Privacy Policy
Last updated October 11, 2026
Sill collects nothing. There is no account and no server: your screen and what you type travel only between your own devices, and Sill never sends anything about you to the developer.
This policy covers the Sill app for iPhone and iPad and Sill for Mac.
The short version
- No account and no sign-in.
- No analytics, ads or tracking, and no code from third parties (SDKs) in either app.
- No servers. Sill on your iPhone or iPad talks only to Sill on your own Mac.
- Once a day Sill for Mac asks GitHub whether a newer version is out. Sill sends only its version number and a fixed language (“en”), and GitHub sees the IP address of your Mac, as with any website. You can turn this off.
- If you test Sill through TestFlight, or let your iPhone or iPad share analytics with app developers (Settings › Privacy & Security › Analytics & Improvements), Apple may give the developer crash reports from Sill. Sill itself sends nothing.
What travels between your devices
Sill connects your iPhone or iPad straight to your own Mac, in one of these ways:
- over your local network, such as your Wi-Fi at home;
- over a USB cable between the two;
- over peer-to-peer Wi-Fi, when Direct Wireless Connection is on;
- through your own VPN, or a port you forward on your router, when Remote Access is on.
Sill sends nothing to the developer.
From your Mac to your iPhone or iPad
- The picture of the window you pick, or of your desktop.
- The name of your Mac, its open windows with their titles and small previews, and the apps installed on it with their icons.
- The menus of the app you’re using, read from its menu bar: their titles while you’re connected, and a menu’s items, with their shortcuts and which ones are checked or turned off, when you open that menu on your iPhone or iPad.
- The shape of the pointer and, while it is over what you’re looking at, where it is.
- Sill’s streaming settings, and whether the connection keeps up with them.
- Which version of Sill for Mac it runs.
From your iPhone or iPad to your Mac
- Your taps, clicks, scrolls, three-finger gestures, keys and typed text.
- Which window to show, which app to open, and window commands such as close or minimize.
- The size of the area that shows your Mac, and the scale and frame rate it wants.
- Changes you make in Sill’s settings panel.
- Which of the app’s menus to show, and the menu items you choose.
- While it’s connected, once a second, a short report: the frame rate, how long frames and replies took, and the device’s name and model, such as “iPad (iPad14,1)”. iOS gives apps a generic name like “iPad”, not the name you gave your device.
- When it connects, which version of Sill it runs, so your Mac can say when the app needs an update to keep working with it.
When you pair a device, your Mac and the device exchange their names, the device’s model and their public keys, and each keeps what it needs to recognize the other and to connect again later. When a device connects over a USB cable, your Mac also reads its serial number and keeps only a code made from it, never the number itself: the code lets your Mac recognize that iPhone or iPad the next time it is on the cable, so that the cable never pairs a second key for the same device by itself.
While Remote Access is on, your Mac also tells the devices you paired the addresses it can be reached at from other networks, such as its VPN address, and they keep them to connect from there.
Every connection between your devices and your Mac is encrypted with TLS 1.3. Once a device is paired, each end also checks that the other holds the key it paired with.
Who can connect
Only the iPhones and iPads you pair can connect to your Mac. You pair each one once: your Mac shows a code for the device to scan or type, or, over a USB cable while your Mac is unlocked, the device pairs by itself. You can remove any of them in Sill’s Settings › Devices on your Mac.
If you turn off Require pairing there, any iPhone or iPad with Sill on the same network, or nearby while Direct Wireless Connection is on, can connect to your Mac without pairing, see it and control it, and so can any app on your Mac. The connection is still encrypted. Leave it on unless you trust everyone on your network.
With Remote Access on, the devices you paired can also connect from other networks, through your own VPN or a port you forward on your router.
Update check
Sill for Mac checks for updates. Unless you turn off “Check for updates automatically” in Sill’s Settings › General, once a day it asks GitHub (api.github.com) whether a newer version of Sill has been released, and again whenever you click Check Now. Like any visit to a website, that request shows GitHub the IP address of your Mac, and it says which version of Sill you have (for example “Sill/1.0”) and gives a fixed “en” as its language. Sill sends nothing else: no identifiers, no cookies, nothing about your devices or what you stream. The developer receives nothing from these checks; GitHub’s privacy statement covers what GitHub keeps. Sill never downloads or installs anything by itself.
The iPhone and iPad app checks for nothing: the App Store updates it. It does tell your Mac which version of Sill it runs when it connects, so that your Mac can say when the app needs an update to keep working with it.
What stays on your devices
Each app keeps a few things on the device it runs on. None of it is sent to the developer or to anyone else, beyond what travels between your devices (above) and what your Mac advertises on your network so they can find it: its name and whether it requires pairing.
On your iPhone or iPad
- For each Mac, the order you put its windows in.
- The names of Mac computers it has seen with Direct Wireless Connection on, so it knows to look for them nearby.
- Which parts of the tour of Sill’s controls you have seen, and whether you skipped it, so it shows you only what you haven’t seen.
- Whether three-finger gestures are on.
- The Mac computers you paired: each one’s name, key and addresses, and when it last connected.
- This device’s pairing key, in its keychain. It isn’t synced, and it works only on this device: a backup can put it back on this same iPhone or iPad, never on another.
On your Mac
- Sill’s settings.
- A log of what Sill did, in the Library/Logs/Sill folder in your home folder. It includes window and app names, the menu items and three-finger gestures chosen from a device, device names and network addresses. It stays on your Mac unless you send it to someone, and Sill keeps at most two log files of 10 MB each.
- In your Mac’s keychain, in a part that only Sill can read and that is never synced or moved to another Mac: its keys, the devices you paired (each one’s name, model and key, when and how it paired, and for one that connected over a USB cable the code made from its serial number) and whether pairing is required. With Sill’s settings: when each device last connected, and how.
Permissions
On your Mac
- Screen Recording, to show the windows you pick on your iPhone or iPad. Nothing is recorded or saved.
- Accessibility, so your iPhone or iPad can click, scroll and type on your Mac and choose from its menus, and so Sill can move and size the window it shows.
- Local Network, so your iPhone and iPad can find your Mac.
On your iPhone or iPad
- Local Network, to find your Mac and connect to it.
- Camera, only to scan the pairing code your Mac shows. Nothing the camera sees is saved or sent.
You can turn any of these off at any time: in System Settings › Privacy & Security on your Mac, and in Settings › Privacy & Security on your iPhone or iPad.
Deleting your data
The developer holds no data about you, so there is nothing to ask for or delete on the developer’s side. To remove what Sill keeps on your devices:
- On your iPhone or iPad, delete the Sill app. What it kept goes with it, except that iOS may keep its pairing key in the device’s keychain. On your Mac, remove the device in Sill’s Settings › Devices, and the key no longer lets it in.
- To forget one Mac you paired, touch and hold its row on the connect screen and choose Forget.
- On your Mac, quit Sill and move it to the Trash. Delete the Sill folder in Library/Logs in your home folder. To remove its settings, run
defaults delete me.saffer.sill.macin Terminal. - Sill’s keys and the list of devices you paired stay in your Mac’s keychain, where only Sill can read them, so remove each device in Sill’s Settings › Devices before you quit Sill for the last time.
- If you used Remote Access with Sill for Mac 0.3.1 or earlier, also open Keychain Access and delete the key “Sill Remote Access” and the passwords for “me.saffer.sill.remote” in your login keychain.
Changes
When this policy changes, this page changes with it, and the date at the top says when.
Contact
Sill is made by Noah Saffer. For questions about privacy, email support@getsill.app.