Privacy Policy
Yappr is a macOS dictation app. It records what you say, turns it into text, and pastes the text where your cursor is. This page describes what the current version of that software does with the data it touches. It is written from the code, not from an intention.
1. Who is responsible for this
Yappr is made and run by one person. There is no company behind it — no incorporated entity, no team, no staff. Through the rest of this page, “I”means that individual developer and “you” means you. An earlier draft of this page said “we”, which flattered the size of the operation and left every obligation attached to nobody.
The developer is based in Spain. Under the EU General Data Protection Regulation that individual is the data controller for whatever processing described here is his to answer for — section 10 is specific, and honest, about where that is and is not the case. Because the developer is established in Spain, the Spanish supervisory authority is the lead authority; see your rights.
2. What this covers
This policy covers the Yappr macOS application and this website. It describes the behaviour of the app as of the date at the top of the page. Where the software changes, this page has to change with it; see Changes to this policy.
It does not cover what the third parties named in section 5 do with what reaches them. Those are their systems and their documents, and section 5 links them rather than paraphrasing them.
3. What happens when you dictate
One dictation is one pass through the following. Nothing here is optional or configurable except where it says so.
- You hold the hotkey and speak. The app captures audio from the microphone you have selected in macOS.
- The audio is written to a file on your Mac before anything else happens, so that a crash mid-dictation does not lose your words. See what is stored for how long those files live.
- The audio is transcribed on your Mac, by a speech model that runs locally on your machine. The audio is not uploaded.
- The transcript text may then be sent to a third-party inference provider to be cleaned up — filler removed, punctuation added, and, in some apps, restructured. That provider is named in section 5. This step is skipped for short dictations and for dictations into a code editor; see what is sent.
- A set of fixed, local corrections always runs on the result — your dictionary, brand-name spellings, question marks. These run on your Mac whether or not the cleanup step ran.
- The text is placed on your clipboard and pasted into the app you are focused on. If pasting is blocked, the text stays on the clipboard and the app tells you so.
4. What is sent off your Mac
Everything in this section leaves your Mac and travels to the companies named in section 5. It goes first to a server I operate, which checks your plan and counts your usage without storing what you said — see section 7 — and then on to a routing service, which passes it to whichever company is running the language model that does the cleanup. Those model companies are not mine and I do not operate them.
Sent as part of a normal dictation
- The transcript of what you said, when the cleanup step runs.
- The name of the app or web surface you are dictating into — for example “Slack”, “Gmail”, “Cursor” — and a category derived from it, so the cleanup can match the register. The app reads the URL and window title of your frontmost browser tab in order to work that name out; the URL and the window title themselves are not sent.
- The choices the app made about how to clean it up — the kind of app, how polished to make it, whether to shape it as a prompt for an AI — and any custom prompt you have set for that app. Since version 0.1.30 the instructions the model receives are written on my server from those choices; until then the app wrote them and sent them itself.
Sent when you use select-and-rewrite
- The text you had selected in the other application, in full, along with your spoken instruction. This is how the feature works: the model cannot edit a selection it has not been given. The selection is read at the moment you press the hotkey, either through macOS accessibility APIs or, in apps where that does not work, by triggering a Copy and reading the clipboard (the app restores your previous clipboard text afterwards).
Sent while context memory is on — and only what you supplied
Context memory is on by default, and it only ever sends what you have supplied. Until you write, paste or import something — about yourself, the people and words you use, or a project — nothing below is sent, not even your email address. Turn it off in Settings → You and none of it is sent at all, until you add something new: adding context, during setup or later, switches it back on, because adding it is you asking for it to be used.
Until 22 September 2026 it was off by default, and setup asked for a profile that it then never used: what you pasted was stored and sent nowhere. Existing installs are switched on once, and everyone using one was told before it happened (section 16); after that the switch is yours.
While it is on, the following is added to the instructions sent with every cleanup:
- The remembered facts for the current project, plus any facts you have marked as global — short sentences that you added. The app does not write them; until 11 September 2026 it also drew them from your dictations, and that is removed.
- An overview paragraph about you — the one you wrote or pasted in Settings. Nothing else writes it.
