Trust Center

New recordings keep their source audio on your device. If you choose workspace processing, the audio is streamed temporarily through Voicecape to Soniox for real-time transcription. Voicecape does not store the audio in the cloud, and Soniox does not retain the stream. The resulting workspace transcript and summary are stored as encrypted text.

What stays on your Mac

Workspace processing is optional and starts only after you choose it and confirm the workspace processing notice. Voicecape reads the saved local source in bounded pieces and streams it through the Relay to Soniox in real time. The Relay forwards audio without storing it; Voicecape requests Soniox’s no-storage real-time mode, and neither side keeps source audio from that stream. The transcribed text is then sent to the language-model provider our server is set to — currently OpenAI, L.L.C., reached through the Cloudflare AI Gateway — which produces the summary, decisions and action items. Audio is not sent to that provider.

The text you dictated follows a switch too. Leave the processing mode off Polish with AI and the tidying runs on the device, your personal dictionary stays on the Mac, and Voicecape keeps no dictation transcript on any server (workspace Recording transcripts are stored encrypted, as described above). You can check this from the outside: turn both off and dictate in airplane mode, or watch it with a firewall monitor.

What the app sends on its own

Besides dictation audio while Cloud dictation is on, and session renewal while you are signed in, the app makes three requests on its own. Licence activation, when you paste a key and press Activate (existing Polar or PortOne contracts only). A quiet re-check of that licence afterwards, carrying the same key, device identifier and activation identifier. And a daily update check that sends a version number.

There is one more that is conditional rather than routine: if the speech model inside the app is found damaged, Voicecape can fetch a replacement. That is the Hugging Face entry below, and it does not happen in ordinary use.

Some hosts in the table are reached by something other than the app: your browser goes to the billing console at app.voicecape.com when you subscribe, where Paddle handles checkout, and our own licence server asks Polar whether a legacy key is valid. They are on the list anyway, because who opened the socket is not what decides whether someone received your data.

Why this list is generated

A page like this rots the moment a feature adds a recipient nobody wrote down. So it is not written by hand: it is rendered from the host ledger in the source code, which is itself held to the code in both directions by a build gate — a host in the code but not in the ledger fails the build, and a host in the ledger that the code no longer reaches fails it too.

What that gate cannot do is find a recipient that leaves no trace in the code. A native framework or a redirect can reach a host without the address ever appearing in a source file, and the ledger says so about itself. Those entries are added by a person; the gate then keeps them honest.

Every host in the ledger

The whole ledger, in the order it is declared in the source. Nothing is filtered out of it here.

  • api.voicecape.com

    Our first-party API for entitlement, account and note text, and user-started real-time speech processing. Recording PCM is streamed through this host to Soniox and is not stored as audio by Voicecape.

    What is sent
    Audio and text — the line above states the purpose and retention contract
    Who opens it
    Your Mac, directly
    In a published build
    Reachable
    Named in the privacy policy as
    voicecape.com
  • voicecape.com

    The update feed the app reads once a day, and the help and re-download links in the app. The update check sends a version number and nothing else.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Your Mac, directly
    In a published build
    Reachable
    Named in the privacy policy as
    voicecape.com
  • huggingface.co

    Fetches a replacement speech model if the copy inside the app is found damaged. It does not run in normal use — the model ships inside the app and nothing downloads on first launch.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Your Mac, directly
    In a published build
    Reachable
    Named in the privacy policy as
    Hugging Face — not in the privacy policy yet
  • voicecape-relay.egpnwme.workers.dev

    The optional cloud text-polishing service. It receives text, never audio, and it is not reachable from a published build.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Your Mac, directly
    In a published build
    Reachable
    Named in the privacy policy as
    Cloudflare, Inc.
  • api.storekit.apple.com

    Not in the shipping app — Voicecape is a Mac app today and there is no mobile build to buy a subscription in. It is here because the code path exists: for the version that ships on phones, our server would ask Apple directly, sending the transaction identifier and an account identifier — no audio, no dictated text, no email.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Not reachable — development builds only
    Named in the privacy policy as
    Apple Inc.
  • api.storekit-sandbox.itunes.apple.com

    Not in the shipping app. The same check as above, against the test store Apple uses for review builds — same identifiers, nothing more.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Not reachable — development builds only
    Named in the privacy policy as
    Apple Inc.
  • androidpublisher.googleapis.com

    Not in the shipping app — there is no Android build yet. It is here because the code path exists: for the version that ships on phones, our server would ask Google directly, sending the purchase token and an account identifier — no audio, no dictated text, no email.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Not reachable — development builds only
    Named in the privacy policy as
    Google LLC
  • oauth2.googleapis.com

    Not in the shipping app, for the same reason as the check above. Exchanges our own service credential for a short-lived token so that check can run. Nothing about you is sent here — not even an identifier.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Our server, on your behalf
    In a published build
    Not reachable — development builds only
    Named in the privacy policy as
    Google LLC
  • www.googleapis.com

    Not in the shipping app, for the same reason as the checks above. When Google tells our server that a subscription changed, the notice is signed by Google; before acting on it, our server downloads Google’s public signing certificates from here to verify that signature. Nothing about you is sent here — the request only downloads the certificates. The same name also appears in our code as the label of the permission scope the check above requests.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Our server, on your behalf
    In a published build
    Not reachable — development builds only
    Named in the privacy policy as
    Google LLC
  • api.polar.sh

    Legacy only. Our licence server may ask Polar whether a key from an existing contract remains valid. New Voicecape subscriptions are not created here.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Polar Software, Inc.
  • api.portone.io

