Supra
LEGAL · PRIVACY

Privacy Policy

Version 1.2 · Effective September 2, 2026 · Last updated September 2, 2026

The short version. Supra’s CAD database and artifacts are local by default. The current free beta has no Supra account, entitlement, device-authorization, billing, or cloud-sync system. Website and installer delivery still expose ordinary network metadata to Vercel and GitHub. AI use is also not offline: prompts and selected engineering context are sent to the provider you configure. Supra does not currently run advertising or first-party behavioral analytics. Supported desktop credentials are encrypted through the operating system’s credential protection when available. Do not submit classified, export-controlled, patient, children’s, biometric, payment, or other sensitive data without an approved legal and security workflow.

1. Scope and operator

This Policy covers the Supra desktop application, its local backend, the website at supra.silviaai.dev, public downloads, update checks, configured Silvia relay features, and support communications. “Silvia AI,” “we,” or “us” means the operator of Supra. Supra is currently a pre-commercial beta. The operator has not yet published a complete contracting-entity name and postal address. For that reason, Supra must not be used for commercial, regulated, production, or safety-critical work until the operator identity and any legally required representative details are published and reviewed. Contact: hello@silviaai.dev.

This Policy does not govern independent third parties such as Anthropic, OpenAI, GitHub, Vercel, component suppliers, or sites you open. Their notices and your direct contracts govern their processing.

2. Data categories and where they come from

CategoryExamplesDefault location
Project and engineering contentPrompts, requirements, conversations, parameters, sketches, CAD source, STEP/mesh files, drawings, photos/scans, renders, simulations, BOMs, firmware, tool calls, measurements, checks, failures, verdicts, revisions, and provenance.Local application-data directory and user-selected export locations. Selected context is transmitted when an AI or remote feature is invoked.
Credentials and configurationAnthropic/OpenAI API keys, relay tokens and URLs, model selection, repository path, preferences, acceptance version, and update state.Local settings.json and browser local storage. Keys are not sent to Silvia AI when you connect directly to your chosen provider, but are sent to that provider for authentication.
Operational recordsLocal logs, errors, job state, token/cost estimates, latencies, artifact hashes, build and verifier metadata.Local files/database. Information you intentionally attach to a support email is received by Silvia AI and its email provider.
Website and download metadataIP address or provider-generated network identifiers, approximate region inferred by infrastructure, user agent, requested platform/build, artifact hash, timestamp, referrer, security and delivery logs.Processed by Vercel and GitHub for the website, public release delivery, and abuse prevention. We do not currently add first-party ad trackers.
CommunicationsEmail address, name or organization you provide, message, attachments, and support history.Email and support systems used to answer you.
Consent and session recordsLegal-document version, acceptance timestamp, and age/authority acknowledgements.The website stores clickwrap acceptance locally. The desktop stores supported provider credentials through operating-system credential protection when available.

We do not intentionally collect payment-card data, government identifiers, precise geolocation, biometric templates, health records, or children’s data through Supra. Engineering content can nevertheless contain personal or sensitive data if you put it there. You control that content and must minimize or de-identify it.

3. Purposes and legal bases

We and relevant service providers process data to: provide requested generation, editing, verification, storage, support, downloads, and updates; authenticate provider requests; maintain security; diagnose failures; estimate provider cost; preserve project history; meet legal obligations; prevent misuse; and improve Supra when you separately and explicitly opt in.

Where GDPR/UK GDPR-style law applies, the anticipated legal bases are: contract for requested product functions; legitimate interests for security, reliable delivery, fraud/misuse prevention, and product debugging balanced against user rights; legal obligation for required records or lawful requests; and consent only for genuinely optional processing presented through a separate choice. Acceptance of this Policy is acknowledgment, not blanket consent. You may refuse optional processing without losing unrelated functionality.

Supra does not currently use first-party project content to train shared models. A local trajectory may become locally eligible as an example only after explicit acceptance and verification. It is not uploaded for Silvia AI training unless a distinct opt-in names the data, purpose, recipients, and withdrawal method. Provider model-training practices are governed by your provider account and contract.

4. Recipients, disclosures, and international transmissions

Model providers

When you use an AI feature, Supra may send the minimum context selected by the workflow: instructions, conversation history, engineering constraints, source excerpts, tool schemas/results, measurements, and selected images, drawings, snapshots, or renders. Anthropic API, OpenAI API, or a configured relay processes that information and returns model output. Provider retention, abuse monitoring, training choices, and locations vary. Review Anthropic’s Privacy Center and OpenAI’s Privacy Policy. As of this Policy’s date, Anthropic states standard API inputs/outputs are generally deleted within 30 days subject to exceptions, and OpenAI states API business data is not used for training by default and is generally removed after 30 days subject to exceptions and endpoint settings. Provider terms may change; your account settings and contract control.

