Privacy Policy
Troctor has a live mode that captures what the other people say, and your own microphone only if you tick it for that meeting, streaming the audio from your Mac to a transcription vendor. That is the largest thing this policy has ever had to describe, so it is described first and in full rather than folded in. Your vault still never reaches us, and neither does a recording. Your question and the excerpts it retrieved do pass through our backend on the way to a model vendor, and that is now true of every model rather than of one. Everything we hold is short enough to list line by line, and this page lists it.
In short
Every earlier version of this page said that no audio was captured, that Troctor never asked for your microphone or your system audio, that it requested no privacy permission from macOS, and that macOS could show no recording indicator because there was nothing to indicate. All of that has been deleted, because none of it is true any more.
Troctor has a live mode. It captures the audio your speakers were asked to play, and your microphone as well if you tick it for that meeting, and streams what it captures to Soniox, a transcription vendor, to be turned into text while the meeting happens. What leaves is not a summary and not a question you chose to type. It is the conversation itself, as it is spoken, and the half that always leaves is the half said by people who never installed anything.
Four things bound it, and each is stated again in full under what leaves when Troctor listens. It is off unless you switch it on, and that is a decision per meeting rather than a setting you make once. It runs on our Soniox account: our backend mints a key that lasts sixty seconds and can do nothing but open a stream, and the audio then goes from your Mac to Soniox without passing through us. The audio is written to disk on your own Mac, as WAV files beside the transcript, so a meeting can be played back afterwards; those files are never uploaded, and the app offers Show in Finder, Delete, and a switch that stops the audio being written at all. And live mode is unproven, so it is described here in full and is not something we would ask you to depend on yet.
Answers run on our vendor keys. In v0.1 that was one default model and you could avoid it by pasting a key of your own. Every model now works that way, and there is no longer an option that does not: the app has no key storage and no vendor client left in it, so it sends a model id to our backend and the backend decides which vendor answers.
So: your question and the excerpts Troctor retrieved from your meetings pass through infrastructure we control. Before v0.1 nothing about a meeting ever reached our servers, and this page said so at length and emphatically. It no longer says so, because it would no longer be true, and there is no setting that makes it true again.
The messages are relayed and not stored, and the exact list of what is written down is in what leaves when you ask. What bounds it is a daily allowance of 200 credits per licence rather than a bill, and the allowance cannot be raised, because there is no key to add.
Audio is captured only in live mode, only during a meeting you started. With live mode off, which is how it arrives, Troctor asks macOS for no privacy permission and there is no audio anywhere in the app. Switching it on asks for one or two permissions depending on what you told it to capture, and the difference matters: capturing only the other side of a meeting needs no microphone permission and produces no recording indicator, while adding your own microphone puts the orange dot in your own menu bar, on your own screen, where nobody else on the call can see it. Nothing tells the other people in the meeting that transcription is running. That is your job, not the operating system's.
Transcription happens at Soniox, on our account. There is no speech-to-text on your Mac and none on our servers. In live mode the audio goes from your Mac to Soniox and comes back as text, over a socket your Mac holds directly, using a temporary key our backend minted for that meeting. You need no account with them. Troctor also still works from transcripts you already have, exported from the tools that produced them, and that path involves no audio and no vendor at all.
Your screen is never captured. Troctor does not record the screen, does not read what is on it, and asks for no screen-recording permission in any configuration.
Your vault never reaches us. It is a folder of Markdown files on a disk you chose. The search index is derived from those files and sits in Troctor's own folder in your user library, along with any recordings live mode has written. None of it is ever uploaded, and there is no upload step in the app to trust us about. What can reach us is narrower than that and narrower than it was: only what you attached to the meeting you are asking in, and what has been said in that meeting. Every other meeting on the disk stays where it is, and a question is not matched against them at all.
When you ask a question, your question and that meeting's own material go to our backend, which forwards them to a model vendor on our account. That is the only route there is. Which vendor depends on the model you picked, and the choice of vendor is ours rather than yours.
What we do hold is the paperwork of running a private beta: the form you filled in to ask for a key, your licence and the Macs it is activated on, one line each time you download the build, a closed list of counts and timings from the app, and a count of the answers and the transcription minutes we paid for.
Usage reporting is on by default. It is not opt-in. It is disclosed on the activation screen, with the switch sitting next to the disclosure, before a single event is sent, and it can be turned off there or in Settings at any time. We rely on legitimate interests rather than consent, which is the honest description of a default-on setting, and the whole of what it sends is listed further down this page rather than summarised.
Who we are
Troctor is a product of Globyskytek LLC ("we", "us"), a limited liability company registered in North Carolina, United States. For the purposes of data protection law, Globyskytek LLC is the controller of the personal data described here.
Our registered address is Globyskytek LLC, #2150, 207 W Millbrook Road, Suite 210, Raleigh, NC 27609, United States. You can reach us at privacy@troctor.com.
