Privacy
Listen Orb is an AI voice dictation app that runs on your Mac. With Local, transcription, optional AI polish, and explicit Orb Commands are processed on your Mac. With cloud processing, they go directly to the speech provider you select — OpenAI or xAI — using that provider's key; Listen Orb does not run a speech server. Keys are never mixed. There is no Listen Orb account and no telemetry in the app. Polar sees checkout, tax data, and license-key checks. Polar does not receive your microphone, provider API keys, or transcripts.
The optional Request a Feature… form uses a separate product-feedback path. Nothing from the form leaves your Mac until you press Send Request. The app then sends the form fields, contact choice, Listen Orb version, and macOS version to a Listen Orb endpoint hosted on Vercel. Resend delivers the request to our support inbox. A contact email is included only when you explicitly allow a follow-up. No audio, transcript, API key, vocabulary, logs, or destination context is included.
The product site is hosted on Vercel. Vercel Web Analytics may record cookieless page views and anonymous interactions such as preset-demo destination choices, video plays, halfway points, completions, downloads, and checkout clicks. Those events contain the action, page location, non-sensitive interface or video identifier, and, when available, the campaign identifiers described below. The analytics script never receives your microphone, API key, dictated text, vocabulary entries, or transcripts.
When a page URL contains utm_source, utm_medium, utm_campaign, utm_content, or utm_term, the site keeps only those values in the browser's session storage so they can follow internal navigation. Purchase links forward them to Polar. New values in a page URL replace older values for the same field, and the site does not forward unrelated parameters. These sanitized, length-limited campaign identifiers may also be included with anonymous Vercel Analytics events. This attribution is not retained across browser sessions.
The public product demonstrations are presets. They do not request browser microphone permission, record or upload audio, or call a transcription endpoint. The installed Mac app follows the selected local or cloud path described below.
The optional vocabulary-pack catalog and verified fallback copies are bundled with the app, so opening the catalog does not contact Listen Orb. Previewing or turning on a category also uses the bundled copy and does not make a network request. If an update is available, choosing Update after Check for Updates requests the pinned public catalog and selected category file from www.listenorb.com. Vercel may receive the ordinary network metadata needed to serve those static files, including the selected category ID in the requested path, IP address, time, and user agent. Those requests do not contain your API key, dictated text, personal vocabulary, enabled-category list, hidden-term choices, or local category customizations.
Local processing
On Apple silicon with macOS 14 or later, Local runs speech and text models on your Mac. Audio, transcripts, optional context, and Orb Command selections are not sent to OpenAI, xAI, or Listen Orb for processing. Local recordings keep their local processing path during recovery; a failure does not switch them to a cloud provider.
Model downloads contact the model host and reveal ordinary network metadata, such as your IP address and the requested model files. Downloaded models and your model choices remain on your Mac until you remove or change them. No provider API key is needed. Downloads, license checks, updates, and optional online features still use the internet; Local does not disable those features.
Trial word count
The trial keeps a necessary word total locally on your Mac, independently of optional Dictation Stats, including when Stats are off or reset. This counter stores no audio, transcripts, destination identity or per-dictation history. It stops growing at the seven-day cap or after purchase. The trial start, policy marker, and a copy of the confirmed word total are kept in macOS Keychain. These trial records are not uploaded to Listen Orb.
