FlowKeys Privacy Policy
Effective date: the date FlowKeys paid plans launch
FlowKeys is an on-screen keyboard and dictation app for macOS. This policy explains what information FlowKeys handles, where it goes, how long it is kept, and what you can do about it. "FlowKeys", "we" and "us" mean the developer of FlowKeys. You can reach us at getflowkeys.app@gmail.com.
The short version
- Typing, predictions, your learned vocabulary, your dictation History and your usage stats are stored on your Mac. We have no copy of them.
- Dictation sends your recorded audio to a speech-to-text provider: AssemblyAI by default, with ElevenLabs as an automatic backup if AssemblyAI fails.
- AI polish and rewrites send text to Anthropic (the company behind Claude).
- The dictation demo on flowkeys.app works the same way: your speech goes to AssemblyAI and the transcript to Anthropic for cleanup, and nothing is stored.
- These requests pass through, or are authorized by, our server, which runs on Cloudflare.
- Your account (email and sign-in provider) is held by Google Firebase; payments are handled by Paddle, and we never see your card details.
- We don't sell your data, we don't show ads, we don't use analytics tools, and we don't train AI models on what you type or say. Crash reports are sent only if you turn them on.
What stays on your Mac
These are stored only on your Mac, and we don't keep a copy of any of them:
- Learned typing vocabulary, replacement rules and your "never suggest" list.
- Usage stats on the Today dashboard: keystroke and word counts, timings and the names of the apps you used. They never include the text you typed or dictated, or document titles.
- Dictation History: your transcripts, kept until you delete them, plus the raw audio recordings, kept for as long as you choose (see "Your controls").
- Settings, including your saved dictation vocabulary (names and terms). That vocabulary is sent along with dictation requests; see below.
To suggest words and run rewrites, FlowKeys reads the text in the field you're typing in, using macOS Accessibility permissions. It reads this text in memory as you type and does not save it to disk.
What leaves your Mac, and who receives it
Dictation: AssemblyAI (default) and ElevenLabs (backup)
When you dictate, FlowKeys sends your recorded audio to a speech-to-text provider, together with your saved dictation vocabulary so that it spells your names and terms correctly.
- AssemblyAI is the default. Most dictations stream audio straight from your Mac to AssemblyAI, using a short-lived, single-use access token issued by our server. Some dictations, such as very short or very long ones or a retry after a streaming failure, are instead uploaded as a file through our server.
- Retention: our AssemblyAI account is opted out of model training, which means AssemblyAI does not keep streamed audio or transcripts. For uploaded files, FlowKeys asks AssemblyAI to delete the audio and transcript as soon as it has read the result. If that deletion request fails, AssemblyAI deletes them automatically under our account's retention setting (at most 72 hours).
- ElevenLabs is the backup. FlowKeys uses it automatically when AssemblyAI fails, so that you don't lose the dictation. Audio either streams directly to ElevenLabs with a single-use token from our server or is uploaded through our server.
- Retention: by default ElevenLabs keeps requests under its standard retention policy, which at the time of writing allows up to 2 years. ElevenLabs offers a zero-retention mode only on enterprise plans, which our account is not on, so this applies to every dictation ElevenLabs handles. ElevenLabs' API terms do not allow it to use this data to train models.
The app also contains code for two other speech-to-text providers, Groq and DeepInfra, which we use for internal testing. The released app does not send your audio to either one. The only way to use them is to set up a developer configuration file on your Mac containing your own API key for that provider. If you do that, your audio goes to that provider under your own account and that provider's terms.
AI polish and rewrites: Anthropic
- Dictation polish. After a dictation is transcribed, FlowKeys sends the transcript, your saved dictation vocabulary and your chosen tone setting to Anthropic's Claude to clean up filler words, punctuation and capitalization. You can turn this off in Vibe → Auto Polish by choosing "None".
- Rewrites. When you tap a rewrite or reply action, FlowKeys sends the text you picked to Anthropic: your selection, the copied message you're replying to, or the contents of the current field. If you've written a custom tone, its instructions are sent too. Rewrites happen only when you ask for one.
All of these requests go through our server, which holds the Anthropic account key. This traffic falls under Anthropic's commercial API terms. Anthropic does not train its models on it and deletes it within 30 days, except where it must keep data longer for legal or safety reasons.
