Security & Data

Where your data lives, how we protect it, and which providers receive it.

Effective August 16, 2026

Local-first by design

Security in Mach Studio starts with data minimization. When you select an on-device model, model inference and chat content stay on your Mac. Chats, files, and agent memory are stored locally by default, while account services and network-backed capabilities you enable or invoke may connect to their respective services.

Where your data lives

  • On your Mac. Chats, prompts, generated artifacts, and agent memory are stored locally (for example, in a SQLite database within your user data directory) and protected by your operating system's account and disk-level protections.
  • In cloud services, when a feature requires a connection. Hosted inference, connected integrations, web-backed tools, Channels, account services, updates, and permitted analytics may contact Syzygy or third-party services. Content needed to perform an explicit remote action is sent to that service; account and operational metadata may also be exchanged while the relevant service is enabled. We do not collect Mach Studio usage analytics from Europe.

Encryption

Traffic between the app, our services, and our providers is encrypted in transit using industry-standard TLS. Persistent databases and object storage use the storage protections supplied by their hosting providers. Temporary queues, caches, and third-party services apply their own controls, so we minimize the content sent to and retained in those systems.

Integration credentials

When you connect a third-party tool, access is authorized through that provider using OAuth where available. Connection credentials are handled securely and used only to perform the tasks you initiate. You can revoke a connection at any time from the app or from the third-party provider.

Infrastructure and access controls

We limit production credentials to the services and operators that need them, use provider identity and access controls, and review dependencies and deployment configuration as part of release work.

Service providers and network destinations

The providers involved depend on the features you use. Current named providers and their purposes include:

  • Supabase — authentication, account and organization data, operational databases, and desktop release storage and distribution.
  • Vercel — hosting for the public website and account dashboard, website traffic analytics, and routing for Mach Studio product analytics.
  • Fly.io — hosting for Syzygy Gateway and the Mach Studio integrations, browser-session, and remote-control APIs.
  • Upstash — Redis queues, caches, and rate-limit state.
  • Stripe — payments, subscriptions, invoices, usage billing, and related fraud prevention.
  • Resend — workspace invitation email when that feature is used.
  • Cloudflare Turnstile — abuse-prevention challenges on account authentication and recovery forms when enabled.
  • Google and GitHub — optional identity providers when you choose either provider for account sign-in or identity linking.
  • Composio — authorization and tool execution for third-party integrations you connect.
  • Browserbase — hosted browser sessions you explicitly start through the managed browser capability.
  • Exa — web search and page extraction requests you ask the agent to perform through the managed web tools.
  • PostHog — pseudonymous product analytics. We do not send Mach Studio usage analytics from Europe. Outside Europe, Mach Studio sends only content-free allowlisted events unless analytics are turned off in Settings. Account-dashboard analytics are a separate opt-in.
  • OpenRouter — routing for hosted model requests that use Syzygy Gateway; the underlying model provider also processes that request.
  • User-selected inference providers — including Vercel AI Gateway or a custom OpenAI-compatible endpoint — receive prompts and outputs when you configure and select them in Mach Studio.
  • Hugging Face — a user-directed source for model catalog searches, metadata, and model files you ask Mach Studio to retrieve.

Some providers process data on our behalf, while providers behind a feature you choose may operate under their own terms and privacy policies. We update this page when the provider set materially changes. Questions can be sent to support@withsyzygy.com.

Data you control

You can delete on-device conversations or clear Mach Studio app data directly. For data held in our hosted Services, you can use available deletion controls or request access or deletion as described in our Privacy Policy. Third-party providers may require a separate request under their policies.

Reporting a vulnerability

We welcome reports from the security community. If you believe you have found a security vulnerability, please email support@withsyzygy.com with details and steps to reproduce. We will acknowledge your report, investigate promptly, and keep you informed. Please give us a reasonable opportunity to remediate before any public disclosure, and avoid accessing or modifying other users' data while testing.

Incident response

If we learn of a security incident affecting personal information, we will evaluate it and notify affected users and regulators as required by applicable law.

Contact us

For security questions or reports, email support@withsyzygy.com.