Privacy
Your recordings stay on your Mac.
Last updated 27 August 2026
What MemoFlow records
- —Microphone audio, and — if you grant Screen Recording — the audio other participants are producing, saved as two separate tracks.
- —Transcripts, summaries, action items and tags derived from those recordings.
- —Text you dictate, along with how long each dictation took.
All of it is written to ~/Library/Application Support/MemoFlow — audio as files, everything else in a SQLite database.
How that data is protected
MemoFlow does not add its own encryption layer. Your recordings and database are ordinary files, protected by your macOS user account and by FileVault if you have it switched on — we recommend you do. Anyone with access to your unlocked Mac can read them, exactly as they could read your Documents folder.
API keys are the exception: those are stored in the macOS Keychain rather than in the database or preferences.
Transcription happens on your Mac
Speech becomes text using models that run locally — Apple's on-device speech recognition, or a Whisper model downloaded to your Mac. Both work with no network connection. Audio is never sent anywhere for transcription.
Cloud models are optional, and off by default
You can choose to use Google Gemini or OpenRouter for summaries, chat answers and transcript cleanup. This is off unless you enable it and supply your own API key. When it is on:
- —Transcript text — never audio — is sent to that provider to produce the answer.
- —Your API key is stored in the macOS Keychain and used only to make those requests.
- —That provider's own privacy and retention policy then applies to the text you send. With OpenRouter, the text is also passed on to whichever model you select.
- —If a request fails, MemoFlow falls back to the on-device model rather than retrying elsewhere.
Turning it off in Settings stops it immediately. Dictation polish always runs on-device, regardless of this setting.
Permissions, and why each is asked for
- —Microphone — to record you.
- —Screen Recording — macOS requires it to capture system audio, which is how other participants are recorded. No video or screenshots are captured.
- —Accessibility — to type dictated text into the app you are using, and to watch for a modifier-only shortcut.
- —Calendar — read-only, to show reminders before a meeting starts. Events are read on your Mac and never transmitted.
- —Automation — only if you create a dictation mode that targets a website, to read the current tab's address from your browser.
What MemoFlow sends us
Nothing. The app has no account, no sign-in, and no analytics or telemetry. It contacts the network only to download a transcription model, to check for updates, and to reach a cloud provider you have configured.
This website
If you ask for a download link, we store the email address you give us and which platform you asked about, so we can send you the link and let you know about updates. There are no third-party analytics or advertising trackers on this site.
Email us to have that address removed and we will delete it.
Deleting your data
Deleting a meeting in the app removes its recording and transcript. Settings ▸ Reset removes every meeting, transcript, dictation, chat and setting from your Mac. You can also delete the MemoFlow folder in Application Support directly. Because none of it was uploaded, that is the whole of it.
Changes
If this policy changes in a way that affects what leaves your Mac, the release notes will say so plainly rather than pointing at a revised date.