Privacy & data flow
Where your voice data goes, and doesn’t.
A plain-English reference for compliance officers, IT directors, and individual users who want a complete picture of what DictateSI transmits, what it stores, and what it never touches.
Last updated 2026-07-02 · Version 0.3.0
TL;DR
- Audio never leaves your Mac. Speech is transcribed locally with whisper.cpp. There is no cloud STT path and no way to enable one.
- AI cleanup runs on-device by default: a small model on your Mac, no key, works offline. Cloud (Anthropic) is an opt-in alternative that sends only text, never audio.
- No telemetry, analytics, screenshots, URLs, app contents, or external keystrokes are sent anywhere.
- No account required. DictateSI has no login, no user database, no email collection.
- History stays on your machine in your home directory. We cannot read it.
- Optional tamper-evident audit log (off by default) records metadata only (which backend ran and whether anything left the Mac), never the transcript. Built to prove the on-device claim to a reviewer.
- Model downloads are integrity-verified: pinned to immutable revisions and SHA-256-checked before install. What you audited is what runs.
What DictateSI does with your data, step by step
1. Recording
When you press the hotkey, DictateSI begins capturing audio from your microphone via AVAudioEngine. Audio frames are held in process memory only. They are not written to disk and not transmitted anywhere.
2. Transcription (always local)
When you stop recording, DictateSI passes the in-memory audio buffer to whisper.cpp, an open-source on-device speech-recognition engine bundled with the app. The Whisper inference runs entirely on your Mac’s CPU and Apple Silicon GPU. There is no network connection involved in this step.
3. AI cleanup (on-device by default)
Polishing raw dictation into clean writing runs on your Mac by default: a small open-licensed model (Qwen2.5, Apache-2.0, ~1.1 GB, downloaded once) runs in-process via embedded llama.cpp. No network connection, no API key, works offline. An automated test fails the build if any networking code ever enters this path.
Three optional alternatives exist if you choose them in Settings:
Ollama (a daemon on your own machine; text stays on the device),
Anthropic with your own key (the transcript text + a short prompt + the model ID
go to api.anthropic.com), or an
OpenAI-compatible endpoint: OpenAI, Azure OpenAI, Gemini, Groq, Mistral, OpenRouter,
or a gateway your IT team runs. The endpoint receives the same three things at the URL you entered.
If that URL is this machine (localhost), the text never leaves it and the audit log records it as
on-device; any other host, including a server on your own network, is recorded as off-device.
Audio is never sent under any backend.
If cleanup fails, DictateSI falls back to the raw transcript, and a failure on a local backend never silently escalates to the cloud. Only the backend you selected is ever used.
4. Paste or type-out
The final text (raw or cleaned) is delivered to your cursor via the macOS clipboard + ⌘V (default) or per-character keystroke synthesis (opt-in). DictateSI does not retain the pasted text anywhere except the local history database below.
5. History (local SwiftData store)
DictateSI records each completed transcription locally. Each entry contains timestamp, duration, source app name, raw transcript, polished transcript (if cleanup was used), and a flag indicating which. This database lives only on your Mac. DictateSI has no server-side component to sync, mirror, or back it up. You can clear all history from Settings → History at any time.
History is user-controllable: a "Save dictation history" toggle (off = nothing new is recorded) and a retention window (forever / 1 / 7 / 30 / 90 days) that automatically purges older entries. Deployments that must minimize data at rest can disable history entirely.
6. Read-aloud (text-to-speech, always local)
When you press the read-aloud hotkey, DictateSI reads the text currently selected in your frontmost app (captured the same way ⌘C copies it, then the clipboard is restored) and passes it to Apple’s on-device AVSpeechSynthesizer. Every voice tier (default, Enhanced, Premium, Personal Voice) synthesizes on your Mac. There is no network connection in this step and no cloud TTS path in the app. The selected text is held in memory only: never written to disk, never added to history.
Higher-quality voices are optional ~100 MB+ files. If you install one, the download is performed by macOS itself via System Settings → Accessibility → Spoken Content, not by DictateSI. DictateSI only reads the list of voices already installed and never initiates a download.
