# Security Policy

Peerscy runs entirely on your machine. This file is the short technical
counterpart to the public [Security & Trust page](https://revyoutech.org/security),
which has the full threat model and itemised network/storage paths.

## Data Storage

All app data lives in `~/.peerscy/` (Linux/macOS) or `%LOCALAPPDATA%\peerscy\`
(Windows), with owner-only permissions where supported (0700 directories,
0600 files):

- `settings.json` — preferences; license key/instance ID and trial timestamps
  (only if you used a trial or a license).
- `models/` — downloaded GGUF models and optional vision projectors.
- `conversations/session.json`, `autosave.json` — message text, extracted
  document text, the file paths of attached documents, and any **images you
  attach** (stored base64). Original document files are **not** copied.
- `prompts/` — built-in review templates and any custom prompts you create.

Images rendered from document pages for vision are **not** persisted. Temporary
files (e.g. `peerscy_pdfium`, `peerscy_soffice`, `peerscy-projector-*`) are
created under the OS temp directory for PDF rendering and document conversion.

## Network Requests

Peerscy has **no telemetry** (no analytics, crash reporting, or accounts). It
contacts the network only in the following cases:

- **Model downloads** — when you choose to download a model, from HuggingFace
  (`huggingface.co`).
- **Optional web & literature tools** — **off by default**; when enabled, your
  query is sent to the service you use: OpenAlex, Europe PMC, arXiv, PubMed,
  Semantic Scholar, or Crossref (DOI resolution), or to the page you ask it to
  read. The page reader blocks requests to private IP ranges, loopback
  addresses, and cloud metadata endpoints.
- **Update check** — the app asks GitHub (`api.github.com`) for the latest
  release tag at most once per day. No personal data is sent. This can be
  disabled in Settings ("Update check").
- **License activation/validation** — only when you activate Pro; only the
  license key is sent to LemonSqueezy (`api.lemonsqueezy.com`).

Opening links (GitHub, this site, checkout) hands off to your browser.

## Verifying Releases

Each release ships `SHA256SUMS` and its GPG signature `SHA256SUMS.asc`. The
public key and verification commands are on the
[Security & Trust page](https://revyoutech.org/security).

## Reporting Vulnerabilities

Please email **info@revyoutech.org**. Do not open a public GitHub issue for
exploitable problems before we have had a chance to respond.

## Known Dependency Advisories

| Crate | RUSTSEC | Severity | Status |
|-------|---------|----------|--------|
| `genpdf` → `lopdf` v0.26.0 | RUSTSEC-2026-0187 | HIGH | Awaiting genpdf upstream release |
| `docx-rs` → `quick-xml` v0.36.2 | RUSTSEC-2026-0194/0195 | HIGH | Awaiting docx-rs upstream release |
| `office2pdf` → `quick-xml` v0.37.5 | RUSTSEC-2026-0194/0195 | HIGH | Awaiting office2pdf upstream release |
| `meval` v0.2.0 | (unmaintained) | LOW | Used only for calculator tool (simple math expressions) |

These vulnerabilities affect document export features (PDF, DOCX) and the web
search tool. They are accepted risks until upstream crates release fixes. The
`crossbeam-epoch` advisory (RUSTSEC-2026-0204) is resolved via `cargo update` to
>= 0.9.20.

## Build-Time

- PDFium binaries are downloaded from `https://github.com/bblanchon/pdfium-binaries`
  during `cargo build` and embedded into the application binary.
- GGUF models are downloaded from HuggingFace at runtime when the user adds a
  model.
