Security & privacy architecture
SayWrite security and privacy architecture
SayWrite turns your voice into text on your Mac's Neural Engine, deletes the temporary recording as soon as it's transcribed, and only ever talks to AI at 127.0.0.1, which is your own Mac. There are no accounts, no telemetry and no SayWrite servers.
Data flow
What happens when you hold Fn
What runs where
Every component, and whether it touches the network
| Component | Where it runs | Network |
|---|---|---|
| Microphone capture | Your Mac, into a temporary file in the app's temp folder | None |
| Speech recognition | NVIDIA Parakeet TDT 0.6B v2 via FluidAudio and Core ML, on the Apple Neural Engine | None |
| Cleanup (fillers, commands, snippets, dictionary) | Your Mac | None |
| AI Polish with Apple Intelligence | Apple's on-device foundation model (macOS 26+) | None |
| AI Polish with Ollama or LM Studio | Your own server on your Mac | 127.0.0.1 only (loopback, never leaves the machine) |
| Text insertion | macOS Accessibility, or paste with your clipboard restored | None |
| History, Stats, file transcripts | Your user Library, in a folder only your account can read | None, and no iCloud sync |
| Speech model download | Once, when you click Download Model | Hugging Face |
| Update check | Once a day while automatic checks are on | GitHub |
Guarantees
What never leaves your Mac
- Your audio. It exists only as a temporary file while it's transcribed, then it's deleted, including when you cancel or something fails. Leftovers are swept when SayWrite starts.
- Your text. Dictations, AI rewrites, History and file transcripts are never uploaded.
- Your screen. SayWrite never takes screenshots or reads the screen to add “context”. Per-app tone uses only the name of the app you're typing in.
- Usage data. There are no analytics, crash reporters or telemetry SDKs. The app's own logs record state names, durations and byte counts, never audio or transcript text.
- Your identity. There's no account, sign-in, license server or email capture.
Network
The only three network connections
- Speech model download, once, when you ask. Clicking Download Model fetches the Core ML version of Parakeet (about 465 MB) from Hugging Face. Hugging Face sees an ordinary download request, including your IP address. After that, dictation needs no internet at all.
- Update check, once a day, if you allow it. SayWrite fetches a small appcast file from the public releases repository on GitHub. It sends no system profile. Turn it off in Settings › General and check by hand instead.
- Your own AI server, only if you turn it on. With Ollama or LM Studio selected, the text to rewrite (never audio) goes to 127.0.0.1 on your Mac. Apple Intelligence makes no network request at all.
None of these carry anything you say or write off your Mac.
AI Polish
Why AI is locked to 127.0.0.1
A local model is only private if the app can't be talked into sending text somewhere else. SayWrite's AI client enforces that in code:
- It accepts only
127.0.0.1,::1orlocalhost, and rewriteslocalhostto127.0.0.1so DNS can't redirect it. - LAN addresses, other hostnames,
0.0.0.0, decimal IP spellings and look-alikes such aslocalhost.example.comare refused, even if you type them in Settings. - The URL is re-checked right before every request, HTTP redirects are refused, and system proxies, cookies and caching are off.
- AI is off until you turn it on. While it's off, SayWrite makes no AI requests of any kind.
More on choosing a model: Bring your own model and AI Polish with Apple Intelligence.
Storage
What's stored, and where
- History (text, time, target app, length) is on by default so you can search and paste past dictations. Choose 7, 30, 90 or 365 days or forever, or turn it off. Password managers (1Password, Bitwarden, Apple Passwords, Keychain Access) are excluded by default, and spoken AI instructions aren't saved.
- Stats store numbers: words, durations and filler-word counts without the text. Typing speed is opt-in and records keystroke timing only, never which keys you press.
- File transcripts keep the text and timestamps, never the audio.
- Everything lives in
~/Library/Application Support/LocalDictation/, a folder only your user account can read, plus the app's preferences. Nothing syncs to iCloud. - Delete it all from inside the app, or remove the folders. The privacy policy lists each one.
macOS permissions
Permissions, and why each is needed
- Microphone: to hear you. Recording only happens while you hold or have tapped the trigger, and the pill shows a red live dot the whole time.
