Saywave · Legal
Privacy Policy
Current Mac releases process speech and text locally. The website, licensing, and model downloads involve the separate online data flows described below. Legacy cloud features are explained for users of earlier versions.
Last updated: 11 September 2026
1. Controller and contact
The controller under the GDPR is Bent Eisheuer, Freisinger Landstraße 47a, 85748 Garching, Germany. Email: legetdev@gmail.com. No separate data-protection officer has been designated; privacy requests can be sent directly to the controller.
2. Website delivery
The website is hosted by Vercel Inc. When you visit, Vercel and the controller process technical request data such as your IP address, timestamp, requested path, referrer, and browser or device information. This is necessary to deliver and secure the site. The legal basis is Article 6(1)(f) GDPR: the legitimate interests in reliable and secure publication of the website. Server logs are retained according to the hosting plan and then deleted or aggregated unless longer retention is needed to investigate abuse.
The site does not run audience analytics, advertising pixels, contact forms, or optional tracking cookies. It uses locally served fonts. Essential browser storage, if introduced by the hosting layer for security or delivery, is used only where technically necessary.
iPhone and iPad app
The free mobile release processes speech on your device and does not send recordings, transcripts or typed text to us. Notes, meetings, settings and history are stored locally; the keyboard and app share data through an Apple App Group. Full Access enables that communication, not a Saywave cloud transcription service. The local typing keyboard works without Full Access. Your dictionary can sync through your own iCloud account using Apple key-value storage; recordings and transcripts do not sync through Saywave. Apple provides App Store delivery and speech-model services under its own privacy terms.
The mobile launch has no licence activation request, account, advertising or embedded analytics. Microphone access is requested for recording. Delete recordings and history using the app controls; uninstalling removes the app's local data subject to your Apple backup settings. Dictionary copies may remain in iCloud and on your other devices. These local features serve the requested app functionality; we do not receive the content.
3. Download and local app data
The replacement installer and update feed are delivered through downloads.saywave.app using Cloudflare Workers and private R2 storage. Cloudflare processes IP addresses and request metadata to deliver files and limit abuse, under Article 6(1)(f) GDPR (reliable and secure software delivery). No audio or transcripts are involved in these requests. The app stores its settings, dictionary, dictation history, statistics, meeting transcripts, summaries, action items, and optional remembered-voice representations locally on your Mac. Licence details and user-supplied AI API keys are stored in a local Application Support file with access restricted to your macOS user account. Values are obfuscated, not encrypted by Keychain. These records can remain after uninstalling the app; remove them using the app's relevant controls or by removing its local Application Support data. Current releases preserve existing summaries, action items and credentials but do not generate new summaries or use cloud AI keys.
The app requests microphone access for dictation, Accessibility access to insert text, and Screen Recording access when you use system-audio meeting capture. Screen Recording is the macOS permission used for system audio; Saywave does not use it to make a video recording. Core speech transcription runs on the device after the selected model is available.
4. Free lifetime licence activation
On first use without a valid licence, Saywave sends a stable, app-specific SHA-256-derived device identifier to our existing Cloudflare Workers and KV licensing service. The service sees ordinary connection metadata, including your IP address. It stores the derived identifier and a signed licence code with an issue date. From Mac version 1.5, that signed code also contains the derived device identifier and is accepted only on the matching Mac. IP addresses are used for abuse controls, not to determine licence ownership. It does not receive your raw Mac platform identifier, name, email, audio, or transcripts. The device identifier is pseudonymous personal data: it recognises the same Mac to restore an existing grant.
This processing is necessary to issue and restore your requested lifetime licence under Article 6(1)(b) GDPR. The record is retained for the lifetime of that restoration service, without automatic expiry, because the licence does not expire. You may request deletion; keep a private copy of the licence code first. Deleting the server record does not invalidate a saved code, but removes automatic restoration from that record. Once activated, the signed licence works offline and is not sent for recurring validation. Local credentials are stored as described above. Failed activation can be retried at launch, from Settings, when starting dictation, and periodically while the app remains unlicensed.
Older versions before this free launch use trial records. Those records expire 24 months after their last trial validation. Current versions neither create nor refresh trial records.
5. Licence activation and purchases
Sales are currently closed. If sales open, Lemon Squeezy acts as Merchant of Record and processes checkout data under its own buyer privacy terms. Activating or validating a licence sends the licence key, Lemon Squeezy instance identifier, and your Mac's local name to Lemon Squeezy. The response may include the customer name and email, which the app stores in its local credential file. The legal basis is Article 6(1)(b) GDPR for licence performance and Article 6(1)(f) GDPR for fraud prevention. Avoid putting sensitive personal information in your Mac's device name.
6. Model downloads
On-device speech and speaker models that are not bundled with the installer download from Hugging Face when first selected or required. Hugging Face receives the IP address and normal download request metadata. The legal basis is Article 6(1)(b) GDPR because the requested model is needed to provide that feature. Once downloaded, the model is stored on your Mac until you remove the related local app data.
7. Legacy OpenAI or Anthropic features (before version 1.3)
Earlier Mac versions allow you to add your own OpenAI or Anthropic API key and choose cloud-backed rewrite, cleanup, translation, or meeting-summary functions. When invoked, Saywave sends the selected dictated text or meeting transcript, together with the instruction, directly from your Mac to the provider you selected. The API key is sent for authentication. Audio is not sent by this cloud-text feature. The legal basis for Saywave initiating the request is Article 6(1)(b) GDPR. The provider processes the request under your direct account and its current API terms and privacy documentation.
Do not send personal, confidential, special-category, or third-party data unless you have a lawful basis, appropriate authority, and a provider configuration suitable for that data. Current releases disable these features, including their on-device generative alternatives. Previously saved content and settings remain available for a future reviewed release.
8. Recipients and international transfers
Depending on the feature, recipients are Vercel (website hosting), Cloudflare (licensing and legacy trial infrastructure, installer and update delivery), Lemon Squeezy (future checkout and licensing), Hugging Face (model downloads), and either OpenAI or Anthropic only when using a cloud AI feature in a legacy Mac version before 1.3. These providers may process data outside Germany or the EEA. Where the GDPR requires a transfer safeguard, processing relies on the provider's applicable adequacy mechanism, including an EU–US Data Privacy Framework certification where valid, or standard contractual clauses with supplementary safeguards. Contact us for the mechanism applicable to a specific flow.
9. Retention
- Website request logs: according to the active hosting plan and security need.
- Free launch licence records: for the lifetime of the restoration service, or until requested deletion.
- Legacy trial records: 24 months after the device's last trial validation, unless erased earlier.
- Purchase records: retained by the Merchant of Record under its legal obligations.
- Licence validation data: while needed to provide and protect the licence.
- Local app data and credential files: until you delete them as described above.
- Legacy cloud requests: under the provider terms and settings of your own account.
Data may be retained longer where necessary to establish, exercise, or defend legal claims, or where a binding legal duty requires it.
10. Your rights
Subject to the legal conditions, you may request access, rectification, erasure, restriction, data portability, or object to processing based on legitimate interests. You may also lodge a complaint with a supervisory authority. Our competent authority is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach. No decision producing legal or similarly significant effects is made solely by automated means.
To exercise a right, email legetdev@gmail.com. We may ask for information necessary to verify that the request relates to you. Providing technical website data is necessary to receive the site; providing licence, model-download, or legacy cloud data is necessary only when you choose the corresponding feature.
11. Changes
We update this policy when data flows or legal requirements change. Material changes are presented before the affected processing where required. The date below identifies this version.