Security & privacy
Lyra's whole design is to keep your data with you. This page is an honest account of what we do โ and, just as importantly, what we don't claim. Where something is planned rather than achieved, we label it Planned.
Data residency
- Local by default. Local models run entirely on your Mac. In local mode nothing is transmitted โ it works in airplane mode.
- Optional cloud pipeline โ Australia. If you turn on Lyra's cloud pipeline (paid plans), it runs on servers in Sydney, Australia, handled in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- Bring-your-own-key (BYOK). When you connect a cloud model with your own key, that request goes from your device to the provider you choose (e.g. Anthropic, OpenAI, Google) โ which may be hosted overseas. We don't proxy or store that traffic.
What leaves your device โ and what doesn't
| Mode | What's sent | Where |
|---|---|---|
| Local models | Nothing โ processed on-device | Your Mac |
| Cloud pipeline (paid) | Your query, after PII redaction | Sydney, AU |
| BYOK cloud model | Your query (redaction applied first) | The provider you choose |
PII detection & redaction (Presidio)
Before any optional cloud call, personal identifiers โ names, emails, phone numbers, TFNs, Medicare numbers, dates of birth and financial data โ are detected and redacted using Microsoft Presidio, and sensitive queries default to on-device models.
Honest caveat: automated PII detection is best-effort, not a guarantee. No detector catches 100% of every identifier in every phrasing. Treat cloud mode accordingly, and keep the most sensitive work on local models.
Sub-processors
Third parties that may process data on our behalf when you use the optional cloud features:
| Sub-processor | Purpose | Region |
|---|---|---|
| Vultr | Cloud pipeline hosting | Sydney, AU |
| Stripe | Subscription payments | United States |
| Cartesia | Text-to-speech (Voice tier) | United States |
| Anthropic / OpenAI / Google | Cloud LLMs โ only when you enable BYOK | Provider's region |
| Transactional email provider | Download links & account email | United States |
We keep this list current as our stack changes; material additions are posted here.
Retention & deletion
- On-device data (chats, local memory) lives on your Mac โ you control it; deleting the app removes it.
- Cloud-pipeline memory can be cleared from within Lyra at any time.
- Account & download-lead records are retained while your account is active, then deleted within 30 days of account closure (redacted operational logs are also kept no longer than 30 days).
- Request deletion or a copy of your data via the security contact below.
Data processing agreement (DPA)
Businesses can request our DPA. Email raj@pdvr.com.au with "DPA request" and we'll send it over.
Security contact & responsible disclosure
Found a vulnerability? Please report it to raj@pdvr.com.au. We'll acknowledge and work with you on a fix; please give us reasonable time before public disclosure.
Assurance status
We will not claim certifications we don't hold. Current status, stated plainly:
- Local-first architecture In place โ most work never leaves your Mac.
- Signed Mac download In place โ Developer-ID signed & Apple-notarized.
- Essential Eight self-assessment Planned โ target Q4 2026.
- Independent penetration test Planned โ target Q1 2027.
- Portable, cryptographically signed audit log (Trust Envelope) Planned โ a tamper-evident record of every action, portable across your tools. Wiring it into every Lyra action is in progress, but the open specification and verifier are available now, Apache-2.0 licensed, so you don't have to take our word for any of it.
๐ Verify any Lyra action yourself. The Trust Envelope uses RFC 8785 canonicalisation + SHA-256 + Ed25519 signatures over a hash-chained ledger. Everything is open and independently checkable: try the interactive demo โ (generate โ sign โ verify โ tamper, entirely in your browser) or read the source & spec on GitHub.
Download Lyra free โ