Legal

Privacy policy.

The short version: your voice is processed on your Mac by default, cloud requests go directly to providers you choose, and dictated content never passes through our servers.

LAST UPDATED: 2 AUGUST 2026 · RECURSE LTD

Who we are

ShoutFlow is made and sold by Recurse LTD ("we", "us"), a company registered in the United Kingdom. This policy covers the ShoutFlow macOS application and this website. Questions to support@shoutflow.ai.

Your voice and your text

ShoutFlow's defining design decision is that dictation does not pass through our servers, in any mode:

  • Local mode (default on Apple Silicon). Audio is transcribed by WhisperKit and cleaned up by an MLX language model, entirely on your Mac. Your audio and text never leave the device. After the one-time model download, this works offline.
  • Bring-your-own-key (BYOK) cloud mode. If you choose a cloud provider (OpenAI, OpenRouter, DeepSeek, Gemini, Kimi, xAI, or a custom endpoint), your Mac sends audio and/or text directly to that provider over TLS, authenticated with your API key. We never proxy, log, or store this traffic; it is not technically in our path. The selected provider's own privacy policy applies to those requests, and the app shows you which stage sends what, where, before you enable it.

Your personal dictionary, voice snippets, transcription history, and settings are stored locally on your Mac. Provider credentials entered in the current app are stored in the macOS Keychain and never on our servers. For compatibility with older local installations, ShoutFlow can also read an OpenAI key from a legacy local settings file, an Application Support .env file, or a development environment variable and attempts to migrate file-based credentials to Keychain. Those compatibility sources stay on your Mac; remove them after confirming migration if you do not want a local plaintext fallback.

What the app sends to ShoutFlow services

The app uses ShoutFlow services for trial access, licensing and feature entitlements, and release checks or downloads. These operational requests are separate from the dictated-content path:

  • Trial. Checking whether a trial is available is public. Starting one requires no paid license, but sends an installation public key, a device label, a one-way device fingerprint made on your Mac from its platform identifier, and signed request proof. The raw platform identifier never leaves the Mac. We retain the trial and fingerprint records to preserve the original expiry after reinstall and to review abuse; the fingerprint is not hardware attestation or advertising data.
  • License and features. Activation sends the license key, installation public key, device label and signed proof. We store a hash of the license key, the installation identity and public key, device label, activation state and lease-event records. Lease refresh, feature synchronisation and deactivation send the license key, installation identity and signed proof; feature synchronisation also sends the app's current feature-policy revision and developer-access state. These records support seat limits, offline leases, entitlement changes, fraud prevention and customer support.
  • Updates and releases. Stable update metadata and stable downloads are public requests. They send ordinary HTTPS metadata and the app's user agent, which includes its version and basic Mac system/architecture information; downloads increase an aggregate release counter. An authenticated switch between Stable and Developer builds additionally sends the license key, installation identity, requested channel and signed proof.

These calls also carry timestamps, short-lived replay-protection values, and standard HTTPS handling metadata such as IP address. We keep operational records as needed to administer the trial or license, prevent reuse of an expired trial, provide support, prevent fraud and meet legal obligations; expired replay-protection values are purged. None of these requests carries audio, transcribed text, prompts, provider keys, or dictation-usage analytics. The app has no account system and embeds no analytics or tracking SDK (website analytics are covered below and never touch the app).

Purchases

Payments are processed by Stripe. We never see or store your card details. From a purchase we receive and keep what we need to deliver and support your license: your email address, the license record, and Stripe's payment reference. We use your email to send the license and for essential service messages, not for marketing lists you didn't ask for.

This website: cookies and analytics

The site is served via Cloudflare, which processes standard server logs (IP address, user agent) to deliver and protect the service.

We use Google Analytics 4 to understand which pages bring people to ShoutFlow, running under Google Consent Mode v2 with every advertising signal permanently denied: analytics only, no ads, no cross-site tracking. Until you make a choice in the cookie banner, and whenever you decline, it runs in cookieless mode: no analytics cookies are set, no identifiers are stored on your device, and Google receives only anonymous, aggregate pings. Whatever you choose, the site sets one first-party cookie, sf_consent, recording your choice for about six months.

If you accept, Google Analytics sets its _ga cookies so repeat visits can be counted. Google Analytics 4 does not log or store IP addresses. Google's processing is described in the Google Privacy Policy. You can withdraw consent at any time via "Cookie settings" in the footer; withdrawing removes the analytics cookies and returns the site to cookieless mode. The site sets no advertising cookies.

On Notes articles, the email prompt uses two functional browser-storage entries so it does not keep interrupting you: sf_nl_dismissed lasts for 14 days after you close the prompt, and sf_nl_done remains after a successful signup until you clear your site data. They are not used for advertising or analytics and are not sent to us.

Email updates from the Notes section

If you sign up for email updates on our Notes pages, we store the email address you provide and which page you signed up from. We use that information to administer the list, handle support and opt-out requests, and measure which Notes pages generate signups. Email delivery is not live; if we introduce it, we will use active, confirmed addresses to send Notes updates. We never share or sell the list, and it is kept separate from dictation. Signing up tells us nothing about how you use the app. Email support@shoutflow.ai at any time to stop receiving updates. We retain an opted-out address as an unsubscribe record so it stays suppressed; submitting the public signup form again will not reactivate it without confirmation that you control the address. Ask us if you want that record deleted instead.

Retention and your rights

We keep purchase and license records for as long as your license is active and as required for tax and accounting. Under UK GDPR you can request access to, correction of, or deletion of your personal data, and you can complain to the ICO. Email support@shoutflow.ai and we'll act on it. Deleting a license record means the license can no longer be reactivated.

Changes

If we change this policy we'll update this page and the date at the top. Material changes to how the app handles your data will also be called out in release notes.