Transparency

What leaves
your Mac.

Most privacy pages are written to be defensible. This one is written to be checked. Below is every network request the app makes, what is actually inside it, and how to turn it off. If you find something here that doesn’t match what the app does, tell us and we’ll fix whichever one is wrong.

The short version

Your voice never leaves this machine.

Transcription runs entirely on your Mac’s own silicon. There is no audio upload, because there is no server to upload it to. Once the model is installed you can put the Mac in airplane mode and dictate all day.

Never sent, under any setting

The 5 things that do use the network

Two of these are on by default and can be switched off in the app’s settings without losing any dictation features. We’d rather say that plainly than bury it.

Sign-in

Required
Where it goes
Clerk (authentication provider, United States)
What’s in it
Your email address, your name if you provide one, and a session token. Nothing about your dictation.
Your control
Required to use the app. Delete your account to remove it.

Model download

Required
Where it goes
Cloudflare R2 (our file storage)
What’s in it
A standard file request. No account data is attached. Your IP address is visible to Cloudflare, as it is to any website you load. Happens once, at roughly 1.5 GB.
Your control
Required once. Afterwards the app works fully offline.

Update checks

Optional
Where it goes
Cloudflare R2 (our file storage)
What’s in it
Your app version and macOS version, so we can offer the right update. Your IP address is visible to Cloudflare.
Your control
Disable automatic updates in Settings.

Product analytics

Optional
Where it goes
PostHog and Google Analytics
What’s in it
Content-free events recording which features you use — app launched, dictation completed, a note created, a reminder ticked, a connector approved, and similar — each tagged with the feature area, your app version, your macOS version and your release channel. These are linked to your account: your Clerk user ID, email and name are held on your analytics profile so we can see which features a given customer relies on. Word counts and durations are sent as ranges (“10–24 words”, “15–30s”), never exact figures. Your transcripts, notes and recordings are never sent.
Your control
Settings → General → “Share usage data”. On until you turn it off.

Stats backup

Optional
Where it goes
Our own dashboard (MongoDB Atlas)
What’s in it
A daily summary tied to your account: date, words dictated, number of dictations, total duration, corrections made, and the names of the applications you dictated into. This one is not anonymous — it is how your stats survive a reinstall.
Your control
Settings → General → “Back up my stats”. On until you turn it off.

Why we publish this

We ask for two permissions that deserve suspicion: your microphone, and Accessibility, which lets the app type on your behalf. Any app with both could, in principle, do something ugly. “Trust us” is not a good enough answer, so instead we publish the list and let you audit it with a network monitor like Little Snitch. That is the only form of this promise that is worth anything.

The same reasoning is why we publish our accuracy numbers including the bad ones— the noisy-room and Bluetooth-microphone figures where we currently do worst. A vendor who only shows you their good numbers is telling you about their marketing, not their product.

Read the formal versions

This page is the plain-English one. The binding documents say the same thing in the language lawyers need.