Peerscy

Security & Trust

Peerscy runs locally. This page documents exactly what it does with your data, what it sends over the network, how updates work, and how you can verify a download.

Principles

Threat model

What Peerscy protects against

What Peerscy does not protect against

Assumptions

Network paths

Every outbound request the app can make. Nothing else is contacted.

ServiceWhenDefaultWhat is sent
HuggingFace
huggingface.co, /api
Downloading a model; browsing recommended modelsOnly when you use itThe repo/query (no manuscript data)
GitHub
api.github.com
Update checkAutomatic, at most once per 24 h — can be turned offNothing but a version query
Optional web & literature tools: OpenAlex, Europe PMC, arXiv, PubMed, Semantic Scholar, Crossref/DOIOnly when you enable tools and use themOffYour search query / DOI / URL
Page reader (read_url)Only when a tool reads a page you requestOffThe page URL (private/loopback and cloud-metadata addresses are blocked)
LemonSqueezy
api.lemonsqueezy.com
Only when you activate or validate a Pro licenseOnly on activationYour license key (no manuscript data)

Storage

All app data lives in ~/.peerscy/ (Linux/macOS) or %LOCALAPPDATA%\peerscy\ (Windows), with owner-only permissions where the OS supports it (0700 directories, 0600 files).

PathContents
settings.jsonPreferences; license key/instance ID and trial timestamps (if you used a trial or license).
models/Downloaded GGUF models and optional vision projectors.
conversations/session.json, autosave.jsonMessage text, extracted document text, the file paths of documents you attach, and any images you attach. Original files are not copied.
prompts/Built-in review templates (regenerated on update) and any custom prompts you create.

Temporary files (e.g. peerscy_pdfium, peerscy_soffice, projector caches) are created under the OS temp directory for PDF rendering and document conversion. Images rendered from document pages for vision are not persisted. Deleting models or conversations removes them from disk.

How updates work

Verify a download

Each release ships a SHA256SUMS file and its GPG signature SHA256SUMS.asc.

# Linux / macOS
sha256sum -c SHA256SUMS
gpg --import peerscy.gpg.asc          # public key (below)
gpg --verify SHA256SUMS.asc SHA256SUMS

# Windows (PowerShell), per file:
(Get-FileHash .\peerscy-windows-x86_64.zip -Algorithm SHA256).Hash
Signing key
RevyouTech <[email protected]>
Fingerprint: 4371 A574 2F34 9E18 C51B  C3AE B3C8 616B 157E F715
Download public key (peerscy.gpg.asc)

Verify an offline run

  1. Download a model once (this is the only step that needs the network).
  2. Disconnect networking (turn off Wi-Fi / unplug Ethernet), and optionally disable the update check in Settings.
  3. Open a local PDF and run a review — it completes with the network off.
  4. Optionally confirm nothing is connecting out:
    # Linux
    ss -tupn | grep -i peerscy   # or: lsof -i -a -c peerscy
    
    # macOS
    lsof -i -a -c peerscy        # or use the built-in "nettop"
    
    # Windows: Resource Monitor → Network, or:
    netstat -bno | findstr /i peerscy

Sub-processors

Third parties the app or website may contact, and why: GitHub (release hosting + update check), HuggingFace (model downloads), LemonSqueezy (license/payment processing, once Pro is on sale), Cloudflare (website hosting/DNS). No analytics or advertising providers are used.

Reporting

Found something? Email [email protected]. Please do not post exploit details publicly before we have a chance to respond.

Last reviewed: 2026-10-02 · See also the Privacy Policy.