What never leaves your Mac
index.db in the app's own folder under ~/Library/Application Support. It is derived from the vault and can be rebuilt from it. Protected by macOS file permissions, and by FileVault if you have it on.~/Library/Application Support, so that a meeting survives a crash and can be played back afterwards. Audio is about 115 MB per channel hour, and nothing deletes it on a timer, because the recording somebody wants is usually the old one a timer would have removed. The app lists every recording with its size and offers Show in Finder and Delete, and a switch stops the audio half being written at all, in which case only the transcript is kept. We have nothing to hand over if anybody asks us, because none of it reaches us.Importing, indexing, searching and reading citations all work with the network switched off entirely. Two things need a connection: generating an answer, because every model runs on our keys behind our backend, and live mode, because transcription happens at a vendor.
What leaves when Troctor listens
This section covers live mode only. If you never switch it on, none of it applies to you and nothing in it happens.
One thing about its maturity, stated here rather than left to the roadmap, because it belongs next to the disclosure rather than away from it: live mode is written and it is unproven. It has not been through a beta user's week of real calls, and the way it obtains its transcription key changed again recently. That is not a reason to read the rest of this section as hypothetical, since the code is in the build you installed and the moment you switch it on the audio described below is what leaves. It is a reason not to depend on it yet.
What is captured, and what macOS asks you first
Two channels, chosen by you, each with its own macOS permission. Nothing is requested at install or at launch; a permission is asked for the first time you start a meeting with that channel switched on.
The two channels are kept separate all the way to the vendor, which is what lets a transcript say who said what without guessing. It is also why capturing both costs twice as much as capturing one.
Everything else in this policy is about material you already had. This part is about a conversation, and half of it belongs to people who did not install Troctor, did not read this page, and will not be told by their operating system or ours that a transcript is being made. There is no technical control that fixes that. Telling them is the control, and Responsible Use is where we say what we think you owe them and where the law may already require it.
What goes to the transcription vendor
The vendor is Soniox. While a meeting is running, Troctor opens one connection per channel and sends:
- The audio itself, as raw 16 kHz mono samples in tenth-of-a-second frames. Unedited and unfiltered: everything the channel heard for as long as the meeting ran.
- A temporary key, the model name, the audio format, and the languages you said to expect.
- A list of terms you typed, if you typed one. Product names, people, acronyms, to help it spell them.
Nothing else. No vault content, no file names, no account of yours with us, and no identifier of ours. The transcript comes back over the same connection and is written into that meeting, which is to say into your vault, on your disk, and into the recording described above.
The key is ours, and it is temporary. Your Mac asks our backend for one when a meeting starts, our backend exchanges our real Soniox key for one that expires in sixty seconds and can do nothing but open a stream, and your Mac then holds the socket itself. The audio does not pass through our servers at any point, and it is worth saying why that is the design rather than an accident: relaying it would put every word of every meeting through a process we own, and add a hop to a delay measured in tens of milliseconds. What crosses our side is a request for a key and, while the meeting runs, a count of seconds. Never a word of it.
This does change one thing that used to be said here. Soniox was previously a company you had an account with; it is now a vendor of ours, on our key and our bill, so it is named under who we share with rather than kept off that list. What Soniox retains from a stream is governed by their own terms.
What goes to a model, and when
Live mode occasionally puts a suggestion on screen, which means one model call. It is rarer than a sentence: a line has to look like a question, a claim, a figure or a date; a rate limit has to be clear; retrieval has to find something in your vault; and the model has to decide there is anything worth interrupting you for, which it is instructed to say no to by default.
When one is made it carries the last six lines of the live transcript, the line that set it off, up to four passages from your vault and up to two excerpts from what you attached to the meeting. Never audio. The model never receives audio at any point in this product.
It travels exactly as a question you typed does: through our backend, to the vendor behind the model selected for that meeting, and it spends credits from the day's allowance, so a live meeting can consume part of that allowance without you typing anything. The model can be set for the meeting alone, and the assistant can be turned off entirely, in which case no model call is made for any reason.
The window it draws on
Suggestions appear in a small always-on-top window over your call. It is built with setContentProtection applied, which asks macOS to exclude it from screen recording and from screen sharing. It stopped working on macOS 15. Apple changed the compositor so every window is flattened into one image before capture, and ScreenCaptureKit, which is what Zoom, Teams, Meet and QuickTime now use, reads that image; the per-window flag has nothing left to apply to. On macOS 15 and later the panel is shared like any other window whatever this is set to, there is no workaround we know of, and the app says so on its own face rather than leaving you to find out in a meeting. It is still honoured on macOS 12 through 14. What does keep it out of the picture, on every version of macOS, is sharing a single window rather than your whole display: macOS captures a chosen window on its own and leaves out anything drawn over it. A second display works too. That is now a setting rather than a constant, because showing the panel is sometimes the point, and it is hidden by default and hidden after every kind of doubt: a stored value the app does not recognise, or a settings store that will not answer, both leave it hidden. Both windows say in words which state it is in, and the switch takes effect on the window immediately rather than at the next launch. That protection exists so a private note is not broadcast to the room the moment somebody clicks Share, and the security page is where we set out why we will not sell it as a way of being undetectable. The window also never takes the keyboard unless you press the shortcut that opens its ask box.
