Legal
Privacy Policy
Sotto is local-first: raw microphone and system audio are processed on your Mac and are not uploaded by Sotto. AI responses require sending selected text—and an optional screenshot when you enable screen context—to an AI service.
Information processed on your Mac
Sotto processes microphone and system audio locally to produce a transcript. The app stores settings, custom modes, reference text, and conversation history locally in your macOS user account. Content-bearing diagnostic logs are off by default and are written locally only when you explicitly launch the app with diagnostics enabled. API keys and the anonymous beta device token are stored in macOS Keychain.
Managed beta inference
When managed inference is enabled, Sotto sends the relevant transcript, your prompt, custom instructions, and any screenshot you explicitly attach through Sotto's Cloudflare-hosted service to the configured AI provider. The service stores an opaque device token, app version, platform, feature flags, and usage counters. The application code does not intentionally persist prompt content or model responses on the Sotto backend.
Bring-your-own-key inference
When managed inference is disabled, requests are sent directly from the app to OpenAI using the API key in your Keychain. Reference-knowledge embeddings may also be sent directly to OpenAI. OpenAI handles that data under your agreement and its policies.
Screen context
Screen context is off by default. When enabled, Sotto captures one image of the active display at ask-time, excludes Sotto-owned windows where supported, compresses the image, and attaches it to that AI request. Sotto does not continuously record your screen.
Accounts, analytics, and sales of data
The beta does not require a personal account and does not ask for your name or email in the app. A one-way hash of the connecting IP is retained for up to 24 hours to rate-limit device registrations. Sotto does not sell personal information and does not use advertising trackers. Infrastructure providers may generate operational and security logs as part of delivering the service.
Retention and deletion
Local data remains until you delete it or remove Sotto's application data. The anonymous backend entitlement record remains while the beta operates. To request deletion or get exact local-removal instructions, open a support issue without posting your device token, API key, transcript, or other sensitive information; the maintainer will arrange a private verification channel.
Your responsibilities
You are responsible for obtaining any consent required to capture, transcribe, or process other people's speech or screens. Recording and consent requirements differ by location and context.
Changes and contact
Material changes will be posted on this page with a new effective date. For questions, contact the beta maintainer without posting sensitive information.