Privacy Policy
Last updated: October 3, 2026
The short version
- The app works on your Mac. Your speech is turned into text on your own computer. The app makes no network connections other than to the speech engine on your own Mac. We don't receive your audio, your text or your usage stats.
- The app has no accounts, no telemetry and no update checks. Audio is never saved to disk.
- The website has no cookies and no forms, and uses only basic, cookieless analytics. Like every website, it can't be delivered without your browser sending some technical information, such as your IP address, to our hosting provider.
- We don't sell or share your personal information, and we don't use it for advertising.
- Questions? Email samir.kharel66@gmail.com.
This policy has two main parts: The website and The app. They work very differently, so we describe them separately.
Who we are
talkflow is run by Samir Kharel, an individual developer ("we", "us", "our"). You can contact us at samir.kharel66@gmail.com.
For the website information described in Part 1, and for any emails you send us, we decide how that information is used. Under data protection laws such as the GDPR and UK GDPR, that makes us the "controller" of that information.
What this policy covers, and what it doesn't
This policy covers:
- this website;
- official releases of the talkflow app downloaded from this website or from https://github.com/saamirkhrl/talkflow;
- emails you send us.
It doesn't cover:
- Other websites we link to, such as GitHub. Their own privacy policies apply.
- The apps you dictate into. Once talkflow types your words into another app, such as a chat app, an email client or a document, that text is handled by that app and its provider under their own privacy policies.
- Modified versions of talkflow. talkflow is open source, so anyone can build and share their own version. Those versions may work differently, and this policy doesn't describe them.
Part 1: The website
What information is collected
When you visit the site, your browser sends our hosting provider the technical information that every website needs in order to respond. This typically includes:
- your IP address, and the approximate location that can be worked out from it;
- your browser type and operating system (the "user agent");
- the page you asked for, the page that linked you to us (the "referrer"), and the date and time of the request.
Our hosting provider is Vercel Inc.
What the site doesn't do
- It doesn't set cookies.
- It doesn't use advertising, tracking pixels or session recording. It does use Vercel Web Analytics to count page views and visits in aggregate (pages viewed, referrer, country, browser and device type). It doesn't use cookies for this, doesn't build a profile of you and doesn't follow you across other websites.
- It doesn't ask you for any personal information. There are no sign-up, contact or email forms.
- Its fonts are served from our own site, not from Google, so your browser doesn't contact Google Fonts.
- To show the right download button, the page checks in your browser which operating system you're using. That check happens on your device, and the result isn't sent to us.
The GitHub star count
The page shows how many people have starred the project on GitHub. Our server fetches this public number from GitHub's API, at most once an hour. Your browser does not contact GitHub for this, and GitHub does not receive your IP address from it.
Why we use it, and our legal basis
This information is used only to deliver the site to you, keep it running, and protect it from abuse such as attacks and excessive traffic.
Under the GDPR and UK GDPR, our legal basis is our legitimate interests in running a working and secure website (Article 6(1)(f)). You have the right to object to this. See "Your rights" below.
Who handles it for us
Our hosting provider (Vercel Inc.) handles this information in order to serve the site. See Vercel's Privacy Notice.
We don't share website information with anyone else, except where the law requires it.
How long it's kept
Vercel keeps request logs for a limited time under its own policies. We don't copy or export them.
Downloads
If you download or view talkflow on GitHub, GitHub receives your request, including your IP address, and handles it under the GitHub Privacy Statement.
"Do Not Track" and Global Privacy Control
We don't track visitors across other websites, and we don't allow other companies to do so through our site. Our aggregate analytics don't use cookies or build a profile of you. So there's nothing for a "Do Not Track" or Global Privacy Control signal to switch off. The site works the same way whether or not your browser sends one.
Part 2: The app
How dictation works
When you hold the talkflow hotkey (the fn key), the app:
- records sound from your microphone and keeps it in your computer's memory;
- sends that audio to a speech engine (whisper.cpp) running as a separate program on your own Mac, at the address 127.0.0.1 (also called "localhost"), which always means your own computer;
- turns the speech into text using the Whisper speech model (the English-only "small.en" version), running on your Mac;
- types the text into the app you're using.
Audio is never saved to disk. It stays in memory only, until your next dictation or until you quit talkflow.
The speech engine is a program on your computer. It is not a cloud server, and your audio doesn't travel over the internet.
What we receive from the app
Nothing. The app doesn't send your audio, your text, your stats or any other information to us or to anyone else. There are no accounts, no telemetry, no analytics, no crash reports sent to us and no update checks. The only network connection the app makes is to the speech engine on your own Mac.
Because we don't receive anything from the app, we can't see, recover or delete anything on your Mac for you. You are in control of it.
Setting up the app
When you set talkflow up, you download other software. Those services see your IP address when you download, and handle it under their own privacy policies:
- The Whisper model (small.en, English only) is downloaded from Hugging Face. See the Hugging Face privacy policy.
