Privacy Policy
Effective 2026-05-01
CodeVox is built local-first by design. The most important thing to know is the simplest:
Your speech audio, transcribed text, and clipboard contents never leave your device. Speech recognition runs entirely on your Mac using the Parakeet-TDT model bundled with the app. CodeVox does not stream, upload, or transmit any of these in any circumstance: not for analytics, not for crash reporting, not for support, not ever.
What we collect
Account information (only if you create an account)
If you sign up for CodeVox, we collect your email address and the authentication tokens issued by our auth provider (Clerk). If you subscribe, our payment processor (Stripe, via Clerk Billing) collects and processes payment details on its own systems; CodeVox does not receive your card number.
Crash and fatal-error reports (opt-out, on by default)
When the desktop app encounters a crash or fatal error, it sends a report containing only:
- the macOS version (e.g. “14.5”)
- the CodeVox version (e.g. “1.0.0”)
- a redacted stack trace and minimal app state
Crash reports do notinclude your speech audio, transcription text, clipboard contents, file contents, file paths containing personal information, or any text from windows other than CodeVox itself. You can disable crash reporting at any time from CodeVox → Preferences → Privacy.
Behavioral analytics (opt-in, off by default)
Behavioral analytics (which screens you visit, which buttons you press, conversion-funnel events) are off by default. They are only enabled if you explicitly opt in via a first-run prompt or in Preferences → Privacy. When opt-in is enabled, events are sent to our analytics provider (PostHog) and contain no speech, transcription, or clipboard content.
Server logs
Standard server access logs (timestamps, IP addresses, request paths, user agents) are retained for a short window for debugging and abuse prevention. These logs are not used for advertising and are not sold or shared with third parties beyond our infrastructure providers (Cloudflare, Convex).
What we do not collect
- Audio recorded via the microphone
- Transcribed text produced by the model
- Clipboard contents
- Contents of windows the app pastes into
- Names of files you have open
- Keystrokes outside of the configured push-to-talk hotkey
Third-party processors
The third-party services we use:
- Clerk: authentication and subscription billing; processes email, session tokens, and subscription state
- Stripe: payment processing (via Clerk Billing); processes payment method details
- Cloudflare: web hosting + DDoS protection; processes server logs
- Convex: application database; stores your account record and trial state
- PostHog: behavioral analytics, only if you opt in
- Crash reporting provider (configurable; disclosed in-app on first run)
Your rights
You can request access to, correction of, or deletion of the personal data we hold about you by emailing privacy@codevox.io. If you delete your account, we will stop any ongoing payments and remove your account record from Convex; some information retained by our payment processor may persist for legal and accounting purposes.
Verification
You can independently verify the “your speech never leaves your device” claim by inspecting outbound network traffic while using CodeVox. With analytics disabled, the app makes no network requests during active transcription. With analytics enabled, requests carry only the event metadata described above.
Changes
Material changes to this Policy will be announced on the Site with an updated effective date. Continued use of CodeVox after the effective date constitutes acceptance of the revised Policy.
Contact
Questions about privacy can be sent to privacy@codevox.io.