Privacy notice
VocalCode performs speech recognition on your device. This notice distinguishes that local processing from the limited online services used for downloads, checkout, licensing, recovery and updates.
What stays on your device
- Microphone audio is processed in memory for recognition. VocalCode does not upload it or intentionally write recordings to disk.
- Recent transcript history is kept in memory, capped at 50 entries, so you can recover a failed insertion. It disappears when the app process ends and is not written to disk or uploaded.
- Clipboard use occurs when you copy a History entry, teach a selected word through a copy action, or enable the optional Paste text mode. VocalCode attempts to restore the previous clipboard after its operation, but the operating system, clipboard-history features, cloud clipboard, password managers or other clipboard tools may retain or synchronize copied transcript text. Paste text is off by default.
- Text selected for Teach is read only when you explicitly invoke the Teach command (through a local copy action or the macOS Service) and is used to create a replacement-dictionary rule. The rule is stored locally until you edit it or remove app data; selected text and rules are not uploaded.
- Learn my corrections, when enabled, locally watches only the same non-secure input control that just accepted a VocalCode transcript, for the short interval selected in Settings. If you edit and send that input, VocalCode can store a short word or name fix as a local replacement-dictionary rule; sentence rewrites, punctuation edits and oversized changes are ignored. The complete input value is not written to disk, logged or uploaded; password and other secure controls are excluded, and the watch ends when the target changes or the bounded session expires.
- App state stored on disk includes settings, replacement-dictionary rules, downloaded models, aggregate dictation/word/character counts, a signed device-bound trial receipt, a signed paid-licence receipt and bounded diagnostic logs. Aggregate counters do not contain transcript text. Diagnostic logs are designed not to record recognised text, but can include errors, local paths, usernames or hardware identifiers.
System permissions and text insertion
VocalCode observes system-wide keyboard, mouse, gamepad, HID and media/consumer-control events only to match the talk, send and teach controls you configure, and to capture a candidate control while you explicitly rebind one. Unrelated events are discarded rather than stored or uploaded. Microphone permission is used while recording speech.
On macOS, the app also requests Accessibility and Input Monitoring. Input Monitoring detects configured talk controls; Accessibility lets VocalCode identify the intended focused target and send recognised text through native macOS input APIs. VocalCode does not send Apple Events and does not request Automation permission. Where the operating system exposes a reliable target identity, VocalCode checks it again during insertion and stops when it detects a change. Higher-privilege Windows processes, secure fields, browser-rendered controls and some apps may reject synthetic input or prevent reliable target identification; VocalCode may therefore refuse those targets. Refused text remains recoverable in the in-memory History while the app session is open.
When VocalCode connects
| Action | Data sent and purpose |
|---|---|
| Website, model and update downloads | Normal request metadata such as IP address, user agent, requested file and time is handled by Cloudflare to deliver the site, models and releases. A model file path reveals whether the Mandarin-Chinese/Paraformer or European/Parakeet route was downloaded; all 25 European preference labels use the same Parakeet files, so the request does not reveal which European label was selected. No audio or transcript is included. |
| Advertising measurement on public website pages | The public marketing pages load the Google Ads tag for limited, cookieless page measurement and record selected VocalCode installer-download clicks and outbound Stripe purchase-link clicks as conversion events. VocalCode configures advertising and analytics storage, ad user data and ad personalization as denied, disables the conversion linker, redacts advertising data and does not pass the current URL through links. Google can still receive a limited measurement request containing normal connection and page metadata such as IP address, user agent, page URL, page title, selected event and time. The tag is not loaded on the licence-delivery page, which handles the Stripe Checkout Session identifier and displays the reusable licence key. No audio or transcript is included. |
| Manual activation | The licence key and a stable pseudonymous device fingerprint are sent through the VocalCode Cloudflare Worker to Keygen to validate the licence and enforce the device limit. The current app stores the returned signed receipt rather than the reusable key. During an upgrade from the older key-based format, a local legacy-migration recovery backup can retain the old key until conversion succeeds. |
| Free-trial provisioning | On the first official signed-trial launch, the stable pseudonymous device fingerprint is sent to the VocalCode Cloudflare Worker. A keyed one-way device index addresses a Durable Object that keeps the first-seen trial epoch; the app receives a signed, device-bound 30-day receipt. This prevents editing, deleting or reinstalling the local cache from starting a new trial. No audio or transcript is included. Initial trial provisioning therefore requires a network connection; the signed receipt is then checked offline. |
| Paid-licence refresh | The signed receipt and the same fingerprint are sent for live Keygen validation before the current 30-day receipt expires. Recognition can run without a network connection, but a paid licence needs this periodic online refresh to remain authorised. |
| In-app checkout polling | A random checkout reference and the fingerprint are used to bind a purchase to that device. The active polling binding expires after 24 hours; a one-way device-owner hash remains as a permanent anti-takeover record so another device cannot claim the same reference later. Stripe supplies payment status and the purchase email; the app receives a device-bound receipt rather than the reusable key. |
