Kotonoha日本語

Kotonoha Privacy Policy

Last updated: 2026-08-14

This policy covers the first macOS release. Windows, iOS, and Android are planned for later; this policy will be reviewed against each platform before that version is released.

In one line

Kotonoha does not send your speech, or the text it becomes, anywhere.

Speech recognition and formatting both run on your device. No cloud speech service and no cloud AI is contacted. There is no analytics, no advertising and no crash reporting in the app.

Using it requires signing in. What that entrusts to us is an email address, plus your settings and dictionary if you switch syncing on. Your voice, your transcripts and your history do not pass through it. See "1. What we are entrusted with" and "6. Your account".


1. What we are entrusted with

What When Detail
An email address When you sign in (required) If you hide it with Sign in with Apple, the relay address instead
Settings, dictionary, snippets Only if you switch syncing on See below
Whether you have purchased If you buy a paid feature The fact of the purchase, and what is needed to carry it across your devices

Your dictionary contains the names and in-house terms you typed into it. That can be personal information, so switching syncing on is your decision. Left off, your dictionary does not leave the device.

Not entrusted to us
Your voice Does not leave the device
Transcripts and formatted text Does not leave the device
Dictation history Does not leave the device
Name, phone number, location, contacts, date of birth Not obtained
Payment details Not obtained — the payment provider handles them, and your card details do not reach us
Your password Never stored. Sign-in is Sign in with Apple and Sign in with Google only
Analytics, advertising, crash reporting Not present — there is no such mechanism in the app

2. What happens to your voice

Where it is processed On your device only
Is it sent anywhere No
Is it written to a file No

Audio from the microphone passes through memory, becomes text, and is gone. It is never written to a temporary file either.

This is not a promise to be careful. It is enforced: the repository contains a test (INV-3) that mechanically checks that no code anywhere writes audio to disk, and code that breaks it does not build.

The macOS release uses Apple's SpeechAnalyzer, built into your device. Recognition completes on the device; your audio does not leave it.


3. What happens to the text

The transcript and the formatted text stay on your device.

Formatting (removing fillers, adding punctuation, adjusting politeness) is done by an AI model that runs on the device: Apple's Foundation Models in the macOS release. No external AI service is contacted.


4. What is stored on your device

The following is stored on your device. Of it, your audio and your history are synced nowhere.

Stored Why How to remove it
Dictation history (text) So you can review and re-insert it Delete individually or all at once from the history screen. You can also turn the history off entirely
Dictionary (your terms) So proper nouns come out right Delete from the dictionary screen
Settings So the app remembers how you work Reset from settings
Diagnostic log So faults can be investigated. What you dictated is never written to it (mechanically checked) Delete the app's data folder

History can be switched off completely. With it off, no text, no transcript and no timing is recorded at all.

What syncs, and what does not

If you use more than one device, your setup can travel with you. It only does so when you switch it on.

Can be synced, if you choose to Settings, dictionary, snippets
Never synced — not a setting, a fact Audio, transcripts, dictation history

The top row is what you typed into settings, not what you said — but your dictionary can hold people's names (§1), which is why syncing is off by default and turning it on is your call.

The bottom row has no screen that would sync it. For audio specifically, the absence of any code that writes it to disk is checked mechanically (INV-3, see the appendix).


5. When the app uses the network

The app connects to the internet in exactly four situations. None of them carries your audio or your transcripts.

When What is sent
Signing in The credential Apple or Google issues, and your email address
Syncing your setup, if you switched it on Settings, dictionary, snippets (the top row of §4)
Downloading a speech model, when you choose to Which file is wanted
Checking whether a newer version exists, at launch (you can switch it off) Nothing

The version check has nothing to send. It reads one fixed file that says which version is newest and compares it with yours on your machine. Not your version, not an identifier, not a usage count. What the server unavoidably learns is what any web request tells it: that some connection asked for that file.

You can switch it off in Settings ▸ Help. With it off, the request never happens.

Models are hosted on Hugging Face. What is sent there is which file is wanted — not one byte of audio, text, history, identifiers or usage.

On macOS, the operating system may download language assets for Apple's engines. That is a function of macOS and falls under Apple's privacy policy. The app can neither see the contents of that exchange nor add anything to it.


6. Your account

Signing in is required. After that, dictation keeps working offline.

How you sign in Sign in with Apple / Sign in with Google, only
What we hold An email address, and nothing else (§1)
On a day our server is down Speaking and getting text does not stop. Only syncing stops
On a day you have no network The same. Once you have signed in, it keeps working
Syncing Off by default. Until you turn it on, neither settings nor dictionary leave the device

That is the design, not a happy accident. Recognition and formatting both complete on the device, so nothing on the dictation path needs the network at all.

To delete your account, contact us at the address below. Everything in the §1 table goes with it — the email address, your settings and dictionary if you were syncing, and the purchase record. Your voice and your text were never held in the first place.


7. About the clipboard — worth knowing

When the text cannot be inserted at your cursor, the app places it on the clipboard and tells you to press ⌘V. That is a local operation.

However, if you have Apple's Universal Clipboard enabled on macOS, clipboard contents are shared with your other devices signed in to the same Apple ID. That is an Apple platform feature rather than something Kotonoha does — but it would be a surprise if you did not know, so it is written here.

To turn it off: System Settings ▸ General ▸ AirDrop & Handoff ▸ Handoff.


8. Sharing with third parties

None.

No advertising network, no analytics vendor and no cloud speech or AI provider receives anything. Your voice and your text never leave the device, so there is nothing to share.

Apple and Google learn that you signed in with them. They do not learn what you said.

If you buy a paid feature, the payment provider takes the payment. Your card details stay with them and never reach us.


9. Children

The app can be used at any age. Signing in goes through Apple or Google, which apply their own age rules; beyond the email address they return, nothing about a user is collected.


10. Your rights

What you can ask to see, correct or delete is what the §1 table lists: the email address, the settings and dictionary if you switched syncing on, and the purchase record. Write to the address below.

The data on your device — history, dictionary, settings, logs — is, per the table above, yours to erase at any time, without asking us.


11. Changes to this policy

If this policy changes, the "Last updated" date above changes with it. If a change ever means we would hold something more, it will be announced in the app and your consent will be asked for first. There is no such plan.

In particular, your audio, your transcripts and your history will not start leaving the device. That is what this product is. Of it, "audio is never written to disk" is the part checked mechanically (INV-3, see the appendix).


12. Contact

Email: support@kotonoha.page


Appendix: why "does not send" can be stated flatly

These properties are checked mechanically by tests. If any one of them breaks, a release build cannot be produced.

Check What it asserts
INV-3 No code under crates/ writes audio data to disk, temporary files included (allow-list based)
Log check No code passes transcribed text to a log statement
INV-1 No failure loses your speech — i.e. the design never recovers by sending it somewhere
INV-8 That this page cannot state a claim a decision has retracted (below)

What the table does not say is worth saying too. What is checked is that audio never reaches the disk and that transcripts never reach the log. "We do not upload your text" is a commitment, not a mechanical check. They are deliberately not written with the same force — keeping that distinction honest is what INV-8 is for.

The source is not public, but the existence of these checks is the evidence.

Requiring a sign-in changes none of the three rows above. What travels at sign-in is an email address, not a voice.