Yappy privacy model
The privacy page is the plain-language version. This one is component by component, for people who want to check.
Never leaves the machine
| Component | Where it runs | Why it cannot leak |
|---|---|---|
| Microphone capture | AVAudioEngine, in-process | Buffers are handed straight to the local recogniser and released. |
| Speech recognition | whisper.cpp, local | The model file is on disk; there is no network client in this path. |
| Screen context | Apple Vision OCR, on-device | The screenshot is read into text and discarded; never written to disk. |
| Learned playbooks | Local files under ~/.yappy | Written and read by the app only. |
| Correction history | Local | Used to bias the next transcription toward words you actually use. |
There is no configuration in which audio is uploaded. Not on the free tier, not on the hosted plan.
Leaves the machine, by your choice
| Component | What is sent | When |
|---|---|---|
| Cleanup with a hosted provider | The text of one transcript | Only when llm.provider is a hosted option |
| Agent Mode | Task text plus the screen-derived context to carry it out | Only when you hold Right ⌘ |
| Task write-back | One row per task: what you asked, the answer, the app, the window title, which tools ran | Only when a memory is connected and agent.fillOffers is on (default off) |
| Dictation write-back | The cleaned-up text of takes over ~25 words, with app and window title | Only when agent.fillOffers is on (default off) |
| Update check | App version, to fetch a signed appcast | When autoUpdate is on |
| Usage analytics | Feature events, app and OS version | When shareUsageAnalytics is on |
| Send Feedback | What the dialog shows you before sending | Only when you press send |
Set llm.provider to ollama and turn Agent Mode off, and nothing in the dictation path touches the network.
What the write-back never contains
The exclusions are structural, not a filter applied afterwards: the record type that becomes a memory row has no field for any of this, so there is nothing to leak even if a future change is careless.
- Tool arguments and tool results — where file contents, shell output and pasted credentials actually live.
- Screen OCR, the selected text, and the text surrounding your cursor.
- The agent's step-by-step narration and its internal reasoning.
- The raw transcript of a dictation take, as opposed to the cleaned-up text.
What does travel is passed through a secret redactor first — private keys, provider API tokens, JWTs, bearer headers and NAME=value assignments whose name says secret — and each row records how many redactions fired, so "did Yappy send my keys anywhere" has a number for an answer. Rows are keyed so that re-sending one updates it in place rather than duplicating it, and everything Yappy has written to an office can be removed by disconnecting that source.
What analytics never contains
Transcripts, audio, screen contents, filenames, window titles, prompts, and clipboard contents are all excluded at the point of capture, not filtered later. The events are things like "dictation completed", "agent task started", app version, and macOS version.
Verifying it yourself
You do not have to take our word for the local claims:
- Turn Wi-Fi off.
- Set
llm.providertoollama(or turn AI Cleanup off entirely). - Dictate.
The text still appears. Whisper, cleanup, and OCR are all running on your Mac. Little Snitch or nettop will show you the same thing with the network on.
macOS permissions
| Permission | Needed for | If denied |
|---|---|---|
| Microphone | Any dictation | Dictation is unavailable; everything else works |
| Accessibility | Global hotkey and inserting text | The key does nothing; grant and relaunch |
| Screen Recording | Screen context only | Screen context silently stays off |
Each is revocable in System Settings → Privacy & Security and takes effect immediately. Yappy degrades to the features that permission is not needed for rather than nagging.
Retention
Yappy keeps no transcripts server-side, because it sends none. Local correction history lives on your machine and is deleted with the app. Analytics events are retained by PostHog under the project's retention window and carry no content.