Tirona ← Back to the site

Privacy

Last updated 28 August 2026 · v3

The short version. Your voice and your transcripts stay on your device. No server of ours ever receives your dictation. The free version needs no account and never contacts us at all. Buying Pro on the Mac adds an email address, used only to carry your purchase between your own Macs — and never to receive anything you said. On Android, Pro is bought through Google Play and no account with us exists at all.

This page describes what Tirona does with data on macOS and Android. It is written to be checkable: everything below can be verified by watching the app’s network traffic.

What stays on your device

All of it, unless you deliberately turn on one of the optional features described further down. Each of those is off until you switch it on.

DataWhat happens to it
Audio you dictate Held in memory while you speak, transcribed by a model running on your own hardware, then discarded. It is never written to disk and never uploaded. When you record a meeting the audio is held for the length of that meeting rather than a single phrase — it is what lets Tirona work out who spoke, which it does in one pass at the end — and it is released as soon as that finishes. Still in memory, still never written to disk, and gone if the app quits. Meetings longer than ninety minutes are transcribed without speaker names rather than having the audio kept for longer.
Transcripts Stored on the device so you can see your recent dictations. You can clear them at any time from the app. On Android they are also excluded from Google’s automatic app backup, along with your API keys, so neither is copied to Drive behind your back — that exclusion is deliberate, because “stays on your device” has to survive the platform’s own defaults, and Android’s default is to back everything up.
The field you dictate into Read only to place the text and confirm it arrived. Password fields are excluded and never dictated into.
Calendar (optional) If you enable it, Tirona reads meeting titles, times and attendee names, to spell names correctly and to know which meeting a recording is of. It also reads the invitation’s description and location, for one purpose only: to tell whether the meeting is a video call, so it only offers to take notes on meetings that actually are one. The answer it keeps is “yes, a Zoom call” or “no” — never the link, and never anything else from the body. That matters because meeting bodies routinely carry dial-in PINs and passcodes, and the joining link is often the only credential a meeting has. Nothing from your calendar is written back, and nothing is uploaded.
Notes folder (optional) If you choose a folder, Tirona reads it to learn how you spell names. The notes themselves are never uploaded.

When Tirona uses the network

Six times, four of which are not about your data at all.

Be aware of the last two. Both send your own words to a company you picked, under their privacy policy and not this one — the cleanup one sends the transcript, and the speech one sends the recording itself. We never see either, and we never receive your key: it is stored in your system keychain. Both are off until you configure them, and Tirona records the date you first switched speech transcription on, so “since when has my audio been leaving this machine?” has an honest answer. If you would rather nothing ever left, leave both off — that is the state they ship in, and the on-device model is what runs instead.

What we do not collect

If you buy Tirona Pro

Buying Pro on the Mac creates an account, and this is the one place Tirona asks for an email address. The reason is narrow: a purchase made on one Mac should unlock your other Macs, and there is no way to recognise you on a second machine without something that identifies you on both.

On Android there is no account. Pro is bought inside the app through Google Play; Google keeps the record of the purchase and handles refunds, and nothing about it — not the purchase, not your Google account — reaches us. The app asks Google Play whether Pro is bought, and that conversation stays between your phone and Google.

The free version never touches this. If you have not bought Pro, no account exists, nothing is sent, and there is nothing to sign in to. The paragraphs below describe a service you will never contact.

What the account holds: your email address, and which purchases are attached to it. That is the whole record. It does not know what you dictate, how often, which device you are on, or which features you use — the server that answers "has this person bought Pro?" is never told anything else, and has nowhere to put it if it were.

Signing in is a link sent to your email. There is no password to choose, reuse or lose.

Your Pro features keep working when we are unreachable. Tirona checks your purchase about once a month and remembers the answer for thirty days. A flight, an outage, or this service being discontinued does not take away something you paid for. It never re-checks in a way that could interrupt you, and it never downgrades you because a request failed — only because a successful reply said so.

Usage statistics

There are none. Tirona does not count what you do, does not send usage reports, and has no setting to turn any on — because there is nothing to turn on. The app has no analytics code path at all.

If that ever changes it will be opt-in, off by default, counts-only rather than content, and described here before it ships — not after.

Feedback you choose to send

If you use Send feedback, we receive what you typed, the category you picked, and your email address if you chose to give one. Nothing is sent unless you press the button — there is no timer, no send on launch, and nothing in the background.

Attached to it: the app version, your device model, the OS version and your locale, and which of Tirona's features are switched on — whether the accessibility service is enabled, whether a model is downloaded, which backend each job points at, whether a Mac is paired. That last group is there because “dictation does nothing” is almost always one of them, and asking takes a day.

You can read the exact text before you send it. The section has a “See exactly what’s attached” control that shows the literal payload — not a description of it.

What is not attached: anything you dictated, any meeting transcript, any audio, any API key, and neither the name nor the address of a paired Mac. The identifier is a random one generated when Tirona is installed, so two messages from the same person can be recognised as such; it is not derived from your hardware, and clearing the app’s data replaces it.

The website

tirona.app uses Cloudflare Web Analytics, which counts page views without cookies and without building a profile of you. It records aggregate figures — pages, countries, referrers, browsers — and does not identify individual visitors. That is why this site has no cookie banner: there are no cookies to consent to.

Accessibility permission

Tirona asks for Accessibility permission on macOS, and to run an accessibility service on Android. This is what allows it to place text into whatever field you are typing in, which is the entire function of the app.

It is used only to read which field currently has focus, to insert your transcribed text there, and to confirm the text arrived. It does not read, record or transmit the contents of your screen, and it does not run while you are not dictating. Password fields are detected and refused — Tirona will not type a transcript into one.

The iOS keyboard, and Full Access

Tirona's iOS keyboard asks for Allow Full Access. That is a broad-sounding permission and it is worth saying plainly what it is for here, because the keyboard cannot do its job without it and you should not have to take that on trust.

The keyboard does not record you. iOS does not permit an app extension to use the microphone — an entitlement check refuses it — so the keyboard never captures audio at all. It asks the Tirona app to record, and the app hands the finished text back. Full Access is what allows those two to speak to each other through a shared keychain group: the request going one way, the transcript coming back the other.

It is also what lets the keyboard read the pairing details for a Mac you have paired, so a dictation can use that Mac's larger speech model instead of the phone's. Nothing else is read, and nothing is sent anywhere by the keyboard.

What the keyboard never does: it does not log your keystrokes, it does not send what you type anywhere, it contains no analytics and no network code of its own, and it has no access to what you type in other apps beyond the field you are actively using it in.

Keeping dictation ready. If you turn on Keep dictation ready, the Tirona app holds the microphone open in the background so the keyboard's microphone button works without switching apps each time. iOS shows the orange indicator for as long as it does. Audio is still only transcribed when you press the button, still held in memory, and still discarded — and the session closes on its own after a period of silence. The setting is off until you turn it on, and turning it off closes the session immediately.

Children

Tirona is not directed at children and collects no personal information from anyone, including children.

Changes

If this policy changes in a way that affects what leaves your device, the change will be described in the release notes for the version that introduces it, not only here.

Contact

Questions about this policy: [email protected].