Privacy Policy
1. Summary
GlyphDeck transcribes speech on your Mac. In its default configuration:
- We collect nothing. No account, no telemetry, no analytics, no crash reporting.
- Your audio and text never reach GJIRA Enterprises Ltd. We operate no servers that receive your dictation content.
- Everything stays on your device.
Two features are off by default and send data off your device only if you switch them on and supply your own API key:
| Feature | What leaves your Mac | Who receives it |
|---|---|---|
| AI enhancement | Transcribed text | OpenAI or Anthropic (your choice) |
| Cloud transcription | Recorded audio | OpenAI or Google Gemini (your choice) |
2. Data we process
2.1 Data stored on your device only
| Data | Purpose | Retention |
|---|---|---|
| Audio buffer while dictating | Producing a transcript | Discarded once transcribed; never written to disk |
| Transcription history | Letting you review and reuse dictations | Until you delete it, or auto-delete after your chosen period |
| Custom dictionary and snippets | Improving accuracy | Until you delete them |
| Preferences | Running the app as configured | Until you delete the app |
| API keys | Authenticating to the provider you chose | macOS Keychain, until you remove them |
| Consent log | Recording that you accepted an off-device disclosure | Until you delete the app |
| Estimated-cost log | Showing what the optional features cost | Until you reset it |
None of the above is transmitted to GJIRA Enterprises Ltd.
2.2 Data sent to third parties (only if you opt in)
- AI enhancement: the transcript text and your chosen rewriting instruction.
- Cloud transcription: an audio recording of the dictation.
- Model downloads: speech models are fetched from Hugging Face (huggingface.co). This reveals your IP address and which model you requested to that host. It contains none of your dictation content. Downloads are governed by Hugging Face's own Terms of Service and Privacy Policy.
- Hugging Face sign-in (optional): if you add a Hugging Face access token to download models reliably, that token is your own credential. It is stored only in your Mac's Keychain and sent only to huggingface.co as an authorization header on model downloads. GJIRA Enterprises Ltd never receives it. Your use of a Hugging Face account is subject to Hugging Face's terms, between you and them.
3. Roles: who is responsible for what
This matters legally, so it is stated plainly.
Because you supply your own API key and choose when to use it, you are the data controller for any processing performed by OpenAI, Anthropic or Google at your instruction. Those providers act as your processor under your agreement with them.
GJIRA Enterprises Ltd is not a party to that transfer. We do not receive, store, transmit or have access to your dictation content, and we have no contract with those providers on your behalf. We supply software that, at your direction, sends data to a provider you selected using credentials you supplied.
The provider — not GJIRA — determines:
- how long your data is retained;
- whether staff may review it;
- whether it is used to train or improve their models;
- which countries it is processed in.
Review the privacy policy and terms of any provider before enabling these features.
4. Legal bases (UK/EU GDPR)
| Processing | Basis |
|---|---|
| On-device transcription | No GDPR processing by us — data never reaches us |
| Sending data to your chosen provider | Consent, Art. 6(1)(a), collected via the in-app dialog before the first transfer |
| Model downloads | Necessary to perform the contract, Art. 6(1)(b) |
Consent is freely given (both features are off by default and the app is fully functional without them), specific (separate consent for text and for audio, and re-prompted if you change provider), informed (the dialog names the provider, the payload and the consequences), and unambiguous (an explicit affirmative click; the default button declines).
Withdrawing consent is as easy as giving it (Art. 7(3)): a single toggle in Settings ▸ AI, or one click in the menu bar. Withdrawal takes effect immediately and does not affect the lawfulness of processing before it.
4.1 Special category data (Art. 9)
A voice recording is personal data. It becomes biometric data under Art. 4(14) only where it is processed *for the purpose of uniquely identifying* a person. GlyphDeck does not do this, and does not perform speaker identification. If your chosen provider does so, that processing is between you and them.
4.2 International transfers
Providers may process your data outside the UK/EEA. As controller, ensuring an appropriate Art. 46 safeguard (typically the provider's Standard Contractual Clauses) is in place is your responsibility. GJIRA Enterprises Ltd makes no such transfer and offers no such safeguard.
5. Your rights
Because we hold no personal data about you, there is generally nothing for us to access, correct, export or erase. Data on your Mac is under your direct control — delete it in-app or by removing the application.
For data you sent to a provider, exercise your rights directly with that provider; only they hold it. Where you are the controller, you are also the party who must respond to any request from a third party (for example, someone recorded in the background).
Subject to the above, you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national authority.
California (CCPA/CPRA): we do not collect personal information, and we do not sell or share it. We do not use it for cross-context behavioural advertising.
Canada (PIPEDA): we collect no personal information; consent for third-party transfers is obtained in-app as described above.
6. Recording other people
Cloud transcription uploads whatever your microphone captures — which may include people near you.
Recording others may require their consent depending on where you are. Several US states require all-party consent; similar rules exist in parts of Canada and the EU. You are responsible for complying with the recording and privacy laws that apply to you.
7. Health, financial and other regulated data
GlyphDeck is not suitable for protected health information (PHI). GJIRA Enterprises Ltd is not a HIPAA Business Associate, holds no Business Associate Agreement with you or with any provider, and using the off-device features for PHI would likely breach HIPAA.
The same applies to any data under PCI DSS, financial-services confidentiality rules, legal professional privilege, or an NDA. Do not send it.
8. Children
GlyphDeck is not directed at children and is not intended for use by anyone under 16 (or the age of digital consent in your jurisdiction). We do not knowingly process children's data — we process no user data at all.
9. Security
API keys are stored in the macOS Keychain. Data in transit to a provider uses TLS as implemented by that provider's API. On-device data is protected by macOS file permissions and, if you enable it, FileVault.
No method of transmission or storage is completely secure. See the limitation of liability in the Terms.
10. Changes
Material changes to how off-device features work will be reflected here and, if they change what you consented to, re-prompted in the app.
11. Contact
support@gjiraenterprises.com — GJIRA Enterprises Ltd, 208-8026 207 ST, Langley, BC V2Y 0N5, Canada