Until 10 September 2026 a model wrote it, from your past dictations. That is removed, and the reason is worth stating: it was asked to work out a name and an age from a batch of recent dictations, and where those dictations were emails to other people it recorded one of them as the user. Who you are is not something that can be inferred from what you happened to say last week, so nothing infers it any more.
On 11 September 2026 the same was done for the remembered facts. Nothing in the context layer is now written by the app: every sentence in it is one you typed, pasted or imported, and you can edit or delete any of them in Settings. - Facts derived from the project you are working in — no longer produced. Until 11 September 2026 the app read your project’s
package.jsonand emitted a short sentence such as “Built with Next.js.” It stopped along with the rest of automatic writing. It never read your source code and never sent file contents, file paths or dependency lists. - A list of names and words to spell exactly— at most 30, taken from the people you added in Settings → You, the words in your dictionary, and the names and file names that appear in the current project’s remembered facts. Since version 0.1.30. Everything on it is something you typed, pasted or imported.
- Your account email address, so the app spells it — and the name inside it — correctly, and so “here’s my email address” can be written out for you. It is the address you signed in with. Until 13 September 2026 this was a separate field you typed in Settings; that field is gone, because a second copy could disagree with the first. It is sent only alongside facts or an overview you supplied — never on its own.
- Up to 50 of your stored past dictations, in one background call — no longer sent. Rebuilding the overview paragraph used to mean sending the text of those dictations — with the app name and how long ago each one was — to the provider, periodically, while your machine was idle. Nothing rebuilds the overview any more, so that call was removed on 11 September 2026 and no background batch of your dictations leaves your Mac. The only text sent is the dictation you just spoke.
Sent when you import context
- The text you paste into an “About you” or project box, once, so a model can sort it: which of your projects it belongs to, and which lines are notes, names, terms or links. Sent with it are the names of your existing projects and up to two notes from each, so a project you already have is recognised rather than added twice. It is sent when you paste, before you confirm what will be saved, so cancelling does not unsend it. Nothing is saved until you confirm. If you are signed out, nothing is sent and the paste is filed on your Mac as before.
Sent when the app first sets itself up
- The speech model that runs on your Mac is downloaded, once, from a third-party model host — see section 5. That request carries your IP address and the app’s version string, as any download does.
5. Who receives it
This is the complete list of third parties that receive anything, in the version of the app this page describes.
- Supabase — hosts the server the request passes through, and the database behind it. It receives your transcript in transit, because the request travels through code running on its platform. That code does not store the text; what the database holds is your email address, the hashed form of your password, which plan you are on and when your Pro time ends, counts of your usage, and — since 27 September 2026 — your invite code, who referred whom, and a running total of how many words have been cleaned up for your account (a number, never the words; see section 15). That database is in US East (Ohio), which makes it an international transfer in its own right — see section 11. And see section 7 for exactly what that server does and does not keep.
- OpenRouter — the routing service my server sends the request to. It receives everything listed in section 4: your transcript, the app name and category, the instructions the app writes, your selected text on a rewrite, the text you paste when you import context, and — while context memory is on and only once you have supplied some — your remembered facts, your overview paragraph and your account email. It then passes that on to whichever company is running the model.
- The company running the model — one of exactly four, and here they all are. My server asks for Groq first, and permits Fireworks, Together AI and DeepInfra as fallbacks if Groq is unavailable, so that your dictation still works rather than failing. Which one handles any given request can therefore differ from one dictation to the next.
An earlier version of this page said only “usually Groq” and noted it was not guaranteed. That was true and it was not enough: a recipient you cannot name is one you cannot check. The list is set in the routing configuration, it is these four and no others, and adding a fifth is a change to this page as much as to the code.
Every request also carries an instruction telling the router to refuse any provider that would collect data from it. I restrict the list to providers that state they do not retain requests or train on them — but I am naming a policy I set and an instruction I send, not auditing their machines. These companies are in the United States, so this is a transfer out of the EEA; see section 11. Groq’s documents: privacy policy, terms of use, and the legal index for its cloud service, which is where its services agreement and its data processing addendum live. - Hugging Face — hosts the speech model file the app downloads once, on first run, so that transcription can happen on your Mac. It receives what any file download tells a host: your IP address and the request headers. No dictation, audio or text is involved; this happens before you have said anything.
