dolfinspeak
FeaturesPricingBlog Download for Mac

Draft · last updated June 2026

Privacy Policy

The short version

dolfinspeak gives you controls over your data. Transcription runs on your Mac by default; when you use a cloud feature, your text (and, where you've enabled it, audio) is processed to generate a result. Whether your content is used to improve and train our models is off by default — you turn it on in Data Controls. This policy explains exactly what we collect, how we use it, who we share it with, and the choices you have.

This Privacy Policy describes how The Harambe Company LLC ("dolfinspeak," "we," "us") collects, uses, and shares information when you use the dolfinspeak Mac application (the "app") and this website (together, the "Services"). By using the Services, you agree to this Privacy Policy. If you don't agree, please don't use the Services. Questions? support@dolfinspeak.com.

Who is responsible for your data

The Harambe Company LLC (doing business as dolfinspeak), 755 W Big Beaver Rd, Ste 2020-R, Troy, MI 48084, is the controller of personal data processed through the Services. For any privacy request, contact support@dolfinspeak.com.

Information we collect

Information you provide

  • Account — to use the app you create an account. We collect your email address and name, and, if you sign in with a third-party account — Google or Apple (via our authentication provider, WorkOS) or Discord — the basic profile information (such as name and email) that provider shares with us.
  • Billing — paid subscriptions are processed by Stripe. We receive billing status and limited details (such as card brand and last four digits) but never see or store your full card number.
  • Support and other communications — correspondence you send us, and any feedback or survey responses you choose to provide.

Customer Content (your inputs and outputs)

To provide the Services we process the content you create with dolfinspeak, which may include: your audio recordings, the raw transcript produced from your speech, the processed output generated when you use a cloud "mode," and any edits or corrections you make to that output (together, "Customer Content"). Audio recordings are stored on your device by default; see "How your content is processed."

Usage and device data

  • Usage, analytics, and diagnostics — information about how you interact with the app, such as app version, operating system and device type, language, unique device identifiers, logs, performance metrics, the application you're dictating into, crash/error data, and feature-usage events (for example, when a recording or transcription starts or completes). Our product-analytics providers (Amplitude and Statsig) may also capture session replays of your interactions with the app to help us understand and improve usage.
  • Website data — standard server logs (such as IP address and user agent) processed by our hosting/CDN provider for security and reliability, and, once enabled, website-usage analytics via PostHog (which we plan to configure to be privacy-respecting). [TODO(site): PostHog is not installed yet — add it (ideally cookieless) before this statement is relied upon.]

How your content is processed

  • Local transcription runs on your Mac using an on-device model (Parakeet). For local transcription, your audio is processed on your device.
  • Cloud modes — when you use an LLM-powered mode, the relevant content (your text, and where you have enabled it, audio) is sent to our backend and routed through OpenRouter to a large-language-model provider we select (for example, Anthropic's Claude; we may use additional providers such as OpenAI, Google, or others, and we configure providers ourselves). The result is returned to you.
  • Audio — we may process and store audio on our servers to provide and improve features where you enable them. Because voice recordings can constitute biometric or sensitive information under some laws, we handle them accordingly and seek any consent the law requires. [TODO(legal): if/when audio is uploaded, add a dedicated biometric-data notice — e.g. Illinois BIPA, GDPR Art. 9.]

How we use information

We use personal data and Customer Content to:

  • provide, maintain, secure, and improve the Services;
  • process subscriptions, payments, and account administration;
  • respond to support requests and communicate with you about the Services;
  • diagnose problems, prevent fraud and abuse, and ensure reliability;
  • send service messages, and — where you don't opt out — product and marketing updates;
  • create de-identified or aggregated data, which is no longer personal data and which we may use and disclose for any lawful business purpose; and
  • comply with law and enforce our terms.

Using your content to train and improve AI models is optional and off by default. We use Customer Content to develop, train, and improve our and our providers' models only where you have turned this on in your Data Controls settings (or otherwise given consent). You can change this choice at any time; changes apply going forward.

We reserve the right to collect, store, and retain Customer Content — including audio, transcripts, outputs, and your edits — to support the purposes above, including building datasets and improving models, even where a particular feature does not require it and even if we are not doing so today. Any use of your Customer Content for model training, and any sharing of it, remains subject to your choices and the opt-outs described in this policy.

