VoxAI 隐私政策

最后更新:2026 年 7 月 15 日 · 适用版本:v2.0

一句话版本:VoxAI 没有服务器,你的录音和转录文字默认全部留在你自己的 Mac 上,一份都不会传给我。没有账号,没有追踪,没有遥测。四件你应该知道的事:录音永久保留直到你自己删除;通话场景会录到对方的声音(告知对方是你的责任);你主动接入 AI 助手后,它能读到你的转录内容;如果你主动开启会后云端精处理,那场录音会上传到第三方服务(默认关闭,用你自己的账号)。

VoxAI 是什么

VoxAI 是 macOS 上的 AI 副驾。它听你的会议、通话和面谈,实时转成文字并区分说话人;你可以把自己的 AI 助手(Claude Code、Cursor 等)接进来,让它读到这些内容并给你建议。VoxAI 也保留了最初的语音输入能力——说话转文字,自动复制到剪贴板。

VoxAI 不做什么

你的数据存在哪里

全部在你这台 Mac 上,在 App 的沙盒容器内:

~/Library/Containers/com.ethanys.voxai/Data/Library/Application Support/VoxAI/

录音文件

会议、通话、面谈场景的录音会写入磁盘,保存为未压缩的 WAV 文件,存在上面那个目录的 recordings/ 下。

录音永久保留:VoxAI 不会自动删除任何录音,也没有保留期设置。录音会一直留在你的 Mac 上,直到你主动做以下之一:在 App 里删除那场会议(录音会连带删除),或者卸载 VoxAI(容器随之删除)。未压缩的音频占用空间可观,建议你定期清理不再需要的会议。

转录文字

所有会议的逐句转录存在同目录的 meetings.json 里,是明文 JSON:每句包含时间戳、说话人标签和原文。

说话人识别(声纹)

会议和面谈场景会实时区分说话人。这项识别完全在你的 Mac 上本地完成,用的是本地 CoreML 模型(FluidAudio)。

语音对话模式

你在语音对话模式里说的话,最近 100 条会存在本机的 dialog_input.json,供你接入的 AI 读取。这个文件在本机,不会上传。

偏好设置与试用次数

VoxAI 在本机的 UserDefaults 里存 App 自己的偏好(识别语言、外观、是否自动复制到剪贴板等)。副驾功能的试用次数也只记在本机(单场录制满 60 秒才计一次)——这个计数不发送给任何人,包括作者和 Apple。

系统剪贴板

语音输入停止后,VoxAI 会把转录文字写入系统剪贴板(默认开启,可在设置里关闭)。剪贴板的内容完全由你控制。

通话场景:关于录到对方的声音

请先征得对方同意。通话场景会捕获并录下通话对方的声音。许多国家和地区的法律要求录音必须取得所有参与者的同意。VoxAI 会在你首次使用通话场景时提示这一点,但是否告知对方、是否取得同意,法律责任在你,不在 VoxAI。

技术上是这样实现的:通话场景需要 macOS 的屏幕录制权限,VoxAI 用它捕获你 Mac 播放出来的声音,也就是对方在通话里说的话。

它捕获的是你 Mac 的全部输出音频,不只是通话 App 的声音。如果你在通话时还开着音乐、视频或其他会发声的程序,那些声音同样会被捕获进来并参与转录。(VoxAI 自己发出的声音已被排除,不会自录。)如果你不希望某些声音被录进来,请在开始通话录制前关掉它们。

对方的声音会和你的声音分别录成两个 WAV 文件、分别转成文字,对方的部分标记为「对方」。两者都和其他录音一样存在你本机的容器里,永久保留直到你删除,不会上传给 VoxAI——VoxAI 没有服务器可传。

VoxAI 什么时候联网

VoxAI v2.0 的 App 沙盒权限有三条:

第三条是 v2.0 新增的。以下是它的全部用途,没有别的:

什么时候连向谁发出去什么默认
会议 / 面谈首次录制 HuggingFace 只下载说话人识别模型(约 13 MB,一次性)。不发送任何音频或文字。对方能看到的只有你的 IP 地址和这次下载请求。 开启(说话人识别的必需品)
语音转文字 Apple 在 macOS 26 及以上,VoxAI 优先使用 Apple 的本地识别引擎;在更早的系统上使用 SFSpeechRecognizer,按 Apple 的隐私政策,音频可能被发送到 Apple 的服务器处理。两者都是 Apple 的系统框架,VoxAI 不经手。 系统行为
App 启动、购买、恢复购买 Apple App Store StoreKit 查询商品价格与你的购买状态。Apple 会知道这台设备 / 这个 Apple ID 是否购买过。不涉及你的录音或转录。 开启
AI 朗读(仅当你选择 Azure 语音) 微软 Azure 要朗读的那段文字,用你自己的密钥和额度发给微软。VoxAI 不中转、不留副本。适用微软的隐私政策。 关闭——默认用 macOS 自带的本地朗读,完全不联网
会后云端精处理(仅当你主动对某场录制点「精处理」) AssemblyAI 那场录制的完整音频文件,用你自己的密钥和额度上传,换回质量更好的转录与说话人分离。VoxAI 不中转、不留副本,适用 AssemblyAI 的隐私政策。这是唯一会让你的录音离开这台 Mac 的功能。 关闭