- GitHub(owned by Microsoft) — hosts the installer and the update feed. Clicking “Download for Mac” on this site fetches the installer from it, and the app asks it whether a newer version exists and downloads the update from it. Each of those requests tells it your IP address and the request headers, as any file download does. No dictation, audio or text is involved, and nothing about your account is sent.
- The host of this website — a third-party provider serving these pages as static files. Loading a page sends your IP address and user agent to it, as loading any web page does. This site sets no cookies, loads no analytics or tracking script, and serves its fonts from its own domain rather than fetching them from Google while you read.
There is nothing else. No payment processor — there is no billing yet, see the Terms. No email provider, because the contact address is published in section 17; the mail provider behind it belongs on this list. No crash reporter, no error tracker, no analytics vendor, no advertising network of any kind.
6. What is not sent
- Your audio. Transcription runs on your Mac. The app pins this: every read of its settings forces the local transcription engine, so the cloud transcription path cannot be selected in this build.
- The URL or window title of your browser tab. Read locally, used to pick a category, not transmitted.
- The list of programs running on your Mac. When you dictate into a terminal or a code editor, the app reads the list of running programs to tell whether an AI coding tool is running in it. It reads their names, and the full command lines only of the programs running inside that terminal or editor. This is held in memory for that one check and is not stored or sent. The app also reads program names, not command lines, to notice whether another dictation app is running. Until 28 September 2026 the check read the command line of every program on the Mac.
- The Claude app’s own log file.When you dictate into the Claude desktop app, Yappr reads the end of that app’s log file (usually the last 256 KB, further back only until it finds the last time you switched tabs) to tell its Code tab from Chat. It is held in memory for that check and is not stored or sent.
- What you type. To notice your hotkey, the app is told about key presses on your Mac. It uses that for three other things. It notices that you are typing a message, so the notch can remind you that you could say it instead; for that it keeps only the times of your last few key presses. It notes whether any key was pressed since its last paste, so a dictation that follows straight on gets a space in front of it, and one after you pressed Enter or moved the cursor does not. And when you press Use my words on the notch, it checks whether you pressed a key or clicked somewhere else since the paste, so it never undoes anything but that paste. All of it is kept in memory, never which keys they were. Nothing about your typing is written to disk or sent anywhere. You can turn the reminder off in Settings → General.
- Your source code, your file contents, or your file paths.
- Your dictation history, your statistics or your log file. These stay on disk. Nothing uploads them. The log file is one you may choose to send for support, at which point you are sending its contents — see Logs.
7. Whether anything reaches me
Your text does. An earlier version of this page said nothing reached me, because the app called the model provider directly with a credential kept on your Mac. That is no longer how it works. The request now goes from your Mac to a server I operate, and from there to the model provider. Every transcript that gets cleaned up passes through my infrastructure.
What that server does with it is narrow, and it is the part worth being precise about. It reads the request in memory to check three things: that you are signed in, that your plan allows the request, and how many words it contains so your weekly allowance can be counted — the same count is added to your account’s running total, which decides whether an invite counts (section 15). Since version 0.1.30 it also writes the instructions for the model around your text, from the choices the app sent (see section 4). Then it forwards the request and discards the body. The text of a dictation is not written to a database, a log or a file at any point. (There is one thing you can hand over deliberately — a bug report — and it is described below.) What is written is counts and timestamps: requests this minute, dictations and words this week, dictations today, tokens today, and a running total of words for your account — and, since version 0.1.29, how long each dictation took. Those are numbers about your usage, not copies of what you said.
Those counts are deleted on a schedule, and the schedule is short because the numbers stop being useful almost immediately. The per-minute request count is kept for one day; it exists to stop a runaway loop, and the window it guards is one minute. The weekly word count is kept for four weeks — the current week, plus enough history to answer a question about a limit you hit recently. The daily token total, a single number for the whole service and not attached to anyone, is kept for a year so I can tell what the thing costs to run.
Two counts are kept for as long as your account exists, and deleted with it. The number of dictations you made each day, which is how I see which days Yappr is used and which enforces the published limit of 600 a day; and the running word total, which exists only to decide whether an invite counts. Until 27 September 2026 this page did not list the daily count at all, although it had been kept since 13 September; that was an omission, and this is the correction.
