Trust
Privacy, in plain language
Meosu handles the most personal input there is — your voice, speaking your unfinished thoughts. These are the defaults it ships with, stated plainly. The formal policy document lives here too once counsel signs it; this page is the promise it will formalize.
While you dictate
Dictation runs on your Mac by default. Its audio leaves your Mac only if you turn on one of two settings. Cloud dictation (Settings → Privacy) lets Meosu send a request's audio to its server when on-device recognition can't handle that request. Meosu Cloud speech (Settings → Dictation → Meosu Cloud → Speech → Use) sends the audio of every dictation to the server. Both are off until you choose them. The microphone is open only while you're dictating, capturing a meeting you started, or running a mic test you asked for, and while the wake phrase is on, when it listens for the phrase on your Mac and keeps nothing it hears.
What leaves your Mac
Each of these happens only when you use the feature that needs it.
- Dictation audio, with either cloud setting on. With Cloud dictation, the audio of a request that on-device recognition can't handle; with Meosu Cloud speech, the audio of every dictation. It goes over an encrypted connection to Meosu's server, which has a speech-recognition provider transcribe it. Meosu's server keeps no copy after the request.
- Text you format in the cloud. The default formatter, Apple Intelligence, runs on your Mac. Only when you choose Meosu Cloud as your formatter, or ask for a spoken edit to selected text, does Meosu send its server the dictated text, the trimmed context of the field you're typing into, the name and kind of app you're in, and your saved corrections. A language-model provider formats it and the result comes straight back. Meosu's server keeps no copy of the text. To avoid running a retried request twice, it holds a short fingerprint of the request, which expires within 10 minutes.
- Meeting audio, while notes are on. During the meeting the audio is recorded to an encrypted file on your Mac. When the meeting ends, it is uploaded over an encrypted connection to Meosu's server with the meeting's calendar title and start time, the app it was captured from, when each speaker talked, and any names you give speakers. The server has a speech-recognition provider transcribe it and a language-model provider write the notes, and deletes the audio in the same step that saves the finished notes. If processing doesn't finish, deleting the audio can be delayed; that's a known gap we're fixing. For a meeting you don't keep, the server deletes its transcript and notes as soon as your Mac has them; for any meeting, within about a day of the upload. A meeting you keep is kept on your Mac.
- Bot prompts, to your own model provider. A Bot
sends its prompts, including what it reads for the task, from your
Mac straight to the model provider you connected, over HTTPS — or
plain HTTP only to a model server on your Mac or a
.localaddress on your network. Meosu's servers don't see these prompts. Your key stays in the macOS Keychain, and how long the provider keeps a prompt is set by that provider's terms. - Actions in apps you connect. When a Bot or Act uses an app you connected, the action, what it sends to the app, and the app's reply pass through Meosu's server on their way to and from that app.
- Site icons in the dictation panel. To show the icon of the website you're dictating into, your Mac may look it up once and remember it. It asks the website you're on, and wherever that site says its icon lives — never a third-party icon service.
Off by default
- Cloud dictation is off unless you turn it on.
- Meosu Cloud speech and the Meosu Cloud formatter are off until you choose them.
- Dictation history is off unless you turn it on.
- Audio retention (for retry and playback) is off unless you turn it on, capped at 14 days, and purged when you turn it off.
- Only the trimmed context of the field you're typing into is used to format your text — never your screen, never a full document, and web addresses are reduced to a coarse category on your Mac before anything is sent.
Analytics that cannot carry your words
Product analytics are optional and asked about during setup — nothing is sent before you choose. The schema is closed: it has no field capable of carrying transcripts, audio, or text, and unknown fields are rejected. Raw events expire after 30 days, and Settings has working delete buttons for this Mac and for your account.
Progress stays local
Streaks, time saved, and usage metrics are computed and stored on your Mac, independent of analytics sharing. Where-voice-helped breakdowns use broad app categories — email, chat, IDE — never app names or addresses.
Your account
You sign in with Apple, with Google, or with a link sent to your email. Meosu asks each provider for your email address and nothing else — never your name.
- Apple. Meosu receives Apple's ID for you and your email address when Apple confirms it. If you choose Hide My Email, that's the relay address, and Meosu notes that it is one.
- Google. Meosu receives Google's ID for you and your email address when Google has verified it.
- Email link. You type your address, and Meosu's email provider sends you a sign-in link that works for 10 minutes. The email also shows a matching code and your Mac's name, so you can tell the request is yours. Your address is how that sign-in knows you. A sign-in you start in the browser or by email but don't finish keeps your Mac's name and, for an email sign-in, the address you typed, with no deletion deadline yet; that's a known gap we're fixing.
For sign-in, Meosu keeps your email address and, for each way you sign in, that provider's ID for you and the address it gave. For each Mac you sign in on, it keeps the computer's name as set in macOS, the kind of device, the app version, when it last connected, an ID for that installation and the Mac's public signing key. Session keys live in your Keychain. A paid plan also has billing details, listed on the billing page. Deleting your account from the app clears your email address, removes your sign-in methods and your account's sign-in records, deletes the card, next-charge and invoice details (the subscription record is kept; see the billing page), and signs out every Mac. The record of each signed-out Mac is kept, including its name, kind of device, app version and when it last connected. Local data removal is documented, completely, on the uninstall page.
Cloud processors
When you use a cloud feature — Cloud dictation, Meosu Cloud speech or formatting, spoken edits, or meeting notes — Meosu's server sends that request to a speech-recognition provider or a language-model provider to process it. Sign-in emails, and billing emails when they're turned on (receipts, a trial ending, a failed payment), go out through an email delivery service over an encrypted connection. The formal list of these processors is pending and will be published here once counsel approves it.
- TypeSafe AI, Inc. — candidate for typed semantic judgments (structure and routing decisions over trimmed text, never audio). Not admitted: zero-retention terms for the Meosu gateway account, region, and data-transfer basis are still required before any user text is sent. Default vendor retention is not treated as zero retention.
Region, transfer basis, and signed retention evidence for TypeSafe are recorded as placeholders until counsel fills them. Settings on this Mac state that the typed-judgment path is unavailable while admission is incomplete.