Effective August 11, 2026

Privacy policy

Boca Libre turns speech into text without creating an account or building a history of what you say.

What Boca Libre never receives

Boca Libre does not have user accounts, a transcript database, advertising, tracking, or a third-party analytics or crash-reporting SDK. The developer never receives your microphone audio, transcripts, API key, custom vocabulary, learned corrections, cursor context, filenames, the apps where you dictate, exact hardware identifiers or detailed configuration, locale, or contact information.

Apple On-Device transcription

When Apple On-Device is selected, microphone audio is processed by Apple's on-device Speech framework. Boca Libre requires an on-device recognizer and does not intentionally fall back to network recognition. Audio is held in memory only for the active dictation and is discarded when dictation finishes or is cancelled. The transcript is discarded after insertion.

OpenAI transcription

OpenAI transcription is optional and requires an API key supplied by you. When enabled, Boca Libre sends live microphone audio, the selected locale, and optional vocabulary context directly from your Mac to OpenAI over TLS. Boca Libre's usage service is never in this path and is not a transcription proxy.

Retake cleanup is on by default and can be turned off in Settings. When it detects a likely spoken correction, Boca Libre sends the current dictation text to OpenAI's Responses API using your API key so the newer phrasing can replace the false start. The request uses store: false, consumes additional OpenAI API usage, and does not include text outside the current dictation.

Boca Libre does not retain this audio or transcript. OpenAI states that API data is not used to train models unless the API customer opts in. OpenAI also states that Realtime and Responses API customer content may be retained in abuse-monitoring logs for up to 30 days by default.

Eligible API customers can separately apply to OpenAI for Zero Data Retention and configure it for their API organization or project. Approval, eligibility, configuration, and all other OpenAI data terms are between you and OpenAI; Boca Libre cannot enable or guarantee them. See OpenAI's current API data controls and Zero Data Retention terms.

API keys and preferences

Your OpenAI API key is stored in the macOS Keychain with this-device-only protection. Model, shortcut, locale, and vocabulary preferences are stored locally. Boca Libre does not synchronize them to a developer-operated service.

Optional correction learning

If you turn on correction learning, Boca Libre can store up to 100 short heard → preferred replacement pairs in your macOS Keychain. It watches only the text field where it just inserted a dictation, for up to 30 seconds. When a correction is detected, Boca Libre shows the proposed pair for six seconds with a Don't add action; otherwise it is added automatically after the countdown. It does not save the full field, surrounding text, or the transcript. You can review, delete, or clear every learned pair in Boca Libre Settings. These pairs stay on your Mac when Apple On-Device is selected. If you select OpenAI transcription, applicable preferred terms are sent to OpenAI as transcription hints with your next dictation.

Cursor-aware formatting

To match spacing, capitalization, and punctuation to the insertion point, Boca Libre may read a bounded amount of text immediately before and after the original cursor. This context is used in memory during the active dictation and is discarded afterward. It is never saved or sent to Boca Libre's developer or OpenAI.

Some virtual browser editors do not expose usable cursor context through macOS Accessibility. Only in that case, Boca Libre can briefly select and copy the adjacent words, then immediately restore the original caret and every clipboard representation. The copied words are never retained, logged, or transmitted, and Boca Libre does not use the clipboard to deliver the transcript.

Software updates

Boca Libre fetches its signed update feed from GitHub over HTTPS when the app starts and then once a day while it is running. If automatic update alerts are off, this check does not open an update window or download or install anything; a blue update control appears in the dictation capsule only when a newer version is found. The update window opens when you click that control or choose Check Now. Automatic update alerts and automatic downloads remain separate settings.

Boca Libre disables Sparkle system profiling and does not include audio, transcripts, vocabulary, API keys, usage insights, or detailed hardware information in an update check. As with any internet request, GitHub processes standard network information such as the source IP address to deliver the feed and any update download.

Optional usage insights on your Mac

Usage insights are off until you choose to enable them. When enabled, Boca Libre stores daily aggregate dictation counts, durations, success and failure counts, transcription engines, and model identifiers on your Mac for up to 400 days. These aggregates do not contain audio or transcribed text. You can pause collection or clear the local history at any time in Settings.

Optional sharing to improve Boca Libre

Sharing is a separate opt-in. If enabled, Boca Libre sends at most one pseudonymous summary per day covering up to three recent weeks. The summary contains a random installation identifier stored in Keychain; the Boca Libre app version, major macOS version, and a broad hardware class such as apple-m2 or intel; week, engine, and model identifiers; and rounded duration and success/failure counts.

The identifier is not an Apple identifier, advertising identifier, email address, or account ID. It allows Boca Libre to count participating installations and measure repeat use and reliability without revealing who you are. One person with multiple Macs appears as multiple installations, and resetting the identifier starts a new installation record. Its persistence means the data is pseudonymous rather than fully anonymous.

Hardware is deliberately generalized: for example, an Apple M2 Max is reported only as apple-m2. The exact Mac model, processor variant, memory size, serial number, and other hardware identifiers are never shared.

Summaries travel over HTTPS to a dedicated Boca Libre service on Google Cloud. The service hashes the identifier before storage, stores one aggregate record per installation and week, and expires records after 120 days. It never receives audio, transcripts, vocabulary, API keys, filenames, target apps, locale, or contact information. Boca Libre excludes Cloud Run request logs so it does not retain source IP addresses; Google Cloud temporarily processes network information to deliver the request.

Shared summaries are used only to measure adoption and reliability and improve Boca Libre. They are not sold, used for advertising, combined with third-party data, or used to identify you. Turning sharing off stops future uploads. After resetting the sharing identifier, new reporting starts the following day so earlier local aggregates are not uploaded again under the new identifier. Earlier shared summaries expire automatically.

macOS permissions

Boca Libre requests Microphone, Speech Recognition, and Accessibility access only to provide press-to-dictate, on-device recognition, global shortcut detection, and insertion at the focused field. You can revoke these permissions in System Settings.

Changes and contact

If Boca Libre's practices change, this policy will be updated before the affected feature is released. Public support contact information will be published on the support page.