Until 10 September 2026 there was no schedule at all. The per-minute counter had been accumulating since the server went live, which made it a minute-by-minute record of when each account was active — far more than a rate limiter needs, and longer than I have any business keeping it. It is now deleted hourly, and the old rows are gone.
I am telling you this rather than claiming it is nothing. “It passes through my server and is not kept” is a weaker statement than “it never reaches me”, and it is the true one. You do not have to take the storage part on faith either — it is a property of code I can be held to, not of a company I cannot audit.
Bug reports — the one thing you can hand over
If something goes wrong, you can send me a bug report from Settings. That report reaches me, and it is stored. It is the only thing in this product you can deliberately give me, and it exists because a report that never arrives fixes nothing.
You read it first. The entire report is shown on screen before anything is sent: the description you wrote, which app the dictation landed in, how long it was and how much came back. What you actually said is included unless you untick the box. The box starts ticked, because the words are what usually find the bug, and you see them in the report before you send it. When the dictation was spoken over text you had selected — to rewrite it, or a dictation that replaced it — the same box also includes that selected text, which can be words from your document or from someone else’s message. Untick it and the report carries the shape of the dictation and none of its words, selected or spoken. Right beside the Send button, the app shows the actual words that pressing it will send — what you said, what you had selected and what Yappr pasted — and the button itself says whether your words go with it.
It is never automatic. A report exists because you read it and pressed Send. Nothing is gathered in the background, and there is no code path that sends one without that press. If that ever changes, this section changes with it.
Reports are deleted after 90 days. That is shorter than anything else on this page, and deliberately so: a report can contain what you said, which is more than an email address, and a bug that has not been found in ninety days will not be found from that row. A copy is also written on your Mac, in ~/Library/Application Support/Yappr/bug-reports/, which you can read or delete yourself at any time. That copy is written first, so a report is never lost to a failed send.
Wait times — how long each dictation took
Since version 0.1.29, the app records how long each dictation tookand sends that to my database when you are signed in. It is the one thing collected without you pressing a button, so it is spelled out exactly. Each dictation sends: the total wait from releasing your key to the text appearing, how much of that was transcription and how much was the AI step, which kind of cleanup it went through, how many words it had, the name of the app it landed in (such as “Slack”), and the version of Yappr.
None of your words are in it — no text, no window title, no file name. The table it goes into has no column that could hold any. It exists so I can see when someone is waiting unusually long and fix it, without asking them for their log files. It is deleted after 90 days, on the same schedule as bug reports, and it is sent only after the text is already on your screen, so it never adds to the wait it measures.
The audio is unchanged by any of this: it is transcribed on your Mac and is never uploaded. There is no third-party analytics and no crash reporter, and nothing about what you dictate is collected in the background — only the timings above. A bug report is different again: you write it, you read it, and you decide whether it is sent.
8. What is stored on your Mac
All of it lives in the app’s support folder, ~/Library/Application Support/Yappr/. It is ordinary files on your disk, readable by anything running as your user account, protected by macOS file permissions and by FileVault if you have it on. The app does not encrypt these files itself.
yappr-history.json— your dictations. For each one: what was transcribed, what was pasted, the app name, the timestamp, and the project it belonged to, plus which of the pasted words were spelling corrections, so the dashboard can show you what changed. For a browser tab it also records the site —mail.google.com, never the address of the page — so that a correction you make in the dashboard applies to that site. Capped at the most recent 1,000 entries; older ones are dropped as new ones arrive.context.db— an SQLite database holding your remembered facts and the overview paragraph. It holds only what you supplied, and is read while context memory is on.yappr-stats.json— counts and durations used for the dashboard. No dictation text. Not pruned, so it covers all time without keeping what you said.yappr-recording-ledger.json— when each recording in the last hour ended and how long it ran, which is how the app knows whether you are inside the 30 minutes of speech an hour that cleanup covers. Two numbers per recording and no text. Entries older than an hour are dropped each time it is written, so it never holds more than that.yappr-settings.json— your settings, including your dictionary, your per-app rules, and any API credential the app has been given. Stored as plain JSON; the credential is not encrypted or held in the macOS Keychain.recordings/— the audio of dictations, written before processing and deleted once the text has landed. Files that failed to process are kept so they can be retried, and are pruned to the 20 most recent and to 7 days, whichever is stricter.yappr.log— a diagnostic log. It records timings, lengths, app names, error messages and short previews of dictated text. Credentials and licence keys are scrubbed from it before it is written, by name and by value shape. The log stays on your machine unless you send it for support, at which point you are sending its contents.
