What Sotto sends, and what it records.
Sotto listens to you for a living, so this page is specific rather than reassuring. Every sentence here was checked against the code before it was written.
Your voice goes to our own service, which forwards it to a speech-to-text provider and sends the text back. So your audio does pass through our servers — we do not store it there. Your dictation history is written to your own Mac and is never uploaded. Call recording is switched off by default; if you turn it on, Sotto records both sides of the call. Sotto Chat messages are stored on our server in readable form. We do not sell anything to anybody, we run no advertising, and nothing you say is used to train a model.
Who we are
Sotto is made by HT&DT Sp. z o.o., ul. Grójecka 214/118, 02-390 Warsaw, Poland. For anything on this page, write to kontakt@sottodesk.com.
Dictation — your voice
Sotto starts recording when you press and hold the dictation key, and stops when you let go. Nothing is recorded between takes.
That recording is sent over an encrypted connection to a proxy service we operate, which forwards it to the speech-to-text provider we use and returns the text. Your audio passes through our servers on the way. We do not write it to disk there and we do not keep it, but we are not going to tell you it never reaches us, because it does — that is how a shipped copy of Sotto works without a provider key inside it.
The text is then usually sent, through the same proxy, to a language model that tidies it into finished writing. Short takes skip that step and are tidied on your Mac instead.
- What travels with the text. To make the clean-up fit what you are writing, Sotto also sends the name of the app you are in, its window title, and up to 1500 characters of the text already in the field you are typing into. If that context would be sensitive, use Privacy mode or turn the clean-up off.
- We do not keep your audio, and we do not keep the text of your dictations on our servers.
- Nothing you say is used to train models — not by us, and not, under our agreements, by the providers.
- One exception, on your own Mac. When a transcription fails, Sotto keeps that recording as a file in its own folder so you can retry it. Those files stay until you delete them — see "Deleting things" below. Privacy mode stops them being written at all.
- You do not manage a provider key. We attach nothing to the request beyond the subscription token that authorises it. We will name the current provider on request, and will say so here if it changes.
Recording calls — the Notetaker
Sotto has a feature that records a call and turns it into notes. It is switched off by default and it does nothing until you turn it on. This section describes what happens when you do.
When it is on, Sotto watches for a call in the apps it knows — Zoom, Teams, Meet, Slack, WhatsApp, Discord, FaceTime, Signal, Telegram and about a dozen others — and the first time it sees one it asks you. Nothing is recorded until you answer yes. Your answer is remembered; you can change it in Settings.
It records both sides. Your microphone, and the other person's audio, captured through macOS Screen Recording. The other person is not told and Sotto does not ask them. Without Screen Recording permission only your own microphone is captured, and Sotto says so.
The recording is chunked and transcribed by the same route as a dictation — through our proxy — and the transcript and notes are then written to your Mac. We do not keep the call audio or the transcript on our servers. A session ends when the call ends, or when both sides have been silent for the time set in Settings.
Please read this part. In many places — including California, Illinois, Florida, Pennsylvania and Washington in the United States, and Germany under §201 StGB — recording a conversation without the permission of everyone in it is a criminal offence. Sotto gives you the tool; getting that permission is yours to do, and we have deliberately made the feature ask rather than assume.
Reading your selection and your screen
The translate and rewrite keys work on text you have selected in another app. macOS offers no way to read another app's selection except through the clipboard, so Sotto presses Copy for you, reads the result, and then puts your clipboard back exactly as it was.
The honest caveat: for up to 1.2 seconds your selected text is on the system clipboard. A clipboard manager — Maccy, Paste, Alfred, Raycast — samples the clipboard every few tenths of a second, so if you have one it will have taken its own copy. Sotto puts the clipboard back; it cannot reach into another app's history to remove anything. Don't use these keys over a password.
The screenshot mode reads text off the screen on your Mac, using Apple's Vision framework. The image never leaves your Mac. The text it recognises is then treated like any other take — so it goes to the model with everything else.
