Privacy

Last updated 22 September 2026 · SayLess 2.32.9

SayLess turns what you say into text. That is unusually personal data, so this page describes exactly what the app keeps, where it keeps it, and the only circumstances in which anything leaves your Mac.

No account required

SayLess works fully without an account. It collects no analytics and transmits no usage data, and your dictations, transcripts, and notes are stored on your Mac, not on our servers. Three things do leave without a provider configured: a check for updates (a request to GitHub for the release feed, when the app opens and hourly after), a one-time download of the on-device speech model from Hugging Face when you turn it on, and Apple's speech recognition as described under Three ways it can run.

An account is optional. Signing in — with Google, or with a six-digit code emailed to you — creates a SayLess account whose identity is your email address, held by our authentication service (Supabase) and shown to you in Settings. Nothing rides along with sign-in: no transcript, note, memory, style information, vocabulary, app identity, or audio is part of any sign-in request. If you choose the code, your address is sent to our authentication service so it can email the code; nothing else is sent. The session token is stored in your Mac's Keychain; signing out deletes it. To have the account itself deleted, email privacy@sayless.club.

Three ways it can run, and what leaves on each

Every job the app does — turning speech into text, cleaning it up, writing a meeting note, answering a question about one — takes one of three routes, and the app names the route on every result.

What is stored, and where

Everything the app remembers lives in your own user folders on this Mac:

Audio is temporary, always

A recording exists only as long as it takes to turn into text. The temporary file is deleted when transcription succeeds, when it fails, and when you cancel. SayLess has no setting that retains audio, and no feature that uploads a recording for storage.

What goes to AI providers

If you configure a provider — OpenAI, Anthropic, Google Gemini, DeepSeek, Kimi, Vercel AI Gateway, or a compatible endpoint of your choosing — SayLess sends that provider the audio or text it needs to do the job you asked for, using your API key and your account with them. Their terms govern that data.

You can also run SayLess with no provider at all; the first route above describes exactly what happens then.

Some things are deliberately excluded from every provider request:

One exception worth naming: requests through Vercel AI Gateway carry an anonymous per-installation tag so the gateway can meter them. It identifies this install, not you, and Settings says so where that route is chosen.

Meetings and other people

SayLess captures audio through macOS rather than by joining your call, so no participant appears in your meeting. A recording indicator is visible whenever it is listening, and it asks you to confirm consent before capture begins.

Recording other people may require their knowledge or agreement where you live. SayLess deliberately provides no hidden or silent capture mode, but complying with the law where you are is your responsibility.

Calendar access

If you allow it, SayLess reads upcoming event titles and times from macOS Calendar so it can offer to take notes before a meeting starts. It reads only; it never creates or changes events, and calendar details are never sent to any AI provider.

Connecting a Google account

Separately from sign-in, you can connect a Google account in Settings → Connections. Each permission maps to one visible feature, and SayLess requests nothing it does not use:

Google user data is processed on your Mac to provide these features at your request. It is not stored on SayLess servers, not used for advertising, not sold, and not read by any human. Your OAuth tokens live in the macOS Keychain, and you can disconnect in Settings or revoke access at myaccount.google.com/permissions at any time. SayLess's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your control

This website

sayless.club sets no cookies and runs no analytics. The theme toggle keeps your light-or-dark choice in your browser's local storage, which never leaves your browser. If you enter your email on the download form, we store that address with a timestamp and coarse country — no IP address, no user agent — to send release notes and nothing else, never sold or shared. Every email says how to leave — an unsubscribe link or a reply-to-leave address — and privacy@sayless.club removes it too.

Two pages talk to GitHub from your browser: the changelog loads the release list from api.github.com, and the download itself is served from github.com, so GitHub sees your IP address for those requests under GitHub's privacy statement. The site is hosted on Vercel, which keeps short-lived request logs for operating the service.

Who is responsible, and your rights

The controller for the little that is processed on our side — the optional account identity, the hosted-model counters, and the download form's address list — is the operator of sayless.club, reachable at privacy@sayless.club; name and postal address are in the Impressum. The legal bases are the ones you would guess: performing what you asked for (Art. 6(1)(b) GDPR — signing you in, relaying a generation, sending the download) and consent for the release-notes list (Art. 6(1)(a)), which you can withdraw from any email.

Processing runs on Supabase (the account and the counters), Vercel (this site and its endpoints), Resend (email), GitHub (the download and the release feed), and — only for the hosted route — Google (Gemini API), under its API terms. Some of these process data outside the EU under standard contractual clauses.

You can ask what we hold about you, have it corrected or deleted, restrict or object to processing, and take your data with you (Art. 15–21 GDPR) — one email to privacy@sayless.club does any of these. Account identities are kept while the account exists; the counters are meaningless after their day or week; the address list is kept until you leave it. You can also complain to a data-protection authority — in Germany, the supervisory authority of your state.

Children

SayLess is not directed at children under 16 and is not intended for their use.

Changes

When the boundary changes, this page changes first — the optional account above was added to this page in the same release that introduced it. If a future version stores more outside your Mac (for example, syncing settings between devices), that will be an explicit, opt-in choice presented in the app, and described here before it ships.

Contact

Questions about this policy: privacy@sayless.club