Your Privacy Gap

Everything you have to hand over to get an answer — that is your Privacy Gap. Here is ours, shown before it is said:

Video poster: The Cable — 60 seconds, one unbroken take
The Cable — 60 seconds, one unbroken take. We unplug the network cable and keep working. Watch this — you'll know we're on your side. Video ships shortly — the poster frame is the plan, not a placeholder for hype.

The two modes, plainly

Local — zero gap. The default we recommend. The AI runs on your machine, over your files. In local mode your documents, your questions and your line of thinking never leave; in anonymised mode a stripped request does, and the paragraph below says exactly what. Locally there is nothing to log, nothing to subpoena, nothing to breach — and you can verify that on your own wire rather than take it from us.

Anonymised — reduced gap, not closed. When you genuinely need a frontier model, SCL strips your content before anything goes out. It exists for capability, not for privacy — and we will not pretend the remaining gap is nothing:

  • Requests are logged and retained by the provider, for periods and purposes set by them.
  • Policies change, and they change unilaterally — retention rules, training rules, tiers.
  • Logs can be breached, subpoenaed, or acquired along with the company.
  • Anonymised content is not anonymous behaviour. A researcher’s query pattern identifies them: an unusual intersection of topics, a distinctive vocabulary, a sequence of questions only one person in the world would ask. Stripping names from the text does not strip the fingerprint from the questions.

This is not about whether the providers are good people. It is about what their systems permit and what the incentives reward. Companies that promised not to do things have done them, repeatedly, and the promise was never the thing that stopped them.

A policy is a promise. Architecture is a fact.

What leaves your machine, and what doesn’t

  • Never: your PDFs, your annotations, your library structure, your local questions and answers. No mode, no setting and no opt-in changes that line.
  • Local mode: nothing about your work. Unplug the cable; keep working.
  • The exception, named rather than rounded down: SCL signs in to our licence service, and checks for updates. Those connections exist in every mode and carry no document content. We list them because a privacy page that says “nothing at all” and is then contradicted by a packet capture has taught you exactly the wrong lesson about us. Check it yourself →
  • If you write to us, that leaves — because you typed it and pressed send. A message contains your words and the boxes you ticked; no document content and no usage data ride along with it, and an email address only if you want an answer. The form says so on its face →
  • Anonymised mode: only the stripped request needed to answer the question you asked — and we publish, at behaviour level, exactly what that is.
  • Bring your own key: use your own OpenAI / Anthropic / Google account — or a fully local model — with a hard monthly cap you set.

The one thing that could change, and how you will know

We would like to know which features actually get used. The honest way to get that is to ask, so: optional, off by default, and not shipped yet — a weekly block of usage counters (how often a feature was used, never what it was used on) that would ride the sign-in SCL already makes. If it ships, you will see the exact payload in settings before anything is sent, the schema will be published on this page, and the answer stays no with no loss of function.

Two things we will not do: turn it on by default, and change this page after the fact. If the counters ever exist, these sentences change first — dated on the changelog — and the verification page is re-run against a build with sharing off. That ordering is the whole promise; the counters are a detail.

Want to know your own exposure? The $1 privacy analysis measures your Privacy Gap on your own content, locally, before anything goes anywhere.

Code signing

The current beta build is not yet code-signed — the certificate for ShortCut Linking, Inc. is in validation (expected late August 2026). Windows SmartScreen will warn you, and it should. We publish the SHA-256 of every build; verify before you run. We won’t open the public download until the build is signed.

Security contact: founder@shortcut-linking.com