Security & privacy architecture

SayWrite security and privacy architecture

SayWrite turns your voice into text on your Mac's Neural Engine, deletes the temporary recording as soon as it's transcribed, and only ever talks to AI at 127.0.0.1, which is your own Mac. There are no accounts, no telemetry and no SayWrite servers.

Data flow

What happens when you hold Fn

How your voice moves through SayWriteYour voice goes from the microphone into your Mac, where speech recognition, the temporary recording and AI Polish all run, and the text goes straight into your app. Nothing goes to cloud servers.Your voiceYOUR MACSpeech → textParakeet on the Apple Neural EngineTemporary recordingDeleted as soon as it's transcribedAI Polish (optional)Apple's model, or your server at 127.0.0.1Your apptext at the cursorNo cloud stepHugging Facemodel, once, on requestGitHubdaily update checkNeither request contains anything you say or write.How your voice moves through SayWriteYour voice goes from the microphone into your Mac, where speech recognition, the temporary recording and AI Polish all run, and the text goes straight into your app. Nothing goes to cloud servers.Your voiceno cloudYOUR MACSpeech → textParakeet on the Neural EngineTemporary recordingDeleted once it's transcribedAI Polish (optional)On-device, or 127.0.0.1Your apptext at the cursorHugging Facespeech model, once, when you askGitHubdaily update check (optional)Neither request containsanything you say or write.
Mic → your Mac (speech recognition on the Neural Engine, temporary recording deleted, optional AI Polish on-device or at 127.0.0.1) → text in your app. The only outbound requests are the model download you start and the optional daily update check.

What runs where

Every component, and whether it touches the network

SayWrite components
ComponentWhere it runsNetwork
Microphone captureYour Mac, into a temporary file in the app's temp folderNone
Speech recognitionNVIDIA Parakeet TDT 0.6B v2 via FluidAudio and Core ML, on the Apple Neural EngineNone
Cleanup (fillers, commands, snippets, dictionary)Your MacNone
AI Polish with Apple IntelligenceApple's on-device foundation model (macOS 26+)None
AI Polish with Ollama or LM StudioYour own server on your Mac127.0.0.1 only (loopback, never leaves the machine)
Text insertionmacOS Accessibility, or paste with your clipboard restoredNone
History, Stats, file transcriptsYour user Library, in a folder only your account can readNone, and no iCloud sync
Speech model downloadOnce, when you click Download ModelHugging Face
Update checkOnce a day while automatic checks are onGitHub

Guarantees

What never leaves your Mac

  • Your audio. It exists only as a temporary file while it's transcribed, then it's deleted, including when you cancel or something fails. Leftovers are swept when SayWrite starts.
  • Your text. Dictations, AI rewrites, History and file transcripts are never uploaded.
  • Your screen. SayWrite never takes screenshots or reads the screen to add “context”. Per-app tone uses only the name of the app you're typing in.
  • Usage data. There are no analytics, crash reporters or telemetry SDKs. The app's own logs record state names, durations and byte counts, never audio or transcript text.
  • Your identity. There's no account, sign-in, license server or email capture.

Network

The only three network connections

  1. Speech model download, once, when you ask. Clicking Download Model fetches the Core ML version of Parakeet (about 465 MB) from Hugging Face. Hugging Face sees an ordinary download request, including your IP address. After that, dictation needs no internet at all.
  2. Update check, once a day, if you allow it. SayWrite fetches a small appcast file from the public releases repository on GitHub. It sends no system profile. Turn it off in Settings › General and check by hand instead.
  3. Your own AI server, only if you turn it on. With Ollama or LM Studio selected, the text to rewrite (never audio) goes to 127.0.0.1 on your Mac. Apple Intelligence makes no network request at all.

None of these carry anything you say or write off your Mac.

AI Polish

Why AI is locked to 127.0.0.1

A local model is only private if the app can't be talked into sending text somewhere else. SayWrite's AI client enforces that in code:

  • It accepts only 127.0.0.1, ::1 or localhost, and rewrites localhost to 127.0.0.1 so DNS can't redirect it.
  • LAN addresses, other hostnames, 0.0.0.0, decimal IP spellings and look-alikes such as localhost.example.com are refused, even if you type them in Settings.
  • The URL is re-checked right before every request, HTTP redirects are refused, and system proxies, cookies and caching are off.
  • AI is off until you turn it on. While it's off, SayWrite makes no AI requests of any kind.

More on choosing a model: Bring your own model and AI Polish with Apple Intelligence.