- Accessibility: to type the text at your cursor and to notice the Fn key while another app is in front. Without it, SayWrite copies the text to the clipboard instead.
Those are the only two privacy permissions SayWrite asks for. It doesn't request Screen Recording, Full Disk Access, Contacts, Calendars or Location, and the Control-Option-D shortcut is a standard hot key that needs no extra permission.
Supply chain
Code signing and updates
- Updates use Sparkle. Every update archive is signed with an EdDSA key, and the app checks that signature against the public key built into it before installing anything.
- Builds use Apple's hardened runtime, and each release is published on GitHub with its notes.
- Not notarized yet. During early access SayWrite isn't notarized by Apple, so the first launch needs Open Anyway in System Settings. Updates installed by the app don't need that step again.
Trust, but verify
Verify it yourself
- Turn off Wi-Fi and dictate a paragraph. It still works.
- Install a network monitor such as LuLu (free, open source) or Little Snitch and watch SayWrite while you dictate and Polish.
- Or, in Terminal, while dictating:
The process is still called LocalDictation internally. Expect no connections, or only 127.0.0.1 when AI uses Ollama or LM Studio.lsof -i -n -P -c LocalDictation
Open components
Model sources and licenses
- Speech model: NVIDIA Parakeet TDT 0.6B v2 by NVIDIA, licensed CC BY 4.0. SayWrite downloads the Core ML conversion published by FluidInference on Hugging Face. Attribution: “Parakeet TDT 0.6B v2” © NVIDIA, used under CC BY 4.0; converted to Core ML by FluidInference.
- Speech runtime: FluidAudio, licensed under the Apache License 2.0.
- Updates: Sparkle (MIT-style license). Shortcuts: KeyboardShortcuts (MIT).
- AI models you run in Ollama or LM Studio are yours, under their own licenses. Apple's on-device model is part of macOS.
Honesty
What we don't claim
- SayWrite holds no HIPAA, SOC 2, ISO 27001 or other certifications, and it isn't a compliance product.
- It hasn't had an independent security audit.
- The source code is private, so you're trusting this description and your own network checks.
- On-device doesn't protect against malware on your Mac or someone with access to your user account.
Responsible disclosure
Report a security issue
Found a vulnerability? Email hello@saywrite.app with steps to reproduce. Please give us a reasonable chance to fix it before you disclose it publicly. We'll reply, credit you if you want, and note the fix in the changelog.
Frequently asked questions
Does SayWrite send my voice or text to a server?
No. Speech recognition runs on your Mac's Neural Engine and the temporary recording is deleted as soon as it's transcribed. AI Polish runs on Apple's on-device model or on your own server at 127.0.0.1. SayWrite has no servers of its own to send anything to.
Can I point SayWrite's AI at a server on my network or in the cloud?
No. SayWrite only connects to 127.0.0.1, ::1 or localhost for AI, and rewrites localhost to 127.0.0.1 so name resolution can't redirect it. LAN addresses, other hostnames and tricks like localhost.example.com are refused even if you type them, and redirects and proxies are ignored.
Is SayWrite HIPAA compliant or SOC 2 certified?
No. SayWrite holds no certifications and is not a compliance product. Its design keeps audio and text on your Mac, which may help with your obligations, but check your own requirements with your compliance team.
How can I check that SayWrite works offline?
Turn off Wi-Fi and dictate: text still appears. For more certainty, watch SayWrite's network activity with a firewall such as LuLu or Little Snitch, or run lsof -i -n -P -c LocalDictation in Terminal while you dictate. You should see no connections except to 127.0.0.1 if you use Ollama or LM Studio.
Is SayWrite open source?
No. The source code is private. That's why this page describes the architecture in detail and explains how to verify the network behavior yourself.
Keep reading
Say it messy. We'll write it neat.
Hold Fn, talk, and let SayWrite type it. Everything stays on your Mac.
Free during early access · macOS 15+ · Apple silicon