Your Data Controls and choices

  • Training & improvement — opt in or out of using your Customer Content to train and improve models in Data Controls (off by default).
  • Marketing — opt out of marketing emails via the unsubscribe link in any such email.
  • Analytics & diagnostics — manage product analytics, session replay, and crash reporting in the app's settings.
  • Sale/sharing — exercise your "Do Not Sell or Share" right as described below.

Lawful bases (EEA/UK users)

Where the EU or UK GDPR applies, we rely on: performance of a contract (to provide the Services), legitimate interests (to secure, analyze, and improve the Services, and to develop our business, where not overridden by your rights), consent (for example, optional model training, certain analytics, marketing, and any processing of sensitive/biometric data — withdrawable at any time), and legal obligation.

How we share information

We may disclose personal data:

  • Service providers (subprocessors) — to vendors acting on our behalf under contract, for example: Stripe (payments); WorkOS (authentication, including Google/Apple sign-in) and Discord (sign-in); OpenRouter and the downstream LLM providers it routes to, such as Anthropic (cloud modes); Amplitude and Statsig (product analytics, experimentation, and session replay); Postmark (transactional and marketing email); Mux (hosting for demo and in-app content videos); Better Stack (uptime monitoring and status page); cloud infrastructure (Google Cloud Platform), database hosting (PlanetScale), and hosting/CDN (Cloudflare). We plan to add PostHog (website analytics), Sentry (error and crash monitoring), Honeycomb (observability), and CrabNebula (app update distribution and download analytics). [TODO(legal): keep this list current and publish it, and ensure a data-processing agreement (DPA) is in place with each subprocessor; add Adapty if/when mobile in-app purchases launch.]
  • Business and commercial purposes — consistent with this policy and your Data Controls/consent choices, we may share or otherwise make available Customer Content and other data (including, where applicable, on a de-identified or aggregated basis) with research, model-development, or data partners. We reserve the right to do so, and we will provide any notice and honor any opt-out the law requires.
  • Legal and safety — when required by law or to protect the rights, property, or safety of our users, the public, or us.
  • Business transfers — in connection with a merger, financing, acquisition, or sale of assets.
  • Affiliates, and others with your consent.

Sale or sharing of personal information (California and similar laws)

Depending on our partnerships, some disclosures of personal information for value, or sharing for cross-context behavioral advertising, may be considered a "sale" or "sharing" under the CCPA/CPRA and similar laws. Where that's the case, you have the right to opt out. To exercise it, email support@dolfinspeak.com [TODO(legal): add a "Do Not Sell or Share My Personal Information" link/mechanism and confirm whether any such sale/share actually occurs before launch]. We do not knowingly sell or share the personal information of individuals under 16.

Data retention

We retain personal data for as long as needed for the purposes in this policy — for example, account and billing records for the life of your account and as required for tax and legal compliance. De-identified and aggregated data may be retained and used indefinitely. [TODO(legal): confirm specific retention windows, including for Customer Content used in training.] You can request deletion of your account data (see "Your rights").

Security

We use reasonable technical, administrative, and physical safeguards to protect personal data, including encryption in transit and access controls. No method of transmission or storage is perfectly secure, but we work to protect your information.

International data transfers

We may process data in countries other than where you live, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, to withdraw consent, and to opt out of sale/sharing. To exercise any of these, email support@dolfinspeak.com; we may need to verify your identity, and we won't discriminate against you for exercising your rights. EEA/UK users may also lodge a complaint with their local data protection authority. California residents may request the categories and specific pieces of personal information we've collected and the categories of recipients.

Children's privacy

To use the Services you must be at least 13 if you reside in the United States, and 16 elsewhere. We don't knowingly collect personal data from children under those ages; if you believe a child has provided us information, contact us and we'll delete it.

Third-party links and services

The Services rely on third parties (such as Stripe, WorkOS, Discord, OpenRouter and the LLM providers, and our analytics providers) and may link to sites we don't control. Their practices are governed by their own policies.

Changes to this policy

We'll update this policy from time to time; we'll change the "last updated" date above, and if a change meaningfully reduces your rights we'll provide additional notice. Changes are not retroactive. Continued use after changes take effect means you accept them.

Contact

Questions, or want to exercise a right or change your Data Controls? support@dolfinspeak.com.

dolfinspeak

Talk. It types. Mac, Apple Silicon.

Support Privacy Terms

© 2026 dolfinspeak