Privacy policy
What stays on your Mac, what leaves it, and what happens to the little that reaches a server. Written against the code rather than from a template.
This policy covers the Speaklively app for macOS and the website at www.speaklively.com. It is written by the person who builds both, and it describes what the software actually does today — 28 August 2026.
1The short version
- Your voice never leaves your Mac. There is no recording and no upload. Listening and transcription happen on the machine, on Apple’s on-device models.
- Your words leave only when you press a button that sends them — the AI Rewrites (Polish and Structure), and two optional features described in section 3.
- Nothing you dictate is stored on any server. The proxy that meters those requests keeps counts and costs. It does not keep the text going through it, and it does not keep the reply.
- Your dictation history stays on your disk, as plain files. It is never uploaded.
- Nothing is sold, ever, to anybody, for any purpose. There are no advertising networks and no third-party tracking SDK inside the Mac app.
2What never leaves your Mac
These are not settings you have to find and switch off. There is nothing to send in the first place.
- Microphone audio. Heard on the machine and gone when the dictation ends. It is never written to disk as a recording and never transmitted.
- Live transcription. Apple’s on-device speech models, which is why dictation works with no network at all.
- Original and Tidy. Both are produced on the Mac. Nothing you dictated — no transcript, no fragment of one — reaches any server, including ours. The anonymous counts in section 5 and the app events in section 6 still happen, and section 7 is the switch for both.
- Your history. Plain files on your own disk, under your own user account.
- What was on screen when you pressed. The app reads the focused window’s title and the text already in the field, to bias the recogniser toward names it can see you are working with. Those terms live for the length of one dictation and are then discarded. They are not stored, and they are never sent anywhere.
If you never turn on an AI Rewrite and never make an account, no text you dictated ever leaves your Mac. What still leaves is described in sections 5 and 6: counts of words and seconds, and a short list of named events about whether the app worked. Neither carries anything you said. Section 7 is the switch that stops both.
3What leaves, and only when you ask
Three features send text to Anthropic’s Claude models. The app’s Privacy pane shows them under SENT TO AI, alongside two things that are kept rather than sent, and carries a switch for three of the five.
- Polish and Structure — the one transcript you are looking at, sent when you press the button, so it can be rewritten. Each is switchable. The request carries a short context block with it, because that context is what makes the rewrite good rather than generic: the name of the app you are dictating into (“Mail”, “Slack”), a one-line note on how people write there, your vocabulary terms for that app, and your voice profile if you have built one. That is the one place an app’s name leaves your Mac — it never reaches our own servers, which see only a category.
- Vocabulary suggestions — a batch of your recent corrections (what the recogniser heard, and what you changed it to) used to propose words it should have known, each tagged with the bundle identifier of the app it came from so a term can be scoped to where you actually use it. Switchable, in Settings → Privacy or Settings → Vocabulary.
- Writing style — the samples you record for the Voice feature, sent when you build or rebuild a style. There is no switch because the feature is the sending: if you never record a sample, nothing goes.
Two routes, and the difference matters
Which one you are on depends on how you set up access, and it changes who can see the request:
| If you are using | The text goes | We can see |
|---|---|---|
| Your own Anthropic API key | Straight from your Mac to api.anthropic.com | Nothing. It never touches our server, and neither does your key — that is held in your Mac’s Keychain |
| The free allowance, or a paid plan | Through our proxy, then on to Anthropic | That a request happened, and what it cost — never what it said. See section 4 |
In both cases Anthropic processes the text under its own terms and privacy policy. Anthropic states that it does not train its models on API inputs or outputs; the current statement is the authority, not this sentence.
4What the server records when it does
When a request goes through our proxy, one row is written per call. Successful or not, it holds:
- the time, the model name, and the HTTP status;
- token counts and the cost in millionths of a dollar — this is what the allowance is measured against;
- which feature made the call (cleanup, vocabulary or voice), so background work is not charged against a free allowance somebody wanted for dictating;
- a one-off identifier for the dictation, so pressing both Polish and Structure on the same sentence counts once rather than twice. It is generated per dictation, kept nowhere on your Mac, and means nothing once that dictation is over;
- a hash of the access token the call was made with.
No prompt, no reply, no transcript. The proxy is built to meter without reading, and the storage has nowhere to put the text even if it wanted one.
5Anonymous usage counts
The app sends a small report on its own schedule — every few hours for the first days after installing, then daily. That is how many installs are actually running is known at all, and it is the only way to see whether the parts that never touch a server are working. It carries:
- An install identifier — a hash of a random identifier the app generated on first launch. It is not derived from your hardware, your name, or anything about the machine, so it dies with the install rather than following you to your next Mac. If you make an account, we link that install to it, so that a support request can be answered and so we can see whether the app is actually working for people. The link is recorded with a date and is deleted along with everything else if you ask. Neither is ever joined to what you dictate, because what you dictate never reaches us at all.
- the app version and build number;
- four totals describing what the app changed about your words — how many words you said, how many were inserted, how many filler words were removed, and how many words were corrected. Four numbers, added up across a day; never the words themselves, and nothing that could be used to reconstruct them.
- your country, as Cloudflare’s network already determined it from the connection. Not a city, not a region, and not from anything the app knows;
- counts — words dictated, number of dictations, seconds spoken. Never the words themselves;
- a category of app and which engine produced the text. The category is one of five fixed buckets — technical, correspondence, short informal, notes, general — and is never an app name or a bundle identifier. Anything the app does not recognise falls into “general” by construction, so unusual and personal apps collapse into one bucket automatically rather than because somebody remembered to strip them.
There is a switch for all of this, in Settings → Privacy, on by default. Turning it off stops the counts report and the events in section 6, throws away anything already queued rather than holding it, and stops the app saying which install it is when it checks for updates — you keep receiving updates, that is a separate switch. One thing it does not stop: dictation counts already recorded but not yet reported stay on your Mac, and are simply never sent.
No IP address is stored with any of this. Exact mode runs entirely on your Mac and no text from it reaches any server; these counts, and the engine named on a first dictation in section 6, are the only way it is visible at all. They exist so that “is anybody using this” has an answer that does not require reading anything anybody wrote.
6Your account, if you make one
You can use Speaklively without an account. Dictation, live transcription, Tidy and history never ask for one, and the first fifteen AI Rewrites do not either. Verifying an email address gets you a further hundred. If you make an account, this is what exists:
- Your email address, stored in readable form — not hashed, unlike everything else here. That is deliberate: an address nobody can read is one you cannot be sent a receipt at, answered from, or refunded to. Gmail addresses are normalised (dots and +suffixes removed) so that one person cannot be two accounts by punctuation.
- Your plan and, if you are paying, when it renews.
- A six-digit verification code, while you are signing in. Stored as a hash, expiring shortly, with a limited number of attempts, and deleted as soon as it is used or finally fails.
- An access token, stored only as a hash — the token itself exists on your Mac, in the Keychain, and nowhere else. This is why a lost token can be reissued but never recovered.
- A hashed device identifier, so the free allowance cannot be reset by removing the app and adding it again.
- One row per dictation spent from an allowance, holding the account or device it belonged to and the time — never the dictation.
- A record of a few moments, sent to our analytics provider. Twenty-six named events, and they come from two places.
Five are made by our server as it answers a request: a sign-in code being asked for, a code being checked, a token being issued, an allowance running out, and the “I would pay for this” button being pressed.
Twenty-one are made by the app, on your Mac, and sent from it. They are the switch in section 5’s subject, and they are how a solo developer learns that something is broken on a machine he has never touched. Named individually, because a list you can count is worth more than an adjective:
- install_created and app_launched — that this copy of the app exists, and then once per launch. Between them they carry your macOS version, whether Apple Intelligence is available and — when it is not — which of Apple’s three reasons applies, your Mac’s model name (Mac14,2 and the like: the same string on every unit of that model, so it names the product and not your machine — never the serial number, never the hardware id), which of the four permissions are granted, whether the fn key is free, and which key you hold to dictate.
