What leaves your Mac, and what doesn't.
A dictation app hears everything you say. This page sets out exactly where that goes, how it is protected, and where the protection stops.
Local by default.
Transcription and cleanup never need the network. The only thing that can leave is finished text, and only if you add your own cloud key.
| Data | Leaves your Mac? | Detail |
|---|---|---|
| Microphone audio | Never | Transcribed on your Mac by WhisperKit. Never uploaded. |
| Vault notes and search index | Never | Stored in vault.enc on your Mac. |
| Vault encryption key | Never | Generated on your Mac, held in your Keychain. |
| Cleanup | Never | Runs on a local model on your Mac. |
| Finished transcript text | Opt-in | Only if you add your own cloud key (Pro, off by default): text goes to the provider you chose. |
One encrypted file.
Threads, notes, entity facts and full-text indexes share a single SQLCipher database. We never receive the key, so we cannot read the vault or recover it.
- Database
- SQLCipher via GRDB
- Key
- 256-bit, random, per Mac
- Key storage
- macOS Keychain
- Key derivation
- 256,000 iterations
- Memory security
- Enabled
- File permissions
- folder 0700 · vault.enc 0600
Guards on the paste.
Tyne inserts text through the pasteboard and a synthetic ⌘V. These checks run before every insertion.
No pasting into password fields
If the focused field is a secure text field, Tyne copies the text to your clipboard instead of inserting it.
No pasting while you hold a modifier
Holding Shift, Control or Option while text is ready turns a paste into a copy, so a stray shortcut cannot fire.
Credentials stripped before storage
Key and token shapes, such as API keys, JWTs and private keys, are redacted before text is indexed, written or sent.
Temporary audio removed
Recording files exist only for the session and are deleted after transcription. History keeps the transcript, not audio.
Where it stops.
- Redaction uses pattern matching. It cannot catch every secret, especially one that is misheard or spelled out. Don’t dictate credentials.
- Tyne is not App-Sandboxed. Typing into other apps needs the Accessibility API, which the sandbox blocks, so Tyne ships with Developer ID signing and notarization instead.
- The vault key is readable after your Mac’s first unlock following a restart. Anyone who can use your unlocked Mac account can use Tyne.
- Backups, such as Time Machine, copy vault.enc in its encrypted form. Older Markdown folders from earlier versions are not encrypted by Tyne.
Report a vulnerability
Email security@tyne.io with steps to reproduce. Please give us a chance to fix it before disclosing publicly.