Sajilo is designed to be local-first and account-free.
- Do not commit API keys, certificates, provisioning profiles, or local
.envfiles. - Do not log clipboard content, precise location, or personally identifying data.
- Use HTTPS for every remote data source.
- Request location or notification permission only after a user enables the related feature.
- Report security concerns privately to the repository owner rather than opening a public issue.