The speech model file itself is also downloaded to your Mac. It contains no data about you.
9. What you can delete, and how
- Dictation history: Settings → History → Clear history. This empties
yappr-history.json. - Remembered facts: Settings → You for what is about you, and Settings → AI → Projects for each project. Individual facts and whole project groups can be deleted, and the overview paragraph can be edited or replaced.
- Stop sending context entirely: turn context memory off in Settings → You. It is on by default and sends nothing until you have supplied something. It stays off until you add something new, which switches it back on.
- Everything, at once: quit Yappr and delete
~/Library/Application Support/Yappr/. That removes history, facts, statistics, settings, stored audio and logs. The app starts fresh. - The account, and everything held off your Mac: write to useyappr@gmail.com and ask. That is your email address, your plan state and when your Pro time ends, your invite code and referral records, the per-minute, per-day and per-week COUNTS of how often cleanup ran, and the running word total — there is no dictation text in any of it. It is deleted by hand, within a month, and there is no self-service button for it yet; saying so is more honest than implying otherwise.
- Stop it listening or typing:revoke Microphone or Accessibility access in System Settings → Privacy & Security. The app cannot record or paste without them.
Text already sent to Groq is not mine to delete. Deleting your local history does not reach back into their systems.
One control that does not exist today: there is no switch that keeps dictation working while stopping the cleanup step. One existed, it was removed in a Settings redesign, and the stored value is reset when the app loads. If it comes back, this section and section 12 change with it.
10. Legal bases for processing (GDPR)
A legal basis presupposes a controller. For the files on your Mac, that is genuinely doubtful — I never receive them, never see them and cannot act on them; it is your machine and your copy. For the request that leaves your Mac it is much clearer: the software I wrote decides that the transcript is sent, what travels with it, and where it goes, so I treat that as processing I answer for. The list below is written on that reading. It has not been reviewed by a lawyer, and the reading itself is one of the things a review would test.
- Running a dictation — the transcript, the app name and category, the instructions the app writes, and, on a rewrite, the text you had selected. Basis: Article 6(1)(b), performance of a contract. You press the hotkey to get text back; sending it for cleanup is how the feature you invoked works, and the feature cannot be delivered without it. If it were held that no contract exists while the app is free, the fallback basis would be Article 6(1)(f), legitimate interests — delivering the function you asked for at the moment you asked for it, which is also the least surprising possible use of it.
- Storing your data on your Mac — history, remembered facts, statistics, settings, recent audio, the log. Basis, to the extent this is processing I carry out at all: Article 6(1)(b). History, retry-on-failure and your dictionary are features that cannot work without a file. None of it leaves your machine, and you can delete any of it at any time — section 9.
- Context memory — remembered facts, the overview paragraph, and your account email alongside them. Basis: Article 6(1)(a), consent.The switch is on by default, but nothing about it happens until you supply something: every sentence in it is one you typed, pasted or imported for this purpose — during setup, on a screen that says it goes along with your dictations, or in Settings → You, where the switch that controls it lives. Supplying it is the affirmative act, each time — adding context after you had switched it off switches it back on — and a switch that is on with nothing behind it sends nothing. Consent is the right basis because the feature is optional — the app works without it, so it cannot be “necessary” for the contract. Turning it off, or deleting what you supplied, withdraws consent for the future; it does not reach back into what has already been sent.
- Downloading the speech model — your IP address reaches the model host. Basis: Article 6(1)(b). The app cannot transcribe anything until the model is on disk.
- The trial and invites — your invite code, who referred whom, and your running word total. Basis: Article 6(1)(b). The trial and the invite rewards are terms you agreed to (Terms, section 9b), and paying a reward means knowing whose code was entered and whether the 1,000 words have been reached.
