Effective August 3, 2026
Privacy policy
Boca Libre turns speech into text without creating an account or building a history of what you say.
What Boca Libre never receives
Boca Libre does not have user accounts, a transcript database, advertising, tracking, or a third-party analytics or crash-reporting SDK. The developer never receives your microphone audio, transcripts, API key, custom vocabulary, learned corrections, cursor context, filenames, the apps where you dictate, exact hardware identifiers or detailed configuration, locale, or contact information.
Apple On-Device transcription
When Apple On-Device is selected, microphone audio is processed by Apple's on-device Speech framework. Boca Libre requires an on-device recognizer and does not intentionally fall back to network recognition. Audio is held in memory only for the active dictation and is discarded when dictation finishes or is cancelled. The transcript is discarded after insertion.
OpenAI transcription
OpenAI transcription is optional and requires an API key supplied by you. When enabled, Boca Libre sends live microphone audio, the selected locale, and optional vocabulary context directly from your Mac to OpenAI over TLS. Boca Libre's usage service is never in this path and is not a transcription proxy.
Boca Libre does not retain this audio or transcript. OpenAI states that API data is not used to train models unless the API customer opts in. OpenAI also states that Realtime API customer content may be retained in abuse-monitoring logs for up to 30 days by default unless the API organization has an approved retention control. See OpenAI's current API data controls.
API keys and preferences
Your OpenAI API key is stored in the macOS Keychain with this-device-only protection. Model, shortcut, locale, and vocabulary preferences are stored locally. Boca Libre does not synchronize them to a developer-operated service.
Optional correction learning
If you turn on correction learning, Boca Libre can store up to 100 short heard → preferred replacement pairs in your macOS Keychain. It watches only the text field where it just inserted a dictation, for up to 30 seconds. When a correction is detected, Boca Libre shows the proposed pair for six seconds with a Don't add action; otherwise it is added automatically after the countdown. It does not save the full field, surrounding text, or the transcript. You can review, delete, or clear every learned pair in Boca Libre Settings. These pairs stay on your Mac when Apple On-Device is selected. If you select OpenAI transcription, applicable preferred terms are sent to OpenAI as transcription hints with your next dictation.
Cursor-aware capitalization
To match capitalization to the insertion point, Boca Libre may read up to 256 characters immediately before the original cursor. This short prefix is used in memory during the active dictation and is discarded afterward. It is never saved or sent to Boca Libre's developer. In OpenAI mode, this cursor prefix is not sent to OpenAI.
Software updates
If you enable automatic update checks or choose Check for Updates, Boca Libre fetches its signed update feed from GitHub over HTTPS. Boca Libre disables Sparkle system profiling and does not include audio, transcripts, vocabulary, API keys, usage insights, or detailed hardware information in an update check. As with any internet request, GitHub processes standard network information such as the source IP address to deliver the feed and any update download. You can turn automatic checks and automatic downloads on or off independently in Boca Libre Settings.
Optional usage insights on your Mac
Usage insights are off until you choose to enable them. When enabled, Boca Libre stores daily aggregate dictation counts, durations, success and failure counts, transcription engines, and model identifiers on your Mac for up to 400 days. These aggregates do not contain audio or transcribed text. You can pause collection or clear the local history at any time in Settings.
Optional sharing to improve Boca Libre
Sharing is a separate opt-in. If enabled, Boca Libre sends at most one pseudonymous summary per day covering up to three recent weeks. The summary contains a random installation identifier stored in Keychain; the Boca Libre app version, major macOS version, and a broad hardware class such as apple-m2 or intel; week, engine, and model identifiers; and rounded duration and success/failure counts.
The identifier is not an Apple identifier, advertising identifier, email address, or account ID. It allows Boca Libre to count participating installations and measure repeat use and reliability without revealing who you are. One person with multiple Macs appears as multiple installations, and resetting the identifier starts a new installation record. Its persistence means the data is pseudonymous rather than fully anonymous.
Hardware is deliberately generalized: for example, an Apple M2 Max is reported only as apple-m2. The exact Mac model, processor variant, memory size, serial number, and other hardware identifiers are never shared.
Summaries travel over HTTPS to a dedicated Boca Libre service on Google Cloud. The service hashes the identifier before storage, stores one aggregate record per installation and week, and expires records after 120 days. It never receives audio, transcripts, vocabulary, API keys, filenames, target apps, locale, or contact information. Boca Libre excludes Cloud Run request logs so it does not retain source IP addresses; Google Cloud temporarily processes network information to deliver the request.
Shared summaries are used only to measure adoption and reliability and improve Boca Libre. They are not sold, used for advertising, combined with third-party data, or used to identify you. Turning sharing off stops future uploads. After resetting the sharing identifier, new reporting starts the following day so earlier local aggregates are not uploaded again under the new identifier. Earlier shared summaries expire automatically.
macOS permissions
Boca Libre requests Microphone, Speech Recognition, and Accessibility access only to provide press-to-dictate, on-device recognition, global shortcut detection, and insertion at the focused field. You can revoke these permissions in System Settings.
Changes and contact
If Boca Libre's practices change, this policy will be updated before the affected feature is released. Public support contact information will be published on the support page.