Plain-language promise: ReadySaid does not sell personal information or use dictation to train a ReadySaid model. Core Mac dictation processes microphone audio on the device. Optional cloud refinement, account synchronization, billing, and support each have separate data paths described below.
1. Summary
- ReadySaid is intentional, push-to-talk dictation. It is not designed for covert or continuous background recording.
- On supported Macs, core speech recognition uses Apple’s on-device speech technology. ReadySaid does not upload microphone audio to its account or text-refinement services.
- Exact and Clean processing run locally. Natural and Professional wording may use an optional, separately enabled cloud text-review feature.
- ReadySaid does not maintain a developer-hosted archive of your audio or ordinary dictation history.
- An account stores identity, device, preference, personalization, consent, and entitlement information so ReadySaid can authenticate you and restore approved settings.
- Google, Apple, and Microsoft sign-in are intended for identity only. ReadySaid does not use sign-in to read your mail, files, contacts, or calendars.
- Direct payments are handled by Stripe. App Store payments are handled by Apple. ReadySaid does not receive complete card numbers or security codes.
- The website early-access form stores the email address and plan interest you submit. ReadySaid does not run third-party advertising trackers.
More operational detail is available in Data Controls.
2. Information processed on your device
Microphone audio
When you deliberately start dictation, ReadySaid temporarily processes audio from the selected microphone. Current Mac recognition uses Apple’s on-device Speech framework. ReadySaid does not intentionally save an ordinary dictation recording to disk or send microphone audio to ReadySaid’s Supabase account backend, text-refinement gateway, or OpenAI.
A bounded in-memory audio buffer may temporarily hold recent audio while a dictation turn is being processed. It is limited in duration, never written to disk by ReadySaid, and is discarded when it is consumed, canceled, or no longer needed. Apple may download an on-device language asset through macOS; Apple handles that download under its own privacy practices.
Transcript and output processing
Partial and completed text may be held in application memory so ReadySaid can display, clean, copy, or insert it. Exact mode performs local normalization. Clean mode applies deterministic local rules such as filler removal, punctuation evidence, repetition handling, and supported self-corrections. ReadySaid does not create an app-managed, developer-hosted transcript-history database.
When ReadySaid inserts text into another application, copies it to the clipboard, or you save it in a cloud-connected destination, that destination and your operating-system settings control what happens next.
Clipboard, focus, and secure fields
To place and verify text in the intended location, the direct-download Mac edition may temporarily inspect Accessibility information about the frontmost application and focused control, including limited destination metadata, selection information, and the focused field’s before-and-after value. It does this only for the insertion you request; ReadySaid does not passively monitor or learn from other applications. This processing stays on the device. ReadySaid may also preserve, replace, and restore bounded clipboard contents during paste-based insertion. It refuses controls identified as password or secure fields and refuses dictation while macOS reports Secure Keyboard Entry.
Speech Profile and private Insights
If you personalize recognition, ReadySaid may store language, recognition mode, vocabulary, correction mappings, shortcuts, output preferences, and approved calibration results in local Application Support storage with restrictive file permissions and backup exclusion. ReadySaid does not separately encrypt that profile file. If account synchronization is enabled, the structured profile and selected preferences may also sync to your ReadySaid account.
Private Insights may store local aggregate counts, word totals, timings, delivery outcomes, and an optional typing-baseline value used for local comparisons. It is designed not to store transcript text, audio, app names, window titles, document names, or website addresses.
3. Optional cloud-assisted refinement
Cloud-assisted refinement is a separate, optional feature for eligible Natural or Professional output. It is designed to be off unless the user enables it, the account has consented, and ReadySaid’s server-side activation and allowance checks permit the request.
Before a completed text turn is sent, ReadySaid applies local cleanup and replaces values identified by local safeguards—such as email addresses, URLs, names, numbers, dates, and approved shortcuts—with opaque placeholders. This protection is heuristic and is not a guarantee that every sensitive value will be detected. The request is designed not to include microphone audio, partial speech, recognition alternatives, confidence values, clipboard contents, surrounding document text, app or window names, or the original values that were replaced.
The request also contains operational metadata needed to validate and route it, including random request and turn identifiers, platform, app version and build, locale, Natural or Professional selection, punctuation settings, personalization revision, and completion metadata. Your Supabase session authenticates the request to ReadySaid’s gateway. OpenAI receives a keyed pseudonymous safety identifier rather than the raw ReadySaid account identifier.
The placeholder-shielded text is processed by ReadySaid’s authenticated gateway and may be sent to OpenAI’s API for bounded rewriting or meaning verification. Requests use store: false. OpenAI states that API inputs and outputs are not used to train its models by default. Under OpenAI’s default API controls, content may still appear in abuse-monitoring logs for up to 30 days unless the applicable ReadySaid project has approved shorter retention controls. ReadySaid does not claim Zero Data Retention unless that provider setting is active and verified.
ReadySaid validates a proposed rewrite and falls back to the locally cleaned text when a result fails its safety, meaning, placeholder, or formatting checks. No automated system can guarantee that a rewrite is correct. Review text before sending or relying on it.
4. Accounts, social sign-in, and synchronization
A ReadySaid account may store your email address, backend user identifier, installation and device identifiers, platform, app version, last-seen time, synchronized preferences, Speech Profile, cloud-consent state, subscription status, and feature entitlements.
If you continue with Google, Apple, or Microsoft, that provider authenticates you and may give ReadySaid basic identity information such as a provider account identifier, email address, name, or profile image, depending on the provider and your choices. ReadySaid does not receive your provider password. The provider consent screen controls the exact information shared.