What the app handles
| Data | Where it lives | Leaves the Mac? |
|---|---|---|
| OpenAI API key | Process memory and the app's own process environment while running; Keychain item listen-orb-openai | Only as the Authorization header to OpenAI, including the Realtime validation check, when OpenAI is active or that key is being validated |
| xAI API key | Process memory and the app's own process environment while running; Keychain item listen-orb-xai | Only as the Authorization header to xAI, including the speech-to-text validation check, when xAI is active or that key is being validated |
| License key | Process memory during license checks; Keychain item listen-orb-license. The key is not stored in license.json. | Polar activation receives the key, Polar organization ID, and a non-identifying local label. Validation receives the key, Polar organization ID, and activation ID. |
| License activation record | Application Support (Listen Orb/license.json): activation ID, non-identifying label, key-saved timestamp, and last-validation timestamp | No |
| Trial start | Keychain item listen-orb-device | No |
| Entitlement record | Keychain item listen-orb-entitlement: the latest time observed during an access check; for a license, a one-way digest of the license key, the activation ID, and the last successful validation time; for a trial, the trial start and confirmed trial word total. It is used to detect a rolled-back clock or a lost or edited local record. The local trial record also keeps an hourly copy of the observed time. | No |
| Local processing record | Keychain item listen-orb-local-processing: a random signing secret and one-way digests that let a recording admitted during valid access finish transcription and one polish request. It contains no audio or text, and the digests are cleared when the app starts. | No |
| Microphone audio | Process memory during a listen, with a complete recovery copy. Interrupted recordings remain in Audio Recovery until a retry succeeds, Clear All removes them, or the app quits. A successful retry replaces audio with copyable text; normal successful transcription releases its audio copy. Up to five entries and 64 MB of audio are retained, with a 24 MB per-recording limit; limits stop or refuse recording visibly instead of evicting failed work. No recording files are written. Closing the panel keeps entries. Clear All does not interrupt an active recording; an in-flight retry may finish but cannot restore a cleared entry. Recovery does not survive a crash or restart and is independent of the Recent Dictations text-history setting. On a potential Orb Command turn, at most the first two seconds are also held in memory for a prefix-only Orb detector. | Local: no; audio stays on your Mac, including recovery. Cloud: yes — directly to the active provider. OpenAI uses Realtime transcription; xAI uses streaming speech-to-text. After a retryable xAI streaming failure, Listen Orb can automatically send the in-memory recovery copy once to the xAI file transcription API. Authentication and quota failures are not retried automatically. An automatic retry can finish the active dictation normally. Explicit Retry sends the retained recording and its original transcription hints to that provider's file transcription API. Recovered text from an explicit retry is offered for explicit Copy, without automatic insertion, polishing, or Orb Command execution. Recovery stores no destination context or selected text and writes no audio or transcripts to logs. Live “Orb” recognition can turn the capsule violet on OpenAI or xAI. A bounded prefix may also go to a separate live session on that same provider (OpenAI GPT Live Transcribe, or xAI streaming speech-to-text); the detector receives no selected text and is disabled when Orb Commands are off. |
| Final transcript | Memory, then inserted into the focused app. By default, the last five ordinary dictations remain in a session-only recovery buffer, regardless of insertion outcome. Each entry contains text and a local timestamp, starting with the original transcription and updating to the final text before insertion. No audio, destination context, or Orb Command selections are added to this buffer. Clear All, quitting, or turning off Settings → Keep Recent Dictations in Memory clears it. Closing a recovery window does not clear this buffer. It is never saved to disk; only the on/off preference is saved. Explicit Copy places the chosen text on your clipboard, which Clear All does not erase. | Local: no; polish runs on your Mac. With cloud, Standard polish and Contextual polish may send it to the active provider's text API. Off does not make a polishing request. A narrow set of already-complete brief phrases also bypasses polishing unless replacing selected text in Contextual mode. |
| Destination context | Memory only. App identity is captured for local routing. Selected and nearby text are collected for polishing only when the effective mode is Contextual, the dictation is not an approved brief phrase or a local metadata check detects a selection, and Accessibility exposes the requested ranges. Destination identity, selected text, and nearby text are not written to logs. | Local: no. With cloud, only an effective Contextual polish request may send it to the active provider. Off and Standard polish do not collect nearby text for polishing. |
| Orb Command selection | When Orb Commands are enabled, selection metadata remains in memory while the listen is active. Selected text is read only after an explicit spoken Orb Command. A verified replacement keeps the original and replacement in memory for up to two minutes for conditional Undo. | Local: no; instructions and selections are processed on your Mac. With cloud, the instruction and up to 32,000 UTF-16 units of selected text go directly to the active provider's text API with that provider's customer key. The request sets store to false. No nearby or off-screen text is included. When Orb Commands are off, no selection metadata is captured for this feature and no Orb Command request is made. |
