Privacy Policy

Last updated: October 3, 2026

The short version

This policy has two main parts: The website and The app. They work very differently, so we describe them separately.

Who we are

talkflow is run by Samir Kharel, an individual developer ("we", "us", "our"). You can contact us at samir.kharel66@gmail.com.

For the website information described in Part 1, and for any emails you send us, we decide how that information is used. Under data protection laws such as the GDPR and UK GDPR, that makes us the "controller" of that information.

What this policy covers, and what it doesn't

This policy covers:

It doesn't cover:


Part 1: The website

What information is collected

When you visit the site, your browser sends our hosting provider the technical information that every website needs in order to respond. This typically includes:

Our hosting provider is Vercel Inc.

What the site doesn't do

The GitHub star count

The page shows how many people have starred the project on GitHub. Our server fetches this public number from GitHub's API, at most once an hour. Your browser does not contact GitHub for this, and GitHub does not receive your IP address from it.

Why we use it, and our legal basis

This information is used only to deliver the site to you, keep it running, and protect it from abuse such as attacks and excessive traffic.

Under the GDPR and UK GDPR, our legal basis is our legitimate interests in running a working and secure website (Article 6(1)(f)). You have the right to object to this. See "Your rights" below.

Who handles it for us

Our hosting provider (Vercel Inc.) handles this information in order to serve the site. See Vercel's Privacy Notice.

We don't share website information with anyone else, except where the law requires it.

How long it's kept

Vercel keeps request logs for a limited time under its own policies. We don't copy or export them.

Downloads

If you download or view talkflow on GitHub, GitHub receives your request, including your IP address, and handles it under the GitHub Privacy Statement.

"Do Not Track" and Global Privacy Control

We don't track visitors across other websites, and we don't allow other companies to do so through our site. Our aggregate analytics don't use cookies or build a profile of you. So there's nothing for a "Do Not Track" or Global Privacy Control signal to switch off. The site works the same way whether or not your browser sends one.


Part 2: The app

How dictation works

When you hold the talkflow hotkey (the fn key), the app:

  1. records sound from your microphone and keeps it in your computer's memory;
  2. sends that audio to a speech engine (whisper.cpp) running as a separate program on your own Mac, at the address 127.0.0.1 (also called "localhost"), which always means your own computer;
  3. turns the speech into text using the Whisper speech model (the English-only "small.en" version), running on your Mac;
  4. types the text into the app you're using.

Audio is never saved to disk. It stays in memory only, until your next dictation or until you quit talkflow.

The speech engine is a program on your computer. It is not a cloud server, and your audio doesn't travel over the internet.

What we receive from the app

Nothing. The app doesn't send your audio, your text, your stats or any other information to us or to anyone else. There are no accounts, no telemetry, no analytics, no crash reports sent to us and no update checks. The only network connection the app makes is to the speech engine on your own Mac.

Because we don't receive anything from the app, we can't see, recover or delete anything on your Mac for you. You are in control of it.

Setting up the app

When you set talkflow up, you download other software. Those services see your IP address when you download, and handle it under their own privacy policies:

What stays on your Mac

The app keeps a small amount of information on your own computer:

These files are not encrypted by talkflow. They are protected by your macOS user account, and by FileVault disk encryption if you have it turned on.

Deleting them. You can delete these files at any time. Deleting the talkflow app may not delete them, so remove the files above if you want them gone.

What the app reads while you dictate

Through macOS Accessibility, talkflow reads the one character before your cursor, so it can add a space when needed, and the text it typed itself. It never reads whole documents. This happens in memory, and that text isn't saved or sent anywhere. talkflow never uses the clipboard.

Permissions the app asks for

You can turn any of these off at any time in System Settings > Privacy & Security, but talkflow won't work without them.

Things outside talkflow's control

Some things that happen on your Mac are up to you, your organization or other companies, not us:

Future versions

This part describes the app as of the "Last updated" date above. If we ever add a feature that sends any information off your Mac, such as update checks or crash reports, we will update this policy before releasing that version and describe the change in the release notes.


Emails you send us

If you email us, we receive your email address, your name if you include it, and whatever you write. We use it only to reply and to deal with your request. Our legal basis is our legitimate interest in answering you.

Our contact inbox is Gmail, provided by Google, which processes messages on our behalf. We keep emails only as long as needed to handle your request.

Selling and sharing

We don't sell your personal information. We don't "share" it for cross-context behavioral advertising, as California law defines those terms, and we don't use it for targeted advertising. We haven't done any of these things in the past 12 months.

Children

The site and the app are not aimed at children under 13, and we don't knowingly collect personal information from children under 13. If you believe a child under 13 has sent us personal information, for example by email, contact us and we'll delete it.

Your rights

Depending on where you live, you may have the right to:

In practice we hold very little. We have no app data about you at all, and we don't keep copies of website request logs. If you contact us about website logs, we may not be able to find them, because they are held by our hosting provider.

How to make a request. Email samir.kharel66@gmail.com. We'll reply within one month. If we need to confirm who you are, we'll ask only for what we need.

Complaints. If you have a concern about how we handle your information, please tell us first at samir.kharel66@gmail.com. You also have the right to complain to a data protection authority:

If you live in California or another US state with a privacy law, you can make the same requests by email. We'll handle them in the same way, whether or not that law applies to us.

Keeping information safe

No system is perfectly secure, but we keep the information we hold to a minimum, which is itself a protection.

International transfers

Vercel is based in the United States and serves the site from data centers around the world, so website request information may be processed outside your country, including in the United States. Vercel handles this under its own policies.

Changes to this policy

We may update this policy. When we do, we'll post the new version on this page and change the "Last updated" date at the top. Significant changes to the app's data handling are also noted in the release notes.

Because the app doesn't connect to the internet for updates, we can't notify you inside the app. Please check this page or the release notes when you update. See also our Terms of Use.

Contact

Samir Kharel
Email: samir.kharel66@gmail.com