1. Scope and operator
This Policy covers the Supra desktop application, its local backend, the website at supra.silviaai.dev, public downloads, update checks, configured Silvia relay features, and support communications. “Silvia AI,” “we,” or “us” means the operator of Supra. Supra is currently a pre-commercial beta. The operator has not yet published a complete contracting-entity name and postal address. For that reason, Supra must not be used for commercial, regulated, production, or safety-critical work until the operator identity and any legally required representative details are published and reviewed. Contact: hello@silviaai.dev.
This Policy does not govern independent third parties such as Anthropic, OpenAI, GitHub, Vercel, component suppliers, or sites you open. Their notices and your direct contracts govern their processing.
2. Data categories and where they come from
| Category | Examples | Default location |
|---|---|---|
| Project and engineering content | Prompts, requirements, conversations, parameters, sketches, CAD source, STEP/mesh files, drawings, photos/scans, renders, simulations, BOMs, firmware, tool calls, measurements, checks, failures, verdicts, revisions, and provenance. | Local application-data directory and user-selected export locations. Selected context is transmitted when an AI or remote feature is invoked. |
| Credentials and configuration | Anthropic/OpenAI API keys, relay tokens and URLs, model selection, repository path, preferences, acceptance version, and update state. | Local settings.json and browser local storage. Keys are not sent to Silvia AI when you connect directly to your chosen provider, but are sent to that provider for authentication. |
| Operational records | Local logs, errors, job state, token/cost estimates, latencies, artifact hashes, build and verifier metadata. | Local files/database. Information you intentionally attach to a support email is received by Silvia AI and its email provider. |
| Website and download metadata | IP address or provider-generated network identifiers, approximate region inferred by infrastructure, user agent, requested platform/build, artifact hash, timestamp, referrer, security and delivery logs. | Processed by Vercel and GitHub for the website, public release delivery, and abuse prevention. We do not currently add first-party ad trackers. |
| Communications | Email address, name or organization you provide, message, attachments, and support history. | Email and support systems used to answer you. |
| Consent and session records | Legal-document version, acceptance timestamp, and age/authority acknowledgements. | The website stores clickwrap acceptance locally. The desktop stores supported provider credentials through operating-system credential protection when available. |
We do not intentionally collect payment-card data, government identifiers, precise geolocation, biometric templates, health records, or children’s data through Supra. Engineering content can nevertheless contain personal or sensitive data if you put it there. You control that content and must minimize or de-identify it.
3. Purposes and legal bases
We and relevant service providers process data to: provide requested generation, editing, verification, storage, support, downloads, and updates; authenticate provider requests; maintain security; diagnose failures; estimate provider cost; preserve project history; meet legal obligations; prevent misuse; and improve Supra when you separately and explicitly opt in.
Where GDPR/UK GDPR-style law applies, the anticipated legal bases are: contract for requested product functions; legitimate interests for security, reliable delivery, fraud/misuse prevention, and product debugging balanced against user rights; legal obligation for required records or lawful requests; and consent only for genuinely optional processing presented through a separate choice. Acceptance of this Policy is acknowledgment, not blanket consent. You may refuse optional processing without losing unrelated functionality.
Supra does not currently use first-party project content to train shared models. A local trajectory may become locally eligible as an example only after explicit acceptance and verification. It is not uploaded for Silvia AI training unless a distinct opt-in names the data, purpose, recipients, and withdrawal method. Provider model-training practices are governed by your provider account and contract.
4. Recipients, disclosures, and international transmissions
Model providers
When you use an AI feature, Supra may send the minimum context selected by the workflow: instructions, conversation history, engineering constraints, source excerpts, tool schemas/results, measurements, and selected images, drawings, snapshots, or renders. Anthropic API, OpenAI API, or a configured relay processes that information and returns model output. Provider retention, abuse monitoring, training choices, and locations vary. Review Anthropic’s Privacy Center and OpenAI’s Privacy Policy. As of this Policy’s date, Anthropic states standard API inputs/outputs are generally deleted within 30 days subject to exceptions, and OpenAI states API business data is not used for training by default and is generally removed after 30 days subject to exceptions and endpoint settings. Provider terms may change; your account settings and contract control.
Infrastructure
Vercel hosts the public website; GitHub hosts public release notes and installer artifacts; email infrastructure handles support communications. These entities may process network identifiers and logs as independent controllers or processors under their own policies. A managed relay may process usage, prompts/context, outputs, timing, and billing/abuse signals as described when configured. It must not be enabled silently.
We may disclose information to professional advisers and authorities when reasonably necessary to comply with law, protect rights or safety, investigate misuse, or complete a corporate transaction subject to appropriate confidentiality and notice where required. We do not sell personal information or share it for cross-context behavioral advertising. We do not provide data to data brokers.
