Privacy

Last updated September 9, 2026

The short version

Stroki transcribes on your device — your Mac, your iPhone, or your iPad. Audio and words never leave that device. We do not upload recordings or transcripts.

If you create an account, we store your email and sign-in method so we can run your trial and subscription.

The Mac app sends a thin health check-in (that it ran, which version, onboarding progress, whether you share usage data) to our Cloudflare server so we can support the product, your account, and your subscription. That stays on.

If you leave Share usage data on, we also send allowlisted product events (features, engines, session length). Never audio or transcripts. You can turn that off in Settings → Privacy. Turning it off does not stop health, account, or update checks.

The iPhone app sends no Stroki product analytics. The single exception is that Google's sign-in library logs technical detail about its own request if you choose Sign in with Google, which is explained further down.

We use no third-party analytics or advertising SDK. No Google Analytics, no PostHog, no Mixpanel, no Segment, no ad networks. We do not track you across other apps or websites, and we do not sell or rent your data to anyone.

What never leaves your device

On every platform, we never receive, store, or transmit:

  • Your audio, in any form.
  • Your transcripts, your recaps, your summaries, or any other text Stroki produces.
  • Anything you type on the Stroki keyboard.
  • Your custom vocabulary.
  • The contents of your files.
  • Specific file names, app names, or bundle identifiers. On Mac only, and only when analytics are on, we record a coarse category for the dictation context — "code editor", "browser", "chat", "other" — so we know whether dictation gets more use in IDEs than in browsers.
  • Your precise location.

Speech recognition runs on your device's own neural engine, not on a server. On iPhone, recap summaries are generated by Apple Intelligence on the device as well, so that text does not go to Apple's servers or to ours.

Your Stroki account

An account exists so that your trial and your Pro subscription can follow you rather than a particular machine. On iPhone and iPad, an account is required to use the app. On Mac you can dictate without one; an account is needed for the trial or for Pro.

When you create an account we store:

  • Your email address.
  • A random account identifier we generate. It is not derived from anything about you or your hardware.
  • The date the account was created, the date your trial started, and whether the trial has been used.
  • If you signed in with Apple or Google, the anonymous subscriber identifier that provider gives us, so we recognise you when you sign in again.

We do not store your name on our servers. If Apple or Google supplies a display name at sign-in, the app keeps it locally on your device to show you in the app, and it is never sent to us.

If you use Sign in with Apple and choose "Hide My Email", we only ever see the relay address Apple generates. We are not able to see your real address, and we do not try to resolve it.

If you sign in with an emailed link, we store only a hashed form of the link token, never the link itself. The token expires shortly after it is issued and can be used once.

Signing in issues a session token that keeps you signed in for up to a year. Signing out discards it. We do not keep a server-side record of your devices or sessions.

The Stroki keyboard, and "Allow Full Access"

On iPhone, the Stroki keyboard is how you dictate into other apps. Before it will work, iOS asks you to turn on "Allow Full Access", and shows you a warning while doing so. That warning is generic, it applies to every third-party keyboard, and you are right to read it carefully. Here is exactly what it means for Stroki.

Full Access lets the keyboard reach the shared storage area that the Stroki app already uses on your device. That is how the keyboard knows which plan you are on and how much free time you have left this week, and how it hands audio to the app to be transcribed.

The Stroki keyboard opens no network connections at all. It does not log, store, analyse, or transmit anything you type — not the words, not their length, not the app you typed them into. Keystroke data never leaves the keyboard, because there is nowhere for it to go.

You can turn Full Access off at any time in iOS Settings → General → Keyboard → Keyboards → Stroki. Dictation needs it in order to reach the app, so it will stop working until you turn it back on.

The microphone

Stroki asks for microphone permission the first time you dictate, and iOS and macOS both show an indicator whenever the microphone is live.

Recorded audio is written into Stroki's own storage on your device, transcribed there, and stays there until you delete it. It is never uploaded. If you delete the app, everything it recorded goes with it.

Speech models are downloaded on first use

Stroki does not ship with its speech-recognition model built in — the files are far too large. The first time you use an engine, the app downloads that model from Hugging Face (huggingface.co), which hosts the open model files, and then keeps it on your device.

Like any download, that request tells Hugging Face's servers your IP address. It carries nothing about your Stroki account and no identifier we created. After the download completes, transcription is entirely local and Stroki does not contact Hugging Face again unless you pick a different engine.

Health check-in — Mac, stays on

After you finish the usage-data step in Mac setup, the app POSTs a thin health check-in to our server, then once per UTC day when the app launches or comes forward. It is not usage analytics and it is not on the dictation hotkey.

Fields: an opaque install id, app version, macOS version, onboarding step, whether Share usage data is on or off, and your account id once you are signed in. No engine names, no dictation counts, no error codes, no country, no hardware model.

After sign-in this can be joined to your email so we know which version you are running and can support your account and subscription.

The iPhone and iPad app has no Stroki health check-in. It makes network requests only to sign you in, to check your subscription, and to download a speech model. The one caveat is Sign in with Google, described below.

Optional usage data — Mac only

Only if Share usage data is on. Allowlisted events (app launched, engine used, dictation completed with a coarse duration and app category). No transcripts.

These events are stored with this install id and, after sign-in, your account — they are not anonymous and we can link them across days. Kept about 18 months. Cloudflare may store a 2-letter country on these event rows only. We never store your IP address.

You can turn this off in Settings → Privacy; we record that choice on the health check-in. Turning it off does not stop health, account, or update checks.

