The short version
- Your dictations are not stored on our server. Audio and text pass through it to the speech and language-model providers and come back.
- History, recordings, dictionary, snippets, automations and settings stay on your computer.
- We keep what an account needs: your email, your devices, and a record of each cloud request’s duration and cost — never its words.
- Feedback is up to you: if you send it on an answer of the Command key (the app asks you first), we keep that request, with what the model saw, for 90 days to make the answers better. For that, a Command request stays in our server’s memory for up to 30 minutes, never on disk.
- If you delete your account, we close it at once and keep its records for one more year to detect abuse of the service; then they are erased.
- Our providers don’t train on your data. So that the text fits where it goes, the model also sees the app, the window and the text around your cursor; you can turn that off. With the Command key, the window’s text goes only when the request needs it, as an AI model decides at the start, and a screenshot only when that text is not enough.
- Payments go through Paddle; we never see your card number. The website uses Google’s cookies for its statistics and our ads: in Europe only if you allow them, elsewhere until you turn them off. We don’t sell data, and what you dictate or keep in your account never goes to advertising.
1. Who is responsible
The controller of your personal data for WhooshType — the app for macOS and Windows, the cloud service behind it and the website whooshtype.com — is:
Email for anything about your data: [email protected]
This policy follows the Serbian Law on Personal Data Protection and the EU General Data Protection Regulation (GDPR), which are alike. If you live in the EU, the EEA, the UK or Switzerland, you have the rights those laws give you (section 10). The policy describes the version of the app we ship to users.
2. What stays on your computer
The app keeps your working data on your computer and does not send it to us: the history of your dictations, edits, answers and transcriptions — the text and, unless you turn it off, the recording; your dictionary, snippets, automations, modes and settings; samples of your corrections, when style learning is on; and the keys that identify your installation to our server, which are stored encrypted. You choose in the settings how long history is kept, and you can delete any entry or all of them. Uninstalling the app together with its data removes everything.
The version we ship writes no log file and sends no diagnostics, crash reports or usage statistics. A local interface lets WhooshType’s command-line tool and AI agents on your computer (Claude Code, for example) work with your history, settings and automations; only your user account can reach it, it is on by default, and you can turn it off.
Parts of this data leave your computer only as section 3 describes: when you use the cloud, and when you ask History to transcribe or rewrite an entry again.
3. What the cloud receives
When you use the cloud, the app sends the request to our server, which passes it to a provider and returns the result. The server holds a request only while it is being processed and keeps no copy of its content — not the audio, not the text, not the files — with the exceptions in section 5. Every request carries the token of your installation, a fingerprint of your computer and the app’s version.
| When you… | What leaves your computer |
|---|---|
| Dictate or translate | Your voice, as you speak. Then the recognized text with what the model needs to write it for the place it goes: the name of the app you are typing in, the window title (in a browser, the page address), the text around your cursor, your dictionary and snippets, the style of the mode and the rules learned from your corrections. A short dictation (up to five words) first goes to a decision model that tells whether it can go in as recognized, with no editing. The first time you dictate into an app or site no style covers, its name and window title (or the site and page title) go to that model to pick the style. The window and the text around the cursor can be turned off in the settings; password fields are never read. |
| Use the Command key | Your voice, as you speak, and then what you said, with the earlier requests and results of the same card; the text you selected, if any; the name of the app, the window title (in a browser, the page address), your dictionary, snippets and style, and the time and time zone on your computer; the names, example phrases and descriptions of your automations, never the scripts, files or addresses they use. The app reads the window when you press the key and keeps what it read on your computer: its text goes only when the request needs it — to write a reply to someone on screen, for example — as an AI model decides at the start (or the model writing the answer asks for it), and a screenshot of the window only when that text is not enough. You can turn either off in the settings. When web search is on (it is by default), the model may search the web with a query it writes itself. A webhook in one of your automations sends what you set up to the address you chose. |
| Send feedback on a Command answer | Only with your consent, which the app asks for the first time: the reason you chose and your comment, with the request the answer was for — your words, the answer and what was sent with them, including the window’s text or the screenshot the model saw. You can take the consent back in Settings → Privacy. |
| Fix what you just said, use a mode of your own, answer Claude Code | The words you said and what they work on: the dictation you are fixing; the mode’s instructions, and the selected text or the clipboard only if the mode asks for them; Claude Code’s permission question. |
| Let the app learn your style | Pairs of what the app inserted and how you corrected it, so the model can write rules for your style. On by default; you can turn it off. |
| Transcribe a file | The audio file. Our server deletes the uploaded audio at the provider as soon as the text is back. |
| Use local models (Mac) | Nothing you say or write. The app still asks our server for the license and the models’ instructions, with the installation id, your computer’s name and the app’s version. The models themselves are downloaded from Hugging Face. |
Speech is recognized as you speak, so the audio reaches the provider before you release the key. If you dictate other people’s words — a meeting, a voice message — you decide that they may be processed this way.
