Privacy
Plain words about your data.
Rambleproof keeps processing on your Mac by default and makes every cloud path an explicit choice. This page lists what the app and website do with data, in the order you will meet it, including the defaults and where to change them.
The app, in local mode (the default)
When you hold the hotkey, audio is captured from your microphone and kept in memory and, unless Do not keep is selected, in a short-lived journal file while the dictation is processed. In Local mode, transcription and cleanup run on your Mac. No audio or transcript is sent to a provider.
What the app keeps on your Mac, and for how long
Text history. The raw transcript and the final text of each dictation are stored in Application Support. The default is Forever. You can choose 30 days, 7 days, or Do not keep, which holds text in memory only until the app quits and writes no transcript file.
Recordings folder. By default, every dictation is also saved to Documents/Rambleproof/Recordings, failed ones included: the audio as a WAV file, the raw transcript, the final text, and a small metadata file with the engine, microphone, timings, outcome and the name of the app you dictated into. History uses these files for playback and retry. The folder carries a marker that asks Spotlight not to index it, so dictated text stays out of search on setups that honor the marker. Turn this off in Settings under History and Privacy, or choose Do not keep, and nothing more is written there.
If iCloud Drive is set to sync your Desktop and Documents folders, macOS will sync that Recordings folder to iCloud like any other file in Documents. Rambleproof itself never uploads it. If you do not want recordings in iCloud, turn the Recordings folder off or keep Documents out of iCloud Drive.
Journal audio. The short-lived journal audio of a completed, copied or cancelled dictation is deleted as soon as processing finishes. Audio from a failed dictation is kept for 24 hours so you can retry it; this is on by default and can be turned off. A recording interrupted by a quit or a crash is protected for 14 days so it can be recovered.
Dictionary. Your terms live in a local file in Application Support. Nothing is uploaded.
Settings under History and Privacy has two delete actions. Delete all history removes every dictation, all saved audio, and the Documents/Rambleproof/Recordings folder. Delete all Rambleproof data is the full reset: history, recordings, dictionary, settings, saved API keys, any license, the login item and, if you choose, the downloaded models. The app returns to its first-launch state.
Learning from your corrections (on by default)
After inserting text, the app watches the one editable field it inserted into for up to two minutes, to notice when you fix a word it got wrong. To do that it reads the text of that field, locally and in memory only, and discards it when the field loses focus or the two minutes end. Only short pairs of what was inserted and what you typed instead are kept, as suggestions you can review or dismiss. Password and other secure fields are never watched. Turn this off in Settings under History and Privacy.
What the app notes about where you dictate
The name and identifier of the app you dictated into are stored locally with each dictation, so History can show them and the Recordings folder can be named by app. When app-aware formatting is on, the site host of a supported browser is inspected locally to pick a writing style; the host and the window title are not stored and never sent to a provider. The app does not take screenshots.
What leaves your Mac in local mode
Nothing about your dictations. There is no product telemetry, advertising identifier, hosted account, or transcript logging. Network requests happen only when you choose cloud processing, download a model, or check for an app update. Provider status codes and processing durations may be written to macOS unified logs; transcripts, audio and API keys are not.
The app, in cloud mode (off until you turn it on)
If you enable cloud transcription or cleanup, you add your own API key for OpenAI, OpenRouter or Google Gemini. Cloud transcription sends the audio and up to 60 of your enabled dictionary terms as vocabulary hints. Cloud cleanup sends the raw transcript, your formatting preference and up to 120 enabled dictionary terms. Each stage is chosen separately, so you can keep one local and send the other. Keys are stored in macOS Keychain and requests are made by the Mac app, not proxied through a Zena Labs service. Provider terms apply. OpenRouter cleanup is used only on a zero-data-retention route; if none is available, the app falls back to local cleanup. When a cloud request is slow or fails, Rambleproof can use a local fallback.
Model downloads and updates
Downloading a local model or checking for an app update contacts the host that serves the files. Those requests carry no personal data beyond what any web download carries (your IP address and the file you asked for).
The app checks for updates once a day and installs them automatically when it quits. The check sends only the app version and your macOS version. Both behaviors have toggles in Settings under Advanced.
Licensing, if you buy Pro
To unlock Pro you paste your Gumroad license key into Settings. The app sends the key to Gumroad once to verify the purchase, and again every 14 days to re-check it. Without a network connection, Pro keeps working for 30 days from the last good check; after that the app falls back to the Free tier. It never locks you out. The key and a hash of the purchase email, not the address itself, are stored locally in Application Support. There are no accounts.
This website
This site uses no advertising pixels, cross-site analytics, or tracking cookies. It handles data you submit to the waitlist or contact form, and a live-demo recording only after you explicitly accept its provider disclosure.
For the optional live demo, your clip is sent to OpenAI for transcription and its transcript to OpenRouter for cleanup. The site does not intentionally persist either. Providers process the data under their terms. Built-in examples require no microphone.
A waitlist submission is forwarded to the service we configured to hold the list (an email or form-handling provider) and is used to send you one email when the app is ready. It is not sold, shared for marketing, or combined with other data. Reply to that email, or write to use the contact form, and ask for the address to be removed.
The contact form works the same way: your message, your email and optionally your name are forwarded to that service so we can read and answer them, and they are used for nothing else.
The site is hosted on Vercel, which keeps standard server logs (IP address, time, requested path) for a limited time to operate the service.
The download link at /download/latest counts each download with a timestamp, the referring page, and a country code. No IP address and nothing personal is recorded there.
Permissions the app asks for
- Microphone, to hear you while the hotkey is held. Nothing is recorded when the key is not held or hands-free mode is not active.
- Accessibility, to insert text at your cursor, to check that the focused field is not a password field, and, while learning from corrections is on, to read the one field it just inserted into. Rambleproof refuses to insert into secure fields.
- Documents folder access, which macOS may ask for the first time the Recordings folder is written. If you decline, the dictation still completes and its audio stays in the journal until you change the setting.
Who we are
Rambleproof is made by Zena Labs. Questions about this page: contact us.
Last updated: 31 August 2026.