- engine_ready — that dictation became usable, how long that took from launch, whether a speech model had to be downloaded first and how long that took, and for which language.
- window_opened and pane_opened — that the window came up and why, and which of the app’s seven screens you moved between. The name of the screen, never anything on it.
- permission_requested, permission_granted and permission_denied — which of the four gates you were asked for, whether it was a dialog or a trip to System Settings, how many times it has been asked this launch, how long after installing, and what you answered.
- setup_completed — that setup finished, how long it took, and how many gates were outstanding when you started.
- try_it_focused — that you used the practice box on the Welcome screen, whether by clicking into it or by words arriving in it, how long after it appeared, and whether setup was finished by then. Not what you then typed or said into it.
- first_dictation — once ever, on the first dictation that lands. How long after installing, how many words, the app category, which engine, and whether it was the practice box rather than a real app.
- dictation_empty, dictation_failed and event_tap_dead — that a dictation produced nothing, or that the key stopped being heard, with the reason and enough shape to diagnose it: how long you held, whether any audio arrived, whether it was silent, whether any of it was loud enough to be speech, and which language was selected. How much sound, never any of it.
- language_offered and language_changed — that the language picker appeared after a result and which language was selected at the time, and if you used it, which language you moved from and to.
- offer_shown — that the offer of free AI rewrites was on screen.
- keychain_prompted — that macOS asked you for your password to unlock a stored credential, how many seconds it waited, and whether you allowed it. The name of the item, never its contents. It exists because that prompt can hang the app silently, and until it was counted nobody could see it happening.
- tidy_ready — that Apple Intelligence became available after having been unavailable, and how long that took.
- first_cleanup — once ever, the first time a rewrite succeeded. Which one, how many dictations you had done first, which plan paid for it, and whether it ran on your own Anthropic key or through us.
- voice_profiled — that you asked the app to describe how you write, and how many samples you had given it. Never the samples.
None of them can carry text. The app can only put a string, a number or a true/false into an event, and our server accepts nothing else — no nested object, no list — so there is no shape a transcript could travel in even by accident. Every event also carries the app version, the build, and the country our server infers from the connection.
How they identify you. Three kinds of identifier, never your address itself. Events about an account use a one-way scramble of your email; events about a device that has no account use a scramble of a random identifier the app made up and kept; and the app’s own events use a scramble of a second random identifier, made on first launch, that is derived from nothing about your Mac — no serial number, no hardware id. None of the three can be turned back into an address or a machine.
7The website
If you fill in the download form
The form asks for a name and an email address. That is stored so there is a way to ask how the beta is going. It is not a mailing list. Nothing else about the request is recorded alongside it — no IP address, no browser string, no referrer.
Your name and address are never sent to website analytics. Google Analytics is told that a download happened and where the visit came from. It is not told who you are.
If you just download
The download is counted: the time, which file and version, your country from Cloudflare’s network, and where the link said it came from — either a campaign tag written into the link, or the hostname the visit arrived from. Only ever the hostname: the rest of a referring URL is discarded in the browser before any request is made, because that is where a search phrase or a private thread would be. There is no identifier attached, so this is a count of downloads and is honest about not being a count of people.
Analytics and storage in your browser
- Google Analytics 4 runs on the production site only. It sets cookies and receives your IP address, as any web request does, and uses it to derive a coarse location; Google’s own privacy policy governs what it does with that. Blocking it costs you nothing on this site.
- Vercel Speed Insights collects anonymous page performance measurements. No cookies.
- Two sessionStorage entries remember where your visit came from, between arriving and clicking download. Deliberately sessionStorage and not localStorage: it dies with the tab, so it is attribution for one visit rather than a mark that follows you between them.
