- file
- privacy.transcript
- speakers
- You, vocateca
- address
- vocateca.com/en/privacy
- duration
- 00:03:22 · 456 words
Everything that leaves your Mac
Why it matters
A voice identifies a person the way a fingerprint does. And recordings of interviews, sessions or closed meetings carry things nobody in them agreed to hand to a third party. So the transcription happens on the machine the recording is on.
The complete list
This is the same list as on the start page, from the same source. It is checked against the app’s code, not against what we would like it to say.
| # | What | Where and how |
|---|---|---|
| 01 | Audio | Downloaded to your disk and transcribed there. Once a transcript is done, the downloaded audio is deleted by default. Files you imported yourself are kept, and a failed transcription keeps its audio so it can be retried. Never uploaded. |
| 02 | Transcription | Parakeet-TDT by default. Whisper takes over for languages outside Parakeet’s 25. Both run on Core ML and the Neural Engine. Qwen3-ASR, through MLX, if you choose it in Settings; never automatically. |
| 03 | Speaker detection | Who said what is worked out on your Mac. |
| 04 | Library | A local SQLite database, ~/Library/Application Support/Vocateca/state.sqlite. Full-text search runs against it, nowhere else. |
| 05 | Transcript files | Plain Markdown, TXT, SRT, HTML and OKF files in a folder you can open in Finder. |
| # | What | Goes to | Only when |
|---|---|---|---|
| When you add, search or refresh what you follow8 entriesonly when you act | |||
| 01 | Podcast feeds | Straight to the RSS feed, nowhere in between.the show’s own server | A show refreshes, or you add one. |
| 02 | Podcast search | Apple’s public search, with the words you typed.itunes.apple.com/search | You search for a show. |
| 03 | Spotify links | The public embed page, read once to find the show. The audio then comes from the show’s feed.open.spotify.com/embed/… | You paste a Spotify link. |
| 04 | YouTube videos and captions | Fetched by yt-dlp, which ships inside the app.youtube.com | You add a video or playlist, or a channel refreshes. |
| 05 | YouTube search and channel feeds | The search results page, and each channel’s public feed.youtube.com/results · youtube.com/feeds/videos.xml | You search YouTube, or a channel you follow refreshes. |
| 06 | YouTube player | The YouTube Explorer plays the video in YouTube’s own player. The page around it comes from a small server inside the app on 127.0.0.1, which only your Mac can reach.youtube.com/iframe_api | You open a video in the YouTube Explorer. |
| 07 | Instagram, experimental | Fetched by gallery-dl, which ships inside the app, signed in as the separate Instagram account you connect. You sign in on Instagram’s own login page, shown in a window of the app.instagram.com | You connect an account, follow a creator, or a creator refreshes. |
| 08 | Artwork and thumbnails | Loaded once, then kept in a cache on your Mac.the server that hosts each image | A show, channel or search result is shown. |
| The first time a feature needs it3 entriesonce | |||
| 09 | Speech models | The model weights for Parakeet-TDT and Whisper, and for Qwen3-ASR if you choose it, plus the models that tell speakers apart. No network needed afterwards.huggingface.co | Parakeet-TDT while the app sets itself up. Whisper and Qwen3-ASR the first time you use them. |
| 10 | ffmpeg, ffprobe | A pinned release, checked against a fixed SHA-256 hash before it runs.github.com | While the app sets itself up, unless ffmpeg is already on your Mac. |
| 11 | yt-dlp, fallback only | A pinned version. Only used if the copy inside the app can’t run.github.com | Only if the bundled yt-dlp fails. |
| In the background2 entrieson by default | |||
| 12 | Update check | Asks whether a newer signed version exists. No system profile is sent. Our server counts these requests, in aggregate, to estimate how many installations are active.vocateca.com/appcast.xml | Once a day, and when you choose “Check for Updates…”. |
| 13 | Second update check | Asks GitHub for the latest published release. An interim path that runs alongside the first one. You can switch it off with update_check_enabled: false in settings.yaml; the app has no switch for it.api.github.com/repos/madevmuc/vocateca/releases/latest | Every time the app starts. |
| Only if you switch it on2 entriesoff by default | |||
| 14 | Notion | The transcript, with your Notion token.api.notion.com | You send a transcript to Notion. |
| 15 | Webhooks | A message signed with HMAC. The address may be on your own network.exactly the address you enter | A transcription finishes. |
| Only with an account5 entriesoff until you sign in | |||
| 16 | Signing in | Your email address, for a sign-in link.auth.vocateca.com | You sign in. Free never needs to. |
| 17 | Buying Pro | Our server asks Mollie for a payment page, which opens in your browser. The app never talks to Mollie itself.hook.vocateca.com/checkout | You upgrade in the app. |
| 18 | Pro status, cancelling, vouchers | Whether your Pro is active; your cancellation; a voucher code.hook.vocateca.com | While signed in, and when you cancel or redeem. |
| 19 | Invitations | Your invite link, and the code a friend enters.hook.vocateca.com | You share or redeem an invitation. |
| 20 | Export or delete your account | A copy of what the server holds about your account, or its deletion.hook.vocateca.com | You ask for it in the app. |
gallery-dl and yt-dlp ship inside the app. Neither is downloaded, except yt-dlp as the fallback above.
Some podcast feeds are still served over plain HTTP. vocateca allows that, so those feeds keep working.
Links in the app (the Chrome extension, the licence on GitHub) open in your browser, and only when you click them.
- Never
- Telemetry, analytics, tracking, crash reporting. None of those components exist in the app.
- Never
- Audio or a transcript on a vocateca server. Not in Free, not in Pro.
Questions about the list
The first is Sparkle, the update framework most Mac apps use. It asks vocateca.com/appcast.xml whether a newer signed version exists. The second asks GitHub for the latest published release. It is an interim path that runs alongside the first. Both are on by default, and both are in the list above.
Only in the settings file, not in the app. Open ~/Library/Application Support/Vocateca/settings.yaml and set update_check_enabled: false. The app has no switch for it. The first check cannot be switched off; Settings only changes how often it runs.
No. Telemetry, analytics, tracking and crash reporting: none of those components exist in the app. The only thing we count is how often the update check is asked, in aggregate. The code that handles your audio is open, so you can read what it sends.
Not for Free. Pro needs one: you sign in with an email link, inside the app. The account knows that you paid. It never sees your audio or your transcripts. Everything it does is in the group “Only with an account” above.
Your controls
Seven things, all in the app.
| Delete audio after transcription | On by default. Turn it off in Settings if you want to keep the audio. |
| Your data | Settings → Your data shows how much audio and transcript data is on disk. |
| Retention | Set how many days audio and transcripts are kept, separately. 0 means forever. |
| Export and delete | Export settings and subscriptions, or delete everything in one step. |
| Factory reset | Wipes all data on disk and the Keychain entries vocateca created. |
| Keychain | Account tokens, webhook secrets and the Instagram session live in the macOS Keychain, never in a plain file. |
| Log redaction | Copying the diagnostic log removes URLs, file paths and sensitive values. |
The legal version
This page says how vocateca behaves, in plain words. Controller, legal basis and your rights under the GDPR are in the Datenschutzerklärung. The Chrome extension has its own short policy.