Privacy Policy
Overview
Vox.md keeps capture drafts, attachments, transcripts, and note routes on your device. It sends completed files only to destinations you choose and never sends capture content to Vox.md servers. Production builds keep onboarding analytics disabled by default.
This Privacy Policy describes how Vox.md ("we," "our," or "the app") handles information when you use our iOS and macOS applications and their extensions. Audio, transcripts, keystrokes, capture drafts, attachments, exported file contents, and user-entered text are handled locally. Files are written only to locations you select; your chosen storage provider may sync those files under its own terms.
Information We Do Not Collect
Vox.md does not collect or transmit any of the following to Vox.md or third-party servers:
- Audio recordings or voice data
- Transcribed text or transcription history
- Keystrokes, typed text, or keyboard input
- Personal information such as your name, email, or phone number
- Location data, contacts, or unrelated on-device data sent to Vox.md servers
- Photos, scans, sketches, audio, and files you explicitly select for a local capture
- File names, folder paths, template text, exported note contents, or model file paths
- Advertising identifiers, raw IP address storage, or third-party tracking identifiers
Privacy-Safe Onboarding Analytics
Production builds do not send onboarding analytics by default. Development builds can explicitly enable a small first-party event set for setup testing. These events are intentionally coarse and are not used for advertising or cross-app tracking.
Onboarding analytics may include:
- An anonymous Vox.md install ID used only to count funnel progress
- Event names such as onboarding started, microphone permission completed, model setup completed, paywall shown, purchase or restore outcome, and onboarding completed
- App version, build number, platform, and experiment variant
- Coarse setup state such as microphone permission status, model engine and size bucket, file export format/mode, free-minute and successful-Capture usage buckets, and paywall context
These analytics never include audio, transcripts, dictated text, keystrokes, file/folder paths, template text, model file paths, names, email addresses, raw dates, raw IP addresses, or device names.
On-Device Processing
All voice-to-text transcription is performed entirely on your device. On supported iOS 26 devices, Automatic uses Apple's system-managed Speech framework. You can also opt into local Whisper or Parakeet model downloads. Audio captured by the microphone is processed by the selected on-device backend and is never transmitted over a network connection.
If you explicitly enable Capture Text processing for a Capture Preset, eligible typed text, on-device OCR, and voice transcripts can be cleaned or formatted locally with Apple Intelligence. Processing falls back to deterministic formatting or the original text when on-device intelligence is unavailable. Vox.md does not send captured text to its servers or third-party AI APIs.
Transcription results, capture drafts, and retry requests are stored locally within the app's sandboxed container and shared App Group. This data is accessible only to signed Vox.md app components such as the app, keyboard, widgets, and share extension. No Vox.md service or server can access it.
Keyboard Extension
Vox.md includes a custom keyboard extension that enables voice-to-text input across all apps on your device. Apple requires us to disclose the following about keyboard extensions:
- Allow Full Access is required for the current keyboard workflow. It lets the keyboard use shared App Group state and coordinate recording with the main Vox.md app.
- Vox.md does not use Full Access to upload, sell, or analyze keystrokes, dictated text, transcripts, or microphone audio. The keyboard does not transmit that content to Vox.md or third-party servers.
- The keyboard extension communicates with signed Vox.md app components through the shared App Group container on the device.
Microphone Usage
Vox.md requests microphone access to capture audio for voice transcription. Microphone audio is:
- Processed locally by Apple Speech or an optional downloaded Whisper/Parakeet model
- Written temporarily only when local transcription requires a file
- Never transmitted to any server, API, or third-party service
- Removed after transcription unless you explicitly configure a Capture Preset to retain audio or insert a voice recording into a capture draft
Location Usage
Vox.md requests location access only after you tap the location command in the Capture editor. It performs a one-time lookup and can reverse-geocode a short place label, then inserts the coordinates into a Google Maps link in your local Markdown draft. Vox.md does not monitor location in the background, retain separate location history, include coordinates in analytics or logs, or send location to a Vox.md server. The coordinates become part of the note you chose to create, and Apple and your selected file-sync provider may process data under their own terms.
Speech Models
Vox.md does not bundle speech model weights. Apple's supported language assets are managed by iOS. Optional Whisper, Parakeet, and voice-pause model downloads begin only after you choose them and are stored locally on your device. No account or personal information is required to prepare or download a model.
Third-Party Services
Vox.md does not integrate with third-party analytics SDKs, advertising networks, crash-reporting SDKs, or cross-app tracking services. User-initiated Whisper and Parakeet model downloads connect to model-distribution infrastructure hosted by Hugging Face, either directly or through FluidAudio. Model requests never include capture drafts, typed text, audio, transcripts, attachments, file paths, or location, but the provider may receive ordinary HTTPS connection data and the requested model identifier under its own terms.
The Capture editor requests batches of inspirational quotes from ZenQuotes API and rotates through them from an on-device cache. These requests never include capture drafts, typed text, audio, attachments, file paths, location, install identifiers, or analytics. Like any HTTPS service, ZenQuotes may receive technical connection data such as an IP address and user agent under its own terms. If first-party onboarding events are explicitly enabled in a development build, they are sent directly to a Vox.md Cloudflare Worker with the strict allowlist described above.
Data Storage & Deletion
All app data — including transcription history, capture drafts, staged attachments, downloaded models, templates, and settings — is stored locally on your device or in a file destination you explicitly choose. Vox.md also keeps a content-free high-water record of successful free Capture deliveries in the system Keychain so a normal uninstall and reinstall on the same device does not reset the free allowance. It contains only the count and random identifiers for up to ten successful requests, which prevent retries from being charged twice. It contains no captured text, filenames, destinations, or attachment metadata and is never sent to Vox.md.
The local Recent Captures list contains delivery metadata only: outcome, source, Capture Preset identifier and display name, destination identifier and display name, relative note path, attachment count, timestamps, and a coarse failure category. It never duplicates note text, links, coordinates, bookmarks, absolute paths, or attachment filenames. Pending and failed captures retain only the content needed for local recovery. After successful delivery, the recoverable request is immediately replaced by an identifier-and-timestamp-only tombstone; upgrades also sanitize legacy completed requests.
You can delete locally stored user content and settings by:
- Deleting individual transcriptions or clearing Recent Capture metadata from the history views within the app
- Removing downloaded models from Settings
- Uninstalling Vox.md, which removes its app-container data. The content-free successful-Capture high-water record described above remains in the system Keychain to preserve the free allowance after reinstall.
Children's Privacy
Vox.md does not knowingly collect personal information from anyone, including children under the age of 13. The privacy-safe onboarding analytics described above are not intended to identify or contact a child and never include audio, transcripts, keystrokes, or user-entered content.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date.
Contact
If you have questions or concerns about this Privacy Policy, please contact us at:
Email: [email protected]