Vigil · Privacy
Privacy
The product principle
Vigil's entire design is that your home's sensing data is yours. Presence detection, room sensing, camera pose, and sensor-node readings are processed on your Mac. Raw audio, video, and CSI data are never transmitted off your network — and there is no sensing cloud behind the app to transmit them to. We run no server in that path, so we cannot see them, not merely as a policy but as a matter of how the app is built. Device discovery and control stay on your LAN.
The Mac app has no sign-in and needs no account to run: nothing in it contacts a server of ours, and it carries no analytics, crash-reporting or advertising SDK. It is not a claim that the app never opens a socket — it talks to your own LAN hardware constantly. Exactly one path can leave your network, and only if you turn it on: Away Alerts. Buying and downloading Vigil is separate, and runs through the website and checkout, described below.
Away Alerts — what leaves, and where it goes
Away Alerts is off until you configure it. Once you paste an endpoint URL — a free ntfy topic, a Pushover bridge, an Apple Shortcuts webhook, any HTTPS endpoint you control — a critical alert (a gated fall, an intrusion while armed) is POSTed to that endpoint so it reaches you when you're not at the Mac. The POST carries an alert title and message, which can include the resident name you entered. It does not carry audio, video, camera frames, or CSI data.
That endpoint is yours, not ours. We do not receive the alert and cannot see it, and whoever operates the URL you chose can. Non-critical events never trigger a POST, and if no endpoint is configured, nothing is sent at all. Vigil is self-monitored: it does not call a monitoring centre or dispatch emergency services.
What the website and checkout collect
Checkout: subscriptions run through Stripe. We receive the email you used at checkout, to deliver your sign-in and verify your subscription for support. Updates and licensing: handled on the website, not inside the app — the Mac app contains no update check and no licence call, so it never sends us a version, a licence key or a device identifier. Site analytics: we use PostHog (a US processor) to count page views and page exits on this website, so we can see which pages work. It stores a random identifier in your browser's local storage; it is pseudonymous, not tied to your name, and is never joined to anything from inside your home. We do not record your screen or session on this site, we do not run advertising or cross-site tracking, and we do not sell or share this data. To opt out entirely, turn on your browser's “Do Not Track” or block us.i.posthog.com — the site works exactly the same either way. This applies to the website only: the Mac app carries no analytics SDK at all.
Your account
Your account stores your checkout email and what you're entitled to download — nothing from inside your home.
What we never do
We don't sell or share your information, we don't receive your sensing data, we don't send your alerts anywhere except the endpoint you chose, and we don't send marketing you didn't ask for.
Questions or deletion
Reply to your receipt or delivery email, or see support. We'll delete your checkout details on request once your subscription is closed.