How the Mac app identifies an install

Stroki generates a random number the first time it runs and stores it in your local user defaults. It also reads your Mac's hardware UUID (the same identifier Apple recommends for device identity). It hashes the two together once and discards the originals. That digest is the opaque install id on the health check-in.

How to turn usage data off

Open Stroki → Settings → Privacy → toggle "Share usage data" off. Product events stop. Health check-ins, your account, and update checks continue.

Sparkle fetches the update feed so we can ship new versions. That request is not usage analytics. We do not send Sparkle's optional system profile.

Subscriptions and payment

We never see or store your card details, on either platform.

On iPhone and iPad, Pro is bought through the App Store. Apple takes the payment and tells us only that a subscription exists, which product it is, and whether it is active. Apple does not give us your name, your email address, or your payment method.

On Mac, checkout happens on the web and is handled by Stripe. You enter your email address on that checkout page, so our payments provider holds it for those purchases as well.

We use RevenueCat to keep subscription state consistent across your devices. RevenueCat receives your random Stroki account identifier and the subscription details it gets from Apple or Stripe. The iPhone app does not send RevenueCat your email address.

Who else sees a request from Stroki

The complete list, and what each one is for:

  • Cloudflare — hosts stroki.ai, our sign-in API, and the Mac analytics endpoint.
  • Apple — Sign in with Apple, and App Store purchases on iPhone and iPad.
  • Google — only if you choose Sign in with Google.
  • RevenueCat — keeps your subscription status in sync across devices.
  • Stripe — processes payments for web checkout.
  • Hugging Face — hosts the speech-recognition model files the app downloads.

None of these is an advertising or analytics network, and none of them receives your audio, your transcripts, or anything you type.

Sign in with Google, and why the App Store label mentions identifiers

Sign in with Google is optional. Sign in with Apple and the emailed link do exactly the same job and involve Google not at all. If you do choose it, here is the whole of what happens.

We ask Google for two things: your email address, and your basic profile — your name and your profile picture. We request no other permission. Google lists what it is about to share on the approval screen, and emails you afterwards naming what it shared.

To do that, the app includes Google's official sign-in library, and that library attaches its own technical detail to the sign-in request: which version of the library is running, that it is an iOS app, and which version of iOS. Google logs that, as it logs any request to its servers. It describes the sign-in itself and nothing after it — Google has no visibility into your dictation, your transcripts, or how often you open Stroki.

This is why Stroki's App Store privacy card lists identifiers and usage data even though the app has no analytics. Apple asks us to declare what every library inside the app collects, not only what our own code collects, and Google's library declares those categories for itself. It is not Stroki reporting on you, and it has nothing to do with your voice, which never leaves your device on any platform.

Google's declaration also covers categories our integration cannot produce — a phone number and a coarse location among them. We request no permission that would make either available, and Google's own record of what Stroki received lists neither, so we have left them off. If you would rather not involve Google at all, use Sign in with Apple or the emailed link.

How long we keep things

  • Your account and email address: until you delete your account.
  • Mac product events: 18 months, then deleted automatically. Older daily-salted event rows from before we attached install and account ids fall under the same window.
  • Health / install rows: until you delete your account (we detach the install from your email), or 18 months after last seen if never attached to an account. Automatic deletion of install rows is not yet in the same cron — we will add it.
  • Your current subscription record: for as long as your account exists.
  • Our log of billing events (a subscription started, renewed, or lapsed): retained after account deletion for accounting, tax, and fraud purposes, with the link to your account removed so the rows no longer identify you.
  • Sign-in link tokens: they expire within minutes, and the hashed record is deleted with your account.

Who has access

Our analytics dashboard lives at stroki.ai/admin and is protected by a team password. Only Stroki operators can sign in.

The database behind it is in our own Cloudflare account, and so is your account record. Apart from the services named above, each doing the one job described there, we do not copy any of it anywhere else — no third-party warehouse, no CRM, no analytics vendor.

Deleting your account

You can delete your account from inside the app, under Settings → Account. You can also email hello@stroki.ai and ask us to do it.

Deletion is immediate and permanent — not a flag we set and not a queue we work through. It removes your user record, your email address, your sign-in identifiers, and your subscription record, and asks RevenueCat to delete your customer profile there too. The only thing that survives is the billing event log described above, stripped of any link to you.

If you have a live subscription, cancel it first — we refuse deletion while a subscription is active, so that nobody ends up paying for an account that no longer exists.

Deleting your account does not delete anything on your device. Your recordings, transcripts, and recaps stay where they are until you delete the app.

Children

Stroki is not directed at children, and we do not knowingly collect personal information from anyone under 13, or under the equivalent age where you live. If a child has created an account, email us and we will delete it.

Your rights

Whatever jurisdiction you are in, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email hello@stroki.ai. We apply this to everyone rather than checking where you live first, and a person replies.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done either, and none of the third parties listed above is an advertising network.

When this changes

If we ever start collecting something not listed on this page, we will update this page first and call it out in release notes. We will not change the default to a different opt-in/opt-out posture without a fresh in-app disclosure.

Who operates Stroki

Stroki is a product of Nous Labs LLC, a New York limited liability company. Nous Labs LLC is the operator responsible for this policy, for the sign-in API, and for the analytics endpoint described above.

Contact

Questions, corrections, or a data deletion request? Email hello@stroki.ai. We respond to all privacy emails personally.

Nous Labs LLC, 45 Randolph Rd, White Plains, NY 10607, United States.