8What is never collected
Stated as a list because a policy that only describes what it takes leaves the interesting question unanswered:
- Audio. There is no recording, on your machine or anywhere else.
- The contents of your dictations, on any server — including the text sent for an AI Rewrite, which is passed through and not retained.
- The names of the apps you dictate into, or their bundle identifiers. Our servers are told a category — one of five buckets — and never the app. The one exception is described in section 3 and leaves your Mac only when you press a button: a cloud rewrite tells Anthropic which app the text is going into, and a vocabulary suggestion tells it which app a correction came from.
- What is on your screen. It is read locally and discarded locally.
- Your IP address, in our own storage.
- Keystrokes, browsing history, files, or contacts.
- Your own Anthropic API key, if you use one.
- Anything at all through a third-party analytics or advertising SDK inside the Mac app. There is none, and there is no advertising or tracking code of any kind. The app does contain one piece of third-party code — Sparkle, which downloads and installs updates. It talks only to our own update feed. The events in section 6 are named individually and go only to our analytics provider; seven of them are made by the app on your Mac, and five by our server.
9Who else is involved
Running the service means other companies handle parts of it. These are all of them:
| Who | What for | What they get |
|---|---|---|
| Anthropic | The AI Rewrites, vocabulary suggestions and writing style | The text you sent for that one request, and its reply |
| Cloudflare | The proxy, its database, and hosting the app download | Requests in transit, including IP addresses at the edge; the stored rows described above |
| Vercel | Hosting this website and its performance measurements | Web requests to the site |
| Google Analytics | Counting visits to the website | Visit data and IP address. Never your name or email address |
| Resend | Delivering sign-in codes by email | Your email address and the code |
| PostHog | Understanding whether the app works for people | The events in section 6. A one-way scramble of your email address, of a device identifier, or of an install identifier — never the address itself; never anything you dictated, and never your IP address |
When paid plans open, a payment provider will be added to this list. It will be a merchant of record, which means it — not this project — takes your payment details. Card numbers will never reach us. This section will name it before it is switched on.
10How long any of it is kept
- Sign-in codes — minutes. Deleted when used, when the attempts run out, and dead on expiry regardless.
- Account, token and allowance rows — until you ask for them to be deleted, or the account is closed.
- Per-call metering rows, usage counts, download counts — kept while the project runs. They contain no text and no address, and nothing automatically removes them today.
- The analytics events in section 6 — kept for twelve months by our analytics provider, then deleted.
- Your dictations and history — for as long as you keep them, on your own disk. Deleting them in the app deletes them; there is no copy elsewhere to catch up with.
11Getting a copy, or getting it deleted
Write to hello@takeoffdigilabs.com and ask. You can have a copy of everything associated with your address, have it corrected, or have it deleted. Deleting removes your account, your tokens, your allowance rows, and any link recorded between your address and an install. The usage counts themselves stay, and once that link is gone there is nothing in them that identifies you — they are counts of words and seconds, with no address and no text.
Depending on where you live, the India Digital Personal Data Protection Act, the UK and EU GDPR, or your local equivalent may give you these rights formally. You do not need to cite one. Asking is enough, and a reply should take days rather than weeks — this is a project run by one person, so it is answered by a person.
12Children
Speaklively is not directed at children, and an account should not be made by anyone under 16. Nothing here is knowingly collected from them; if you believe an account belongs to a child, write and it will be removed.
13Changes to this policy
The date at the top says when this text took effect. If something changes that widens what is collected or what it is used for, the date moves and anyone with an account is told by email before it applies — not afterwards, and not by quietly editing this page. Corrections and clarifications that do not change what happens to your data are made without notice.
14Contact
Takeoff Digi Labs (OPC) Private Limited is the data controller for everything described above. No. 5/1, Soodamanipuram, Karaikudi, Sivaganga District, Tamil Nadu 630003, India.
Questions, objections and requests: hello@takeoffdigilabs.com. It reaches the person who builds Speaklively.
The companion document is the terms of service.