    Legacy only. Our server uses PortOne to cancel or refund existing Korean-won contracts. It accepts no new Voicecape sale; your Mac never talks to this host.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    주식회사 코리아포트원
  • generativelanguage.googleapis.com

    One of the language models the polishing service can hand text to. Reachable only from a development build.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Google LLC
  • api.openai.com

    A second language model for the polishing service, used when the first one fails. Reachable only from a development build.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    OpenAI, L.L.C.
  • api.groq.com

    A third language model for the polishing service, chosen because it fails for different reasons than the other two. Reachable only from a development build.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Groq, Inc.
  • stt-rt.soniox.com

    The speech-recognition vendor for Cloud dictation. While that switch is on, the audio of what you say is streamed here through our relay and transcribed in real time; by contract no copy is retained.

    What is sent
    Audio
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Soniox Inc.
  • api.deepgram.com

    Used only to process historical cloud-stored audio from retired versions. New recordings and dictation never reach this host; real-time recognition goes to Soniox alone.

    What is sent
    Audio
    Who opens it
    Our server, on your behalf
    In a published build
    Excluded
    Named in the privacy policy as
    Deepgram, Inc.
  • supabase.co

    Accounts — sign-up, sign-in, sessions and deletion. Shipping since 1.3.0. Nothing is sent here unless you create an account or sign in.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Your Mac, directly
    In a published build
    Reachable
    Named in the privacy policy as
    Supabase
  • appleid.apple.com

    Sign in with Apple. macOS makes this call for us and hands back an identity token; we never see your Apple password. The button is only drawn on a build signed for it, and it is off in the current release.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    macOS, on our behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Apple Inc.
  • accounts.google.com

    Sign in with Google, on the website. Your browser is sent there by the account service; the Mac app itself never names this host and has no Google button.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Your browser, handed off by the app
    In a published build
    Reachable
    Named in the privacy policy as
    accounts.google.com
  • example.com

    Not a real destination. It is the placeholder in test fixtures and in an input field hint, and it is listed here only because this table is the whole ledger rather than a selection from it.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Your Mac, directly
    In a published build
    Not an egress at all
    Named in the privacy policy as
    Not a destination
  • api.paddle.com

    For a paid personal or team plan, our server asks Paddle to read, change, cancel or restore that subscription. It sends subscription and price identifiers; team changes also send the seat count. Your card never travels this path — it goes from your browser to Paddle directly.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Paddle.com Market Ltd.
  • cdn.paddle.com

    Your browser loads the checkout script from here when you open the billing page. Card details are typed inside a window that belongs to Paddle, not to us, so the number never reaches our servers.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Your browser, handed off by the app
    In a published build
    Reachable
    Named in the privacy policy as
    Paddle.com Market Ltd.
  • sandbox-api.paddle.com

    Not in anything you use. It is Paddle’s test environment, reachable only from our own machines and preview builds; the shipped console refuses this host.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Not reachable — development builds only
    Named in the privacy policy as
    Not a destination
  • api.resend.com

    Account email only — the confirmation message when you sign up and the link when you reset a password. Your address and that link go out; nothing you recorded or dictated does.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Plus Five Five, Inc.
  • api.notion.com

    Only if an admin in your workspace turns the Notion integration on. Then the summary text — the points, decisions and action items — is written into the database they chose. Turning it off stops it; it is off until someone turns it on.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Notion Labs, Inc.
  • slack.com

    The sign-in step of the Slack integration. When an admin connects Slack, this is where the authorisation happens and where we exchange the resulting code for a token — the summary itself does not travel here.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Slack Technologies, LLC
  • hooks.slack.com

    Only if an admin in your workspace turns the Slack integration on. Then the summary text is posted to the channel behind the webhook address they pasted. Turning it off stops it.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Slack Technologies, LLC
  • api.recordport.app

    Our compatibility API address for previously installed clients. Those clients may still use it, and the Worker routes their requests to the same Voicecape service. Current Voicecape API documentation uses api.voicecape.com.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Your Mac, directly
    In a published build
    Reachable
    Named in the privacy policy as
    Not a destination
  • voicecape.com

    The update feed the app reads once a day, and the help and re-download links in the app. The update check sends a version number and nothing else.

    What is sent
    Request metadata only — nothing you said, nothing you typed
    Who opens it
    Your browser, handed off by the app
    In a published build
    Reachable
    Named in the privacy policy as
    Not a destination
  • app.voicecape.com

    Ours — the web console itself. The address appears in our own code because links in emails, share links and the payment callback have to point somewhere; it is the same site you are signed in to.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Not a destination
  • admin.recordport.app

    Ours — the console’s older address. Links we sent before the rename still point at it, so it stays online and forwards you to the current console. Same site, older name.

    What is sent
    Text, never audio — the line above says which text
    Who opens it
    Our server, on your behalf
    In a published build
    Reachable
    Named in the privacy policy as
    Not a destination

Some rows carry “not in the privacy policy yet”. That marker is read from the ledger’s own backlog, and the build gate holds it in both directions — a recipient still marked after it has been named fails just as loudly as one that was never named. Every row carrying it today is either unreachable from a published build, or receives nothing about you; the generator refuses to render this page if that stops being true.

Reading the rest

The privacy policy is the document with legal force, and it names the same recipients in the terms the law uses. What Voicecape sends over the network walks the three requests one at a time, with the actual endpoints. If you find something on this page that does not match what your firewall shows you, write to us — that is a report we want.

Back to voicecape.com