Skip to main content
undervoice
Quiet dictationRecognitionSecurity
文English
简体中文EnglishDeutschFrançaisEspañol日本語한국어繁體中文
Download

PRIVACY POLICY

Privacy Policy

Effective and last updated: July 30, 2026

This Privacy Policy explains how ldjing studio ("we," "us," or "our"), the developer of undervoice, handles information when you use the undervoice apps for iPhone and Mac, the undervoice website, or contact us for support. undervoice is designed so that your speech and transcript content stays on devices you control rather than being sent to an undervoice cloud transcription service.

1. Key privacy points

We do not operate an audio or transcript relay, storage, or transcription server. We do not use your audio or transcript content to train AI models. We do not sell personal information, share it for cross-context behavioral advertising, show advertising, or use third-party advertising trackers. The website does not use analytics cookies.

Limited information is processed by service providers when needed to deliver the website, download speech models, and verify purchases. Details are provided below.

2. Microphone audio and speech recognition

undervoice accesses the microphone only after you start voice input. For iPhone voice input, microphone audio is held temporarily in memory and sent directly to the Mac you selected and paired. The connection authenticates the paired devices and protects audio, transcript, and control messages with authenticated encryption and per-connection session keys. The Mac performs speech recognition locally using models stored on that Mac. undervoice does not save microphone audio as an audio file.

Devices may connect over your local network or over a private network you configure, such as Tailscale. Network operators can observe ordinary connection metadata such as device addresses, timing, and the amount of encrypted traffic, but not the encrypted audio or transcript content. If you use Mac voice input, audio from the Mac microphone is likewise recognized locally on the Mac.

3. Transcripts and information stored on your devices

Final transcripts are returned to the iPhone and may be inserted into the text field you selected on your Mac. iPhone transcript history is stored locally and automatically expires after 30 days. Mac transcript history is stored locally when enabled; it is enabled by default with a one-hour retention period, and you can choose seven or 30 days, disable history, delete individual items, or clear it.

The Mac app also keeps private, on-device usage statistics such as date and time, character count, speaking and processing duration, recognition model, delivery result, and the name and bundle identifier of the destination app. These statistics do not contain transcript or audio content and remain locally until you remove the app's data. Pairing records, device identifiers, connection settings, and cryptographic material are stored locally, including in the Apple Keychain where appropriate, until you forget or reset a pairing or remove the app's data.

If clipboard compatibility or a clipboard fallback is used, the transcript is placed on the macOS clipboard. Apple features such as Universal Clipboard may process or sync clipboard content according to your system settings. After a transcript is inserted, pasted, copied, or submitted to another app, that app's handling of the text is governed by its own privacy policy.

4. Diagnostics

The apps maintain a limited diagnostic timeline on the device to help explain microphone, recognition, network, and text-insertion behavior. Diagnostic entries may include timestamps, timings, short random identifiers, application bundle identifiers, character counts, device state, and error descriptions. They do not include microphone audio or transcript text. The in-app timeline keeps up to 300 recent entries. We do not receive diagnostics automatically; we receive them only if you choose to export and send them to us, for example in a support email.

5. Permissions

On iPhone, undervoice requests microphone access for voice input, camera access to scan the pairing QR code shown by your Mac, and local-network access to find and connect to your Mac. QR-code images are used for pairing and are not uploaded to us. On Mac, undervoice may request microphone access for Mac voice input, local-network access for the paired connection, and Accessibility access to place recognized text into the field you selected. You can revoke these permissions at any time in Apple System Settings, although the related feature will then stop working.

6. Purchases and free-use status

Apple processes App Store purchases and payment information. We do not receive your full payment-card details. undervoice uses RevenueCat to retrieve product offerings, validate purchases, restore purchases, and maintain entitlement status. RevenueCat may process an automatically generated app user identifier, purchase receipts and history, product and entitlement information, IP-derived country, and technical app or device information for those purposes. The number of successful free transcriptions is stored locally in the Apple Keychain.

Apple and RevenueCat process information under their own policies: Apple Privacy Policy and RevenueCat Privacy Policy.

7. Website, downloads, and support

The website is delivered through Cloudflare. Cloudflare may process standard request and security data, including IP address, browser and device information, requested URL, request time, and security signals, to deliver and protect the site. The undervoice website does not currently use account registration, advertising, analytics scripts, or analytics cookies. See the Cloudflare Privacy Policy.

The Mac app downloads speech-model files directly from Hugging Face. During a download, Hugging Face and network providers may receive ordinary request data such as your IP address, request time, and file URL. See the Hugging Face Privacy Policy. If you independently choose to use Tailscale, Tailscale's handling of account and network metadata is described in its Privacy Policy.

If you email us, we process your email address, message, attachments, and any diagnostic information you choose to provide so that we can respond, troubleshoot, prevent abuse, and maintain support records. Do not send audio or transcript content unless you want us to review it for support.

8. How and why information is used

We and the providers described above use information only as necessary to provide and secure the apps and website, enable and verify purchases, download app resources, respond to support requests, comply with law, and protect our rights and users. Where applicable, the legal bases are performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and your consent where consent is required.

9. Disclosure, international processing, and retention

We disclose information only to the service providers identified in this policy, when you direct us to, when required by law or valid legal process, to protect safety and rights, or as part of a merger, acquisition, financing, or sale of assets subject to appropriate protections. These providers may process information in countries other than yours under their own legal safeguards and privacy policies.

Device-stored information follows the retention periods and controls described in Section 3. Purchase records are retained by Apple and RevenueCat as needed to provide entitlements and meet legal obligations. Website security logs and model-download request logs are retained by the applicable provider under its policies. We keep support correspondence only as long as reasonably needed to resolve the request, maintain business records, prevent abuse, and comply with law, after which it is deleted or anonymized.

10. Your choices and privacy rights

You can stop microphone processing by ending voice input, revoke system permissions, clear transcript history, reset device pairing, stop using optional private-network services, or remove locally stored app data by deleting the app and its data. Purchase records controlled by Apple or RevenueCat may need to be retained for entitlement, fraud-prevention, tax, accounting, or legal purposes.

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information; receive a portable copy; withdraw consent; or appeal a decision. You may also complain to your local data-protection authority. To make a request concerning information we control, email [email protected]. We may need to verify your request. Because most undervoice data remains only on your devices, we generally cannot retrieve or delete that data remotely.

11. Children's privacy

undervoice is a general-audience productivity tool and is not directed to children under 13, or under the minimum age required by local law. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so we can take appropriate action.

12. Security

We use technical and organizational safeguards appropriate to the information we process, including device authentication, authenticated encryption for paired-device messages, per-connection session keys, Keychain storage for sensitive local material, and HTTPS for the website. No storage or transmission method is completely secure, so we cannot guarantee absolute security. Treat a pairing QR code like a password and reset pairing if it may have been exposed.

13. Changes to this policy

We may update this policy when the product, providers, or legal requirements change. We will post the updated policy at this URL and revise the date above. If a change is material, we will provide additional notice where required.

14. Contact

The controller responsible for information covered by this policy is ldjing studio. For privacy questions or requests, contact [email protected].

undervoice

Private voice input for coders.

PrivacyDownloadContact
© ldjing studio