Privacy policy

What Sotto sends, and what it records.

Sotto listens to you for a living, so this page is specific rather than reassuring. Every sentence here was checked against the code before it was written.

Last updated 16 August 2026 · Sotto 0.1.0 (private beta)
The short version

Your voice goes to our own service, which forwards it to a speech-to-text provider and sends the text back. So your audio does pass through our servers — we do not store it there. Your dictation history is written to your own Mac and is never uploaded. Call recording is switched off by default; if you turn it on, Sotto records both sides of the call. Sotto Chat messages are stored on our server in readable form. We do not sell anything to anybody, we run no advertising, and nothing you say is used to train a model.

Call recording is opt-in History stays on your Mac Keys in the macOS Keychain

Who we are

Sotto is made by HT&DT Sp. z o.o., ul. Grójecka 214/118, 02-390 Warsaw, Poland. For anything on this page, write to kontakt@sottodesk.com.

Dictation — your voice

Sotto starts recording when you press and hold the dictation key, and stops when you let go. Nothing is recorded between takes.

That recording is sent over an encrypted connection to a proxy service we operate, which forwards it to the speech-to-text provider we use and returns the text. Your audio passes through our servers on the way. We do not write it to disk there and we do not keep it, but we are not going to tell you it never reaches us, because it does — that is how a shipped copy of Sotto works without a provider key inside it.

The text is then usually sent, through the same proxy, to a language model that tidies it into finished writing. Short takes skip that step and are tidied on your Mac instead.

Recording calls — the Notetaker

Sotto has a feature that records a call and turns it into notes. It is switched off by default and it does nothing until you turn it on. This section describes what happens when you do.

When it is on, Sotto watches for a call in the apps it knows — Zoom, Teams, Meet, Slack, WhatsApp, Discord, FaceTime, Signal, Telegram and about a dozen others — and the first time it sees one it asks you. Nothing is recorded until you answer yes. Your answer is remembered; you can change it in Settings.

It records both sides. Your microphone, and the other person's audio, captured through macOS Screen Recording. The other person is not told and Sotto does not ask them. Without Screen Recording permission only your own microphone is captured, and Sotto says so.

The recording is chunked and transcribed by the same route as a dictation — through our proxy — and the transcript and notes are then written to your Mac. We do not keep the call audio or the transcript on our servers. A session ends when the call ends, or when both sides have been silent for the time set in Settings.

Please read this part. In many places — including California, Illinois, Florida, Pennsylvania and Washington in the United States, and Germany under §201 StGB — recording a conversation without the permission of everyone in it is a criminal offence. Sotto gives you the tool; getting that permission is yours to do, and we have deliberately made the feature ask rather than assume.

Reading your selection and your screen

The translate and rewrite keys work on text you have selected in another app. macOS offers no way to read another app's selection except through the clipboard, so Sotto presses Copy for you, reads the result, and then puts your clipboard back exactly as it was.

The honest caveat: for up to 1.2 seconds your selected text is on the system clipboard. A clipboard manager — Maccy, Paste, Alfred, Raycast — samples the clipboard every few tenths of a second, so if you have one it will have taken its own copy. Sotto puts the clipboard back; it cannot reach into another app's history to remove anything. Don't use these keys over a password.

The screenshot mode reads text off the screen on your Mac, using Apple's Vision framework. The image never leaves your Mac. The text it recognises is then treated like any other take — so it goes to the model with everything else.

Sotto Chat

If you sign in to Sotto Chat, your messages are sent to our server and stored there in readable form. They are not end-to-end encrypted. The connection is encrypted and every message is signed by your Mac so it cannot be forged — but signing is not encryption, and we can read message bodies. We say so plainly rather than let the word "encrypted" do work it has not earned.

A copy also lives in a database file on your own Mac. Signing in is optional; with no account configured, none of this runs and no message leaves your machine.

What is stored on your Mac, and for how long

Everything Sotto remembers is written to your own disk, in your account's Application Support folder, with permissions that restrict it to you:

Deleting things

You can delete a single take from the History screen. You can delete every take, or every take matching a search. And there is an erase that removes all of it at once: every dictation, every call transcript, every word Sotto learned from your speech, and every retained audio file — after which the database file is rewritten, so the text is not left sitting in freed pages. Your settings, modes and text rules are kept, because those are your setup and not your speech.

Deleting the app's Application Support folder removes everything in it too. Nothing about your dictations is retained by us elsewhere, because none of it was ever sent to us.

Crash reports

Crash reporting is off by default. Switched on, a crash sends a technical stack trace, the app version and the macOS version. By design it carries no transcript, no audio, no keys and no file contents, and your home folder path is stripped before anything is sent. You can turn it off again at any time.

Update checks, and how we count installs

Once per launch Sotto requests one small, static, cryptographically signed file from our server to see whether there is a new version. No identifier, no usage data and no account is attached to that request.

But our web server keeps an ordinary access log, and we count those requests — that is how we know roughly how many Macs are running Sotto, and how many people downloaded it. The counting is done by hashing the IP address with a secret and counting distinct hashes per day; we keep the daily totals, not the addresses or the hashes. The app itself sends us no usage events at all — there is no analytics SDK in it — but we are not going to call that "no tracking", because a server counting your update check is still a server counting you.

The beta list and feedback

If you ask for beta access we store the email address you typed, where you came from, your browser's user-agent string, and a hashed form of your IP address (kept to stop the form being flooded). We do not add you to a marketing list, and we do not share or sell it.

If you send feedback from inside the app, the message is stored on our server in full, with the app version and the email address if you gave one. If the app is offline when you send it, it is queued on your Mac and sent at the next launch.

Your rights

Under the GDPR you may ask for a copy of what we hold about you, ask us to correct or delete it, or object to our use of it. What we hold is: your beta-list entry, any feedback you sent, your Sotto account if you have one, and — if you use Sotto Chat — your messages. Your dictations and call transcripts are not on that list, because they are not on our servers.

Write to kontakt@sottodesk.com and we will act on it. Being straight with you: there is no self-service delete button on our side yet — a request is carried out by a person, by hand, and we will confirm when it is done. You may also complain to the Polish supervisory authority, the UODO.

Children

Sotto is not directed at children under 16, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects what we send, keep or record, we will update the date above and say so in the release notes rather than changing it quietly.