Last updated: May 12, 2026

Privacy in plain English

typwrtr listens to your voice and types text. That requires us to handle audio carefully. Here's exactly what we do.

What stays on your machine

Everything sensitive lives on your computer, not on a server you don't control:

  • Your dictation history. Every transcribed sentence is stored in a local SQLite database under your user profile (Windows:%AppData%\com.typwrtr.app). It never leaves your machine. You can disable this anytime in Settings → Save transcriptions.
  • Your taught corrections. When you hit Ctrl+Alt+; to teach typwrtr a fix (or when it auto-learns from your edits), the wrong-text and right-text pair stays in that same local database. We don't sync it. We don't ship it anywhere.
  • Audio clips. Off by default. If you turn it on (Settings → Keep audio clips), the original WAV file is saved alongside its transcript — still local-only.
  • Sign-in tokens. Your Google access token is encrypted with Windows DPAPI (Data Protection API) before it touches disk. Only the OS-level account that signed in can decrypt it.

What leaves your machine (and why)

  • Audio, when you dictate. Each clip is uploaded to typwrtr's relay (a Cloudflare Worker we run) and forwarded to Sarvam AI for speech-to-text. We don't store the audio. Sarvam's own privacy policy governs their retention; per their docs, audio is processed transiently for inference and not used to train models.
  • Your Google identity. When you sign in, we receive your Google sub (a stable but opaque user id), your email, your name, and your profile picture. We use the sub to look up your subscription. Email + name + picture render in the app's Account tab. We don't email you marketing without consent.
  • Subscription metadata. If you upgrade to Pro, your Google sub is linked to a subscription id from our payment provider — Razorpay for India, Dodo Payments for the rest of the world. The provider stores billing info, not us — we never see your card.
  • Ask & Save (Caps Lock + A / Caps Lock + S). Your voice memory lives on your machine: snippets you Save are chunked and embedded on-device and stored in a local database — nothing is uploaded to store them. When you Ask, the selected text (or your memory-search query) and your spoken question go to our LLM gateway only to synthesize the answer; they are not persisted server-side beyond that call. If you'd rather not use it, just don't press the shortcuts — the feature stays dormant.
  • Product telemetry. We send PostHog a small set of anonymous events (app launched, sign-in completed, dictation completed) keyed by your Google sub. No transcript text, no audio, no contact data. You can opt out by turning off save_transcriptions (we use that as the consent flag).

What we never see, ever

  • The contents of your transcripts. They're rendered locally and pasted into your target app. The relay doesn't log them.
  • Anything your microphone captures when typwrtr isn't recording. Push-to-talk only opens the mic stream when you hold Caps Lock (or your configured hotkey). Idle = no listening.
  • Anything you type on your keyboard outside of typwrtr's own windows. typwrtr's keyboard hook only watches the configured PTT key (Caps Lock by default) and the fix-up hotkey (Ctrl+Alt+;); every other keystroke is invisible to us.
  • Your card details, bank account, or any payment info. Our payment provider (Razorpay or Dodo Payments) handles the checkout flow end-to-end; we receive only a "subscription active/cancelled" webhook.

Permissions and what they're for

  • Microphone. Needed to record your voice during push-to-talk. typwrtr can optionally pre-warm the mic at startup (Instant-start microphone setting) — this makes recording snappier but means the OS shows a "mic in use" indicator while typwrtr is running. Turn it off if you prefer privacy mode.
  • Keyboard / Input Monitoring (macOS). Needed to detect your PTT hotkey and to paste the transcribed text via synthetic Cmd+V. typwrtr only watches the configured hotkey, not every keystroke.
  • Accessibility (macOS). Optional. Helps typwrtr read the focused field's type (email, phone, URL) so it can reshape transcripts — "john at gmail dot com" becomes "john@gmail.com" in an email field.

Your controls

  • Stop logging transcripts. Settings → Save transcriptions: off. The dashboard and Learning tab stop showing new entries; the rest of the app keeps working.
  • Clear all learned data. Settings → Clear data wipes the local SQLite database. Tombstones for forgotten corrections are also cleared.
  • Forget a single correction. Learning tab → click the trash next to any row. Stays forgotten across sessions.
  • Cancel Pro. Settings → Plans → Manage subscription. Or email us at the contact below.

Where we host

Authentication and subscription state run on Cloudflare Workers (Cloudflare's edge network, region-routed to whatever's closest to you). User state — your Google sub, subscription status, monthly usage minutes — lives in a Cloudflare D1 database (SQLite at the edge). Sarvam AI's speech-to-text infrastructure handles audio processing; per their documentation, primary inference happens in India.

Children

typwrtr isn't designed for use by children under 13. If you're a parent and believe your child created an account, email us and we'll delete the data.

Changes to this policy

If we materially change what we collect or how we use it, we'll update this page and post a note in the app's release notes. The "Last updated" date at the top reflects when this page last changed.

Contact

Questions, data requests, or "please delete my account": hello@typwrtr.ing. We'll respond within 5 working days.