Privacy notice

VocalCode performs speech recognition on your device. This notice distinguishes that local processing from the limited online services used for downloads, checkout, licensing, recovery and updates.

Effective 29 August 2026 · Controller: VocalCode / Daming Wu · support@vocalcode.app

The short version: VocalCode performs dictation and meeting recognition locally and does not send microphone audio, system audio, transcripts, notes or search queries to its servers. Recent dictation History remains in memory for the current app session; meetings are intentionally stored on disk until deleted under the retention setting. Model downloads, checkout, licensing, recovery and updates use online services. Copying text or enabling Paste text can expose a transcript to the operating system's clipboard history or sync tools.

What stays on your device

System permissions and text insertion

VocalCode observes system-wide keyboard, mouse, gamepad, HID and media/consumer-control events only to match the talk, send and teach controls you configure, and to capture a candidate control while you explicitly rebind one. Unrelated events are discarded rather than stored or uploaded. Microphone permission is used while recording speech. Meeting microphone and system-audio capture starts only after you choose the sources and press Start meeting; a reminder can open the Meetings panel but never starts recording. Record only with every participant's permission.

On macOS, the app also requests Accessibility and Input Monitoring. Input Monitoring detects configured talk controls; Accessibility lets VocalCode identify the intended focused target and send recognised text through native macOS input APIs. VocalCode does not send Apple Events and does not request Automation permission. On macOS 14.6 or later, selecting meeting system audio also requests the separate System Audio Recording permission; VocalCode does not capture video or screen pixels. Where the operating system exposes a reliable target identity, VocalCode checks it again during insertion and stops when it detects a change. Higher-privilege Windows processes, secure fields, browser-rendered controls and some apps may reject synthetic input or prevent reliable target identification; VocalCode may therefore refuse those targets. Refused text remains recoverable in the in-memory History while the app session is open.

When VocalCode connects

ActionData sent and purpose
Website, model and update downloadsNormal request metadata such as IP address, user agent, requested file and time is handled by Cloudflare to deliver the site, models and releases. A model file path reveals which model route was downloaded — Parakeet, Paraformer, SenseVoice or Qwen3-ASR — but shared models do not reveal the selected label within that route. No audio, transcript, meeting note or search query is included.
Advertising and campaign measurement on public website pagesThe public marketing pages load the Google Ads tag for limited, cookieless page measurement and record selected VocalCode installer-download clicks and outbound Stripe purchase-link clicks as conversion events. VocalCode configures advertising and analytics storage, ad user data and ad personalization as denied, disables the conversion linker, redacts advertising data and does not pass the current URL through links. Google can still receive a limited measurement request containing normal connection and page metadata such as IP address, user agent, page URL, page title, selected event and time. When a visit has an explicit src, Product Hunt referral, standard UTM campaign marker, or comes from a recognized public product directory, VocalCode also stores a bounded campaign label in browser local storage for up to 45 days and attaches it to Stripe Checkout metadata if that visit later purchases. Referring-directory recognition uses a small exact-host allowlist and keeps only a fixed label such as saashub; the complete referring URL and path are not stored or attached to Checkout. When an installer link is selected, the website also sends VocalCode's dedicated Cloudflare growth-measurement Worker only the fixed event name download, an allowlisted campaign label (or unattributed) and the selected platform (windows or macos). The measurement Worker has no licence, trial, purchase, payment, recovery or email binding. An unrecognized label is reduced to unattributed rather than stored. Cloudflare Analytics Engine retains these aggregate event points for three months. The event contains no audio, transcript, email address, device identifier, complete URL or referrer. The connecting IP address is hashed only into a short-lived rate-limit key and is not written to the analytics dataset. These aggregate clicks are not linked to a trial device. The Google tag and campaign script are not loaded on the licence-delivery page, which handles the Stripe Checkout Session identifier and displays the reusable licence key.
Manual activationThe licence key and a stable pseudonymous device fingerprint are sent through the VocalCode Cloudflare Worker to Keygen to validate the licence and enforce the device limit. The current app stores the returned signed receipt rather than the reusable key. During an upgrade from the older key-based format, a local legacy-migration recovery backup can retain the old key until conversion succeeds.
Free-trial provisioningOn the first official signed-trial launch, the stable pseudonymous device fingerprint is sent to the VocalCode Cloudflare Worker. A keyed one-way device index addresses a Durable Object that keeps the first-seen trial epoch; the app receives a signed, device-bound 30-day receipt. This prevents editing, deleting or reinstalling the local cache from starting a new trial. No audio or transcript is included. Initial trial provisioning therefore requires a network connection; the signed receipt is then checked offline.
Paid-licence refreshThe signed receipt and the same fingerprint are sent for live Keygen validation before the current 30-day receipt expires. Recognition can run without a network connection, but a paid licence needs this periodic online refresh to remain authorised.
In-app checkout pollingA random checkout reference and the fingerprint are used to bind a purchase to that device. The active polling binding expires after 24 hours; a one-way device-owner hash remains as a permanent anti-takeover record so another device cannot claim the same reference later. Stripe supplies payment status and the purchase email; the app receives a device-bound receipt rather than the reusable key.
Website key deliveryStripe redirects the browser to the thank-you page with the Checkout Session identifier in the query string. That initial request is handled by Cloudflare Pages/CDN and may appear in operational request logs. The page immediately removes the query with history.replaceState before making its own network requests; the response is private/no-store and uses a no-referrer policy and restrictive Content Security Policy. The page then sends the identifier in a bounded POST body. After a signed Stripe webhook has authorised and recorded the purchase, the public route only reads that record; it does not verify payment or create a licence. The identifier acts as a delivery bearer for 15 minutes from the signed paid event, including asynchronous payment success, and Stripe replay cannot extend it. Verified-email recovery remains available after expiry. The identifier is also stored with the Keygen licence so the same purchase does not create duplicate licences and can be recovered.
Purchase fulfilment webhookStripe sends a signed event containing the live Checkout Session, payment status and purchase email so paid purchases can be fulfilled even if the app or thank-you tab closes. The Worker creates or finds the Keygen licence and asks Resend to email the reusable key. No audio or transcript is involved.
Key email and recoveryStripe provides the purchase email. A keyed one-way fingerprint of the normalized address is stored in Keygen licence metadata as a recovery index. A separate short-lived keyed record enforces the recovery-email cooldown before any provider lookup; it does not contain the raw address. The public recovery route performs an exact metadata lookup and may only ask the existing webhook-authorised delivery record to resend its key; it never lists or searches the Stripe account. During migration, a uniquely matched older unkeyed index can be replaced with the keyed form. Ambiguous or missing legacy records are not guessed and require an audited offline migration or support review. Resend receives the address and message, including the reusable key, to deliver the email. The recovery page gives the same response whether or not an address exists.