ReadySaid’s sign-in connection is not a Gmail, Google Drive, Microsoft Mail, OneDrive, Contacts, or Calendar integration. ReadySaid does not use social sign-in to read content from those services.
If you use company SSO, ReadySaid may send the company domain you enter to Supabase for SSO-provider discovery and may receive identity claims from the configured provider after authentication.
5. Other information we handle
| Category | Examples | Purpose |
|---|---|---|
| Subscription and transaction records | Plan, provider, customer or transaction identifiers, status, renewal or expiration dates, entitlement, invoice and dispute references | Verify access, prevent duplicate processing, handle cancellation, refunds, disputes, taxes, and support |
| Cloud-refinement operations | Consent, random request identifiers, character totals, model route, token counts, outcome codes, timestamps | Enforce allowance, prevent abuse, diagnose content-free failures, and reconcile service use |
| Website early access | Email address, Free or Pro interest, source, created and updated timestamps | Manage the launch list and send closely related product communications |
| Website and security logs | IP address, browser or device information, request time, requested page, error and security signals processed by hosting providers | Deliver, secure, and troubleshoot the site |
| Direct-app update checks | When you deliberately choose Check for Updates, ordinary request data such as IP address, request time, and app-update request metadata | Deliver the requested update feed from readysaid.com |
| Support communications | Your contact details, message, and anything you deliberately attach | Respond, troubleshoot, protect the service, and maintain a support record |
Do not include audio, transcripts, screenshots, or sensitive document content in a support request unless it is necessary and you deliberately choose to share it.
6. When information is shared
ReadySaid does not sell personal information. It does not share personal information for cross-context behavioral advertising. Information may be processed by service providers only as needed to operate the requested feature:
- Apple: operating-system speech assets, Mac App Store distribution, and Apple-billed subscriptions;
- Supabase: authentication, account data, synchronization, entitlements, and ReadySaid server functions;
- OpenAI: optional placeholder-shielded text refinement and bounded meaning review;
- Stripe: direct checkout, subscription management, invoices, payment processing, and fraud prevention;
- Google, Apple, and Microsoft: social sign-in when you choose the corresponding provider;
- Vercel and Neon: public website hosting, request handling, and early-access database storage; and
- email and support providers: account, security, transactional, launch, and support communications.
ReadySaid may also disclose information when reasonably necessary to comply with law, protect users or the service, investigate fraud or security incidents, enforce agreements, or complete a financing, merger, acquisition, reorganization, or sale. A successor would remain subject to this policy for covered information unless it gives legally required notice.
7. Retention and deletion
- Ordinary microphone audio and transcript text are not kept in a ReadySaid cloud or disk archive. The latest completed transcript may remain in process memory for the current session or proof display until it is replaced, explicitly cleared, or the app quits.
- Account, device, preference, profile, consent, and entitlement records are kept while the account is active and then deleted or de-identified when an authenticated deletion request is completed, subject to the exceptions below.
- Private Insights aggregates are retained locally for up to 366 days unless you reset them sooner.
- OpenAI may retain API abuse-monitoring content for up to 30 days under its default controls, unless a shorter approved control applies.
- Website early-access and support information is kept while it remains reasonably necessary for the communication, support, security, or legal purpose for which it was collected.
- Minimized billing, tax, fraud-prevention, dispute, and security records may be retained after account deletion for the period required by law or reasonably necessary to establish, exercise, or defend legal claims.
Password-based accounts can use supported deletion controls after reauthentication. If your sign-in method does not currently support that path, email support@readysaid.com from the account address to begin a verified deletion request. We will provide the available verification and billing steps; do not assume an emailed request is complete until ReadySaid confirms it. Deleting a ReadySaid account does not automatically cancel an Apple-billed subscription, so cancel it through Apple first. In a supported direct Stripe deletion flow, cancellation is immediate and non-prorated, remaining subscription time may be forfeited, and deletion does not by itself create a refund.
Device-local preferences, profile information, Insights, and legacy rollback copies may remain until you use available in-app reset controls or manually remove local app data. Uninstalling the app bundle alone may not erase Application Support data, preferences, logs, or clipboard content. Text already inserted into another application must be deleted in that application.
8. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; withdraw consent; or appeal a privacy-request decision. ReadySaid will honor applicable rights and may verify your identity before acting.
- Turn off cloud-assisted refinement to prevent future cloud text requests.
- Review, remove, or reset Speech Profile entries and private Insights using available app controls.
- Revoke social-provider access from the provider’s account settings. Revocation stops future sign-in authorization but does not itself delete the ReadySaid account.
- Unsubscribe from nonessential email using the message link or contact us.
- Request account or early-access deletion by contacting ReadySaid.
International processing
ReadySaid and its providers may process information in the United States and other countries where they operate. ReadySaid will use safeguards required by applicable law for covered international transfers.
Children and younger users
ReadySaid is a general-audience productivity service. A parent or guardian must participate whenever the laws that apply to a user require their authorization or supervision. ReadySaid does not knowingly collect personal information in violation of applicable children’s-privacy laws. If you are a parent or guardian and believe a child provided information contrary to applicable law, contact us so we can investigate and take appropriate action, including deletion where required.
Security
ReadySaid uses measures designed to reduce data exposure, including on-device speech processing, authenticated transport, managed secrets, private database controls, secure-field refusals, placeholder shielding, and local response validation. No application, device, or hosted service can guarantee absolute security.
9. Contact and policy changes
ReadySaid may update this policy as the product, providers, or law changes. The effective date above identifies the current version. ReadySaid will provide additional notice or seek consent when legally required for a material change.
Privacy questions and requests:
ReadySaid LLC
Florida, United States
support@readysaid.com