VoxAI 从不把你的录音或转录文字上传给作者——我没有服务器可以收。上表里唯一会送出你会议内容的是会后云端精处理,而它默认关闭、需要你逐场主动触发、用你自己的账号直接发给 AssemblyAI,不经过我这里。

会后云端精处理(默认关闭)

实时转录难免有误。你可以选择在一场录制结束后,把它送到 AssemblyAI 做一次更高质量的转录和说话人分离。这需要你自己在 AssemblyAI 注册、拿到密钥、填进设置——用的是你自己的账号和额度,VoxAI 不代收费用也不代为中转。

你的密钥存在哪

如果你使用云端精处理或 Azure 语音朗读,需要填入你自己的密钥。两者的存放方式不同,我们照实说明:

两者相同的是:只留在你这台 Mac 上,不会发送给作者,VoxAI 也不会把它们显示给你接入的 AI。

你接入的 AI 能读到什么

这是 VoxAI 的核心功能,也是最需要你了解的一条数据流。

你可以选择安装一个伴生的 MCP server,把 VoxAI 接进你的 AI 客户端(Claude Code、Cursor、Codex 等)。接入之后,你的 AI 可以读取:会议转录、实时转录、说话人标签、你在语音对话模式说的话。

这意味着这些内容会进入你所用 AI 的上下文。如果那是一个云端 AI 服务,你的会议内容就到了那家公司那里,适用他们的隐私政策,不是这一份。是否接入、接入哪家,完全由你决定——不接入的话,一切都留在本机。

关于这条链路的几点澄清:

伴生 server 自己会联网做什么

如果你接入了 AI 并让它开口说话,伴生 server 有两处会联网——都不涉及你的会议内容:

这两件事都发生在伴生 server 里,VoxAI App 本体全程不参与下载、也不执行任何下载来的代码。不安装伴生 server 的话,这一整节都与你无关。

儿童使用

VoxAI 不专门面向 13 岁以下儿童,也不会向作者收集任何用户数据(包括儿童的数据)。

政策变更

如果未来版本改变了本政策描述的任何数据行为——新增联网用途、改变存储方式、引入新的第三方服务——本政策会在该版本发布时同步更新,页首的「最后更新」日期会随之变化。

联系

如有疑问,请发邮件至 redlilyholmes@gmail.com 联系作者。


VoxAI Privacy Policy

Last updated: July 15, 2026 · Applies to: v2.0

TL;DR: VoxAI has no servers. Your recordings and transcripts stay on your own Mac by default — none of it is ever sent to us. No accounts, no tracking, no telemetry. Four things you should know: recordings are kept forever until you delete them yourself; Call mode records the other party's voice (telling them is your responsibility); once you connect an AI assistant, it can read your transcripts; and if you turn on cloud refine, that session's audio is uploaded to a third party (off by default, using your own account).

What VoxAI is

VoxAI is an AI copilot for macOS. It listens to your meetings, calls, and in-person conversations, transcribes them in real time, and identifies who's speaking. You can connect your own AI assistant (Claude Code, Cursor, etc.) so it can read along and advise you. VoxAI also keeps its original dictation feature — speak, get text, auto-copied to your clipboard.

What VoxAI does NOT do

Where your data lives

All of it on this Mac, inside the app's sandbox container:

~/Library/Containers/com.ethanys.voxai/Data/Library/Application Support/VoxAI/

Audio recordings

Meeting, call, and in-person sessions are written to disk as uncompressed WAV files, under recordings/ in the directory above.

Recordings are kept indefinitely. VoxAI never deletes a recording automatically, and there is no retention setting. Recordings stay on your Mac until you do one of the following: delete that meeting in the app (its audio goes with it), or uninstall VoxAI (the container is removed with it). Uncompressed audio takes up real space — we recommend clearing out meetings you no longer need.

Transcripts

Every meeting's transcript is stored in meetings.json in the same directory, as plain JSON: each line has a timestamp, a speaker label, and the text.

Speaker identification (voice embeddings)

Meeting and in-person modes tell speakers apart in real time. This runs entirely locally on your Mac using an on-device CoreML model (FluidAudio).

Voice dialog mode

What you say in voice dialog mode is kept locally — the most recent 100 entries in dialog_input.json — so your connected AI can read it. This file stays on your Mac.

