |
| Communications | Email address, name or organization you provide, message, attachments, and support history. | Email and support systems used to answer you. |
| Consent and session records | Legal-document version, acceptance timestamp, age/authority acknowledgements, short-lived access token, and refresh token. | The website stores clickwrap acceptance locally and keeps the current browser session in session storage. Authentication tokens are processed by Supabase. The desktop stores supported long-lived secrets through operating-system credential protection when available. |
We do not intentionally collect payment-card data, government identifiers, precise geolocation, biometric templates, health records, or children’s data through Supra. Engineering content can nevertheless contain personal or sensitive data if you put it there. You control that content and must minimize or de-identify it.
3. Purposes and legal bases
We and relevant service providers process data to: provide requested generation, editing, verification, storage, support, downloads, and updates; authenticate provider requests; maintain security; diagnose failures; estimate provider cost; preserve project history; meet legal obligations; prevent misuse; and improve Supra when you separately and explicitly opt in.
Where GDPR/UK GDPR-style law applies, the anticipated legal bases are: contract for requested product functions; legitimate interests for security, reliable delivery, fraud/misuse prevention, and product debugging balanced against user rights; legal obligation for required records or lawful requests; and consent only for genuinely optional processing presented through a separate choice. Acceptance of this Policy is acknowledgment, not blanket consent. You may refuse optional processing without losing unrelated functionality.
Supra does not currently use first-party project content to train shared models. A local trajectory may become locally eligible as an example only after explicit acceptance and verification. It is not uploaded for Silvia AI training unless a distinct opt-in names the data, purpose, recipients, and withdrawal method. Provider model-training practices are governed by your provider account and contract.
4. Recipients, disclosures, and international transmissions
Model providers
When you use an AI feature, Supra may send the minimum context selected by the workflow: instructions, conversation history, engineering constraints, source excerpts, tool schemas/results, measurements, and selected images, drawings, snapshots, or renders. Anthropic API, OpenAI API, or a configured relay processes that information and returns model output. Provider retention, abuse monitoring, training choices, and locations vary. Review Anthropic’s Privacy Center and OpenAI’s Privacy Policy. As of this Policy’s date, Anthropic states standard API inputs/outputs are generally deleted within 30 days subject to exceptions, and OpenAI states API business data is not used for training by default and is generally removed after 30 days subject to exceptions and endpoint settings. Provider terms may change; your account settings and contract control.
Infrastructure
Vercel hosts the public website and account API; Supabase provides authentication, row-level-secured account records, and private object storage; GitHub may host public release notes and open artifacts; email infrastructure delivers verification, recovery, and support communications. These entities may process network identifiers and logs as independent controllers or processors under their own policies. A managed relay may process account identifiers, usage, prompts/context, outputs, timing, and billing/abuse signals as described at activation. It must not be enabled silently.
We may disclose information to professional advisers and authorities when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or complete a corporate transaction subject to appropriate confidentiality and notice where required. We do not sell personal information or share it for cross-context behavioral advertising. We do not provide data to data brokers.
Providers may process data outside your country, including the United States. Where legally required, transfers should use adequacy decisions, standard contractual clauses, or another valid mechanism. Because the beta has not yet published an EU/UK representative or a Silvia AI data-processing addendum, organizations requiring those instruments must not submit personal data until they are available.
5. Retention and deletion
- Local projects, settings, credentials, logs, caches, and consent records: retained on your device until you delete them. Uninstalling may leave per-user application data so reinstalls can recover projects. Delete the Supra application-data folder and user-selected exports/backups to remove them.
- Account, entitlement, subscription, and device records: retained while the account is active and afterward as needed for security, chargebacks, tax/accounting, legal claims, and reactivation. Revoked devices remain auditable for a limited security period rather than disappearing immediately.
- Cloud project content: retained until you delete the project or account, subject to backup expiry, legal holds, and recovery windows disclosed when cloud sync launches. Turning sync off stops future uploads but does not itself delete versions already stored.
- Model-provider data: retained under your provider plan and settings; deletion from Supra does not delete provider copies. Use the provider’s controls or contact it.
- Website, download, and security logs: retained by infrastructure providers and Silvia AI under configured policies and legitimate security/operations needs. Download events may be retained to investigate account sharing, fraud, and malware distribution.
