Privacy
SQZ's programs work on your computer and don't send anything anywhere unless you tell them to back up to cloud storage. This page covers what each program connects to and stores, and what this website collects.
The programs#
| Program | Connects to the internet | What it stores |
|---|---|---|
sqz | Only when you use an s3:// backup repository, and then only to the storage service you set up (AWS or the endpoint in SQZ_S3_ENDPOINT). | The archives and backup repositories you create, where you put them. |
sqz-extract | Never. | Only the files you extract. |
| Windows right-click menu | Never. It runs sqz on the files you pick. | Its menu entries, in your user's registry. |
| SQZ Backup app | Never by itself. It runs the bundled sqz, so it connects only if a plan's repository is in cloud storage (the app doesn't offer that yet). | Plans and history as JSON in %APPDATA%\sqz-backup or ~/Library/Application Support/sqz-backup; passwords in Windows Credential Manager or the macOS Keychain; one scheduled task per plan. |
The programs above have no telemetry, no crash reporting, no update check and no account. We checked the source for this: the only network code in sqz is the S3 client, and the desktop app has no network code at all. Its window may load only its own files. The optional conversation vault is different, and is described below.
Conversation vault and public connection (preview)#
The conversation vault saves AI conversations you choose to keep in an encrypted SQZ repository, so an assistant such as ChatGPT or Claude can search them for you. It is a preview and is built into the SQZ Backup app under Connect your AI (how to use it). It has three ways to connect, and they differ in what leaves your computer:
| Connection | What passes through, and where |
|---|---|
| Codex on this computer | Nothing leaves your computer. |
| ChatGPT in a browser (temporary tunnel) | The app downloads a tunnel helper from Cloudflare when needed. Requested message text passes through Cloudflare to the assistant while the tunnel is on. |
Public SQZ (connect.sqzatlas.com) | Your computer makes an outbound connection to the SQZ relay. Requested message text passes through the relay to the assistant. Details below. |
In every mode the conversations themselves stay in the storage you picked (a local folder, a synced cloud folder or an S3 bucket), encrypted by SQZ. Only your password or recovery key unlocks them, and the password never leaves your computer. When an assistant searches or reads a conversation, the text it asks for is sent to that assistant, and the assistant's own data handling then applies. Save only what you want to keep, and don't put anything in a vault that you wouldn't want an assistant to read.
What the public relay does and stores#
The relay is a small service run by us on DigitalOcean, with a PostgreSQL database. It is not end-to-end encrypted: to answer a request it sees the message text it forwards, in memory, for as long as the request takes. It does not store that text, conversation titles or search queries, and it never sees your vault password.
- Per computer: a random installation ID, a one-way hash of its secret, and the time it registered. No name, email address or account.
- Sign-in records: the assistant connections you approve and their access tokens, stored encrypted. Access renews automatically for up to 30 days and ends sooner when you disconnect in the app.
- Usage counts: per day (UTC), how many computers registered and paired, how many desktop connections were made, and how many save, search and retrieve requests were made, with no content. We also record which installation IDs were active on which day, so we can count daily, weekly and monthly active computers. The daily list of active IDs is deleted after 400 days. The daily totals are kept.
- Network addresses: the relay does not store them. To limit sign-ups it keeps recent addresses in memory only, and they are gone when the service restarts. DigitalOcean, which hosts the relay, may keep its own request logs under its own terms.
- What we use it for: running the service, preventing abuse and seeing how much it is used. We don't sell it, share it or use it for advertising.
Files. If you ask an assistant to save an image or PDF, the file passes through the relay to your computer in small pieces, in memory, and is not stored there. The relay checks its type and size and counts the save in the usage counts, without content. On your computer the file is stored encrypted in your vault, and text extracted from a PDF is sent to an assistant only when it reads that file back.
To stop the relay from serving your computer, choose Disconnect in the app, which revokes your access tokens. To have your installation record removed as well, email hello@hanki.tools and include the connection address from the app.
Your backups#
Backup repositories are encrypted on your computer before anything is written, including to cloud storage. The storage provider sees encrypted files of roughly the sizes you store, and never your file names or contents. Only your password or recovery key can unlock them. We can't read them or recover them for you. See the Security model.
.sqz archives are not encrypted. Anyone who has an archive can open it.
This website#
- Analytics. sqzatlas.com and these docs use Microsoft Clarity to see how visitors use the pages, such as clicks, scrolling and which pages are read, but only if you accept it in the cookie banner. Nothing from Clarity loads until you do. You can change your choice any time with Cookie settings at the bottom of every page. Clarity sets cookies. Its data is handled under Microsoft's privacy statement.
- Fonts are loaded from Google Fonts, so your browser contacts Google's font servers.
- Downloads are ordinary files. The web host may log requests as web servers do, but we don't ask for any details to download.
Who we are#
SQZ is made by Iikka Amos Isosaari, business ID FI31038263, Finland. Contact: hello@hanki.tools.
Email#
If you write to hello@hanki.tools, we use your message and address only to reply. Don't send passwords, recovery keys or files you want kept private.