Kotonoha Privacy Policy
Last updated: 2026-08-14
This policy covers the first macOS release. Windows, iOS, and Android are planned for later; this policy will be reviewed against each platform before that version is released.
In one line
Kotonoha does not send your speech, or the text it becomes, anywhere.
Speech recognition and formatting both run on your device. No cloud speech service and no cloud AI is contacted. There is no analytics, no advertising and no crash reporting in the app.
Using it requires signing in. What that entrusts to us is an email address, plus your settings and dictionary if you switch syncing on. Your voice, your transcripts and your history do not pass through it. See "1. What we are entrusted with" and "6. Your account".
1. What we are entrusted with
| What | When | Detail |
|---|---|---|
| An email address | When you sign in (required) | If you hide it with Sign in with Apple, the relay address instead |
| Settings, dictionary, snippets | Only if you switch syncing on | See below |
| Whether you have purchased | If you buy a paid feature | The fact of the purchase, and what is needed to carry it across your devices |
Your dictionary contains the names and in-house terms you typed into it. That can be personal information, so switching syncing on is your decision. Left off, your dictionary does not leave the device.
| Not entrusted to us | |
|---|---|
| Your voice | Does not leave the device |
| Transcripts and formatted text | Does not leave the device |
| Dictation history | Does not leave the device |
| Name, phone number, location, contacts, date of birth | Not obtained |
| Payment details | Not obtained — the payment provider handles them, and your card details do not reach us |
| Your password | Never stored. Sign-in is Sign in with Apple and Sign in with Google only |
| Analytics, advertising, crash reporting | Not present — there is no such mechanism in the app |
2. What happens to your voice
| Where it is processed | On your device only |
| Is it sent anywhere | No |
| Is it written to a file | No |
Audio from the microphone passes through memory, becomes text, and is gone. It is never written to a temporary file either.
This is not a promise to be careful. It is enforced: the repository contains a test (INV-3) that mechanically checks that no code anywhere writes audio to disk, and code that breaks it does not build.
The macOS release uses Apple's SpeechAnalyzer, built into your device. Recognition completes on the device; your audio does not leave it.
3. What happens to the text
The transcript and the formatted text stay on your device.
Formatting (removing fillers, adding punctuation, adjusting politeness) is done by an AI model that runs on the device: Apple's Foundation Models in the macOS release. No external AI service is contacted.
4. What is stored on your device
The following is stored on your device. Of it, your audio and your history are synced nowhere.
| Stored | Why | How to remove it |
|---|---|---|
| Dictation history (text) | So you can review and re-insert it | Delete individually or all at once from the history screen. You can also turn the history off entirely |
| Dictionary (your terms) | So proper nouns come out right | Delete from the dictionary screen |
| Settings | So the app remembers how you work | Reset from settings |
| Diagnostic log | So faults can be investigated. What you dictated is never written to it (mechanically checked) | Delete the app's data folder |
History can be switched off completely. With it off, no text, no transcript and no timing is recorded at all.
What syncs, and what does not
If you use more than one device, your setup can travel with you. It only does so when you switch it on.
| Can be synced, if you choose to | Settings, dictionary, snippets |
| Never synced — not a setting, a fact | Audio, transcripts, dictation history |
The top row is what you typed into settings, not what you said — but your dictionary can hold people's names (§1), which is why syncing is off by default and turning it on is your call.
The bottom row has no screen that would sync it. For audio specifically, the absence of any code that writes it to disk is checked mechanically (INV-3, see the appendix).
5. When the app uses the network
The app connects to the internet in exactly four situations. None of them carries your audio or your transcripts.
| When | What is sent |
|---|---|
| Signing in | The credential Apple or Google issues, and your email address |
| Syncing your setup, if you switched it on | Settings, dictionary, snippets (the top row of §4) |
| Downloading a speech model, when you choose to | Which file is wanted |
| Checking whether a newer version exists, at launch (you can switch it off) | Nothing |
The version check has nothing to send. It reads one fixed file that says which version is newest and compares it with yours on your machine. Not your version, not an identifier, not a usage count. What the server unavoidably learns is what any web request tells it: that some connection asked for that file.
You can switch it off in Settings ▸ Help. With it off, the request never happens.
Models are hosted on Hugging Face. What is sent there is which file is wanted — not one byte of audio, text, history, identifiers or usage.
On macOS, the operating system may download language assets for Apple's engines. That is a function of macOS and falls under Apple's privacy policy. The app can neither see the contents of that exchange nor add anything to it.
6. Your account
Signing in is required. After that, dictation keeps working offline.
| How you sign in | Sign in with Apple / Sign in with Google, only |
| What we hold | An email address, and nothing else (§1) |
| On a day our server is down | Speaking and getting text does not stop. Only syncing stops |
| On a day you have no network | The same. Once you have signed in, it keeps working |
| Syncing | Off by default. Until you turn it on, neither settings nor dictionary leave the device |
That is the design, not a happy accident. Recognition and formatting both complete on the device, so nothing on the dictation path needs the network at all.
To delete your account, contact us at the address below. Everything in the §1 table goes with it — the email address, your settings and dictionary if you were syncing, and the purchase record. Your voice and your text were never held in the first place.
7. About the clipboard — worth knowing
When the text cannot be inserted at your cursor, the app places it on the clipboard and tells you to press ⌘V. That is a local operation.
However, if you have Apple's Universal Clipboard enabled on macOS, clipboard contents are shared with your other devices signed in to the same Apple ID. That is an Apple platform feature rather than something Kotonoha does — but it would be a surprise if you did not know, so it is written here.
To turn it off: System Settings ▸ General ▸ AirDrop & Handoff ▸ Handoff.
8. Sharing with third parties
None.
No advertising network, no analytics vendor and no cloud speech or AI provider receives anything. Your voice and your text never leave the device, so there is nothing to share.
Apple and Google learn that you signed in with them. They do not learn what you said.
If you buy a paid feature, the payment provider takes the payment. Your card details stay with them and never reach us.
9. Children
The app can be used at any age. Signing in goes through Apple or Google, which apply their own age rules; beyond the email address they return, nothing about a user is collected.
10. Your rights
What you can ask to see, correct or delete is what the §1 table lists: the email address, the settings and dictionary if you switched syncing on, and the purchase record. Write to the address below.
The data on your device — history, dictionary, settings, logs — is, per the table above, yours to erase at any time, without asking us.
11. Changes to this policy
If this policy changes, the "Last updated" date above changes with it. If a change ever means we would hold something more, it will be announced in the app and your consent will be asked for first. There is no such plan.
In particular, your audio, your transcripts and your history will not start leaving the device. That is what this product is. Of it, "audio is never written to disk" is the part checked mechanically (INV-3, see the appendix).
12. Contact
Email: support@kotonoha.page
Appendix: why "does not send" can be stated flatly
These properties are checked mechanically by tests. If any one of them breaks, a release build cannot be produced.
| Check | What it asserts |
|---|---|
| INV-3 | No code under crates/ writes audio data to disk, temporary files included (allow-list based) |
| Log check | No code passes transcribed text to a log statement |
| INV-1 | No failure loses your speech — i.e. the design never recovers by sending it somewhere |
| INV-8 | That this page cannot state a claim a decision has retracted (below) |
What the table does not say is worth saying too. What is checked is that audio never reaches the disk and that transcripts never reach the log. "We do not upload your text" is a commitment, not a mechanical check. They are deliberately not written with the same force — keeping that distinction honest is what INV-8 is for.
The source is not public, but the existence of these checks is the evidence.
Requiring a sign-in changes none of the three rows above. What travels at sign-in is an email address, not a voice.