Special category data. Dictation is open-ended: you can say anything into it, including things Article 9 treats as special category — health, beliefs, and the rest. The software cannot detect that and has no separate handling for it. I do not seek it, and no Article 9 condition is claimed for it. In practice the only reliable control is yours: if it is something you would not paste into a third-party service, do not dictate it.
Automated decision-making. Cleanup is automated text processing and it changes your words — that is the product. But there is no automated decision-making about you in the Article 22 sense: nothing here produces a legal effect concerning you or similarly significantly affects you, and no profiling is used to decide anything about you.
11. International transfers
The database holding your account is in the United States, and so is every company involved in cleanup. Until 11 September 2026 this section named only the routing service and the model companies, which described the transfer as something that happens while a dictation is in flight. That was incomplete in the direction that mattered: your email address and the hashed form of your password are stored in the United States, continuously, whether or not you ever dictate anything.
Specifically, the database and the server that runs cleanup are hosted in US East (Ohio). That is a choice about where the project was created rather than anything about you, and it is being reconsidered — but a policy that describes an intention rather than the current setup is worth nothing, so what is written here is where your data is today.
On top of that, every time cleanup runs, the transcript and what travels with it leave the EEA. There is no way to use the cleanup feature without that transfer happening; the only way to avoid it is not to use the feature.
Because the routing service can fall through to a different provider when the first is unavailable, the specific company receiving a given request is not fixed in advance — see section 5. The destination country is: it is the United States either way.
The mechanism is the EU Standard Contractual Clauses, and they are in force for every leg of this. Checked on 11 September 2026, by reading each company’s published addendum rather than assuming one existed:
- The database and the server(Supabase). Its data processing addendum forms part of its terms of service, and states that accepting the agreement “shall have the same effect as signing the SCCs”. Module Two, controller to processor.
- The routing service (OpenRouter). Its addendum is incorporated into its terms and takes effect when the customer accepts them, entering the parties into Module Two of the Standard Contractual Clauses by reference.
- This website (Vercel). Its addendum becomes binding on entering the agreement, and carries the 2021 Clauses for EEA, UK and Swiss transfers.
None of these needed to be separately signed, which is worth saying because it is the opposite of what this page implied for five days. The companies running the models sit behind the routing service as its own subprocessors, and its addendum is what obliges it to hold them to equivalent terms.
Two download hosts are not in that list. GitHub, which serves the installer and the update feed, and Hugging Face, which serves the speech model, both receive your IP address and request headers when a file is fetched from them — see section 5. Both are United States companies, so that is a transfer too. Their addenda have not yet been read against this page the way the three above were, so no mechanism is claimed for them here; nothing you dictate ever reaches either.
Two honest limits on the above.First, this is a careful reading of published documents on a stated date, not a lawyer’s opinion that the Clauses cover this exact shape of processing — that is a real distinction and it is why the date is given. Second, Standard Contractual Clauses are a contractual mechanism: they bind the companies involved, and they are the answer the law asks for, but they cannot bind a government. No adequacy decision and no Data Privacy Framework certification is being relied on here, and none is asserted.
Until 11 September 2026 this section said two things that were wrong. It said the request was made from your Mac with a credential held on your Mac and that no Yappr server was involved — which stopped being true on 7 September, when cleanup moved behind a server of mine. And it said the transfer mechanism had not been established, when in fact nobody had looked. Both are corrected here rather than quietly replaced, because a privacy policy that has been wrong should say where.
12. Your rights under the GDPR
If the GDPR applies to you, you have the rights below. Their shape here is unusual: because nothing reaches me, most of them are exercised on your own machine, immediately, without asking anyone.
- Access (Article 15) — I hold no copy of anything you dictate, so there is nothing on my side to send you. Everything the app keeps is in
~/Library/Application Support/Yappr/and you can open it right now; section 8 says what each file is. - Rectification (Article 16) — remembered facts are editable and deletable in Settings → You and Settings → AI → Projects, and the overview paragraph can be edited or replaced.
- Erasure (Article 17) — section 9. Deleting the support folder erases everything the app holds. Text already sent to Groq is not mine to erase; a request about it goes to Groq.
- Restriction (Article 18) — turning context memory off stops that category of processing, and revoking Microphone or Accessibility access in System Settings stops the app functioning at all without deleting anything. Note the gap flagged in section 9: there is no setting that keeps dictation running while suppressing the cleanup call.