| Capsule position and listening style | Application Support (Listen Orb/position.json) | No |
| Local app preferences | Application Support (Listen Orb/preferences.json): active speech provider, global and per-app polish modes, application names and bundle identifiers, final-period choices, Clean language, Orb Commands, listen-cue preference, and ready-guide suppression | No. These preferences remain local. Provider keys are never written here. |
| Activation progress | Phase and completed milestones only in Application Support ( Listen Orb/activation.json) | No. It never contains keys, licenses, or dictated text. |
| Custom vocabulary | Application Support (Listen Orb/vocabulary.json). Exported JSON is saved where you choose. | With cloud, preferred written forms may be sent to the active provider as transcription vocabulary hints. Listen Orb does not send spoken forms during ordinary app requests. Import and export are local file operations, and exports include spoken forms. |
| Local dictation statistics | Application Support ( Listen Orb/dictation-stats.json): schema version, collection setting, collection and daily-tracking start dates, confirmed-dictation count, total word count, total active-listen seconds, and up to seven daily aggregate buckets containing only a date, count, and active-listen seconds | No. The file never contains transcripts, audio, vocabulary, destination identity or context, per-dictation timestamps, or per-dictation history. |
| Vocabulary categories and local category choices | Application Support (Listen Orb/Vocabulary Packs/and Listen Orb/vocabulary-packs.json). Immutable verified fallback data is bundled with the app. | The selected public category ID appears in its update URL to www.listenorb.com. The enabled-category list, hidden-term choices, and local customizations are not uploaded to Listen Orb. A bounded, priority-ordered subset of preferred terms from enabled packs may be sent directly to the active cloud provider as transcription hints. Local processing keeps these hints on your Mac. |
| Feature request | Memory while the form is open. The app does not save a local copy. | Only when you press Send Request: the form fields, contact choice, app version, and macOS version go to Listen Orbon Vercel and through Resend to our support inbox. An email address is included only after explicit permission. |
| Clipboard | Used for one paste; unconfirmed dictation remains on the clipboard for manual recovery until replaced | No. Local insertion restores previous contents only after verification and only if nothing newer was copied. |
The Polar activation label has the form Listen Orb Mac XXXXXX. Its short suffix is generated randomly on the Mac, saved in license.json, and reused. It is not derived from the Mac hostname, username, serial number, or other hardware identifier.
Secure text fields are never read. The microphone stream closes when the listen ends. macOS may ask for your Mac login password the first time Listen Orb writes those Keychain items. That dialog belongs to macOS. It unlocks Keychain on this Mac. Listen Orb never sees that password and does not store it.
Vocabulary exports are plaintext JSON files. You choose where to save them, so the destination may be local or cloud-synced.
Email a Mac setup link
If you request a Mac download email, your address is sent through our server to Resend solely to send that link. It does not create a Listen Orb account, subscribe you to marketing, or reuse feature-request contact permission. The fixed setup link may contain sanitized campaign tags, but no email address, individual tracking ID, or tracking pixel.
Our application does not persist the address. It keeps keyed hashes of normalized recipients and network addresses for abuse prevention, plus request deduplication records. These sensitive operational records expire after 24 hours and are removed by scheduled retention cleanup. Resend processes the recipient and message under its own retention settings and privacy policy; our application cleanup does not delete the provider’s records. Copying the setup link is available without providing an email address.
Purchase confirmation may use a short-lived, HttpOnly cookie containing only a payment-verification result and expiration, never your checkout reference, identity, or license key. It expires after 30 seconds and does not grant account or license access. Confirmation pages do not send analytics; other page-view URLs have query strings removed.
Local dictation statistics
Local statistics collection is enabled by default and can be disabled in Settings → Dictation Stats…. The screen shows when the current dated collection began and opens a separate seven-day view for collected dictation counts and active-listen minutes. Listen Orb counts a dictation only after the destination positively confirms insertion. Failed insertions, empty or cancelled turns, errors, app shutdown, and --no-paste diagnostic output do not add to the totals. Orb Commands do not add to dictation totals. When collection is disabled, no new totals accumulate. Up to seven day-level aggregate buckets are retained; no individual dictation event is stored. Updating an older aggregate-only stats file preserves its all-time totals and begins only the daily buckets from the update day when collection is active. Because the older file has no trustworthy start date, the screen shows Available after reset until Reset Stats is used; the next collected dictation then establishes the date.
Active dictation time starts only after the microphone has opened and recording has begun, uses a monotonic clock, and ends when the user stops listening. Transcription, polishing, and insertion-confirmation latency are excluded. Average words per minute is total dictated words divided by total active-listen minutes. Estimated time saved is the time those words would take to type at a documented 40 WPM baseline minus active dictation time, with negative results shown as zero. It is an estimate, not a measured fact about a particular user's typing.