Preferences and trial count

VoxAI stores its own preferences in local UserDefaults (recognition language, appearance, auto-copy toggle, and similar). The copilot trial count is also kept only on this Mac (a session counts only once it passes 60 seconds) — that count is not sent to anyone, including us and Apple.

System clipboard

When dictation stops, VoxAI writes the transcript to the system clipboard (on by default, can be turned off in Settings). The clipboard's contents are entirely under your control.

Call mode: about recording the other party

Get their consent first. Call mode captures and records the other party's voice. In many jurisdictions, recording a conversation legally requires the consent of everyone involved. VoxAI reminds you of this the first time you use Call mode, but whether you tell the other party and obtain their consent is your legal responsibility, not VoxAI's.

How it works technically: Call mode requires macOS Screen Recording permission, which VoxAI uses to capture the audio your Mac plays back — that is, the other party's side of the call.

It captures all audio output from your Mac, not just the call app. If music, video, or any other sound-producing app is running during the call, that audio is captured and transcribed too. (VoxAI's own output is excluded, so it never records itself.) If you don't want something recorded, close it before you start a call recording.

The other party's audio and yours are recorded as two separate WAV files and transcribed separately, with their side labeled "partner". Both are stored in your local container like any other recording, kept until you delete them, and never uploaded to VoxAI — there is no VoxAI server to upload to.

When VoxAI uses the network

VoxAI v2.0 declares three sandbox entitlements:

The third is new in v2.0. Here is every use of it — there are no others:

WhenTo whomWhat is sentDefault
First meeting / in-person recording HuggingFace Download only — the speaker identification model (~13 MB, one time). No audio or text is sent. All they can see is your IP address and the download request. On (required for speaker ID)
Speech to text Apple On macOS 26 and later, VoxAI prefers Apple's on-device engine. On earlier systems it uses SFSpeechRecognizer, and per Apple's privacy policy audio may be sent to Apple's servers for processing. Both are Apple system frameworks; VoxAI doesn't handle the transmission. System behavior
App launch, purchase, restore Apple App Store StoreKit queries product pricing and your purchase status. Apple learns whether this device / Apple ID has purchased. None of your recordings or transcripts are involved. On
AI speech output (only if you choose Azure) Microsoft Azure The text to be spoken, sent to Microsoft using your own key and quota. VoxAI neither proxies it nor keeps a copy. Microsoft's privacy policy applies. Off — the default is macOS's built-in local speech, which uses no network at all
Cloud refine (only when you explicitly refine a session) AssemblyAI That session's complete audio file, uploaded using your own key and quota, in exchange for a higher-quality transcript with speaker separation. VoxAI neither proxies it nor keeps a copy; AssemblyAI's privacy policy applies. This is the only feature that takes your recordings off this Mac. Off

VoxAI never uploads your recordings or transcripts to us — we have no server to receive them. The only row above that sends your meeting content anywhere is cloud refine, which is off by default, must be triggered by you per session, and goes directly to AssemblyAI under your own account, never through us.

Cloud refine (off by default)

Live transcription is never perfect. After a session ends, you can choose to send it to AssemblyAI for a higher-quality pass with speaker separation. This requires you to sign up with AssemblyAI, get your own key, and enter it in Settings — it runs on your own account and quota; we neither charge for it nor proxy it.

Where your keys are stored

If you use cloud refine or Azure speech, you supply your own keys. The two are stored differently, and we'd rather say so plainly:

What's true of both: they stay on this Mac, are never sent to us, and VoxAI never shows them to your connected AI.

What your connected AI can read

This is VoxAI's core feature, and the data flow you most need to understand.

You can install a companion MCP server to connect VoxAI to your AI client (Claude Code, Cursor, Codex, etc.). Once connected, your AI can read: meeting transcripts, the live transcript, speaker labels, and what you say in voice dialog mode.

That means this content enters the context of whatever AI you use. If that's a cloud AI service, your meeting content goes to that company, under their privacy policy, not this one. Whether to connect, and to whom, is entirely your choice — connect nothing and everything stays local.

A few clarifications about this path:

What the companion server itself connects to

If you connect an AI and let it speak, the companion server has two network uses of its own — neither involves your meeting content:

Both happen inside the companion server. The VoxAI app itself never downloads or executes any of it. If you don't install the companion server, this whole section doesn't apply to you.

Children

VoxAI is not directed at children under 13, and collects no user data of any kind for us (children's or otherwise).

Policy changes

If a future version changes any data behavior described here — a new network use, a change in storage, a new third-party service — this policy will be updated when that version ships, and the "Last updated" date at the top will change with it.

Contact

For questions, contact the author at redlilyholmes@gmail.com.