Storage

What's stored, and where

  • History (text, time, target app, length) is on by default so you can search and paste past dictations. Choose 7, 30, 90 or 365 days or forever, or turn it off. Password managers (1Password, Bitwarden, Apple Passwords, Keychain Access) are excluded by default, and spoken AI instructions aren't saved.
  • Stats store numbers: words, durations and filler-word counts without the text. Typing speed is opt-in and records keystroke timing only, never which keys you press.
  • File transcripts keep the text and timestamps, never the audio.
  • Everything lives in ~/Library/Application Support/LocalDictation/, a folder only your user account can read, plus the app's preferences. Nothing syncs to iCloud.
  • Delete it all from inside the app, or remove the folders. The privacy policy lists each one.

macOS permissions

Permissions, and why each is needed

  • Microphone: to hear you. Recording only happens while you hold or have tapped the trigger, and the pill shows a red live dot the whole time.
  • Accessibility: to type the text at your cursor and to notice the Fn key while another app is in front. Without it, SayWrite copies the text to the clipboard instead.

Those are the only two privacy permissions SayWrite asks for. It doesn't request Screen Recording, Full Disk Access, Contacts, Calendars or Location, and the Control-Option-D shortcut is a standard hot key that needs no extra permission.

Supply chain

Code signing and updates

  • Updates use Sparkle. Every update archive is signed with an EdDSA key, and the app checks that signature against the public key built into it before installing anything.
  • Builds use Apple's hardened runtime, and each release is published on GitHub with its notes.
  • Not notarized yet. During early access SayWrite isn't notarized by Apple, so the first launch needs Open Anyway in System Settings. Updates installed by the app don't need that step again.

Trust, but verify

Verify it yourself

  1. Turn off Wi-Fi and dictate a paragraph. It still works.
  2. Install a network monitor such as LuLu (free, open source) or Little Snitch and watch SayWrite while you dictate and Polish.
  3. Or, in Terminal, while dictating:
    lsof -i -n -P -c LocalDictation
    The process is still called LocalDictation internally. Expect no connections, or only 127.0.0.1 when AI uses Ollama or LM Studio.

Open components

Model sources and licenses

  • Speech model: NVIDIA Parakeet TDT 0.6B v2 by NVIDIA, licensed CC BY 4.0. SayWrite downloads the Core ML conversion published by FluidInference on Hugging Face. Attribution: “Parakeet TDT 0.6B v2” © NVIDIA, used under CC BY 4.0; converted to Core ML by FluidInference.
  • Speech runtime: FluidAudio, licensed under the Apache License 2.0.
  • Updates: Sparkle (MIT-style license). Shortcuts: KeyboardShortcuts (MIT).
  • AI models you run in Ollama or LM Studio are yours, under their own licenses. Apple's on-device model is part of macOS.

Honesty

What we don't claim

  • SayWrite holds no HIPAA, SOC 2, ISO 27001 or other certifications, and it isn't a compliance product.
  • It hasn't had an independent security audit.
  • The source code is private, so you're trusting this description and your own network checks.
  • On-device doesn't protect against malware on your Mac or someone with access to your user account.

Responsible disclosure

Report a security issue

Found a vulnerability? Email hello@saywrite.app with steps to reproduce. Please give us a reasonable chance to fix it before you disclose it publicly. We'll reply, credit you if you want, and note the fix in the changelog.

Frequently asked questions

Does SayWrite send my voice or text to a server?

No. Speech recognition runs on your Mac's Neural Engine and the temporary recording is deleted as soon as it's transcribed. AI Polish runs on Apple's on-device model or on your own server at 127.0.0.1. SayWrite has no servers of its own to send anything to.

Can I point SayWrite's AI at a server on my network or in the cloud?

No. SayWrite only connects to 127.0.0.1, ::1 or localhost for AI, and rewrites localhost to 127.0.0.1 so name resolution can't redirect it. LAN addresses, other hostnames and tricks like localhost.example.com are refused even if you type them, and redirects and proxies are ignored.

Is SayWrite HIPAA compliant or SOC 2 certified?

No. SayWrite holds no certifications and is not a compliance product. Its design keeps audio and text on your Mac, which may help with your obligations, but check your own requirements with your compliance team.

How can I check that SayWrite works offline?

Turn off Wi-Fi and dictate: text still appears. For more certainty, watch SayWrite's network activity with a firewall such as LuLu or Little Snitch, or run lsof -i -n -P -c LocalDictation in Terminal while you dictate. You should see no connections except to 127.0.0.1 if you use Ollama or LM Studio.

Is SayWrite open source?

No. The source code is private. That's why this page describes the architecture in detail and explains how to verify the network behavior yourself.

Say it messy. We'll write it neat.

Hold Fn, talk, and let SayWrite type it. Everything stays on your Mac.

Free during early access · macOS 15+ · Apple silicon