Privacy

Last updated 21 August 2026 · SayLess 2.32.7

SayLess turns what you say into text. That is unusually personal data, so this page describes exactly what the app keeps, where it keeps it, and the only circumstances in which anything leaves your Mac.

No account required

SayLess works fully without an account. It does not phone home, collect analytics, or transmit usage data, and your dictations, transcripts, and notes are stored on your Mac, not on our servers.

An account is optional. Signing in (currently with Google) creates a SayLess account whose identity is your email address, held by our authentication service (Supabase) and shown to you in Settings. Nothing rides along with sign-in: no transcript, note, memory, style information, vocabulary, app identity, or audio is part of any sign-in request. The session token is stored in your Mac's Keychain; signing out deletes it. To have the account itself deleted, email privacy@sayless.club.

Hosted meeting notes

A signed-in account can generate a limited number of meeting notes each week using SayLess's own model access, for people who have no API key of their own. When you invoke it, the meeting transcript passes through our relay to the model provider and the finished note comes back. The relay is stateless: your words are never stored on it or by us — the only thing written on our side is a per-account weekly count of notes you kept. If you configure your own provider key instead, the relay is never used for those generations.

What is stored, and where

Everything the app remembers lives in your own user folders on this Mac:

Audio is temporary, always

A recording exists only as long as it takes to turn into text. The temporary file is deleted when transcription succeeds, when it fails, and when you cancel. SayLess has no setting that retains audio, and no feature that uploads a recording for storage.

What goes to AI providers

If you configure a provider — OpenAI, Google Gemini, DeepSeek, Kimi, or a compatible endpoint of your choosing — SayLess sends that provider the audio or text it needs to do the job you asked for, using your API key and your account with them. Their terms govern that data.

You can also run SayLess with no provider at all. It falls back to Apple's on-device speech recognition, and nothing goes anywhere.

Some things are deliberately excluded from every provider request:

Meetings and other people

SayLess captures audio through macOS rather than by joining your call, so no participant appears in your meeting. A recording indicator is visible whenever it is listening, and it asks you to confirm consent before capture begins.

Recording other people may require their knowledge or agreement where you live. SayLess deliberately provides no hidden or silent capture mode, but complying with the law where you are is your responsibility.

Calendar access

If you allow it, SayLess reads upcoming event titles and times from macOS Calendar so it can offer to take notes before a meeting starts. It reads only; it never creates or changes events, and calendar details are never sent to any AI provider.

Connecting a Google account

Separately from sign-in, you can connect a Google account in Settings → Connections. Each permission maps to one visible feature, and SayLess requests nothing it does not use:

Google user data is processed on your Mac to provide these features at your request. It is not stored on SayLess servers, not used for advertising, not sold, and not read by any human. Your OAuth tokens live in the macOS Keychain, and you can disconnect in Settings or revoke access at myaccount.google.com/permissions at any time. SayLess's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your control

This website

sayless.club sets no cookies and runs no analytics. The theme toggle keeps your light-or-dark choice in your browser's local storage, which never leaves your browser. If you enter your email on the download form, we store that address with a timestamp and coarse country — no IP address, no user agent — to send release notes and nothing else, never sold or shared. Every email carries a one-click unsubscribe, and privacy@sayless.club removes it too.

Who is responsible, and your rights

The controller for the little that is processed on our side — the optional account identity, the hosted-notes weekly count, and the download form's address list — is the operator of sayless.club, reachable at privacy@sayless.club (postal address in the site notice). The legal bases are the ones you would guess: performing what you asked for (Art. 6(1)(b) GDPR — signing you in, generating a note, sending the download) and consent for the release-notes list (Art. 6(1)(a)), which you can withdraw with one click in any email.

Processing runs on Supabase (the account and both counts), Vercel (this site and its endpoints), Resend (email), and — only for the hosted notes route — the model provider, under zero-data-retention terms. Some of these process data outside the EU under standard contractual clauses.

You can ask what we hold about you, have it corrected or deleted, restrict or object to processing, and take your data with you (Art. 15–21 GDPR) — one email to privacy@sayless.club does any of these. Account identities are kept while the account exists; the weekly counts are meaningless after their week; the address list is kept until you leave it. You can also complain to a data-protection authority — in Germany, the supervisory authority of your state.

Children

SayLess is not directed at children under 16 and is not intended for their use.

Changes

When the boundary changes, this page changes first — the optional account above was added to this page in the same release that introduced it. If a future version stores more outside your Mac (for example, syncing settings between devices), that will be an explicit, opt-in choice presented in the app, and described here before it ships.

Contact

Questions about this policy: privacy@sayless.club