Private by architecture

Not a policy.
A missing network call.

Most dictation tools promise privacy in a document you have to trust. Velora’s speech recognition and cleanup have nowhere to send your audio, because the models sit on your disk. Turn on airplane mode after setup and dictation keeps working. The source is on GitHub if you’d rather check than trust.

The ledger

What stays, and what ever touches the network.

Your voice
stays on the Mac
Transcripts & history
stay on the Mac
Meeting audio & notes
stay on the Mac
Screen context (window titles, on-screen text, optional local text recognition)
stays on the Mac
Voice Edit & Proofread selections
stay on the Mac
Action Mode plans, receipts & window screenshots
stay on the Mac
Accounts, telemetry, ads
do not exist
Model download, first run (and first use of speaker separation)
uses the network once each
Update checks & installs
GitHub, optional, can be turned off
Dictionary sync
your iCloud Drive, whenever it is signed in

Why this holds

Five structural guarantees.

No server

There’s nothing to send to

Velora has no backend, no account system, and no telemetry endpoint. The models that hear and polish your words are files on your disk, loaded into your RAM.

Verifiable

The source is the proof

Velora is MIT-licensed and developed in the open. “Local-only” is a claim you can grep, build and watch on a network monitor, not a marketing page.

Consent surfaces

Recording is always visible

Meeting capture requires a confirmation every time and keeps a recording indicator on screen. Audio only; the screen is never captured.

Closed doors

No open ports

Local automation is off by default and speaks only over an owner-checked Unix socket. No HTTP listener, no URL scheme that types into your apps, no network port at all.

Screen context

Names come from the window in front of you

To spell names right, Velora reads the front window’s title, the site address in your browser, and short strings near your text cursor (a chat header, a file name, a recipient chip). If that is thin, it reads the rest of the front window, and if you have granted Screen Recording, Apple’s on-device text recognition reads an exact screenshot of that window, which is discarded right after. The spellings go to the engine on your Mac over a local socket, nudge the models toward the right spelling, and go nowhere else. Nothing read from the screen is saved. The reads are part of dictation and Settings has no switch that turns them off. Reading the strings near your cursor, the rest of the window, and the recognised screenshot needs macOS Accessibility, so revoking that stops those spelling reads; the front tab’s address and title arrive separately (through accessibility in Safari and Firefox, and a one-time Automation permission in Chrome, Brave, Edge, Arc and other Chromium browsers). Screen Recording is separate and optional, and revoking it drops only the text recognition.

The fine print

  • The model downloads and optional update checks are real network events: they fetch speech models from Hugging Face on first run, speaker-separation models from GitHub the first time you use meeting notes, and release information and update builds from GitHub, and send nothing about you.
  • Dictionary sync runs whenever iCloud Drive is signed in and uses your iCloud Drive under Apple’s terms: confirmed terms only, never audio or transcripts. Without iCloud Drive, the dictionary stays on this Mac.
  • Privacy claims here describe Velora’s boundary. What other apps on your Mac do with text you paste into them is theirs.
  • This website is static, with no analytics, cookies or third-party scripts.

Free. Open source. Local.

Stop typing. Keep writing.

Already using Velora? A star is how the next Mac user finds it.