01
Scope and who we are
Vaak is an open-source desktop voice-input project maintained through the ContextGridTechnologies GitHub organization. In this policy, “Vaak,” “we,” and “us” mean the maintainers of the official Vaak website and desktop releases.
This policy applies to the official Vaak website, official desktop builds, and related support interactions. It does not control independent forks, third-party builds, or the speech, rewrite, hosting, and download services described below.
02
Data we handle
Website and hosting data
The website is static. It currently has no account forms, advertising trackers, or first-party analytics scripts, and it does not set its own marketing cookies.
When the site is hosted on Cloudflare, Cloudflare may process technical request information such as your IP address, browser and device information, requested URL, timestamps, and security signals to deliver and protect the site. Cloudflare may set strictly necessary security cookies when required by its services.
Local desktop data
The desktop app processes microphone audio, transcripts, rewritten text, settings, provider configuration, and local dictation activity. Dictation records—including transcript text and local audio artifacts used for history and playback—may be stored in the app’s local data directory on your device.
A local record may also contain the full destination window title and sanitized application or control metadata used for insertion diagnostics. A window title can reveal the name of a document, conversation, or application. Focused-field contents are not retained as part of this destination metadata.
In local mode, those local records are not uploaded to Vaak. They remain on your device until you remove the associated application data. Provider API keys are stored through the operating system’s secure credential facility where available, such as Windows Credential Manager or macOS Keychain.
Speech and rewrite providers
When you dictate, Vaak sends audio only to the transcription provider you select. If you enable rewriting, transcript text is sent only to the rewrite provider you select. These providers process data under their own terms and privacy policies. You should review the policy of each provider before configuring it.
Optional product telemetry
Official desktop builds may include optional PostHog product analytics and separate error diagnostics. Both controls default to off. If you enable them, Vaak may send event names, app version and environment, selected provider identifiers, stable setting identifiers, and sanitized error details.
Telemetry is designed not to include audio, transcripts, API keys, authorization headers, focused-field contents, or local file paths. Autocapture, pageview capture, and session recording are disabled. PostHog may use a pseudonymous identifier stored locally to associate enabled events from the same installation.
03
How we use information
We use the limited information described above to:
- deliver and secure the public website;
- provide the desktop features you request;
- diagnose reliability problems when you opt into diagnostics;
- understand broad product usage when you opt into analytics; and
- respond to support, security, or privacy requests.
Where applicable law requires a legal basis, essential website processing is based on our legitimate interests in operating and securing the site, provider processing is initiated to perform the service you request, and optional telemetry is based on your consent. You can withdraw telemetry consent in Settings at any time.
05
Retention and security
Local dictation records remain under your control on your device and are not subject to a Vaak cloud-retention schedule. Hosting and download providers retain technical logs according to their own policies and configurations. Optional telemetry is retained according to the configured PostHog project settings and only for as long as reasonably needed for product and reliability analysis.
We use data minimization, OS-backed credential storage, redaction, opt-in telemetry controls, and separation between local records and cloud analytics. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
06
International processing
Cloudflare, GitHub, PostHog, and providers you select may process information in countries other than your own. Their privacy policies describe their locations and transfer safeguards. By choosing a third-party provider, you direct Vaak to send the relevant audio or text to that provider.
07
Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent; or complain to a data-protection authority. We will honor applicable requests after reasonably verifying them.
Vaak cannot access local-only records stored on your device. You control those records by controlling your local application data. For data held by a speech or rewrite provider, submit your request directly to that provider.
08
Children
Vaak is not directed to children, and we do not knowingly collect personal information from children through the website. If you believe a child has provided information to us, contact us so we can review the request.
09
Managed cloud features
Managed transcription, accounts, billing, and sync are not part of the current local-first release. We will update this policy before launching a managed service that materially changes how Vaak collects, stores, or processes personal information.
10
Policy changes
We may update this policy as the product changes. We will revise the effective date above and provide additional notice when a material change requires it.
11
Contact
For privacy questions or requests, start through the Vaak issue chooser and ask the maintainers to establish a private contact channel.