Reset Stats… requires confirmation and deletes the collection start date, seven daily buckets, and every aggregate counter while retaining the current collection choice. The all-time aggregates remain until reset or until Listen Orb's Application Support data is removed; daily buckets are automatically limited to the latest seven calendar days. The calculation is entirely local, creates no Listen Orb account or telemetry event, and adds nothing to OpenAI, xAI, or Polar requests.
Polish modes and destination context
With Local, the content described below is processed on your Mac. Sending content to a provider applies only to OpenAI or xAI cloud processing.
- Off does not make a polishing request. Destination information may still be handled locally to return focus, choose an insertion method, apply spacing, and insert the transcript.
- Standard polish is the default. It sends transcript text only. It does not collect selected or nearby text for polishing, or send the normalized destination category or application identity to the provider.
- Contextual polish is opt-in. In addition to the transcript, it may send the locally derived destination category, destination application name and bundle identifier, selected text, and up to 500 characters before and after the cursor. It asks Accessibility only for those bounded ranges, and only when the dictation is not an approved brief phrase or a local metadata check detects a selection. The metadata check does not read text.
The App Polish Modes window stores explicit per-app overrides only on the Mac. It can show the destination detected before the window opened and list running or user-selected installed apps without activating them. Listen Orb stores only the chosen app's display name, bundle identifier, and app-specific choices. Global always follows the current global Polish mode. Apple Terminal ships with a local Off configuration, and other recognized terminal apps start at Off when you add them. Final-period omission is off by default for every app and can be enabled for individual apps. A narrow built-in set of already-complete brief phrases, including “thank you” and “I love you,” skips the additional Responses polishing request unless replacing selected text in Contextual mode. Transcription, local vocabulary handling, and insertion still run.
Context remains on the Mac whenever Contextual polish is not selected. Listen Orb does not read entire documents, messages, conversations, browser pages, or application windows for polishing, and it never reads secure or password fields. Contextual polish uses destination-specific editing instructions, but results can vary; it does not guarantee a particular transformation.
Clean language is an independent setting and is enabled by default. When enabled, it instructs the model to replace spoken profanity with mild workplace-safe language while preserving the surrounding meaning and content. When disabled, it instructs the model to preserve spoken profanity exactly as dictated without softening, censoring, or omitting it. The setting is used only for an enabled polishing request: it does not turn polishing on, select a polish mode, or change what destination context is handled or sent.
Orb Commands
Orb Commands use the existing Fn interaction rather than another shortcut. They are enabled by default. Choose Settings → Orb Commands in the menu bar to turn them off or back on; that choice is saved locally. While they are off,Listen Orb does not capture selection metadata for this feature, treats an “Orb…” phrase as ordinary dictation, clears any temporary Orb Undo receipt, and makes no Orb Command request or live prefix-probe request.
Live transcription can recognize an opening “Orb” while you hold Fn. If selected text or a temporary Undo receipt makes an Orb Command possible, Listen Orb may turn the capsule violet on OpenAI or xAI before you release. That cue does not require an OpenAI key when xAI is the active provider. The live transcript is reduced to one boolean: whether the opening word was “Orb.” It receives microphone audio only—never selected text, nearby text, destination identity, or the eventual Responses instruction. The boolean cannot supply an instruction. Once it reports the exact opening word “Orb” on an eligible turn, it commits that turn to Orb Command mode; the final transcript remains the sole source of the instruction even if a live model drops the opening “Orb.” An empty or invalid instruction fails as an Orb Command instead of falling back to ordinary dictation. If live detection misses, a final transcript beginning with “Orb” can still invoke the command.
On OpenAI, when standard transcription is selected, the app may also send at most the first two seconds of that listen to a separate GPT Live Transcribe session. Probe audio and partial text are not persisted or written to logs. On xAI, an eligible turn may also send a short prefix to a second xAI speech-to-text session. The extra audio processing uses the customer's API key for the active provider and may add OpenAI or xAI usage.
