15 · Support

Privacy and Security

See what Steno stores, what stays on your Mac, and when it uses the internet.

Privacy Model

The Steno app records, transcribes with whisper.cpp, and applies cleanup rules on your Mac. It does not require a cloud transcription account or API key. Once the selected model is installed, dictation works offline. Optional model downloads contact an external model host and require internet access, and each download is checked against the published file before it is installed. Opening GitHub or support links also uses the network.

While Hold Option to talk is on, Steno notices key presses and mouse clicks in any app so it can tell a shortcut such as Option+Arrow from a dictation. It uses only the fact that a key or button was pressed, never which one.

Optional nearby-text continuation reads a limited range around the selection in supported editors. That context is temporary, is excluded from recognition prompts, and is not stored in History or Insights. Secure or unsupported fields and unconfirmed editor targets are excluded. Clipboard recovery places the completed transcript on the system clipboard; the destination app and other software with clipboard access have their own data handling. Steno never types a dictation into a password or other secure field: it copies the transcript instead and marks it as concealed, so clipboard managers and clipboard history apps leave it out. After an automatic paste, Steno never puts a password back on the clipboard.

When transcription fails, the overlay and VoiceOver give a short, plain message. The transcription tool's full log, which can include file paths from your Mac, goes to the diagnostic log, marked private.

This website uses Vercel Analytics to measure site visits. Analytics is not part of dictation in the Steno app.

Data Storage

History stores raw and cleaned transcripts and session metadata locally, capped at the newest 1,000 entries. It is not an audio archive. Preferences hold settings, word corrections, and shortcuts. Insights stores separate usage metadata, including session dates, app identifiers, and counts, with no transcript text or audio.

Steno keeps a backup copy of the History file and, when a History or settings file can't be read in full, a copy of the original. Deleting a History entry removes its saved transcript, including from those copies, but does not remove Insights totals, text already inserted elsewhere, clipboard copies, or copies retained by your own backups. A kept copy too damaged to edit is left as it is, and Steno says that it still holds older text. Delete all history removes every saved transcript and those copies, and replaces the History file without first copying it into the backup, so a crash during the delete can't leave your transcripts on disk.

Recordings and transcript files left in the temporary folder after a crash or a force quit are deleted the next time Steno starts. History has no fixed expiry date. Other users or software with access to the local files may be able to read them.

Security Reporting

Use the app repository's security policy. Prefer GitHub's private vulnerability reporting when available. If it is unavailable, the policy provides a public contact-request form to request a private channel; do not put exploit details, private transcripts, or attachments in that public request.

For ordinary bugs, include the version/build, macOS version, model, recording mode, whether preview was enabled, approximate duration, and the failing step. Distinguish preview, final text, insertion, and recovery failures. Share only relevant redacted details; do not publish private audio, nearby editor text, or raw system logs.