How Sightline handles your data
Sightline is a desktop app. Observation records stay on your computer, not on our servers, and during ordinary use the app never automatically transmits a student record to us or to any cloud AI provider. This page shows where records are stored, what the app does send, and how to verify all of it yourself. The legal version is the Privacy Policy.
Where records are stored
Student, session, note, transcript, and drafted write-up records are stored in Sightline's local database on your computer. Voice dictation is transcribed on your machine and the audio is then discarded. Exports go wherever you choose to save them. We operate no cloud storage for your records and no sync service, so we cannot read, recover, or delete them for you. Records leave your machine only when you export or send them yourself.
If you observe from your iPhone, the observation stays on the phone until it syncs to your desktop over encrypted Bluetooth. The phone deletes its copy after your desktop confirms the transfer arrived intact. Details in the companion privacy note.
Encryption at rest
Your records are protected by FileVault on macOS or BitLocker on Windows when disk encryption is on. Sightline checks FileVault and warns you in Settings if it is off or cannot be confirmed. There is no equivalent check on Windows yet, so confirm BitLocker with your IT team.
Accounts and access
Buying Sightline creates a license account with us. It holds your email address and subscription, and never a student record. The app itself has no login. Your license key lives in your operating system's keychain, and access to your records is your OS login, the same one that protects everything else on your computer. There is no Sightline password.
On-device AI
Write-up drafting and pattern analysis run on models stored on your machine and work without an internet connection. Observations are processed on your hardware, not sent to a provider. There is no API key.
Model and adapter downloads
We release new models and improved adapters over time. Each one is a file download you choose to start, from our servers or Hugging Face's. The request for a tuned adapter carries your license key and, on trials, a device fingerprint. It never carries observation data.
Our adapters are fine-tuned on synthetic observation cases we wrote ourselves, never on real students' records.
Signed updates
The app asks our update server for the latest release and includes your license credential so the server offers the right build for your tier. Your machine compares versions locally and never sends anything about your records. An update installs only if its cryptographic signature is valid, so a tampered build will not install.
Every connection the app makes
These are the destinations in the shipping build. Watch the network yourself with Little Snitch or any monitor. Large model downloads redirect to Hugging Face's content delivery network, so the final download host can vary by region.
| Why it connects | Hosts | What it sends |
|---|---|---|
| License validation, at activation and periodically | api.keygen.sh | License key, machine fingerprint. |
| Trial issuance, once when a free trial starts | license.sightlinebehavior.com | Hashed device identifier, app version. |
| License heartbeat, each launch of a licensed copy | heartbeat.sightlinebehavior.com | License key, machine fingerprint, app version, first-activation date. |
| Update check, periodic | updates.sightlinebehavior.com | License key, or updater passport and machine hash. Version comparison happens on your machine. |
| Billing portal, when you manage your subscription | billing.sightlinebehavior.com | License key and machine fingerprint, to open your subscription page in your browser. |
| Model & adapter downloads, at your direction | huggingface.co models.sightlinebehavior.com Hugging Face CDN (dynamic hosts) | A file request, plus your license key (and on trials a device fingerprint) for tuned adapters. |
| Usage analytics, off unless you turn it on | us.i.posthog.com | Allowlisted screen and feature events, an installation identifier, app version, subscription tier. The allowlist excludes names, notes, and observation content. |
| Crash reports, off unless you turn them on | *.ingest.us.sentry.io | Stack traces and allowlisted error-class names, scrubbed of names, notes, and observation content. |
| Feedback, only when you click submit | feedback.sightlinebehavior.com | The text you wrote, your email if you add it, and the diagnostics bundle if you choose to attach it after reviewing it. |
None of these connections transmits your observation content. Feedback is the only one that sends text you author, and it sends only what you enter, when you submit it. The Hugging Face CDN hostnames are resolved at download time.
The hashed device identifier exists to stop repeat free trials. It identifies only the device, and is not derived from your name, your email, or your records. The Privacy Policy explains why we keep it.
Customer data we hold
Selling software means holding some customer data: your license records (key, tier, machine fingerprint, activation history), billing email and transaction records with Stripe, the trial ledger's hashed device identifier, usage and crash reports with an installation identifier if you opt in, and any mail you send us. The Privacy Policy lists every category.
None of the fields Sightline collects automatically is drawn from observation records. You control what you put in support and feedback messages, so leave student details out. If the data we hold is ever breached, we will notify you as the law requires, and faster where we can.
Audits and certifications
Sightline does not have a SOC 2 report today. Our servers handle licensing, updates, billing, and model delivery, and student records do not reach them during ordinary use. If your district's review requires a control-by-control answer, write to us and we will go through it with you.
FERPA
FERPA binds your district, not the software, so no app is "FERPA compliant" by itself, and marketing one that way is misleading. Ordinary use of Sightline gives us no access to education records. There is no copy of them on our servers to manage, so there is no school-official designation to make. Your district still evaluates and approves the software under its own policies.
Records stay on devices you control, and we do not use them for advertising, model training, or resale. State student-privacy laws and district policies may impose approval steps or agreements even when no student data reaches us. Your district decides which apply, and keeps its usual authority over access, consent, retention, and disclosure. If your district or state requires a signed student-data privacy agreement, we will sign it.
HIPAA
HIPAA binds covered entities and their business associates, not applications. Protected health information does not reach us through any automatic connection, and a vendor without access to PHI is not a business associate, so in ordinary use there is no BAA to sign. Whether HIPAA applies to your practice is a question for your counsel. This page states what the product does.
If you are a covered entity in private practice, the records on your computer stay in your scope, and the shared responsibility matrix names who owns each safeguard.
If the licensing service is ever discontinued
Paid features validate a license against our servers periodically. If we permanently discontinue the licensing service, the terms commit us to ship an update that keeps paid features working through your paid term, or to refund the unused portion. Your records and the free tier are unaffected either way. Neither depends on our servers.
Reporting a vulnerability
Email support@sightlinebehavior.com with the subject "[SECURITY] Private vulnerability report". Leave student records and exploit details out of the first message and we will arrange a secure channel. We aim to acknowledge reports within three business days and coordinate disclosure with you.