When text is selected at the start of a listen, Listen Orb keeps only the focused element and selection-range metadata in memory. It does not read the selection content unless the final transcript begins with an explicit invocation such as “Orb, make this more professional,” or the bounded detector recognizes the exact opening word “Orb.” Ordinary dictation whose opening word is not “Orb,” such as “The orb is glowing,” does not read or send the selection for an Orb Command.
After recognizing a command, Listen Orb verifies the same app, field, range, and document length, then reads only that selected range, up to 32,000 UTF-16 units. It sends the spoken instruction and untrusted selected content as separate fields to the local model or directly to the active cloud provider. It includes no nearby text, clipboard contents, rest of the document, screen content, tools, or external actions.
Replacement requires another exact target and content check. The app pastes once into the still-selected range when a destination does not accept a verified Accessibility write. Previous clipboard contents are restored after local insertion is verified, if nothing newer was copied; they are handled locally and never included in the provider request. The original and replacement remain only in process memory for up to two minutes. Unconfirmed text remains on the clipboard for manual recovery. Local paste checks use field identity, selection metadata, and only the expected inserted range (up to 64,000 UTF-16 units), for up to 1.5 seconds. These checks do not read surrounding text, send content to AI, or log it. “Orb, undo” and Undo Last Orb Command restore the original only if the same field still contains the exact replacement and the document length has not otherwise changed. Secure fields are never read, and no command content or Undo receipt is logged or persisted.
Orb Commands are independent of Polish mode. An explicit Orb invocation makes its own Responses request even when Polish is Off; without that invocation, the selection path makes no Responses request.
OpenAI
When OpenAI is the active provider, preferred written forms from My Vocabulary and enabled packs may be included in the transcription session as vocabulary hints. Personal terms retain their existing hint behavior and take priority. Customized pack terms come next, followed by high-, medium-, and low-priority pack defaults within a conservative pack count and payload budget. The complete enabled pack list is not automatically sent when that budget is reached. Listen Orb does not send spoken forms to OpenAI during ordinary app requests. Vocabulary exports include personal spoken forms and are saved wherever you choose.
Audio and text sent to OpenAI are processed under OpenAI’s privacy policy and API data usage. The installed app sends OpenAI transcription, polishing, and Orb Command requests directly to OpenAI with your OpenAI API key; installed-app data does not pass through a Listen Orb-operated speech backend. Polish and Orb Command requests set store to false. You are the OpenAI customer; usage is billed to your API project, not to Listen Orb.
xAI
When xAI is the active provider, audio and text sent to xAI are processed under xAI’s privacy policy. Preferred written forms may be sent as speech-to-text key terms. Listen Orb does not host Grok and does not sell xAI usage. Polish and Orb Command requests go to xAI’s text API with your xAI key and set store to false. Orb Commands use a more capable xAI text model than polish. If an xAI polish request has not finished within five seconds, Listen Orb inserts the unpolished transcript. The already-sent request may still finish and incur xAI usage, but its late result is discarded, never inserted or used to replace your edits. Local diagnostics record only request timings, a fixed outcome category and phase, and an HTTP status code when available; they contain no transcript, context, response body, or API key. Live “Orb” recognition can turn the capsule violet from xAI speech-to-text; that cue does not call OpenAI. Eligible turns may also use a separate xAI speech-to-text session for at most the first two seconds. A spoken Orb in the final transcript can still start an Orb Command if live detection misses. You are the xAI customer: usage is billed to your xAI account, not to Listen Orb.
What never happens
- The API key is never written to logs or plaintext files, and is never printed.
- The license key is never written to logs and is not stored in
license.json. - Transcripts, destination identity, selected text, nearby text, and vocabulary entries are never written to logs.
- Orb Command instructions, selected text, replacements, and Undo receipts are never persisted.
- Dictated content, audio, destination identity, and per-dictation events are never stored in the local statistics file.
- The enabled-pack list, hidden-term choices, and pack customizations are never uploaded to Listen Orb.
- Audio and transcripts from the Mac app are never sent to Listen Orb.
- A contact email is never included in a feature request unless you explicitly allow it.
- The Mac app has no analytics, crash reporters, or advertising SDKs.
- Keychain is read only for the
listen-orb-openai,listen-orb-xai,listen-orb-license,listen-orb-device,listen-orb-entitlement, andlisten-orb-local-processingitems.