- The whisper.cpp speech engine is typically installed with Homebrew. See Homebrew's analytics documentation.
What stays on your Mac
The app keeps a small amount of information on your own computer:
- Usage stats. Totals of words dictated, number of dictations and speaking time, and words per day. These power the stats you see in the app. They contain no text and no audio. They are stored in a file at
~/Library/Application Support/talkflow/stats.json. - A technical log. The app writes a log at
~/Library/Logs/talkflow/talkflow.log. It grows until you delete it. For each dictation it records technical details, such as its length and timing and the name of the app you dictated into. It does not record your words. - The speech engine's own log. Depending on how the speech engine is set up on your Mac, it may keep its own log. Check the speech engine's settings if you want to turn that off or delete it.
These files are not encrypted by talkflow. They are protected by your macOS user account, and by FileVault disk encryption if you have it turned on.
Deleting them. You can delete these files at any time. Deleting the talkflow app may not delete them, so remove the files above if you want them gone.
What the app reads while you dictate
Through macOS Accessibility, talkflow reads the one character before your cursor, so it can add a space when needed, and the text it typed itself. It never reads whole documents. This happens in memory, and that text isn't saved or sent anywhere. talkflow never uses the clipboard.
Permissions the app asks for
You can turn any of these off at any time in System Settings > Privacy & Security, but talkflow won't work without them.
- Microphone. macOS asks you to approve this, so talkflow can hear you.
- Accessibility. You grant this yourself in System Settings. talkflow uses it to type the text into the app you're using, and for the reading described above.
- Input Monitoring. You grant this yourself in System Settings. talkflow uses it listen-only, to notice when you press and release the fn key. It sees only modifier keys, never the characters you type.
Things outside talkflow's control
Some things that happen on your Mac are up to you, your organization or other companies, not us:
- Backups and sync. Tools like Time Machine, or other backup and sync software you use, may copy the files listed above. Those copies are governed by the tool you use.
- Your operating system. macOS may make its own network connections, for example when it checks a newly downloaded app before first opening it. If you have chosen to share Mac analytics with Apple, macOS may also send Apple crash reports that involve talkflow. Apple's privacy policy covers those.
- Work computers. If you use talkflow on a computer managed by your employer or school, their security and monitoring tools and policies may also apply.
Future versions
This part describes the app as of the "Last updated" date above. If we ever add a feature that sends any information off your Mac, such as update checks or crash reports, we will update this policy before releasing that version and describe the change in the release notes.
Emails you send us
If you email us, we receive your email address, your name if you include it, and whatever you write. We use it only to reply and to deal with your request. Our legal basis is our legitimate interest in answering you.
Our contact inbox is Gmail, provided by Google, which processes messages on our behalf. We keep emails only as long as needed to handle your request.
Selling and sharing
We don't sell your personal information. We don't "share" it for cross-context behavioral advertising, as California law defines those terms, and we don't use it for targeted advertising. We haven't done any of these things in the past 12 months.
Children
The site and the app are not aimed at children under 13, and we don't knowingly collect personal information from children under 13. If you believe a child under 13 has sent us personal information, for example by email, contact us and we'll delete it.
Your rights
Depending on where you live, you may have the right to:
- ask for a copy of the personal information we hold about you (access);
- ask us to correct it (rectification);
- ask us to delete it (erasure);
- ask us to limit how we use it (restriction);
- object to our use of it based on our legitimate interests (objection);
- receive it in a portable format (portability);
- not be treated differently for using any of these rights.
In practice we hold very little. We have no app data about you at all, and we don't keep copies of website request logs. If you contact us about website logs, we may not be able to find them, because they are held by our hosting provider.
How to make a request. Email samir.kharel66@gmail.com. We'll reply within one month. If we need to confirm who you are, we'll ask only for what we need.
Complaints. If you have a concern about how we handle your information, please tell us first at samir.kharel66@gmail.com. You also have the right to complain to a data protection authority:
- in the UK, the Information Commissioner's Office (ICO);
- in the EU or EEA, the data protection authority in your country (list of EU authorities).
If you live in California or another US state with a privacy law, you can make the same requests by email. We'll handle them in the same way, whether or not that law applies to us.
Keeping information safe
- The website is served over encrypted HTTPS connections.
- The app only ever connects to 127.0.0.1, your own computer. When the speech engine is set up as described in the README, it listens only on your own computer, not on your network.
No system is perfectly secure, but we keep the information we hold to a minimum, which is itself a protection.
International transfers
Vercel is based in the United States and serves the site from data centers around the world, so website request information may be processed outside your country, including in the United States. Vercel handles this under its own policies.
Changes to this policy
We may update this policy. When we do, we'll post the new version on this page and change the "Last updated" date at the top. Significant changes to the app's data handling are also noted in the release notes.
Because the app doesn't connect to the internet for updates, we can't notify you inside the app. Please check this page or the release notes when you update. See also our Terms of Use.
Contact
Samir Kharel
Email: samir.kharel66@gmail.com