Infrastructure

Vercel hosts the public website; GitHub hosts public release notes and installer artifacts; email infrastructure handles support communications. These entities may process network identifiers and logs as independent controllers or processors under their own policies. A managed relay may process usage, prompts/context, outputs, timing, and billing/abuse signals as described when configured. It must not be enabled silently.

We may disclose information to professional advisers and authorities when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or complete a corporate transaction subject to appropriate confidentiality and notice where required. We do not sell personal information or share it for cross-context behavioral advertising. We do not provide data to data brokers.

Providers may process data outside your country, including the United States. Where legally required, transfers should use adequacy decisions, standard contractual clauses, or another valid mechanism. Because the beta has not yet published an EU/UK representative or a Silvia AI data-processing addendum, organizations requiring those instruments must not submit personal data until they are available.

5. Retention and deletion

Backups, synchronized folders, antivirus quarantine, crash dumps, and operating-system restore points may retain copies outside Supra’s control. Hashes or de-identified aggregate records may remain when they cannot reasonably identify a person.

6. Security and credentials

Supra uses a per-launch token to restrict its localhost API, a self-contained runtime, operating-system-backed secret storage where available, public release artifacts, artifact hashes, and release verification. No system is perfectly secure. Other programs running under your logged-in operating-system account, malware, administrators, backups, or a compromised browser session may still access credentials or project data. Use device encryption, a protected OS account, current security updates, dedicated provider keys with spend limits, and prompt credential rotation after suspected compromise. Never send a key in support mail or place it in project content.

Report suspected security or privacy issues to hello@silviaai.dev. Do not include exploit payloads containing third-party personal data.

7. Your choices and privacy rights

Depending on location and applicability, you may request access, correction, deletion, restriction, portability, or an explanation; object to processing based on legitimate interests or direct marketing; withdraw consent for future optional processing; appeal a refusal; and complain to a supervisory or consumer-protection authority. You will not be discriminated against for exercising applicable rights. We do not use Supra data to make solely automated decisions about people that produce legal or similarly significant effects.

Most product data is local and available directly to you. Requests concerning provider data must generally go to the provider controlling it. For Silvia AI requests, email hello@silviaai.dev with the request and country/state. We may verify identity and authority, minimize requested proof, and decline or limit a request where law permits. Authorized agents must show authority. You may lodge a complaint with the authority where you live or work or where an alleged infringement occurred.

You can clear the website’s local clickwrap record and delete local Supra application data and exports you control. Browser Global Privacy Control and Do Not Track signals do not change our current behavior because we do not sell data, share it for cross-context behavioral advertising, or run targeted-ad cookies. If that changes, we will honor legally required signals and present controls before collection.

8. Regional disclosures

California and similar U.S. state laws

In the preceding 12 months, the service may have handled identifiers/network activity, customer records you supplied, commercial/support information, professional or employment information embedded in projects, and inferences generated from engineering requests. Purposes and recipient categories are listed above. We do not knowingly sell or share personal information for behavioral advertising and do not knowingly process sensitive personal information to infer characteristics. If a state law applies, residents may have rights to know, access, correct, delete, obtain portability, opt out, limit, and appeal, subject to exceptions. We do not offer financial incentives for personal information.

EEA, UK, Switzerland and comparable jurisdictions

The transparency, bases, transfers, retention, and rights statements above are intended to supply the information typically required at collection. No DPO, EU representative, or UK representative is currently designated. This limits lawful offering to some organizations and is one reason regulated or commercial processing is prohibited during this beta. Mandatory local law prevails.

Business/customer-controlled data

If your organization determines why and how personal data in a project is processed, it may be the controller/business and may need a data-processing agreement, impact assessment, records, notices, security review, and vendor approval. The free beta does not currently provide a signed DPA, BAA, HIPAA-eligible configuration, FERPA commitment, government authorization, or regulated-cloud attestation.

9. Children

Supra is intended only for adults and is not directed to children. We do not knowingly collect personal information from anyone under 13 and do not authorize anyone under 18 (or the local age of majority, if higher) to download or use Supra. If you believe a child supplied information, contact us so it can be investigated and deleted where applicable. Do not place children’s data in projects.

10. Policy changes and contact

We may update this Policy as the product, providers, laws, or operator details change. The page identifies its version and date. Material changes affecting prior choices will be highlighted and, where required, presented for renewed acknowledgment or consent. Earlier versions will be preserved in source history. Contact Silvia AI at hello@silviaai.dev for privacy, legal, accessibility, or data requests.

Launch limitation: This is an implementation-ready beta disclosure, not a substitute for counsel. Before commercial worldwide launch, Silvia AI must publish its legal entity and postal address, determine establishment and representatives, document retention settings with each vendor, complete required DPAs/transfer assessments, and have qualified counsel adapt this Policy to actual markets and business practices.