4. The providers
These companies process data for us. We chose them for not training on customers’ data; each is bound by its own terms and data-processing commitments.
| Provider | What for | What it receives and keeps |
|---|---|---|
| Soniox (US) | Speech recognition and translation of speech | The audio, the languages you dictate in and a few dictionary terms. Live audio is processed in memory and not stored; an uploaded file is deleted when the text is back. No training on your data. Soniox on privacy |
| Google (US), the Gemini API | The writing: clean-up, translation, edits, answers, messages, style rules, picking automations; web search for the Command key through Google Search | What section 3 lists. A paid service: Google does not use the requests to improve its products and logs them for a limited time only to detect abuse. The instructions that carry your style are cached at Google for up to an hour to speed requests up. Gemini API terms |
| OpenRouter (US) | The same work when Google is slow or unavailable; the way to TypeSafe | The same content, with data collection denied and routed to the same Google model; for TypeSafe, what its row lists. OpenRouter keeps no prompts or answers. OpenRouter on privacy |
| TypeSafe (US) | Deciding at the start of a Command request whether it needs the window’s text or a screenshot too, and whether it runs one of your automations; deciding whether a short dictation (up to five words) can go in as recognized, without the editing model; picking the style for an app or site you dictate into for the first time; understanding your spoken answer when Claude Code asks for permission | What you said, the app’s name, the window title and the page address, whether text is selected, and the names and example phrases of your automations; when the window is needed, its text too; for a short dictation, its text, the app’s name, the window title and page, the text around your cursor, your style’s settings and instructions, the learned rules, your dictionary’s words and your snippets’ trigger phrases (never a snippet’s text or the audio); for a new app or site, its name and window title or the site and page title, with your styles’ names and the start of your own styles’ instructions; for an answer to Claude Code, what you said and what it asks to run. Never a screenshot or the selected text. Reached through OpenRouter, with data collection denied. TypeSafe doesn’t train on your data. TypeSafe’s privacy policy |
| Exa (US) | Web search for the Command key once Google’s search quota is used up | Only the search query the model writes. |
| Resend (US) | The sign-in emails | Your email address and the code. |
| Paddle (UK / US) | Payments, invoices, taxes, refunds — the merchant of record | Your payment and billing details, under Paddle’s privacy policy. |
| Google (US), Google Analytics and Google Ads | Counting the website’s visitors and where they come from; measuring and showing our ads | What section 6 lists about the website, under its cookies; nothing from the app. How Google uses this data |
| Cloudflare (US) | In front of the website, the API and the downloads | Connection data such as IP addresses, briefly, as any host; it tells our server the country a request comes from. |
| Hugging Face (US) | The local models for the Mac | Your IP address and the model’s name when you download one. |
| Hostkey (the Netherlands) | The rented server with our service and database | The server is ours to run; only we hold its keys. |
We may change a provider; when that changes what happens to your content, this policy is updated.
5. Your account on our server
Our server keeps what it takes to run your account, enforce licenses and charge your balance — and nothing of what you say or write, apart from the feedback you choose to send and the exceptions at the end of this section.
| What | Why | How long |
|---|---|---|
| Email address | Signing you in with a one-time code, matching Paddle’s payments to your account, notices about your account | While the account exists, and one year after you delete it (section 10) |
| Devices | The name you gave the computer, its system and app version, the identifiers of the installation and the computer, the IP address and country of the last request, when it was last seen — to count devices per license, to let you sign a device out and to spot stolen tokens. The access tokens themselves are stored only as hashes. | While the account exists, and one year after you delete it (section 10) |
| Usage records | One line per cloud request: the time, the kind, the duration, the cost and whether it succeeded. No text, no audio. To charge the balance, apply the safety caps and find faults. | While the account exists and one year after you delete it, then as long as bookkeeping law requires |
| Feedback on Command answers | What you send with the thumbs-down button once you have agreed to it: the reason, your comment and the request the answer was for — your words, the answer, the window’s text or the screenshot the model saw, and the model’s calls and replies. Used only to find where an answer went wrong and make the answers better; kept apart from the database and its backups. | 90 days; deleted at once when you delete your account |
| Payments ledger | Top-ups, license periods, refunds, Paddle’s transaction ids | As long as bookkeeping and tax law require |
| Invite details | For invited accounts: the name we know you by, the code, the allowance and what it has spent | While the account exists, and one year after you delete it (section 10) |
| Server logs | Technical records: time, kind, outcome, errors, account and installation ids, app version. The IP address only in security events — a refused sign-in, a wrong device, a request without a valid token. | Some weeks |
| Backups | Daily copies of the database above, so a server failure does not lose your balance | A few weeks, on the server and on a computer of ours, fetched over a private, encrypted network |
Exceptions. A request made with the Command key stays in the server’s memory — never on disk — for up to 30 minutes, so that feedback you send on its answer can include it; then it is dropped. For invited (free) accounts only, when the model is slow to answer, the server keeps the model’s own short notes on its reasoning and the timings for a week, to make the service faster — not the transcript and not the answer, though a note may paraphrase the request; never for paying customers, and not in backups. And the owner’s own test account is the only one whose full requests are kept, for a week, to debug the service.
An account you delete is closed at once and its feedback deleted; its other records stay for one more year and are then erased (section 10).
