SkimSpeakRead the Privacy Notice

Trust and evidence · Preview

Show the check.
Show the gap.

Privacy promises deserve evidence tied to the app people download. See what we plan to check, how, and where the gaps are.

First release evidence gate

Two behaviors to observe in the shipped app

The test must start from the exact signed and notarized macOS artifact offered to customers. A source test alone does not pass it.

CONSENT-01

Before consent

Not evaluated

Attempt a summary with synthetic text before provider consent and observe the signed app’s network activity.

Passing observation: No inference request is observed inside the declared network boundary.

VERBATIM-01

100% verbatim

Not evaluated

Invoke a 100% verbatim read with synthetic text and observe the same signed app’s network activity.

Passing observation: No inference request is observed inside the declared network boundary.

Unknown traffic, missing observation coverage, a timeout, or a mismatched artifact leaves the result incomplete. A provider request in either case fails the check.

Source assertion catalog

The broader questions are still open

Eight macOS source assertions were defined for an exact code revision. They have not been assessed as a complete set, and a source result would not by itself describe the installed app.

  • EGRESS-01Outbound connections have a declared purpose.Not evaluated
  • CONSENT-02Provider consent precedes a summary request.Not evaluated
  • VERBATIM-03Verbatim reading avoids the summary provider.Not evaluated
  • ALLOWLIST-04Runtime model routes come from an approved set.Not evaluated
  • REDACT-05The local redaction pass precedes provider serialization.Not evaluated
  • BOUND-06Over-limit source is refused rather than silently truncated.Not evaluated
  • AUDIO-07Generated audio is released or deleted after a run.Not evaluated
  • IDENT-08Reader metadata stays out of provider payloads.Not evaluated

These are bounded source questions, not a claim that every secret can be detected, that all device traffic is controlled, or that a provider keeps no data.

How a result earns its place

A claim needs a subject and a boundary

Exact subject

Identify the version, source revision, artifact digest, signing identity, and platform actually examined.

Visible method

Publish the synthetic case, observation window, tool versions, decision rule, and any traffic the observer could not classify.

Honest state

Show passed, failed, stale, and incomplete results separately. A new build or changed route needs fresh evidence.

What a passing result would not establish

A bounded publisher-run test would not be an independent audit, security certification, guarantee about every device, or proof of a third-party provider’s retention practices. A signature can authenticate a record; it cannot make its observation complete or true.