← WhisperShortcut

Privacy Policy for WhisperShortcut

Last updated: September 29, 2026

Magnus, the developer of WhisperShortcut
— Magnus · Developer
I built WhisperShortcut to be local-first and bring-your-own-key. There's no backend and no accounts — here's exactly what that means for your data.

Overview

WhisperShortcut is a macOS menu bar app for dictation, voice editing, AI chat, text-to-speech, live meeting transcription, and related productivity workflows. The app is local-first and bring-your-own-key: cloud features use your Google Gemini API key, optional OpenAI API key, optional xAI API key for Grok features, optional Anthropic API key for Claude chat models, and an optional OpenRouter API key for dictation through models OpenRouter routes to. Optional Google and Trello connections, and folders you share with the chat, add controlled chat tools. Offline Whisper transcription can run without sending audio to a cloud service. This privacy policy explains what data is stored locally, what may be sent to third-party services when you use cloud or connected features, and what controls you have.

Data Collection Summary

WhisperShortcut collects minimal data and prioritizes your privacy:

What Data We Collect

1. API Keys And OAuth Tokens

To use cloud features, you enter your own provider API keys. Usage is billed to the account for the relevant provider. Optional Google and Trello integrations use tokens only after you connect them.

Credentials

2. App Preferences

3. Temporary Audio Files

4. Chat Sessions

5. Live Meeting Transcripts (Optional)

6. User Context / Interaction Logs

7. Google account — Calendar, Tasks, and Gmail (optional OAuth)

If you choose to connect your Google account, the app can access services you authorize on the Google consent screen, which may include: Google Calendar (read and create events), Google Tasks (read and manage tasks in your task lists, including create, complete, and delete), and Gmail in read-only form (search and read message content requested through the app). Exact permissions depend on the scopes Google shows you at sign-in.

OAuth scopes(as shown on Google's consent screen) align with the following. Google's own short descriptions: Calendar — view and edit events on your calendars; Tasks — create, edit, organize, and delete your tasks; Gmail (read-only) — view your email messages and settings. WhisperShortcut uses them as follows:

8. Trello boards, lists, and cards (optional token)

If you choose to connect Trello, the app can use Trello's API when you ask chat to work with boards, lists, and cards. Trello uses a manual token flow: you create or provide your Trello Power-Up API key, open Trello's authorization page, copy the token Trello shows after you click Allow, and paste it back into the app.

9. Workspace folders shared with chat (optional)

You can share folders with the in-app chat in Settings → Chat → Workspace Folders, with the /folder command, or by dropping a folder onto the chat window. Sharing is explicit and per folder: the app stores a macOS security-scoped bookmark for each folder you pick, and the chat can only use those folders.

Anonymous Usage Statistics (Optional, Off By Default)

If you turn on Share anonymous usage statistics(during setup or in Settings → Privacy & Permissions), the app sends a daily summary of counts to a small server we operate: how often features were used and whether they worked, failure classes such as "network", which built-in models were used (model names you typed yourself are sent as custom), which providers have a key configured (never the key), app and macOS version, the week of your first launch and the days since then, plus one-time notes when you pass a setup step or use a feature for the first time.

It never contains transcripts, prompts, chat messages, replies, audio, clipboard or selected text, screenshots, the apps you paste into, error messages, API keys, or any device or install identifier. The server stores accepted summaries for 400 days, drops any field it does not know, and does not store IP addresses. Its code is public in the app's repository under server/telemetry/.

"See exactly what is sent" in Settings shows the exact JSON. Turning the switch off deletes anything not yet sent. It is unavailable while Offline Mode is on, and administrators can force it off with the telemetryForceDisabled preference.

What Data We Do NOT Collect

Third-Party Services

Google Gemini API

WhisperShortcut can use Google's Gemini API when you configure a Google API key, for Speech-to-Text (cloud), Speech-to-Prompt, Chat, TTS, Smart Improvement, live meeting transcription, and optional flows that may include Calendar, Tasks, and Gmail-related context when you have connected your Google account. Data sent may include audio files, text, screenshots, image attachments, prompt context, and tool results. Data received may include transcribed text, AI chat responses, generated audio, or AI-modified text. Subject to Google's Privacy Policy. When you use cloud features, your audio and/or text may be sent to Google's servers. For offline Speech-to-Text with Whisper, no data leaves your device.

OpenAI API

If you choose OpenAI models, WhisperShortcut sends the minimum needed audio, text, images, chat messages, tool results, or prompt context to OpenAI using your OpenAI API key. This includes OpenAI Transcribe, OpenAI Dictate Prompt, OpenAI chat models, and hosted web search for supported OpenAI chat models when enabled. OpenAI models are used only when selected and are subject to OpenAI's policies and API terms.

xAI Grok API

If you choose a Grok model, WhisperShortcut sends the minimum needed audio, text, chat messages, or prompt context to xAI using your xAI API key. This includes Grok Speech-to-Text, Grok Dictate Prompt, Grok Read Aloud (text-to-speech), and Grok chat models, including web and X search for Grok chat when enabled. Grok models are used only when selected.