Sotto Chat
If you sign in to Sotto Chat, your messages are sent to our server and stored there in readable form. They are not end-to-end encrypted. The connection is encrypted and every message is signed by your Mac so it cannot be forged — but signing is not encryption, and we can read message bodies. We say so plainly rather than let the word "encrypted" do work it has not earned.
A copy also lives in a database file on your own Mac. Signing in is optional; with no account configured, none of this runs and no message leaves your machine.
What is stored on your Mac, and for how long
Everything Sotto remembers is written to your own disk, in your account's Application Support folder, with permissions that restrict it to you:
- Dictation history — the text of every take, as heard and as tidied, with the app you were in. Never uploaded. The most recent 10,000 takes are kept and older ones are dropped as new ones arrive. That is a count, not a clock: there is no time limit, so a take from two years ago is still there if you have not filled the 10,000.
- Call transcripts and notes — the most recent 2,000 sessions, both speakers, in full.
- What Sotto learned from you — up to 2,000 words it picked up from your speech and 500 corrections it learned to make. These are fragments of what you said, and they outlive the take they came from.
- Failed-take audio — the recordings described above. There is no cap and no expiry on these; they stay until you delete them.
- Settings, modes, your dictionary, text rules and tone profiles — your configuration.
- Your keys and tokens — the subscription token, the chat signing key and any account tokens live in the macOS Keychain, encrypted by the system, never written to a file, and not synced to iCloud.
- A diagnostic log — about a megabyte, rotated once. Timings, mode names, backend names, permission state and counts. It does not contain what you said.
- Screen recordings, if you make any, go to Movies → Sotto and are never uploaded.
Deleting things
You can delete a single take from the History screen. You can delete every take, or every take matching a search. And there is an erase that removes all of it at once: every dictation, every call transcript, every word Sotto learned from your speech, and every retained audio file — after which the database file is rewritten, so the text is not left sitting in freed pages. Your settings, modes and text rules are kept, because those are your setup and not your speech.
Deleting the app's Application Support folder removes everything in it too. Nothing about your dictations is retained by us elsewhere, because none of it was ever sent to us.
Crash reports
Crash reporting is off by default. Switched on, a crash sends a technical stack trace, the app version and the macOS version. By design it carries no transcript, no audio, no keys and no file contents, and your home folder path is stripped before anything is sent. You can turn it off again at any time.
Update checks, and how we count installs
Once per launch Sotto requests one small, static, cryptographically signed file from our server to see whether there is a new version. No identifier, no usage data and no account is attached to that request.
But our web server keeps an ordinary access log, and we count those requests — that is how we know roughly how many Macs are running Sotto, and how many people downloaded it. The counting is done by hashing the IP address with a secret and counting distinct hashes per day; we keep the daily totals, not the addresses or the hashes. The app itself sends us no usage events at all — there is no analytics SDK in it — but we are not going to call that "no tracking", because a server counting your update check is still a server counting you.
The beta list and feedback
If you ask for beta access we store the email address you typed, where you came from, your browser's user-agent string, and a hashed form of your IP address (kept to stop the form being flooded). We do not add you to a marketing list, and we do not share or sell it.
If you send feedback from inside the app, the message is stored on our server in full, with the app version and the email address if you gave one. If the app is offline when you send it, it is queued on your Mac and sent at the next launch.
Your rights
Under the GDPR you may ask for a copy of what we hold about you, ask us to correct or delete it, or object to our use of it. What we hold is: your beta-list entry, any feedback you sent, your Sotto account if you have one, and — if you use Sotto Chat — your messages. Your dictations and call transcripts are not on that list, because they are not on our servers.
Write to kontakt@sottodesk.com and we will act on it. Being straight with you: there is no self-service delete button on our side yet — a request is carried out by a person, by hand, and we will confirm when it is done. You may also complain to the Polish supervisory authority, the UODO.
Children
Sotto is not directed at children under 16, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects what we send, keep or record, we will update the date above and say so in the release notes rather than changing it quietly.