Service providers and retention

VocalCode uses Cloudflare for website, download and Worker infrastructure; Google Ads for limited public-page advertising measurement; Stripe for checkout and payment records; Keygen for licence and device records; and Resend for licence email. Full card details are handled by Stripe and are not sent to the VocalCode app or Worker.

Licence identifiers, machine bindings, the Stripe Session linkage and the keyed recovery index are kept while the licence remains available for activation and recovery. The reusable licence key and its webhook-authorised entitlement record are retained in a Session-keyed Cloudflare Durable Object so the key can be delivered and recovered without letting a public request create a licence. That record does not store the buyer's raw email address. A random in-app checkout reference has a 24-hour active polling binding, but its one-way device-owner hash is retained permanently as an anti-takeover tombstone; otherwise somebody who later obtained the reference could assign it to another device. There is no public self-service deletion route for that tombstone. A server-side deletion request may therefore be limited or refused where continued retention is necessary for purchase security, fraud prevention or legal obligations, subject to applicable law; support can explain the decision for a specific request. The keyed trial-device index and first-seen epoch are likewise retained so an expired trial cannot be reset by deleting local data. Purchase and payment records may be retained by Stripe or by VocalCode where needed for accounting, tax, fraud prevention, disputes or other legal obligations. Infrastructure and email providers may retain operational logs or delivery records under their own policies.

Legal bases, automated checks and privacy rights

Where the GDPR or UK GDPR applies, purchase fulfilment, activation, recovery and licence refresh are processed as necessary to provide the product and licence you requested. Fraud prevention, service security, rate limiting and operational support rely on legitimate interests in protecting buyers and the service. Transaction records may also be processed to meet tax, accounting or other legal obligations.

Activation decisions are automated from payment status, licence status, signed receipt claims and the device limit. A refusal prevents licensed text insertion, but you can ask support@vocalcode.app to investigate or correct a mistaken decision. VocalCode does not use this data to build an advertising profile.

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, or complain to your local data-protection authority. These rights can have legal exceptions. Send a request from the purchase address to support@vocalcode.app; additional information may be requested only when needed to verify that the requester is entitled to the record.

Cookies and analytics

Public marketing pages load the Google Ads tag with advertising and analytics storage denied, ad user data and ad personalization denied, advertising-data redaction enabled and the conversion linker disabled. In this configuration VocalCode does not ask the tag to store or read Google Ads cookies, but Google still receives the limited cookieless measurement request described above. A first-party vc_src campaign label and its timestamp may be kept in local storage for up to 45 days as described above; malformed, expired and future-dated values are discarded. Installer clicks may additionally create the three-field, three-month Cloudflare aggregate event described above; it is not an identifier and is not joined to trial or licence records. The tag and campaign script are not loaded on the licence-delivery page. Stripe and the infrastructure providers may use security or checkout storage when you visit their services.

Removing data

The app's Remove app data action removes settings, models, meetings (including retained audio, transcripts and notes), paid-licence state, dictionary, counters and logs, then exits. Deleting an individual meeting removes its local directory; automatic retention applies the period selected in Meetings. The Windows uninstaller performs the same owned-data cleanup. Both deliberately retain the small signed trial receipt (vocalcode-trial.dat) and the monotonic trusted-time high-water mark (vocalcode-time-anchor.bin on Windows; protected Keychain state on macOS). These records preserve offline trial checks and clock-rollback evidence across reinstall.

For complete local deletion after uninstalling, remove the remaining VocalCode data directory:

Deleting the remaining data directory removes both retained files on Windows. On macOS, also remove VocalCode's app.vocalcode.trusted-time Keychain item to remove the protected trusted-time state. Removing these local records does not erase or restart the server-owned trial epoch; the next authenticated trial request returns the original epoch. To ask for access, correction or deletion of server-side licence or recovery metadata, email support@vocalcode.app from the purchase address. Deleting licence records can disable activation and recovery. The permanent checkout-owner tombstone, trial epoch, and some transaction records may need to be retained for purchase security, trial enforcement, legal, tax, fraud or dispute purposes; a request is assessed under applicable law rather than guaranteed.

Changes and questions

Material changes will be reflected here with a new effective date. Questions or privacy requests can be sent to support@vocalcode.app.