Yappy privacy model

The privacy page is the plain-language version. This one is component by component, for people who want to check.

Never leaves the machine

ComponentWhere it runsWhy it cannot leak
Microphone captureAVAudioEngine, in-processBuffers are handed straight to the local recogniser and released.
Speech recognitionwhisper.cpp, localThe model file is on disk; there is no network client in this path.
Screen contextApple Vision OCR, on-deviceThe screenshot is read into text and discarded; never written to disk.
Learned playbooksLocal files under ~/.yappyWritten and read by the app only.
Correction historyLocalUsed to bias the next transcription toward words you actually use.

There is no configuration in which audio is uploaded. Not on the free tier, not on the hosted plan.

Leaves the machine, by your choice

ComponentWhat is sentWhen
Cleanup with a hosted providerThe text of one transcriptOnly when llm.provider is a hosted option
Agent ModeTask text plus the screen-derived context to carry it outOnly when you hold Right ⌘
Task write-backOne row per task: what you asked, the answer, the app, the window title, which tools ranOnly when a memory is connected and agent.fillOffers is on (default off)
Dictation write-backThe cleaned-up text of takes over ~25 words, with app and window titleOnly when agent.fillOffers is on (default off)
Update checkApp version, to fetch a signed appcastWhen autoUpdate is on
Usage analyticsFeature events, app and OS versionWhen shareUsageAnalytics is on
Send FeedbackWhat the dialog shows you before sendingOnly when you press send

Set llm.provider to ollama and turn Agent Mode off, and nothing in the dictation path touches the network.

What the write-back never contains

The exclusions are structural, not a filter applied afterwards: the record type that becomes a memory row has no field for any of this, so there is nothing to leak even if a future change is careless.

  • Tool arguments and tool results — where file contents, shell output and pasted credentials actually live.
  • Screen OCR, the selected text, and the text surrounding your cursor.
  • The agent's step-by-step narration and its internal reasoning.
  • The raw transcript of a dictation take, as opposed to the cleaned-up text.

What does travel is passed through a secret redactor first — private keys, provider API tokens, JWTs, bearer headers and NAME=value assignments whose name says secret — and each row records how many redactions fired, so "did Yappy send my keys anywhere" has a number for an answer. Rows are keyed so that re-sending one updates it in place rather than duplicating it, and everything Yappy has written to an office can be removed by disconnecting that source.

What analytics never contains

Transcripts, audio, screen contents, filenames, window titles, prompts, and clipboard contents are all excluded at the point of capture, not filtered later. The events are things like "dictation completed", "agent task started", app version, and macOS version.

Verifying it yourself

You do not have to take our word for the local claims:

  1. Turn Wi-Fi off.
  2. Set llm.provider to ollama (or turn AI Cleanup off entirely).
  3. Dictate.

The text still appears. Whisper, cleanup, and OCR are all running on your Mac. Little Snitch or nettop will show you the same thing with the network on.

macOS permissions

PermissionNeeded forIf denied
MicrophoneAny dictationDictation is unavailable; everything else works
AccessibilityGlobal hotkey and inserting textThe key does nothing; grant and relaunch
Screen RecordingScreen context onlyScreen context silently stays off

Each is revocable in System Settings → Privacy & Security and takes effect immediately. Yappy degrades to the features that permission is not needed for rather than nagging.

Retention

Yappy keeps no transcripts server-side, because it sends none. Local correction history lives on your machine and is deleted with the app. Analytics events are retained by PostHog under the project's retention window and carry no content.

Reading this as an agent? The same page in markdown: /docs/privacy-model.md · machine index: /llms.txt · API: /openapi.json · MCP: https://yappy.biz/mcp