- Portability (Article 20) — history is JSON, settings are JSON, remembered facts are SQLite. They are already machine-readable files on your disk, yours to copy or move.
- Objection (Article 21) — where legitimate interests are relied on as the fallback basis in section 10, you can object. The controls above give effect to an objection immediately, which is faster than any process I could run.
- Withdrawing consent (Article 7(3)) — turn context memory off. Withdrawal takes effect for the future and does not affect the lawfulness of what was sent while it was on.
- Complaint to a supervisory authority (Article 77) — you can complain to the Agencia Española de Protección de Datos (AEPD), the Spanish authority, at www.aepd.es. If you live or work in another EU or EEA country, you may complain to your own national data protection authority instead — you do not have to come to Spain to do it.
A request that has to come to me goes to the address in section 17. It is published, a person reads it, and the answer comes within one month.
13. If you are in California (CCPA/CPRA)
Categories of personal information the software handles.
- Identifiers — the email address you sign in with, and your invite code. (This line described a Settings field for an email address that was removed on 13 September 2026; the account address is the only one now.)
- Audio information — your recorded voice. It stays on your Mac; transcription runs there and the audio is not uploaded.
- The contents of your communications— what you dictate, and any text you select for a rewrite. Sent to Groq when cleanup runs. Under the CPRA the contents of a consumer’s communications, where the business is not the intended recipient, are treated as sensitive personal information, so that is what this is.
- Electronic network activity— the name and category of the app you are dictating into. Not your browsing history: the URL and the window title are read on your Mac and are not transmitted. The app’s name is also stored, with how long each dictation took, for 90 days — see section 7.
- Inferences — none. The app draws no conclusions about you. The overview paragraph and the remembered facts are text you wrote or pasted yourself; a model wrote the paragraph until 10 September 2026 and mined the facts until 11 September 2026, and both are removed. What is stored is stored on your Mac.
Sources: you, and the software running on your device. There are no data brokers, no purchased lists and no third-party enrichment. Purpose: producing the text you asked for. That is the only purpose. Retention: of what passes through my server while you dictate, I retain nothing — only counts, on the schedule in section 7, and how long each dictation took, kept for 90 days. The one exception is a bug report you choose to send, kept for 90 days and described in section 7; how long the local files live is section 8; Groq’s retention is Groq’s to state, in the documents linked in section 5.
Personal information is not sold and it is not shared. I do not sell personal information, and I do not share it for cross-context behavioural advertising, as the CCPA and CPRA define those terms. There is no advertising, no ad network, no analytics and no data broker anywhere in this product. That is why there is no “Do Not Sell or Share My Personal Information” link — not because one has been withheld, but because there is nothing for it to switch off. Sensitive personal information is used only to deliver the feature you invoked, and not to infer characteristics about you.
Your rights. To know what is collected and to access it; to delete it; to correct it; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of them. In practice the first three are section 9, and you can act on them without me. The fourth has nothing to apply to. There are accounts and plans, but nothing about your plan, your trial or a price changes because you asked for any of this, so non-discrimination costs nothing to honour. Anything that does need to reach a person goes to section 17, which is published.
14. Children
Yappr is for people aged 16 and over. It is not designed for or directed at children, and nothing is knowingly collected from one.
Sixteen is a deliberate single number rather than a per-country one. COPPA sets 13 in the United States, GDPR Article 8 lets each member state set anything from 13 to 16, and the UK Age Appropriate Design Code adds its own expectations. Sixteen is the highest of those, so one figure satisfies all of them and the app needs no idea where you are.
What enforces it: the sign-up screen carries a checkbox, unticked by default, confirming you are 16 or over, and the account cannot be created without it. That is a statement you make, not a document you produce — and it is chosen over a real age gate on purpose. Verifying an age means collecting a date of birth from every user in order to screen out a few: more personal data held, another retention period to publish, and a worse outcome under data minimisation than the problem it solves.
If you believe someone under 16 has an account, write to me and I will delete it and everything attached to it.
15. Accounts
There is an account. You sign in with your email address and a password, and the session that results is what proves to my server that a request is yours. There is no third-party login and no “sign in with” button.
