Skip to content
Roundhand

Privacy policy

What Roundhand does with your audio, your text and your account.

Effective

Audio

Roundhand processes your audio on your Mac. Speech is recognised by a model that the app downloads once, on first run.

Audio is never uploaded, to Roundhand or to anyone else. Audio is never saved to disk: it is held in memory while you dictate and discarded once it has been transcribed.

Transcript text

Transcript text is the text Roundhand writes from your speech. Your dictation history, with that text, is kept in a database on your Mac.

Transcript text is sent to a cleanup provider only when cloud cleanup is on. When it is, the text goes directly from the Roundhand app to that provider.

The provider is either the managed service that comes with a Roundhand account, or a provider you pick and use with your own API key.

Audio and transcript text never pass through Supabase or Vercel, which run Roundhand's account service and website.

Local cleanup

With cloud cleanup off, Roundhand cleans up your text with offline rules on your Mac, and the text is not sent anywhere.

Offline rules are also what Roundhand falls back to when cloud cleanup cannot run.

Cloud cleanup

Roundhand sends transcript text for cleanup only when cloud cleanup is on, and you can turn it off in the app's settings.

Each request goes directly from the Roundhand app to the cleanup provider.

With the managed service, the app sends the text to OpenRouter, which passes it to a language model provider to clean it up.

If you choose your own provider, the app sends the text to that provider with your own API key, and the provider bills you directly.

To help the cleanup fit where you are typing, a request can also carry the identifier of the app you are typing in, its window title, the web address when that app is a browser, and the text already in the field. Nothing is read from password and other secure fields.

Audio and transcript text never pass through Supabase or Vercel on the way to a provider.

Roundhand makes no promise about what a cleanup provider keeps or for how long. Each provider handles the text under its own terms.

Account data

Roundhand is made by Ashwini & Co, which is responsible for the account data described here. You sign in with your email address and a one-time code.

Supabase runs Roundhand's account service and holds your account data: your email address, your account id, your plan tier, the date your trial ends, the Polar customer and subscription references of a paid plan, and a device identity for each Mac you sign in on (a device id, a device label and a fingerprint of that Mac's managed cleanup key).

For the managed cleanup service it records your cleanup spend: when your current credit period started, what you have spent in that period and when that total was last updated.

For each Mac's cleanup key it records the key's total spend, its spend when the period started and the spending limit set on it. It also records when the key was created, when it was last seen, when it was revoked and when it expires, if it has an expiry date.

While a checkout is in progress, it records when that checkout started and which plan it is for. It also keeps a record of each subscription event Polar sends about your account, and, when you open plans from the app, a fingerprint of the single-use sign-in link that the app opens on roundhand.dev.

Supabase Auth, which handles sign-in for the account service, keeps its own records of your sign-ins: your sessions, the time you last signed in and a log of sign-in events, with the IP address and user agent (the app or browser) each came from.

The one-time code is emailed to you through Resend, our email delivery provider, which receives your email address and the code to deliver it.

Supabase also keeps standard request logs of each call to the account service: the IP address it came from, its user agent, the address requested and the time of the request. The account service also logs what each call about your account did, such as a checkout started or a key issued or revoked, with your account id and, for a call about one of your Macs, its device id.

The account service never receives audio or transcript text.

To ask about the account data Roundhand holds, write to support@roundhand.dev.

Windows waitlist

If you join the Windows waitlist on roundhand.dev, Supabase stores your email address and the time you joined. Nothing else about you is stored with it.

Joining sends you one email confirming you are on the list, through Resend, our email delivery provider. Resend sees the address only to deliver that message.

Roundhand uses the address only to tell you about Roundhand for Windows. It is not shared and is not added to any other list.

To be removed from the waitlist, write to support@roundhand.dev.

Support email

Mail you send to support@roundhand.dev goes through Cloudflare Email Routing, which forwards it to the email inbox of Ashwini & Co.

The message is kept in that inbox with your email address and anything you include in it, such as your macOS and Roundhand versions.

Website cookies

The only cookie roundhand.dev sets is the Supabase sign-in session cookie. It is set by the /api/auth/handoff route, which the /checkout/handoff page calls when the Roundhand app signs you in to choose a plan, and it is refreshed only on /checkout/ pages.

The cookie keeps you signed in while you check out. Public pages, like this one, set no cookies.

Website request logs

Vercel hosts roundhand.dev and keeps standard request logs of each visit: your IP address, the URL you requested, your browser's user agent and the time of the request.

Payment

Polar is the Merchant of Record for Roundhand subscriptions. Polar collects your payment details and billing address on its own checkout page.

Roundhand never receives your card details. From Polar it learns which plan you bought and the state of your subscription.

Diagnostics

Roundhand records diagnostics, such as how long each step of a dictation took, in a local log on your Mac. The log never contains transcript text.

The app does not send its diagnostics anywhere.

Analytics

Roundhand has no remote analytics or telemetry by default. Neither the app nor roundhand.dev loads an analytics service or reports how you use it.