Anthropic API (Claude)

If you choose a Claude model in chat, WhisperShortcut sends the minimum needed text, images, chat messages, tool results, or prompt context to Anthropic using your Anthropic API key. Claude models are available in the chat window only—they are not used for Speech-to-Text, Dictate Prompt, or Read Aloud—and only when you select them. Use is subject to Anthropic's policies and API terms.

OpenRouter API (optional)

If you select the OpenRouter transcription model, WhisperShortcut sends your dictation audio and the accompanying prompt directly from your Mac to OpenRouter using your OpenRouter API key, and OpenRouter forwards it to the model slug you configure. Because OpenRouter has no dedicated transcription endpoint, the audio is sent as a chat message, which means your Dictation system prompt and Glossary are included in the request. OpenRouter is used for Speech-to-Text only—not for Dictate Prompt, Read Aloud, or Chat—and only when you select it. Your data is handled by OpenRouter and by the upstream model provider it routes to, subject to their respective policies and terms; the model you pick determines which provider ultimately receives the audio.

Local OpenAI-compatible model (optional)

If you configure a local model endpoint (for example Ollama or LM Studio), chat requests go to the address you configure on your own machine or network instead of a cloud provider. You are responsible for that server, its logs, and its data handling.

Your own endpoint: Azure OpenAI, Vertex AI, or a proxy (optional)

If you enter a custom endpoint in Settings > Chat (for example your own Azure OpenAI / Microsoft Foundry resource, a Google Vertex AI project, or an OpenAI-compatible proxy), chat requests go directly from your Mac to that URL with the key you provide. Processing then happens under your own agreement with that provider, in the region your resource runs in. No WhisperShortcut server is involved.

On-device model downloads (Hugging Face)

On-device Whisper and chat models are downloaded from Hugging Face the first time you pick one. That download request carries no transcript, prompt, or audio of yours; afterwards the model runs entirely on your Mac.

Offline Mode

With Offline Mode on (Settings > Privacy & Permissions), dictation, Dictate Prompt, chat, and Read Aloud run on-device, requests the app builds to cloud services are blocked, and no transcript, prompt, or audio sample is written to the usage log. Requests to your own machine or local network, and model downloads, still work.

Self-hosted transcription endpoint

If you configure the Self-hosted Transcription Endpoint, WhisperShortcut sends dictation audio directly from your Mac to the endpoint URL you provide. This feature is intended for user-controlled or self-hosted OpenAI-compatible /v1/audio/transcriptions services, including an Azure OpenAI deployment. You are responsible for the endpoint, credentials, logs, storage, and retention behavior of that service.

Google Calendar, Google Tasks, and Gmail APIs (optional)

If you connect your Google account, the app may communicate with Google's Calendar, Tasks, and/or Gmail APIs using OAuth tokens stored in your macOS Keychain, as permitted by the scopes you approve. Use of these services is subject to Google's Privacy Policy and Google API Terms of Service, and to Gmail, Calendar, and Tasks product terms as applicable.

Trello API (optional)

If you connect Trello, WhisperShortcut communicates with Trello's API using your Trello Power-Up API key and user token. Board, list, and card data retrieved for you may be included in requests to the cloud AI provider you configure only to produce the response or action you asked for in that session. Trello data and token handling are subject to Atlassian/Trello policies and terms.

Data Protection Mechanisms for Sensitive Data

We apply the following safeguards to sensitive data, including API keys, OAuth tokens, Trello tokens, and Google Workspace data accessed through user-authorized scopes (Calendar, Tasks, Gmail):

Your Rights and Controls

You can access and modify preferences through the app settings, delete your API keys, reset preferences, delete meeting transcripts and interaction data, disable Save usage data, and disable automatic improvement. If you connected your Google account, you can disconnect it in Settings or with the /disconnect-googlecommand in the in-app chat, which revokes the app's use of Calendar, Tasks, and Gmail. If you connected Trello, you can disconnect it in Settings or with the /disconnect-trello command in chat. Microphone and Accessibility permissions can be revoked in macOS System Settings.

Children's Privacy

WhisperShortcut does not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this privacy policy from time to time. We will notify users of material changes by updating the "Last updated" date and posting the new policy in the app repository.

Contact Information

For questions about this privacy policy or our data practices, contact us at mgsgde@gmail.com. You can also open an issue on the public GitHub repository: https://github.com/mgsgde/whisper-shortcut.

This privacy policy is provided to comply with Apple App Store requirements, GDPR principles, CCPA requirements, and other applicable privacy laws.

WhisperShortcut is committed to protecting your privacy and ensuring transparency about our data practices.