Privacy, in plain words.
Your conversations live on your devices. Here’s what that means, and where the boundaries are.
Updated October 5, 2026
Private messaging
Shui sends messages and attachments over end-to-end encrypted connections between participating devices. Conversation history is stored locally. Shui does not provide a cloud inbox or a centrally hosted copy of your conversation history.
Connections and relays
Devices connect directly when possible. When a direct connection cannot be established, relay infrastructure can carry encrypted traffic. Encryption protects message contents; a relay still handles network connections. This is not a promise of anonymity or an absence of network metadata.
Identity and verification
Your messaging identity is generated on your Mac. Keys are kept in your Keychain, without an email address, phone number or iCloud sign-in for messaging. Attachments are checked against their content hashes on arrival to detect corruption. Encryption and integrity checks do not protect a compromised device or prevent a recipient from sharing what they receive.
Local history
Participating peers keep local conversation history and received files. Storage depends on available disk space. Delivery depends on reachable peers. Back up your Mac, and only invite people you intend to share with.
Optional AI
Optional user-created AI agents use the provider you configure. If you choose a remote provider, prompts and the context included in those requests leave your Mac and are handled under that provider’s privacy policy. Apple’s on-device models and local providers offer local options. AI requests are separate from encrypted peer messaging.
Licensing
Optional Pro purchases and license validation use Polar. Purchase and license data are handled separately from your conversations. A Pro license can be activated on up to 3 Macs; the app contacts Polar to activate and validate it. Polar’s policies apply to that information.
This website and downloads
This website sets no tracking cookies and includes no analytics scripts. Fonts and the product-tour preview are served locally. The product tour automatically loads a muted, looping YouTube player from youtube-nocookie.com and its playback controls from YouTube. YouTube may process viewing data under its own privacy policy. With reduced motion enabled, the player loads only when you press play. You can pause the tour at any time. The hosting provider may process ordinary request information, such as IP addresses, to serve the site. Links to builds, releases and support lead to GitHub, where GitHub’s policies apply.
Ask us
Have a question about these boundaries? Open an issue on GitHub.