Privacy Policy

Last updated: April 26, 2026

Plain-English summary: The Heard Right desktop app processes your voice locally on your computer — no audio leaves your device. The website collects the bare minimum needed to operate (an email if you join the waitlist, basic analytics). We don't sell data, we don't use ad trackers, we don't share with third parties beyond what's listed below.

1. Who we are

Heard Right ("we," "us," "the Service") is a local-first dictation software product operated by Adrian D'Souza, an independent developer based in India. Contact: info@heardright.app.

2. What this policy covers

This policy applies to:

3. Data we collect on the website

3.1 Waitlist signup

If you submit your email to join the waitlist, we store:

This is stored in Cloudflare KV (a key-value database). Used only to send you a launch notification and product updates. You can request deletion at any time by emailing info@heardright.app.

3.2 Analytics

We use privacy-friendly analytics that do not use cookies or fingerprinting. We collect aggregate page-view counts and country-level traffic data to understand which pages are useful. No individual user is identified or tracked across pages.

3.3 Cookies

The website does not set any cookies. If we add features in the future that require cookies (e.g. a customer login area), we will update this policy and ask consent where required.

4. Data the desktop app handles

4.1 Local processing — the default mode

The Heard Right desktop app runs the Whisper speech-to-text model entirely on your computer. Audio recordings never leave your device in local mode. Transcripts are pasted directly into the application you're typing in (e.g. your text editor, browser, or chat app), and we do not retain them.

4.2 License validation

On first launch and approximately every 30 days, the app sends your license key and a stable machine identifier (derived from hardware identifiers, not personally identifiable) to our license validation server to confirm your license is active. Nothing else is sent.

4.3 Update checks

The app checks for new versions periodically. The check transmits only the current app version. No personal information is sent.

4.4 Optional anonymous telemetry

If you opt in during onboarding, the app sends a once-daily count of how many transcriptions you ran. No audio, no transcripts, no content of any kind — just an integer counter. You can disable this in Settings at any time.

4.5 Cloud Pro tier (when released)

If you opt into the optional Cloud Pro subscription, audio you dictate is sent to our cloud transcription endpoint, processed using the Whisper model, and the resulting text is returned. Audio is processed in memory and not stored on our servers. Logs of cloud transcription requests are kept only for 7 days for abuse prevention, after which they are permanently deleted.

5. Third-party services we use

Service Purpose Data shared
CloudflareWebsite hosting, DNS, KV storageAll website traffic
ResendSending transactional emailsEmail address, email content
Google WorkspaceReceiving emails sent to info@heardright.appInbound email content
Lemon SqueezyPayment processing (when product launches)Email, billing details, purchase history

Each of these services has its own privacy policy. We share only the minimum data required for them to perform their function.

6. How we use your data

We do not:

7. How long we keep data

8. Your rights

Regardless of where you live, you have the right to:

To exercise any of these rights, email info@heardright.app. We respond within 30 days, usually much faster.

9. Children

Heard Right is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

10. International transfers

Our servers and third-party services may be located in jurisdictions different from yours (primarily the United States, European Union, and Asia-Pacific). By using the Service, you consent to your data being transferred to and processed in these regions.

11. Security

We use industry-standard security: HTTPS everywhere, encrypted data at rest, secrets stored in Cloudflare's encrypted secret store, two-factor authentication on administrative accounts. No system is perfectly secure, but we follow reasonable practices. If a breach affecting your data occurs, we will notify you within 72 hours.

12. Changes to this policy

If we materially change this policy, we will email everyone on the customer or waitlist list at least 14 days before the change takes effect. Minor clarifications (typos, formatting) may be made without notice — the "Last updated" date at the top will always reflect the most recent change.

13. Contact

Questions, complaints, or requests: