Everything that leaves your Mac · 00:03:22 · 456 words
file
privacy.transcript
speakers
You, vocateca
address
vocateca.com/en/privacy
duration
00:03:22 · 456 words
Privacy

Everything that leaves your Mac

00:00:00

Why it matters

00:00:00You

Why make such a point of where the audio goes?

00:00:05vocateca

A voice identifies a person the way a fingerprint does. And recordings of interviews, sessions or closed meetings carry things nobody in them agreed to hand to a third party. So the transcription happens on the machine the recording is on.

00:00:23

The complete list

00:00:23You

Read me the whole list.

00:00:26vocateca

This is the same list as on the start page, from the same source. It is checked against the app’s code, not against what we would like it to say.

Stays on your Mac5 entries
#WhatWhere and how
01AudioDownloaded to your disk and transcribed there. Once a transcript is done, the downloaded audio is deleted by default. Files you imported yourself are kept, and a failed transcription keeps its audio so it can be retried. Never uploaded.
02TranscriptionParakeet-TDT by default. Whisper takes over for languages outside Parakeet’s 25. Both run on Core ML and the Neural Engine. Qwen3-ASR, through MLX, if you choose it in Settings; never automatically.
03Speaker detectionWho said what is worked out on your Mac.
04LibraryA local SQLite database, ~/Library/Application Support/Vocateca/state.sqlite. Full-text search runs against it, nowhere else.
05Transcript filesPlain Markdown, TXT, SRT, HTML and OKF files in a folder you can open in Finder.
Leaves your Mac, and only then20 entries · 5 groups
#WhatGoes toOnly when
When you add, search or refresh what you follow8 entriesonly when you act
01Podcast feedsStraight to the RSS feed, nowhere in between.the show’s own serverA show refreshes, or you add one.
02Podcast searchApple’s public search, with the words you typed.itunes.apple.com/searchYou search for a show.
03Spotify linksThe public embed page, read once to find the show. The audio then comes from the show’s feed.open.spotify.com/embed/…You paste a Spotify link.
04YouTube videos and captionsFetched by yt-dlp, which ships inside the app.youtube.comYou add a video or playlist, or a channel refreshes.
05YouTube search and channel feedsThe search results page, and each channel’s public feed.youtube.com/results · youtube.com/feeds/videos.xmlYou search YouTube, or a channel you follow refreshes.
06YouTube playerThe YouTube Explorer plays the video in YouTube’s own player. The page around it comes from a small server inside the app on 127.0.0.1, which only your Mac can reach.youtube.com/iframe_apiYou open a video in the YouTube Explorer.
07Instagram, experimentalFetched by gallery-dl, which ships inside the app, signed in as the separate Instagram account you connect. You sign in on Instagram’s own login page, shown in a window of the app.instagram.comYou connect an account, follow a creator, or a creator refreshes.
08Artwork and thumbnailsLoaded once, then kept in a cache on your Mac.the server that hosts each imageA show, channel or search result is shown.
The first time a feature needs it3 entriesonce
09Speech modelsThe model weights for Parakeet-TDT and Whisper, and for Qwen3-ASR if you choose it, plus the models that tell speakers apart. No network needed afterwards.huggingface.coParakeet-TDT while the app sets itself up. Whisper and Qwen3-ASR the first time you use them.
10ffmpeg, ffprobeA pinned release, checked against a fixed SHA-256 hash before it runs.github.comWhile the app sets itself up, unless ffmpeg is already on your Mac.
11yt-dlp, fallback onlyA pinned version. Only used if the copy inside the app can’t run.github.comOnly if the bundled yt-dlp fails.
In the background2 entrieson by default
12Update checkAsks whether a newer signed version exists. No system profile is sent. Our server counts these requests, in aggregate, to estimate how many installations are active.vocateca.com/appcast.xmlOnce a day, and when you choose “Check for Updates…”.
13Second update checkAsks GitHub for the latest published release. An interim path that runs alongside the first one. You can switch it off with update_check_enabled: false in settings.yaml; the app has no switch for it.api.github.com/repos/madevmuc/vocateca/releases/latestEvery time the app starts.
Only if you switch it on2 entriesoff by default
14NotionThe transcript, with your Notion token.api.notion.comYou send a transcript to Notion.
15WebhooksA message signed with HMAC. The address may be on your own network.exactly the address you enterA transcription finishes.
Only with an account5 entriesoff until you sign in
16Signing inYour email address, for a sign-in link.auth.vocateca.comYou sign in. Free never needs to.
17Buying ProOur server asks Mollie for a payment page, which opens in your browser. The app never talks to Mollie itself.hook.vocateca.com/checkoutYou upgrade in the app.
18Pro status, cancelling, vouchersWhether your Pro is active; your cancellation; a voucher code.hook.vocateca.comWhile signed in, and when you cancel or redeem.
19InvitationsYour invite link, and the code a friend enters.hook.vocateca.comYou share or redeem an invitation.
20Export or delete your accountA copy of what the server holds about your account, or its deletion.hook.vocateca.comYou ask for it in the app.

gallery-dl and yt-dlp ship inside the app. Neither is downloaded, except yt-dlp as the fallback above.

Some podcast feeds are still served over plain HTTP. vocateca allows that, so those feeds keep working.

Links in the app (the Chrome extension, the licence on GitHub) open in your browser, and only when you click them.

Never
Telemetry, analytics, tracking, crash reporting. None of those components exist in the app.
Never
Audio or a transcript on a vocateca server. Not in Free, not in Pro.
00:00:39

Questions about the list

00:00:39You

Why are there two update checks?

00:00:43vocateca

The first is Sparkle, the update framework most Mac apps use. It asks vocateca.com/appcast.xml whether a newer signed version exists. The second asks GitHub for the latest published release. It is an interim path that runs alongside the first. Both are on by default, and both are in the list above.

00:01:04You

How do I switch off the second one?

00:01:09vocateca

Only in the settings file, not in the app. Open ~/Library/Application Support/Vocateca/settings.yaml and set update_check_enabled: false. The app has no switch for it. The first check cannot be switched off; Settings only changes how often it runs.

00:01:25You

Does vocateca use analytics or tracking?

00:01:29vocateca

No. Telemetry, analytics, tracking and crash reporting: none of those components exist in the app. The only thing we count is how often the update check is asked, in aggregate. The code that handles your audio is open, so you can read what it sends.

Open Core: what is open, and where to read it

00:01:52You

Do I need an account?

00:01:55vocateca

Not for Free. Pro needs one: you sign in with an email link, inside the app. The account knows that you paid. It never sees your audio or your transcripts. Everything it does is in the group “Only with an account” above.

Pricing: Free and Pro

00:02:15

Your controls

00:02:15You

What can I control myself?

00:02:18vocateca

Seven things, all in the app.

Delete audio after transcriptionOn by default. Turn it off in Settings if you want to keep the audio.
Your dataSettings → Your data shows how much audio and transcript data is on disk.
RetentionSet how many days audio and transcripts are kept, separately. 0 means forever.
Export and deleteExport settings and subscriptions, or delete everything in one step.
Factory resetWipes all data on disk and the Keychain entries vocateca created.
KeychainAccount tokens, webhook secrets and the Instagram session live in the macOS Keychain, never in a plain file.
Log redactionCopying the diagnostic log removes URLs, file paths and sensitive values.
00:03:04

The legal version

00:03:04You

And the formal privacy policy?

00:03:08vocateca

This page says how vocateca behaves, in plain words. Controller, legal basis and your rights under the GDPR are in the Datenschutzerklärung. The Chrome extension has its own short policy.