Providers may process data outside your country, including the United States. Where legally required, transfers should use adequacy decisions, standard contractual clauses, or another valid mechanism. Because the beta has not yet published an EU/UK representative or a Silvia AI data-processing addendum, organizations requiring those instruments must not submit personal data until they are available.
5. Retention and deletion
- Local projects, settings, credentials, logs, caches, and consent records: retained on your device until you delete them. Uninstalling may leave per-user application data so reinstalls can recover projects. Delete the Supra application-data folder and user-selected exports/backups to remove them.
- Model-provider data: retained under your provider plan and settings; deletion from Supra does not delete provider copies. Use the provider’s controls or contact it.
- Website, download, and security logs: retained by infrastructure providers and Silvia AI under configured policies and legitimate security/operations needs. Delivery logs may be retained to investigate abuse, fraud, and malware distribution.
- Support communications: retained while resolving the request and afterward as reasonably needed for security, legal obligations, dispute records, and service improvement, then deleted or de-identified.
- Legal and transaction records: retained as required to establish or defend rights, handle refunds or chargebacks, comply with tax/accounting law, or document acceptance.
Backups, synchronized folders, antivirus quarantine, crash dumps, and operating-system restore points may retain copies outside Supra’s control. Hashes or de-identified aggregate records may remain when they cannot reasonably identify a person.
6. Security and credentials
Supra uses a per-launch token to restrict its localhost API, a self-contained runtime, operating-system-backed secret storage where available, public release artifacts, artifact hashes, and release verification. No system is perfectly secure. Other programs running under your logged-in operating-system account, malware, administrators, backups, or a compromised browser session may still access credentials or project data. Use device encryption, a protected OS account, current security updates, dedicated provider keys with spend limits, and prompt credential rotation after suspected compromise. Never send a key in support mail or place it in project content.
Report suspected security or privacy issues to hello@silviaai.dev. Do not include exploit payloads containing third-party personal data.
7. Your choices and privacy rights
Depending on location and applicability, you may request access, correction, deletion, restriction, portability, or an explanation; object to processing based on legitimate interests or direct marketing; withdraw consent for future optional processing; appeal a refusal; and complain to a supervisory or consumer-protection authority. You will not be discriminated against for exercising applicable rights. We do not use Supra data to make solely automated decisions about people that produce legal or similarly significant effects.
Most product data is local and available directly to you. Requests concerning provider data must generally go to the provider controlling it. For Silvia AI requests, email hello@silviaai.dev with the request and country/state. We may verify identity and authority, minimize requested proof, and decline or limit a request where law permits. Authorized agents must show authority. You may lodge a complaint with the authority where you live or work or where an alleged infringement occurred.
You can clear the website’s local clickwrap record and delete local Supra application data and exports you control. Browser Global Privacy Control and Do Not Track signals do not change our current behavior because we do not sell data, share it for cross-context behavioral advertising, or run targeted-ad cookies. If that changes, we will honor legally required signals and present controls before collection.
8. Regional disclosures
California and similar U.S. state laws
In the preceding 12 months, the service may have handled identifiers/network activity, customer records you supplied, commercial/support information, professional or employment information embedded in projects, and inferences generated from engineering requests. Purposes and recipient categories are listed above. We do not knowingly sell or share personal information for behavioral advertising and do not knowingly process sensitive personal information to infer characteristics. If a state law applies, residents may have rights to know, access, correct, delete, obtain portability, opt out, limit, and appeal, subject to exceptions. We do not offer financial incentives for personal information.
EEA, UK, Switzerland and comparable jurisdictions
The transparency, bases, transfers, retention, and rights statements above are intended to supply the information typically required at collection. No DPO, EU representative, or UK representative is currently designated. This limits lawful offering to some organizations and is one reason regulated or commercial processing is prohibited during this beta. Mandatory local law prevails.
Business/customer-controlled data
If your organization determines why and how personal data in a project is processed, it may be the controller/business and may need a data-processing agreement, impact assessment, records, notices, security review, and vendor approval. The free beta does not currently provide a signed DPA, BAA, HIPAA-eligible configuration, FERPA commitment, government authorization, or regulated-cloud attestation.
9. Children
Supra is intended only for adults and is not directed to children. We do not knowingly collect personal information from anyone under 13 and do not authorize anyone under 18 (or the local age of majority, if higher) to download or use Supra. If you believe a child supplied information, contact us so it can be investigated and deleted where applicable. Do not place children’s data in projects.
10. Policy changes and contact
We may update this Policy as the product, providers, laws, or operator details change. The page identifies its version and date. Material changes affecting prior choices will be highlighted and, where required, presented for renewed acknowledgment or consent. Earlier versions will be preserved in source history. Contact Silvia AI at hello@silviaai.dev for privacy, legal, accessibility, or data requests.