Privacy
Last updated 26 August 2026
The short version. Your voice and your transcripts stay on your device. Tirona has no account system, no analytics, no telemetry and no server that receives your dictation. There is nothing for us to hand over, because we never receive anything.
This page describes what Tirona does with data on macOS and Android. It is written to be checkable: everything below can be verified by watching the app’s network traffic.
What stays on your device
All of it, unless you deliberately turn on one of the two features in the next section.
| Data | What happens to it |
|---|---|
| Audio you dictate | Held in memory while you speak, transcribed by a model running on your own hardware, then discarded. It is never written to disk and never uploaded. |
| Transcripts | Stored on the device so you can see your recent dictations. You can clear them at any time from the app. |
| The field you dictate into | Read only to place the text and confirm it arrived. Password fields are excluded and never dictated into. |
| Calendar (optional) | If you enable it, Tirona reads meeting titles, times and attendee names, to spell names correctly. Descriptions and locations are never read. Nothing is written to your calendar and nothing is uploaded. |
| Notes folder (optional) | If you choose a folder, Tirona reads it to learn how you spell names. The notes themselves are never uploaded. |
When Tirona uses the network
Four times, three of which are not about your data at all.
- Downloading the speech model, once, on first run. This fetches model files from Hugging Face. It sends no information about you beyond what any file download requires.
- Checking for updates (macOS only). Tirona asks
downloads.tirona.appwhether a newer version exists. It is not switched on by default — Tirona asks you the first time, and you can decline and check manually instead. - Sending audio to your own Mac (iPhone only, optional). If you pair the iOS app with a Mac, audio travels over your own local network to that Mac and nowhere else.
- Cleaning up text with a language model (optional, off by default). If — and only if — you add your own API key for a provider such as OpenAI, Anthropic or a local Ollama server, the transcript is sent to that provider so it can be tidied.
Be aware of the last one. When you supply your own API key and turn cleanup on, your transcript leaves your device and goes to the provider you chose, under their privacy policy and not this one. We never see it, and we never receive your key — it is stored in your system keychain. If you would rather nothing ever left, leave this feature off; it is off until you configure it.
What we do not collect
- No account, sign-up, or email address is required or requested.
- No analytics, crash reporting, usage statistics or device identifiers.
- No advertising, and no data shared or sold to anyone.
- No licence check that phones home. Licence keys are verified on your device using cryptography, not a server.
Accessibility permission
Tirona asks for Accessibility permission on macOS, and to run an accessibility service on Android. This is what allows it to place text into whatever field you are typing in, which is the entire function of the app.
It is used only to read which field currently has focus, to insert your transcribed text there, and to confirm the text arrived. It does not read, record or transmit the contents of your screen, and it does not run while you are not dictating. Password fields are detected and refused — Tirona will not type a transcript into one.
Children
Tirona is not directed at children and collects no personal information from anyone, including children.
Changes
If this policy changes in a way that affects what leaves your device, the change will be described in the release notes for the version that introduces it, not only here.
Contact
Questions about this policy: [email protected].