7. Audit log (optional, off by default)
Regulated deployments often need to demonstrate that a tool behaved as claimed. When enabled, each dictation appends one record: sequence number, timestamp, source app, duration, the character count of the delivered text, which cleanup backend ran, and whether the text left the Mac (true only for the cloud backend). It never stores the transcript, the audio, or any spoken content; an automated build test fails if a content field is ever added.
Records form an append-only hash chain (each entry’s SHA-256 covers its fields plus the previous entry’s hash), so editing, reordering, or deleting a record is detectable by the built-in Verify integrity check. The full log, including the chain, exports to JSON or CSV for offline review, with the headline figure for a clean deployment: off-device events: 0. An honest limit: like any purely local log, it cannot by itself prove the entire log wasn’t cleared; central log shipping is on the roadmap. The audit log makes no network requests.
What DictateSI explicitly does not do
- ❌ Send audio to any third party
- ❌ Send your selected text to any cloud text-to-speech service
- ❌ Read or transmit URLs from your browser
- ❌ Read text from other apps’ windows
- ❌ Take screenshots
- ❌ Log keystrokes outside DictateSI itself
- ❌ Collect telemetry, analytics, or crash reports
- ❌ Require account or email registration
- ❌ Phone home for licensing or feature gates
For contrast: the dominant cloud-based dictation app on macOS has a “Context Awareness” feature that is on by default and sends nearby text, app names, URLs, dictionary entries, and code variable names to its servers. DictateSI has nothing analogous and never will.
Network endpoints used
| Endpoint | When called | What is sent |
|---|---|---|
| huggingface.co | Once, when downloading a Whisper model or the on-device cleanup model | HTTP GET for the model file. No personal data. URLs are pinned to immutable revisions and every file is SHA-256-verified before install; a mismatch is deleted, never loaded. |
| localhost:11434 | Only if you select the Ollama cleanup backend | Text transcript to a daemon on your own machine. It stays on the device. |
| api.anthropic.com | Only if you select the Anthropic cleanup backend and supply a key | Text transcript + system prompt + chosen model ID. Audio is never sent. |
| the endpoint you configured | Only if you select the OpenAI-compatible cleanup backend (or your IT policy pre-sets one) | Text transcript + system prompt + model name to the URL you entered. Audio is never sent. Recorded as off-device unless the host is this machine. |
That is the complete list. DictateSI has no other outbound network access in normal operation.
Air-gapped deployment
DictateSI can be used entirely offline once Whisper models are pre-positioned:
-
Download the Whisper
.binand cleanup.ggufmodel files separately and place them in~/Library/Application Support/com.dictatesi.mac/WhisperModels/and…/CleanupModels/respectively; the published SHA-256 checksums let you verify the files independently. - Keep the on-device cleanup backend (the default); it runs the AI polish locally with no network.
- Disable network for the DictateSI process via your firewall or MDM if desired.
In this configuration DictateSI makes zero network requests and produces transcriptions purely on-device. This is the deployment posture intended for regulated environments where audio data physically cannot be permitted to leave the network.
Data residency on your Mac
- Whisper models:
~/Library/Application Support/com.dictatesi.mac/WhisperModels/ - Cleanup model:
~/Library/Application Support/com.dictatesi.mac/CleanupModels/ - History database:
~/Library/Application Support/DictateSI-History.store(SwiftData, with its -wal and -shm companions) - Audit log (when enabled):
~/Library/Application Support/DictateSI-Audit.store: metadata only, never transcript content - API keys: macOS Keychain (
com.dictatesi.mac/anthropic-api-keyandcom.dictatesi.mac/openai-compatible-api-key). Never in preferences, never delivered by a profile. - App preferences:
~/Library/Preferences/com.dictatesi.mac.plist - Audio files: None. Never written to disk.
The printable version of this document lives in the source repository as
PRIVACY.md and is suitable
for compliance review. For questions or compliance review requests, contact the DictateSI team.