Security & Trust
Peerscy runs locally. This page documents exactly what it does with your data, what it sends over the network, how updates work, and how you can verify a download.
Principles
- Runs locally with your own model. Your manuscripts never leave your machine for the review itself.
- No telemetry — no analytics, no crash reporting, no account.
- The network is used only for things you trigger, or that you can turn off.
Threat model
What Peerscy protects against
- Uploading confidential manuscripts to cloud LLM services (retention, training on your data, mishandling).
- Leaking documents through API keys or third-party accounts.
- Silent data collection: there is no telemetry path at all.
What Peerscy does not protect against
- A compromised operating system, malware, or someone with access to your device (data is stored locally, in the clear).
- Untrusted model files. GGUF models you download from third parties (e.g. HuggingFace) are treated as untrusted input — only run models you trust.
- Metadata seen by third parties when you use the optional tools, the update check, or model downloads.
- Bugs in third-party components (see SECURITY.md for known advisories).
Assumptions
- Your OS and the local model runtime are trusted.
- Model output is not authoritative — always review it critically.
Network paths
Every outbound request the app can make. Nothing else is contacted.
| Service | When | Default | What is sent |
|---|---|---|---|
HuggingFacehuggingface.co, /api | Downloading a model; browsing recommended models | Only when you use it | The repo/query (no manuscript data) |
GitHubapi.github.com | Update check | Automatic, at most once per 24 h — can be turned off | Nothing but a version query |
| Optional web & literature tools: OpenAlex, Europe PMC, arXiv, PubMed, Semantic Scholar, Crossref/DOI | Only when you enable tools and use them | Off | Your search query / DOI / URL |
Page reader (read_url) | Only when a tool reads a page you request | Off | The page URL (private/loopback and cloud-metadata addresses are blocked) |
LemonSqueezyapi.lemonsqueezy.com | Only when you activate or validate a Pro license | Only on activation | Your license key (no manuscript data) |
Storage
All app data lives in ~/.peerscy/ (Linux/macOS) or %LOCALAPPDATA%\peerscy\ (Windows), with owner-only permissions where the OS supports it (0700 directories, 0600 files).
| Path | Contents |
|---|---|
settings.json | Preferences; license key/instance ID and trial timestamps (if you used a trial or license). |
models/ | Downloaded GGUF models and optional vision projectors. |
conversations/session.json, autosave.json | Message text, extracted document text, the file paths of documents you attach, and any images you attach. Original files are not copied. |
prompts/ | Built-in review templates (regenerated on update) and any custom prompts you create. |
Temporary files (e.g. peerscy_pdfium, peerscy_soffice, projector caches) are created under the OS temp directory for PDF rendering and document conversion. Images rendered from document pages for vision are not persisted. Deleting models or conversations removes them from disk.
How updates work
- The app asks GitHub for the latest release tag at most once per day, only on a normal launch (never on the first run). No personal data is sent.
- There is no auto-download and no auto-install — you download and replace the app yourself.
- You can turn the check off entirely in Settings → "Update check"; the manual Check for updates action still works.
Verify a download
Each release ships a SHA256SUMS file and its GPG signature SHA256SUMS.asc.
# Linux / macOS
sha256sum -c SHA256SUMS
gpg --import peerscy.gpg.asc # public key (below)
gpg --verify SHA256SUMS.asc SHA256SUMS
# Windows (PowerShell), per file:
(Get-FileHash .\peerscy-windows-x86_64.zip -Algorithm SHA256).Hash
RevyouTech <[email protected]>
Fingerprint:
4371 A574 2F34 9E18 C51B C3AE B3C8 616B 157E F715Download public key (peerscy.gpg.asc)
Verify an offline run
- Download a model once (this is the only step that needs the network).
- Disconnect networking (turn off Wi-Fi / unplug Ethernet), and optionally disable the update check in Settings.
- Open a local PDF and run a review — it completes with the network off.
- Optionally confirm nothing is connecting out:
# Linux ss -tupn | grep -i peerscy # or: lsof -i -a -c peerscy # macOS lsof -i -a -c peerscy # or use the built-in "nettop" # Windows: Resource Monitor → Network, or: netstat -bno | findstr /i peerscy
Sub-processors
Third parties the app or website may contact, and why: GitHub (release hosting + update check), HuggingFace (model downloads), LemonSqueezy (license/payment processing, once Pro is on sale), Cloudflare (website hosting/DNS). No analytics or advertising providers are used.
Reporting
Found something? Email [email protected]. Please do not post exploit details publicly before we have a chance to respond.
Last reviewed: 2026-10-02 · See also the Privacy Policy.