Our server: Cloudflare
Our server is a Cloudflare Worker. It relays the requests described above to AssemblyAI, ElevenLabs and Anthropic and issues the single-use dictation tokens. It does not store your audio, transcripts or text. Specifically, it:
- receives your install ID with every request. This is a random identifier the app creates when you first run it, and it isn't linked to your name or email. We use it, together with your account, to enforce plan limits;
- keeps daily usage counters per install ID for builds used without an account (number of requests, bytes of audio, AI token counts), which delete themselves after 7 days;
- writes operational logs with a shortened form of the install ID, the type of request, its size and any error codes from providers. These logs never contain your audio, transcripts or text;
- sees your IP address, as every web server does. We use it only to prevent abuse and to enforce rate limits, and keep it for at most 7 days.
App updates. About once a day, the app checks `dl.flowkeys.app` (hosted on Cloudflare) for a newer version and downloads it if there is one. The check sends only the app's version number, plus your IP address as with any web request. Every update is signed, and the app verifies the signature before installing.
Cloudflare processes this traffic as our hosting provider, and its own request logs can include your IP address and install ID for a short period.
Your account: Google Firebase
When you sign in, Google Firebase Authentication stores your email address, your sign-in provider (Google or email link) and a user ID. Our server receives a short-lived token proving who you are with each request. We use your account to apply your plan and allowance.
Usage records
For each account, our server keeps usage totals: seconds of dictation audio, rewrite counts and the words in rewrite requests, per day and per week, plus your plan, trial dates and your Paddle customer and subscription IDs. These records never include your audio, transcripts or text. They're kept while your account exists and for up to 12 months after, for billing and abuse prevention.
Payments: Paddle
Paddle.com is our reseller and merchant of record. When you buy, Paddle collects your payment details, billing address and email under its own privacy policy (paddle.com/legal/privacy). Paddle tells us that a purchase or cancellation happened and which account it's for; it never shares your card number with us.
Crash reports: Sentry (only if you turn them on)
Off by default. If you turn on Settings → Data & Privacy → Send crash reports, FlowKeys sends the crash logs macOS writes after a FlowKeys crash to Sentry, our crash-reporting service, the next time it opens. Crash logs describe the app's code at the moment of the crash, your macOS version and your Mac's model; they don't contain what you type or dictate. Crashes from before you turned the setting on are never sent.
Website dictation demo
The "Now say it." demo on flowkeys.app lets you try dictation without installing the app. When you press the mic button:
- your browser asks for microphone permission, and nothing is recorded unless you allow it;
- a Cloudflare Turnstile check confirms you're a person. Turnstile is run by Cloudflare under its own privacy terms;
- your speech streams through our server to AssemblyAI for live transcription, for up to 30 seconds. The transcript is then sent to Anthropic once for cleanup. These are the same providers and settings described above for the app;
- we don't store the audio or the text. They exist only in your browser tab and in transit. Refreshing the page clears them;
- your IP address is used to allow a few tries per day. We store only a scrambled (hashed) form of it, never the address itself, and clear it out after about a week.
What we don't do
- No advertising, and no selling or renting of your data.
- No third-party analytics or tracking tools. The app contains none; crash reporting is off unless you turn it on.
- We never see or store your payment card details.
- No training of AI models on your content, by us or, as far as their terms allow us to choose, by our providers.
Your controls
- Erase everything on this Mac: Settings → Data & Privacy → Erase all FlowKeys data permanently deletes learned vocabulary, the "never suggest" list, dictation History (transcripts and recordings) and usage stats. We hold no server-side copy of this content, so there is nothing further for us to delete.
- Dictation recordings: Settings → Data & Privacy → Dictation recordings sets how long raw audio stays in History: "Don't save recordings", 1 day, 7 days (the default), 30 days or Forever. Transcripts stay until you delete them in History.
- PII redaction: Settings → Dictation → PII redaction asks AssemblyAI to remove personal details such as names, numbers and addresses from the transcript. It's off by default and applies only to AssemblyAI.
- Auto Polish: in Vibe → Auto Polish, choose "None" and dictations aren't sent to Anthropic.
- Stop using FlowKeys: delete the app. The usage counters tied to your install ID expire on their own within 7 days.
- Delete your account: email us from the address you signed in with and we'll delete your account and usage records within 30 days. Cancel any subscription first, in Settings → Account → Manage.
If you'd like to ask about, or ask us to delete, anything tied to your install ID, email us with the ID, which you'll find in Settings → Diagnostics. Because we collect so little, we may be able to delete it but not to identify you from it.
Children
FlowKeys isn't directed at children under 13, and we don't knowingly collect personal information from them.
Changes to this policy
If we change this policy, we'll update it here and change the effective date above. If a change significantly affects where your data goes, for example a new provider, we'll also mention it in the app's release notes.
Contact
Questions or requests: getflowkeys.app@gmail.com