- Support communications: retained while resolving the request and afterward as reasonably needed for security, legal obligations, dispute records, and service improvement, then deleted or de-identified.
- Legal and transaction records: retained as required to establish or defend rights, handle refunds or chargebacks, comply with tax/accounting law, or document acceptance.
Backups, synchronized folders, antivirus quarantine, crash dumps, and operating-system restore points may retain copies outside Supra’s control. Hashes or de-identified aggregate records may remain when they cannot reasonably identify a person.
6. Security and credentials
Supra uses a per-launch token to restrict its localhost API, a self-contained runtime, operating-system-backed secret storage where available, private storage buckets, row-level database security, expiring download URLs, device caps, artifact hashes, and release verification. No system is perfectly secure. Other programs running under your logged-in account, malware, administrators, backups, or a compromised browser session may still access credentials or project data. Use unique passwords, multi-factor authentication when offered, device encryption, a protected OS account, current security updates, dedicated provider keys with spend limits, and prompt credential rotation after suspected compromise. Never send a key in support mail or place it in project content.
Report suspected security or privacy issues to hello@silviaai.dev. Do not include exploit payloads containing third-party personal data.
7. Your choices and privacy rights
Depending on location and applicability, you may request access, correction, deletion, restriction, portability, or an explanation; object to processing based on legitimate interests or direct marketing; withdraw consent for future optional processing; appeal a refusal; and complain to a supervisory or consumer-protection authority. You will not be discriminated against for exercising applicable rights. We do not use Supra data to make solely automated decisions about people that produce legal or similarly significant effects.
Most product data is local and available directly to you. Requests concerning provider data must generally go to the provider controlling it. For Silvia AI requests, email hello@silviaai.dev with the request and country/state. We may verify identity and authority, minimize requested proof, and decline or limit a request where law permits. Authorized agents must show authority. You may lodge a complaint with the authority where you live or work or where an alleged infringement occurred.
You can sign out to clear the browser session, revoke an authorized computer from the account page, keep cloud sync disabled, and request account deletion. Deleting an account may terminate downloads and managed services immediately; export any cloud work first. Browser Global Privacy Control and Do Not Track signals do not change our current behavior because we do not sell data, share it for cross-context behavioral advertising, or run targeted-ad cookies. If that changes, we will honor legally required signals and present controls before collection.
8. Regional disclosures
California and similar U.S. state laws
In the preceding 12 months, the service may have handled identifiers/network activity, customer records you supplied, commercial/support information, professional or employment information embedded in projects, and inferences generated from engineering requests. Purposes and recipient categories are listed above. We do not knowingly sell or share personal information for behavioral advertising and do not knowingly process sensitive personal information to infer characteristics. If a state law applies, residents may have rights to know, access, correct, delete, obtain portability, opt out, limit, and appeal, subject to exceptions. We do not offer financial incentives for personal information.
EEA, UK, Switzerland and comparable jurisdictions
The transparency, bases, transfers, retention, and rights statements above are intended to supply the information typically required at collection. No DPO, EU representative, or UK representative is currently designated. This limits lawful offering to some organizations and is one reason regulated or commercial processing is prohibited during this beta. Mandatory local law prevails.
Business/customer-controlled data
If your organization determines why and how personal data in a project is processed, it may be the controller/business and may need a data-processing agreement, impact assessment, records, notices, security review, and vendor approval. The free beta does not currently provide a signed DPA, BAA, HIPAA-eligible configuration, FERPA commitment, government authorization, or regulated-cloud attestation.
9. Children
Supra is intended only for adults and is not directed to children. We do not knowingly collect personal information from anyone under 13 and do not authorize anyone under 18 (or the local age of majority, if higher) to download or use Supra. If you believe a child supplied information, contact us so it can be investigated and deleted where applicable. Do not place children’s data in projects.
10. Policy changes and contact
We may update this Policy as the product, providers, laws, or operator details change. The page identifies its version and date. Material changes affecting prior choices will be highlighted and, where required, presented for renewed acknowledgment or consent. Earlier versions will be preserved in source history. Contact Silvia AI at hello@silviaai.dev for privacy, legal, accessibility, or data requests.