So a hashed form of your password is stored, alongside your email address. Both live in the authentication system Supabase provides. The password is hashed, meaning the stored value cannot be turned back into what you typed, and I never see the password itself. Until 10 September 2026 this page described a different sign-in method entirely — an emailed six-digit code — and stated there was no password to choose. That was wrong. The code route exists as a secondary option and does not currently work; the password is what every account actually uses, and a stored credential is not something a privacy notice may leave out.
The account record itself holds your email address, which plan you are on and when your Pro time ends, your invite code, the running word total, and the usage counters described in section 7. It does not hold anything you have dictated.
Invites and referrals
Since 27 September 2026 every account has an invite code, and a new account can enter someone else’s. What that stores, all of it in the database described in section 5:
- Your invite code — a short random string made when your account is created. It identifies your account to someone you give it to, and to nobody else.
- Who referred whom. If you enter a code, a record that your account was referred by that one, when, whether it has counted yet, and how many days it earned them.
- A running total of words — how many words have been cleaned up for your account, ever. One number, never the words themselves, taken from the count in section 7. It is used for one thing: deciding whether you have reached the 1,000 words that make an invite count. It is counted for every account, including ones that never use an invite, because a code can still be entered up to 7 days after signing up and the words before that have to count too.
The person whose code you entered sees totals only — how many people joined with their code, how many of those have counted, and how many days they have earned. Not your email address, not your name, not your word count, and not which of their friends you are. One honest limit: someone who has invited a single friend can tell from “1 counted” that that friend passed the line. That is the whole of what a total can reveal, and it is why nothing finer is shown.
All of it is kept for as long as your account exists and deleted with it. Deleting either account deletes the referral record between the two; days already added to the other account stay added.
An invite link on this website (/r/followed by a code) is an ordinary page: it shows the code and a download button, and it stores nothing and sends the code nowhere. Opening it reaches the website’s host like any page load, address included — see section 5.
The waitlist, and the invite list
The beta was closed until 27 September 2026. Sign-up is open now. Two lists from the closed beta hold an email address and nothing else. Until 11 September 2026 this policy did not mention either of them — a real omission, because one was filled in by a form on the front page of this site.
The waitlist. Until sign-up opened, the home page had a form for your email address, stored so that I could tell you when you could get in, with a short tag recording where the signup came from. Nothing else. The form is gone; the addresses already on the list stay, under the deletion below. The list cannot be read back by anyone holding the key that ships in the website; reading it requires a credential that never leaves the server.
The invite list. While the beta was closed, signup was refused for any address I had not invited, and this list held those addresses — including people who never signed up. It is kept now only as a switch: if sign-up is ever closed again, it is what decides who may still create an account. While sign-up is open it is not consulted.
Both are deleted after six months, on a schedule, not by hand — the same promise as before sign-up opened. An address that has sat on the waitlist for six months is not a warm lead, and an invitation nobody used in six months has been declined rather than left pending.
16. Changes to this policy
This page carries the date it was last changed at the top, and where a change to the app changes what leaves your machine, this page changes in the same release rather than afterwards.
For a change that widens what leaves your machine, or that adds a recipient, you get an email before it takes effect. Not for a typo or a clarification — for those, the date at the top is the signal. The distinction is the point: a dated page nobody revisits is adequate notice for a rewording and useless for “your words now also go to a company you have not heard of”.
Until 10 September 2026 this section said there was no way to notify you, because there were no accounts and so no addresses. There are both now — section 15 says so on this same page — and this paragraph had simply been left behind.
17. Contact
For anything on this page — a question, or any of the rights in section 12 or section 13 — write to useyappr@gmail.com. A person reads it.
You will get an answer within one month. That is the deadline the GDPR sets and I am not going to quote you a shorter one I might miss. Requests are handled by hand: there is no self-service export or delete button in the app yet, and rather than imply there is, this says plainly that you email and I do it. If a request is complex enough to need longer, the law lets me extend it by two months and requires me to tell you why — so I will.
For formal notice, there is a postal address— the controller’s name and address are published in section 1. Email is faster and is the right route for an ordinary request; the address is there because Article 13 expects a controller to be reachable by post, and an email address on its own is not that.