| Website key delivery | Stripe redirects the browser to the thank-you page with the Checkout Session identifier in the query string. That initial request is handled by Cloudflare Pages/CDN and may appear in operational request logs. The page immediately removes the query with history.replaceState before making its own network requests; the response is private/no-store and uses a no-referrer policy and restrictive Content Security Policy. The page then sends the identifier in a bounded POST body. After a signed Stripe webhook has authorised and recorded the purchase, the public route only reads that record; it does not verify payment or create a licence. The identifier acts as a delivery bearer for 15 minutes from the signed paid event, including asynchronous payment success, and Stripe replay cannot extend it. Verified-email recovery remains available after expiry. The identifier is also stored with the Keygen licence so the same purchase does not create duplicate licences and can be recovered. |
| Purchase fulfilment webhook | Stripe sends a signed event containing the live Checkout Session, payment status and purchase email so paid purchases can be fulfilled even if the app or thank-you tab closes. The Worker creates or finds the Keygen licence and asks Resend to email the reusable key. No audio or transcript is involved. |
| Key email and recovery | Stripe provides the purchase email. A keyed one-way fingerprint of the normalized address is stored in Keygen licence metadata as a recovery index. A separate short-lived keyed record enforces the recovery-email cooldown before any provider lookup; it does not contain the raw address. The public recovery route performs an exact metadata lookup and may only ask the existing webhook-authorised delivery record to resend its key; it never lists or searches the Stripe account. During migration, a uniquely matched older unkeyed index can be replaced with the keyed form. Ambiguous or missing legacy records are not guessed and require an audited offline migration or support review. Resend receives the address and message, including the reusable key, to deliver the email. The recovery page gives the same response whether or not an address exists. |
Service providers and retention
VocalCode uses Cloudflare for website, download and Worker infrastructure; Google Ads for limited public-page advertising measurement; Stripe for checkout and payment records; Keygen for licence and device records; and Resend for licence email. Full card details are handled by Stripe and are not sent to the VocalCode app or Worker.
Licence identifiers, machine bindings, the Stripe Session linkage and the keyed recovery index are kept while the licence remains available for activation and recovery. The reusable licence key and its webhook-authorised entitlement record are retained in a Session-keyed Cloudflare Durable Object so the key can be delivered and recovered without letting a public request create a licence. That record does not store the buyer's raw email address. A random in-app checkout reference has a 24-hour active polling binding, but its one-way device-owner hash is retained permanently as an anti-takeover tombstone; otherwise somebody who later obtained the reference could assign it to another device. There is no public self-service deletion route for that tombstone. A server-side deletion request may therefore be limited or refused where continued retention is necessary for purchase security, fraud prevention or legal obligations, subject to applicable law; support can explain the decision for a specific request. The keyed trial-device index and first-seen epoch are likewise retained so an expired trial cannot be reset by deleting local data. Purchase and payment records may be retained by Stripe or by VocalCode where needed for accounting, tax, fraud prevention, disputes or other legal obligations. Infrastructure and email providers may retain operational logs or delivery records under their own policies.
Legal bases, automated checks and privacy rights
Where the GDPR or UK GDPR applies, purchase fulfilment, activation, recovery and licence refresh are processed as necessary to provide the product and licence you requested. Fraud prevention, service security, rate limiting and operational support rely on legitimate interests in protecting buyers and the service. Transaction records may also be processed to meet tax, accounting or other legal obligations.
Activation decisions are automated from payment status, licence status, signed receipt claims and the device limit. A refusal prevents licensed text insertion, but you can ask support@vocalcode.app to investigate or correct a mistaken decision. VocalCode does not use this data to build an advertising profile.
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, or complain to your local data-protection authority. These rights can have legal exceptions. Send a request from the purchase address to support@vocalcode.app; additional information may be requested only when needed to verify that the requester is entitled to the record.
Cookies and analytics
Public marketing pages load the Google Ads tag with advertising and analytics storage denied, ad user data and ad personalization denied, advertising-data redaction enabled and the conversion linker disabled. In this configuration VocalCode does not ask the tag to store or read Google Ads cookies, but Google still receives the limited cookieless measurement request described above. The tag is not loaded on the licence-delivery page. Stripe and the infrastructure providers may use security or checkout storage when you visit their services.
Removing data
The app's Remove app data action removes settings, models, paid-licence state, dictionary, counters and logs, then exits. The Windows uninstaller performs the same owned-data cleanup. Both deliberately retain the small signed trial receipt (vocalcode-trial.dat) and the monotonic trusted-time high-water mark (vocalcode-time-anchor.bin on Windows; protected Keychain state on macOS). These records preserve offline trial checks and clock-rollback evidence across reinstall.
For complete local deletion after uninstalling, remove the remaining VocalCode data directory:
- Windows:
%LOCALAPPDATA%\VocalCode - macOS:
~/Library/Application Support/VocalCode
Deleting the remaining data directory removes both retained files on Windows. On macOS, also remove VocalCode's app.vocalcode.trusted-time Keychain item to remove the protected trusted-time state. Removing these local records does not erase or restart the server-owned trial epoch; the next authenticated trial request returns the original epoch. To ask for access, correction or deletion of server-side licence or recovery metadata, email support@vocalcode.app from the purchase address. Deleting licence records can disable activation and recovery. The permanent checkout-owner tombstone, trial epoch, and some transaction records may need to be retained for purchase security, trial enforcement, legal, tax, fraud or dispute purposes; a request is assessed under applicable law rather than guaranteed.
Changes and questions
Material changes will be reflected here with a new effective date. Questions or privacy requests can be sent to support@vocalcode.app.