Privacy
Short version: nothing you dictate or read is sent anywhere. The app has no account, no analytics and no crash reporting. (The website is covered separately, below.) This document is written to be checkable — every claim below can be verified by watching the network with Little Snitch or lsof, or by reading the source.
What leaves your machine
During normal use: nothing you said, dictated or read — ever. The app makes exactly two kinds of non-content connections: an occasional licence check (see below) and an update check against our own domain. Neither carries a word of yours.
Your voice and text talk to one thing — a speech engine running on your own Mac, reachable only at 127.0.0.1:8787 and through a Unix socket in ~/Library/Application Support/Univocal/. Loopback traffic never reaches a network interface. If you watch the app with Little Snitch, the complete list of remote hosts it ever contacts is api.lemonsqueezy.com (licence check, below) and univocalapp.com (update check) — and neither request ever contains content.
During installation and first use: downloads, all to fetch the speech engine.
On first launch the app downloads the software it runs on — packages for the speech engine from pypi.org, the speech recognition and synthesis models from huggingface.co, and, only if your Mac has none, a standalone Python from github.com. Roughly 1.4 GB in total. Reading aloud in some languages fetches one more model the first time you use them.
These are ordinary public downloads of published files. Nothing about you is sent with them beyond what any download involves — your IP address is visible to those servers, as it is to any website you visit. Each file is verified against a SHA-256 hash recorded in the installer before it is used.
After this, the app never contacts them again unless you reinstall.
What stays on your machine
- Your voice. Audio is captured, transcribed in this app's own process, and discarded. It is never written to disk and never leaves the process.
- What you dictate. The last 20 dictations are kept locally so the read-it-back gesture works. Clear them any time in Settings.
- What you have read aloud. Synthesised audio is written to a temporary file and deleted when playback ends.
- Your settings and vocabulary, in
~/.config/<app>/and~/Library/Application Support/Univocal/.
The licence key
Activating a licence sends exactly two things to Lemon Squeezy, the payment processor: your licence key and this Mac's name. Never any content — not a word you dictated or read. The app re-checks the key occasionally when the network happens to be available, and the check fails open: an unreachable server never locks you out, and only a definite answer that the key was refunded or moved to another Mac changes anything. If you want to watch it happen, the only host the app ever contacts beyond your own machine is api.lemonsqueezy.com for this check, and our own domain for update checks.
The browser extension
The extension reads the text of a page only when you switch it on for that tab, and sends that text to the same local engine on 127.0.0.1:8787 in order to speak it. It has no permission to reach any other host — the manifest grants exactly one:
"host_permissions": ["http://127.0.0.1:8787/*"]
It stores your highlight colour and control-bar position in Chrome's own synced settings, which is Google's storage, not ours. If you would rather it not sync, turn off extension sync in Chrome.
Analytics, telemetry, crash reports
None in the app. Not disabled by default — not implemented. There is no code that sends usage data, because none was written.
The practical consequence is that we do not know how many people use the app, which features are used, or when it crashes. That is the trade, and it is the right way round for this product.
Third-party services
None at runtime in the app. Purchases are handled by the payment processor named on the purchase page, which sees your payment details under its own privacy policy; we receive only the information needed to issue and support a licence.
The website
univocalapp.com is a website, not the app, and its footprint is separate:
- Hosting and page analytics. The site is served by Cloudflare, which also injects its Web Analytics beacon into each page. On a page view it reports the page visited, the referrer and load-speed timings. It sets no cookies and carries no cross-site identifier. This runs only in your browser on our website — the app never loads these pages.
- The notify-me form. The "Need another platform?" form asks for a name, an email address and the platforms you need. Those three fields are sent only when you submit the form. We store them (in Cloudflare Workers KV) and they are forwarded to our inbox, for exactly one purpose: emailing you if Univocal comes to a platform you asked for. No newsletter, no sharing, no resale. To have your entry deleted, write to support@univocalapp.com.
Children
The app is not directed at children and collects nothing from anyone, so nothing is collected from children either.
Changes
If a future version ever sends anything anywhere, this document will say so plainly before that version ships, and the change will be in the changelog. A version that quietly started reporting usage would be a betrayal of the only thing this product actually promises.
Contact
Questions: support@univocalapp.com