Privacy at RoughSay
Last updated: July 19, 2026
RoughSay has no product analytics or advertising trackers. It sends only the content needed to provide the feature you invoke, and its relay does not log or persist your audio, transcripts, selected text, reply context, prompts, or generated output.
What the app processes
- Cloud + polish: microphone audio is sent through RoughSay's relay to OpenAI for transcription, and the transcript plus relevant polishing inputs are sent to OpenAI for rewriting.
- On-device + polish: microphone audio is transcribed on your Mac. The transcript plus relevant polishing inputs are then sent through the relay to OpenAI for rewriting.
- Private on-device: microphone audio and the transcript stay on your Mac. RoughSay does not call OpenAI, construct a polishing prompt, read selected text or reply context, or send dictation content to the RoughSay relay. It applies local text replacements and delivers the raw transcript.
- In polished modes, selected text and reply context are sent only when you use the corresponding rewrite or reply-context feature.
- In polished modes, the frontmost application and a locally matched surface hint may guide formatting. In Private on-device, local app or site matching may guide only Auto delivery and stays on the Mac. Full browser URLs are discarded and are not stored or sent.
Apple Notes capture and the recent-file picker run locally. RoughSay does not upload attached files to its relay or OpenAI; it places them on the pasteboard for the target application.
What stays on your Mac
Your invite code is stored in macOS Keychain. Settings, presets, text replacements, dictionary entries, local usage counts, and any downloaded on-device transcription model files are stored on your Mac. RoughSay does not send those local usage statistics to an analytics service. You can remove the downloaded model in Settings. Private on-device keeps its in-memory history and local usage count on this Mac.
RoughSay relay data
Beta requests pass through a Cloudflare Worker that checks access and forwards the request to OpenAI. Request content is held only long enough to forward it and is not written to RoughSay logs or storage.
Initial invite verification contacts the RoughSay relay. Once a verified invite is saved in Keychain, Private on-device dictation does not revalidate it online and does not contact the relay. It can therefore continue offline. A remotely revoked invite cannot disable already configured private transcription until the saved code is removed from that Mac.
The relay retains an invite-code access record while beta access is active. It also stores per-invite and global daily usage counters for rate and budget limits; those counters expire after approximately 48 hours. Operational logs contain lifecycle or error metadata, not audio, transcripts, prompts, URLs, or message content.
Service providers
OpenAI processes text only in the two polished modes and processes microphone audio only in Cloud + polish. OpenAI is not called during Private on-device dictation. OpenAI states that API inputs and outputs are not used to train its models by default; retention depends on the API endpoint and account controls. See OpenAI's API data controls.
Cloudflare hosts this website and the relay and may process standard network metadata needed to deliver and protect those services.
If you select either on-device mode, RoughSay makes a one-time model download from Hugging Face. Hugging Face may process standard network metadata for that download. The model then runs locally through FluidAudio.
Website, beta requests, and feedback
RoughSay does not add product analytics or advertising cookies to the website. At present, the beta form opens a prefilled message in your email application; it does not submit your address automatically. Your email provider and ours process a message only if you send it.
Send Feedback in the app opens an editable email containing the RoughSay version, build number, and macOS version. RoughSay does not automatically include transcripts, audio, outputs, selected text, context, settings, logs, application names, or domains.
Your choices and contact
You control when recording starts and can choose Cloud + polish, On-device + polish, or Private on-device. You also control whether selected text or reply context is used in polished modes and whether a feedback or beta email is sent. For questions, access requests, or deletion requests concerning information held by RoughSay, email pawel@devmatejp.com.