6. Payments, email and the website
Payments. Licenses and top-ups are sold by Paddle, our merchant of record. Paddle collects what a payment needs — name, email, country, the payment method, an address or tax id where tax law requires it — under Paddle’s privacy policy. We receive from Paddle your email, your country, the transaction ids, the amounts and the status of each payment, refund or dispute; we never receive your card number. With auto top-up on, Paddle keeps your payment method on file and charges the amount you chose when your balance runs low.
Email. We email you to sign you in, about your account — a license that could not be renewed, a refund — and about changes to our terms. No newsletters, and no marketing without asking you first. Replies and support go to [email protected], which the owner of the business reads.
The website. whooshtype.com uses Google Analytics and Google’s advertising cookies, to learn how many people come, how they find us and which of our ads work: the pages you open, the site, search, ad or link that sent you, your country and city as Google estimates them from your IP address (Google does not keep the address itself), your device, browser and language, how far you scroll, the links you follow off the site, such as the downloads, and the videos and forms you use on it. If you are signed in to Google and allow personalized ads there, Google adds broad groups such as age range, gender and interests and recognizes your visits from different devices; we see only totals. We may use these statistics to measure our ads on Google and to show our ads to people who have visited the site. Our cookies keep random ids for up to 13 months. In the EU, the EEA, the UK, Switzerland and Serbia they are set only if you allow them, and in Europe the site asks you first; elsewhere they are on until you turn them off. Until you allow them, or once you turn them off, Google still gets a signal for each page you open, with no cookie and no id, and uses such signals only in aggregate to estimate visits and the results of ads. “Cookie settings” at the bottom of every page changes your choice at any time, and your browser remembers it. Google keeps the statistics for 14 months. The site has no other cookies or trackers.
Your browser fetches the fonts from Google Fonts, so Google sees your IP address. The site, the API and the download server are behind Cloudflare. The app does not check for updates or phone home: new versions are downloaded from the website by you.
7. The permissions the app asks for
- Microphone — to record your speech while you hold the key.
- Accessibility (macOS; Windows uses its own interfaces without a prompt) — to catch the hotkey, paste the text, read the selected text, the text around the cursor, window titles and, when you press the Command key, the window’s text, and notice your corrections for a short while after an insertion. The app never records your ordinary typing and never reads password fields.
- Screen Recording (macOS) — only for the Command key: when you press it, the app takes a picture of the window you are in, to read its text right on your computer when accessibility exposes none, and as the screenshot that goes to the cloud only when the window’s text is not enough.
8. Legal bases and transfers
We process your data to perform our contract with you (the service, your account, devices, licenses and balance); on our legitimate interests in keeping the service secure and the balance protected (device limits, hashed tokens, safety caps, fault records, abuse prevention, making the service faster); to meet legal obligations (bookkeeping and tax records); and with your consent for what you switch on yourself — feedback on a Command answer, the clipboard in a mode of your own, a webhook you set up — and for the website’s statistics and advertising cookies where the law asks for consent (elsewhere they rest on our legitimate interest in knowing how people find us and which ads work). You can object to the processing based on our legitimate interests (section 10).
Our server and database are in the Netherlands, in the EU. The providers in section 4 are in the United States and the United Kingdom. Each transfer rests on the provider’s data-processing terms with the safeguards the law requires — the EU Standard Contractual Clauses, and the EU–US Data Privacy Framework where the provider is certified under it. Serbia’s law treats the EU, the EEA and the countries the EU recognizes as adequate as safe destinations.
9. Security
- Everything travels encrypted: the app to our server, our server to the providers, the website.
- Access tokens are stored only as hashes; licenses are signed with a key that never leaves the server; the provider keys live only on the server, never in the app.
- The server accepts connections only through Cloudflare, and its administration page only from the owner’s private network. The service is run by one person, the owner; nobody else has access to the database.
If we ever learn of a breach that affects you, we tell you and the authority as the law requires.
10. Your rights
You can ask us, at any time and for free, what data we hold about you and for a copy of it; to correct it, delete it or restrict what we do with it; to object to processing based on our legitimate interests; to withdraw a consent you gave; and to delete your account.
Deleting your account. We close it at once: your devices are signed out, your keys stop working, the feedback you sent is deleted, and nothing of yours is processed any more. The account’s technical records — your email, your devices, the usage lines and our log of what was done with the account — stay for one year after that, so that we can detect abuse of the service (fraud, a reversed payment, a blocked user coming back) and answer claims about it; by using WhooshType you agree to this. After the year they are erased, and only the payment records the law makes us keep remain, for that time only. If you sign in with the same email within that year, your account comes back as it was.
Write to [email protected] from the address you sign in with; we answer within 30 days. You can also complain to a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs); in the EU, the EEA, the UK or Switzerland, the authority of the country you live in. The data on your computer is under your control alone.
11. Children
WhooshType is not meant for children under 16, and we do not knowingly keep an account for one. If you learn that a child has made one, write to us and we delete it.
12. Changes and contact
We update this policy when the app, the providers or the law change; the date at the top says which version is in force, and we tell you in the app or by email when a change matters to you. Questions and requests about your data: [email protected]; our business details are in section 1.