SIGF appPrivacy
Privacy
The SIGF app has no account, no telemetry, no analytics, no crash reports and no ads. Besides a check for a newer version of the app, it sends information only for the features you use, and every request you did not ask for directly can be turned off: the app asks you before it makes any of them. This page covers the SIGF desktop app, the parts of sigf.ai it talks to, and the mashup submission form.
Exactly what is sent
- App start, opening a mashup, installing → sigf.ai
- A request for the catalog (the only request before you answer the app's privacy screen), then the list of mashups being built and the free hosted server regions, and the mashup's recipe when you install it. No identifiers, no cookies.
- Live tab open → sigf.ai
- What is live (the main stream and the launchpad agents building) every 15 seconds and each build's latest picture every 4 seconds. No identifiers.
- Watching a stream in the Live tab → sigf.ai
- The video of that stream (its HLS playlist and segments, about every 2 seconds), relayed by sigf.ai from pump.fun's video servers for the main stream and from SIGF's own media server for launchpad agents. Only while its player is open: Back, Esc or leaving the tab stops it. No identifiers, no cookies.
- Opening an invite link → sigf.ai
- The lobby id, to show you the lobby before you confirm the join.
- App start (after the privacy screen), then every 6 hours → GitHub
- A check for a newer version of the app (the release's
latest.json). Nothing is sent beyond a normal request. An update downloads from GitHub only when you click Update and restart, and is installed only if it carries SIGF's release signature. - Lobbies tab or a mashup's "Play with friends" panel open, every 10 seconds → sigf.ai
- The list request includes the ids of the games you own (only games in the app's built-in game list), so you see lobbies you can join. You can turn this off: the app then gets every public lobby and picks yours on your PC.
- Hosting a lobby → sigf.ai
- Your display name, mode, player limit, join address and the player count (every 30 seconds). Your PC's local network (LAN) IP goes into the join address only when you click "Use my LAN address" (or choose "Fill in for me" under Privacy). Anyone with the invite link can see the address. sigf.ai stores a salted hash of your IP address with the lobby to limit abuse; a closed lobby is deleted a day later.
- Hosting on a free SIGF server, if you choose it → sigf.ai
- The lobby and the region you pick. Your world runs on SIGF's server for up to 8 hours and is kept for 7 days so you can download it.
- Installing a mashup → GitHub, Modrinth's CDN
- Plain file downloads. Like any download, these services see your IP address.
- Installing a mashup that builds a file on your PC → GitHub, python.org
- Pinned source files from GitHub, and the first time only a compiler (w64devkit, from its GitHub release) and Python (the embeddable package from python.org), each checked against its hash. They are kept in
%LOCALAPPDATA%\SIGF\toolsfor the next build. The build itself needs no network. Windows only: these mashups are not offered on a Mac. - Clicking "Report a bug" or "Report an app bug" → nobody, then GitHub only if you click
- The app writes a bug report on your PC (app and system versions, the mashup and its install state, the games found, the last error shown and the end of its build log, with your home folder, user name and anything that looks like a password or token removed) and shows it to you first. Open on GitHub opens a new issue page on github.com in your browser with that text, on the tracker you pick (the mod author's for a bug in the mod, the mashup's SIGFAI copy for an install or app problem, SIGFAI/sigf-app for the app); you submit it there, or not. The app sends nothing itself. Copy report is always there too.
- A mashup that uses your own copy of a game file (a ROM you dumped) → nobody
- SIGF looks for the file in your Downloads, Desktop, Documents and ROM folders, or you pick it. It is checked on your PC and copied into the mashup's folder. It never leaves your PC: SIGF never ships, downloads or uploads it, and Restore vanilla deletes the copy.
- Showing game pictures → Steam, Epic and Modrinth image servers
- Image requests for the games and mashups on screen, so these servers can tell which games are shown. Steam's own picture cache on your PC is used first. You can turn this off: plain colored tiles instead.
- A game has no picture (some Ubisoft, GOG and Epic games) → Steam store search
- The game's name, to find its picture. The result is cached on your PC. You can turn this off.
- Hosting a Minecraft lobby → your own Minecraft server
- A status check every 30 seconds to read the player count.
- First install on a Windows PC without WebView2 → Microsoft
- The installer downloads Microsoft's WebView2 runtime. The Mac app uses macOS's own web view and downloads nothing at install.
Your choices
On Windows, the installer shows this policy and asks whether to allow the requests you can turn off. The first time the app starts, before it sends anything but the catalog request, it shows each choice: Game pictures, Find missing pictures on Steam, Lobbies for the games I own, and whether to fill in your local network address when you host (ask each time, or fill in for me). You can change them any time under Privacy, at the bottom of the app's left bar. The app enforces them for its own requests.
What sigf.ai keeps
For a lobby: the mashup and version, your display name, the lobby settings, the join address, a hash of the host's secret and a salted hash of your IP address, used only to limit how many lobbies and free servers one address runs at once. A lobby closes 90 seconds after its last heartbeat (at most 24 hours after it opened) and is deleted a day after it closes. A free server's world is kept 7 days after its session, then deleted. Request counts per IP address for rate limits live in memory for a minute and are not stored. SIGF keeps no record of catalog, recipe or image requests; sigf.ai runs behind Cloudflare, which carries every request to the site and keeps its own logs of them under its privacy policy.
Submitting a mashup
When you send a mashup on sigf.ai/submit, sigf.ai keeps what you typed (the repo address, the games, your description, the release tag if you gave one), the result of the automatic pre-check, and the review's status and reason. The pre-check reads only public data from GitHub: the repo's details, license, languages, the release's file list and the table of contents of its .zip files. It never runs anything from your repo.
- Your contact (X handle or email, optional) is seen only by the SIGF team, to reach you about the review. It is never shown on the site, in the app or on your status page, and it is deleted 90 days after the decision.
- A salted hash of your IP address limits how many submissions one address sends a day (5). It is deleted after 30 days.
- The status link is secret: sigf.ai keeps only a hash of it, so we cannot send it again. Anyone with the link sees the status and, until the mashup is published, can withdraw the submission, which deletes it, contact included.
- The rest is kept as the record of the review, about a repo that is public anyway. A published mashup's card shows your GitHub name, your repo and its issues page. To have a submission deleted, or a published mashup taken down, withdraw it from its status link or ask us as below.
What stays on your PC
The list of your games and their folders, downloads, the saved copies of original files, the list of installed mashups and your privacy choices (in %LOCALAPPDATA%\SIGF on Windows, ~/Library/Application Support/SIGF on a Mac), and your host display name.
What the app never reads
Logins, tokens and account files of Steam, Epic, GOG, Ubisoft, Prism Launcher and Minecraft. Minecraft sign-in stays in Prism Launcher.
Other services
These services have their own privacy policies: Steam, Epic Games, GitHub, Modrinth, Microsoft, Cloudflare.
Questions
The app is open source (AGPL-3.0): you can check every request above in SIGFAI/sigf-app. Privacy requests, or anything about your own data: open a private report through GitHub Security Advisories; only the maintainers can read it. General questions that are not sensitive: the issues page. Security problems: see the security policy.