Privacy Policy
Your voice stays on your device.
Last updated: June 2, 2026
TL;DR
Your voice never leaves your device. The app uses the network for first setup, license activation, periodic license checks, and updates, but your audio, transcripts, and vocabulary stay local. We do not run user accounts, advertising SDKs, behavioral analytics, or third-party trackers.
Information we collect
No account or dictation data.
hush·hush has no user accounts, no advertising SDK, no behavioral analytics, and no third-party trackers. We do not receive your audio, transcripts, custom vocabulary, or text content. We do receive limited license and device data when the app contacts our server for first setup, purchase activation, periodic license checks, and updates. SeeServer interactions below for the exact bytes that travel and the reason each one travels.
On-device processing
Speech recognition and text organization happen locally on your device, using local models installed during first setup:
- Speech recognition uses a local speech model selected per language.
- Text organization (punctuation, spacing, capitalization) uses an on-device organizing model.
Your audio recordings and transcripts stay on your device. They are not uploaded, queued for later upload, or buffered anywhere off your machine. The app makes no network requests during dictation.
What is stored on your device
hush·hush keeps a small amount of state in your macOS user preferences and Application Support directory, all under your control:
- Transcript history: a local file of past dictations so you can review or re-paste them. You can clear all history from the History tab.
- Custom vocabulary: words you've added or that the app has auto-learned from your corrections, stored locally so future dictations recognize them. You can remove any entry from the Smart Fix tab.
- Preferences: your hotkey, primary language, retention settings, and similar options.
None of this is transmitted off your device. You can delete all app data by removing hush·hush from your device and clearing ~/Library/Application Support/hush·hush and the app's entry under ~/Library/Preferences.
Permissions we request
To do its job, hush·hush asks macOS for two permissions. You grant each one through standard macOS system dialogs, and you can revoke either at any time under System Settings > Privacy & Security.
- Microphone: required to capture audio while you hold the hotkey. The microphone is opened only during a dictation and is released the moment you let go of the key.
- Accessibility: required so the app can listen for your global hotkey and paste the transcribed text into the application you were typing in. The Accessibility permission is not used to read on-screen content, monitor other apps, or capture keystrokes outside of the dictation hotkey path.
Network use
Dictation itself makes no network requests. Audio capture, transcription, and text organization all happen on your device using local models. Your voice and transcripts never touch our server.
The app contacts our server (hush-hush.ai) in scoped situations: first setup, purchase activation, periodic license checks for validation-backed licenses, support-issued license delivery, and update checks. These are documented below.
During first setup, the app may download local model files from approved model hosts, including Hugging Face and our Cloudflare-hosted fallback. Those requests do not include your audio, transcripts, vocabulary, or dictated text.
Server interactions
Trial verification
Trial setup does not send your name, email, audio, transcripts, or location. The app collects nothing that could trace a transcript or recording back to your real identity.
To prevent trial reset abuse, the app sends two non-identifying signals to our server during first setup:
- A one-way hash of your device's hardware identifier, combined with a per-app salt so it cannot be matched against fingerprints stored by any other app or service. The original identifier never leaves your device.
- Non-identifying device specs: model name (e.g.
MacBookPro18,3), OS version, CPU architecture, and coarse memory/storage values. These are aggregate-level. Millions of devices share the same combination.
We store the bounded device metadata object and derived summary buckets to enforce the one-trial-per-device rule and to debug device-specific issues. We cannot reverse the hardware identifier from the hash, but we can use it to recognize the same device if it asks for another trial.
License verification
Once you've purchased and activated a license, the app communicates with our license server (hush-hush.ai) to verify your license remains active. Activation sends your license key, device fingerprint hash, local model name, and OS version to our server. We store the license key encrypted at rest, plus a keyed hash used for lookup. For Lemon Squeezy-backed licenses, we send Lemon Squeezy the license key and a device instance label containing model, OS version, and activation date. The app checks validation-backed licenses roughly every 7 days.
Third parties
Three, all narrowly scoped:
- Lemon Squeezy handles payments and stores the authoritative license record for paying customers. If you buy a license, Lemon Squeezy collects payment and customer information under its own policy. During activation and license checks, we send Lemon Squeezy your license key and a device instance label. We do not share data for advertising, analytics, or any unrelated purpose.
- Cloudflare hosts our website and serves the verification endpoints. Like any web request, the TCP/TLS layer exposes your IP address to the receiving server while the connection is open. Our app database does not store IP addresses.
- Hugging Face may serve local model files during first setup. The request is for model bytes only. It does not include your audio, transcripts, vocabulary, license key, or dictated text.
Children's privacy
hush·hush is not directed at children under 13. We do not knowingly collect personal information from children.
Your rights
Most app data lives on your device, and you can inspect, modify, or delete it at any time using Finder and the app's own controls. If you bought a license or contacted support, email us to request access, correction, or deletion of records we control.
Changes to this policy
If we change this policy, we'll update the Last updated date above and post the revised version at this URL. Material changes will be communicated through the app's release notes.
Contact
Questions? Email [email protected].