Privacy
Last updated 28 August 2026 · v3
The short version. Your voice and your transcripts stay on your device. No server of ours ever receives your dictation. The free version needs no account and never contacts us at all. Buying Pro adds an email address, used only to carry your purchase between your own devices — and never to receive anything you said.
This page describes what Tirona does with data on macOS and Android. It is written to be checkable: everything below can be verified by watching the app’s network traffic.
What stays on your device
All of it, unless you deliberately turn on one of the optional features described further down. Each of those is off until you switch it on.
| Data | What happens to it |
|---|---|
| Audio you dictate | Held in memory while you speak, transcribed by a model running on your own hardware, then discarded. It is never written to disk and never uploaded. When you record a meeting the audio is held for the length of that meeting rather than a single phrase — it is what lets Tirona work out who spoke, which it does in one pass at the end — and it is released as soon as that finishes. Still in memory, still never written to disk, and gone if the app quits. Meetings longer than ninety minutes are transcribed without speaker names rather than having the audio kept for longer. |
| Transcripts | Stored on the device so you can see your recent dictations. You can clear them at any time from the app. On Android they are also excluded from Google’s automatic app backup, along with your API keys, so neither is copied to Drive behind your back — that exclusion is deliberate, because “stays on your device” has to survive the platform’s own defaults, and Android’s default is to back everything up. |
| The field you dictate into | Read only to place the text and confirm it arrived. Password fields are excluded and never dictated into. |
| Calendar (optional) | If you enable it, Tirona reads meeting titles, times and attendee names, to spell names correctly and to know which meeting a recording is of. It also reads the invitation’s description and location, for one purpose only: to tell whether the meeting is a video call, so it only offers to take notes on meetings that actually are one. The answer it keeps is “yes, a Zoom call” or “no” — never the link, and never anything else from the body. That matters because meeting bodies routinely carry dial-in PINs and passcodes, and the joining link is often the only credential a meeting has. Nothing from your calendar is written back, and nothing is uploaded. |
| Notes folder (optional) | If you choose a folder, Tirona reads it to learn how you spell names. The notes themselves are never uploaded. |
When Tirona uses the network
Six times, four of which are not about your data at all.
- Downloading the speech model, once, on first run. This fetches model files from Hugging Face. It sends no information about you beyond what any file download requires.
- Checking for updates (macOS only). Tirona asks
downloads.tirona.appwhether a newer version exists. It is not switched on by default — Tirona asks you the first time, and you can decline and check manually instead. - Sending audio to your own Mac (iPhone only, optional). If you pair the iOS app with a Mac, audio travels over your own local network to that Mac and nowhere else.
- Transcribing with a speech provider you chose (macOS only, optional, off by default). If — and only if — you switch this on and add your own API key, your audio is sent to that provider instead of being transcribed on your machine.
- Cleaning up text with a language model (optional, off by default). If — and only if — you add your own API key for a provider such as OpenAI, Anthropic or a local Ollama server, the transcript is sent to that provider so it can be tidied.
- Checking your Pro purchase (only if you bought Pro).
About once a month Tirona asks
api.tirona.appwhether your purchase is still valid. It sends your session token and nothing else, and receives back one word — the tier you are on. If you have not bought Pro, this never happens: there is no account, so there is nothing to ask about.
Be aware of the last two. Both send your own words to a company you picked, under their privacy policy and not this one — the cleanup one sends the transcript, and the speech one sends the recording itself. We never see either, and we never receive your key: it is stored in your system keychain. Both are off until you configure them, and Tirona records the date you first switched speech transcription on, so “since when has my audio been leaving this machine?” has an honest answer. If you would rather nothing ever left, leave both off — that is the state they ship in, and the on-device model is what runs instead.
What we do not collect
- No account is needed to use Tirona. Dictation, history, vocabulary, modes and batch transcription all work without one, and the app never contacts us on their behalf. An email address is asked for in exactly one situation — see below.
- No advertising, and no data shared or sold to anyone.
- No hardware or device identifiers, ever — including hashed ones.
If you buy Tirona Pro
Buying Pro creates an account, and this is the one place Tirona asks for an email address. The reason is narrow: a purchase made on one device should unlock the others, and there is no way to recognise you on a second device without something that identifies you on both.
The free version never touches this. If you have not bought Pro, no account exists, nothing is sent, and there is nothing to sign in to. The paragraphs below describe a service you will never contact.
What the account holds: your email address, and which purchases are attached to it. That is the whole record. It does not know what you dictate, how often, which device you are on, or which features you use — the server that answers "has this person bought Pro?" is never told anything else, and has nowhere to put it if it were.
Signing in is a link sent to your email. There is no password to choose, reuse or lose.
Your Pro features keep working when we are unreachable. Tirona checks your purchase about once a month and remembers the answer for thirty days. A flight, an outage, or this service being discontinued does not take away something you paid for. It never re-checks in a way that could interrupt you, and it never downgrades you because a request failed — only because a successful reply said so.
Usage statistics
There are none. Tirona does not count what you do, does not send usage reports, and has no setting to turn any on — because there is nothing to turn on. The app has no analytics code path at all.
If that ever changes it will be opt-in, off by default, counts-only rather than content, and described here before it ships — not after.
Feedback you choose to send
If you use Send feedback, we receive what you typed, the category you picked, your email address if you chose to give one, and the same version and system details listed above. Nothing is sent unless you press the button.
The website
tirona.app uses Cloudflare Web Analytics, which counts page views without cookies and without building a profile of you. It records aggregate figures — pages, countries, referrers, browsers — and does not identify individual visitors. That is why this site has no cookie banner: there are no cookies to consent to.
Accessibility permission
Tirona asks for Accessibility permission on macOS, and to run an accessibility service on Android. This is what allows it to place text into whatever field you are typing in, which is the entire function of the app.
It is used only to read which field currently has focus, to insert your transcribed text there, and to confirm the text arrived. It does not read, record or transmit the contents of your screen, and it does not run while you are not dictating. Password fields are detected and refused — Tirona will not type a transcript into one.
Children
Tirona is not directed at children and collects no personal information from anyone, including children.
Changes
If this policy changes in a way that affects what leaves your device, the change will be described in the release notes for the version that introduces it, not only here.
Contact
Questions about this policy: support@tirona.app.