What is kept, and by whom
One further trace, and it is a count rather than content. If Troctor crashes with a transcription connection still open, it writes a small file so the next launch can notice, because a connection nobody closed keeps costing until the vendor's own limit. When that happens the app reports two numbers to us if usage reporting is on: how many channels were open and roughly how many minutes ago it started. Never which meeting, never a word of what was said.
What leaves when you ask
One request, made only when you press ask. What is in it is the same whichever model you chose:
- Your question, as you typed it.
- What you attached to that meeting, and what has been said in it. Nothing is read from the rest of your vault while answering; that path is built and switched off for the beta. Each excerpt carries the file or the speaker, the date and the timestamp it came from, so the answer can cite it.
- Whatever you attached to that meeting: files you dragged in, text you pasted, and the transcript of the meeting the thread was started from, if it was started from one.
- The standing instructions you wrote for that meeting, if you wrote any.
- Up to eight earlier messages from the same meeting, so a follow-up makes sense on its own.
Nothing else, and nothing at any other time. The rest of your vault is not sent, and meetings that did not match are not sent. One correction to a sentence this page used to carry: the name of a file you attach is sent, because the model has to be told what it is reading. The path it came from is not. Before anything goes anywhere, the composer shows you the size of the request as a percentage of the model's context window, itemised by part, so this is a list you can check rather than one you have to trust.
An earlier version of this page said that a weak question sent nothing at all, because retrieval was scored against a floor and below it the model was never called. That gate was removed in v0.1. The model is now called every time you ask, so every question you type is sent, whether or not Troctor found much to answer it with.
Where the request goes, whichever model you picked
The request is posted to https://www.troctor.com/api/v1/chat, which is our own backend. It carries the model id you selected and nothing about a vendor, because the app does not know which vendor answers. Our backend checks that your licence is still good, spends the model's cost from the day's allowance, and forwards the same messages to that vendor over the OpenAI-compatible chat protocol using our API key. The answer streams back through us to your Mac.
Stated once and plainly, because it deserves better than being distributed across a page: on the free tier your question and the excerpts from your meetings transit a server we operate. The free tier is now the only tier, so that sentence covers every question you ask. They exist in that server's memory for as long as the answer takes, and they are not written to our database.
What is written, once per answer, is a single usage record holding the vendor model name, the input and output token counts, whether those counts were measured or estimated, how many milliseconds it took, and whether it failed. That is the whole record. Not the question, not the answer, not an excerpt, not a fragment of one, not a hash of any of it. The same token counts are added to a per-licence daily total, which is what enforces the allowance. Both writes are in functions/src/chat.ts, which is worth reading rather than believing.
One exception, which we would rather name than have someone find. When the vendor refuses a request outright, our server writes the first 300 characters of the vendor's error body to its operational log, because without that an outage cannot be diagnosed. Some vendors quote part of the request back inside that body. Those entries go to our Cloud Logging rather than to any database of ours and are never shown to you or to anyone outside the project, but it is the one path on which a fragment of a question could land in a log line, and it is cheaper to say so here.
Which vendor sits behind a model, and what that vendor calls it, are deployment parameters on our side rather than anything fixed in the app, because vendors rename and retire models on their own schedule and an installed build cannot be redeployed. The models offered during the beta are Groq Turbo on Groq, and GPT (fast) and GPT (deep) on OpenAI. A Google row exists in the same table and is switched off. The app fetches that list from us, so it can change without a new build, and this page names the current vendors rather than permanent ones. We will update it when they change.
The daily allowance
200 credits per licence per day. An answer costs one credit on either free model, two on GPT (fast) and eight on GPT (deep), so a day is 200 answers or 25 depending on what you pick. It is counted per licence rather than per device, so three Macs on one key share one allowance, and it resets at midnight UTC. When it runs out the next question is refused before anything is sent anywhere, with a message saying when the allowance comes back and whether a cheaper model can still afford it. Credits are spent at the moment a request is accepted rather than when it succeeds, and they are not returned if the vendor then fails. There is nothing you can add to raise the limit, because there is no key to add.
What used to be different
Until recently you could pick Claude, GPT, Gemini, Groq or a local model in Settings, paste your own key, and have the request go from your Mac straight to that provider with nothing of ours in the path. That option is gone. The key storage, the vendor clients and the settings screen that held them were all deleted, so there is no configuration in which a question avoids our backend. What you get in exchange is that there is no vendor account to open, nothing to paste, and no key of yours on disk to leak. We think that is the better trade for a pilot, and it is a real trade rather than a free improvement, which is why it is written here rather than left for you to notice.
What we collect
When you ask for a beta key
The form on the download page writes one record: your email address, your name, what you do, your company if you give one, which meeting tools you already use, roughly how many meetings a week you have, the note you wrote about what you would want to ask, and where you arrived from (the query string on the link you followed, or the referring page, truncated). The record is stored under an identifier derived from your address, so submitting the form twice updates a timestamp rather than creating a second entry. Only your email address is required.
If you are let in and sign in
Sign-in is handled by Firebase Authentication. We store your email address, your name if your sign-in provider supplies one, your account status, and the licence attached to it.
The licence record holds the key itself, your email address, its status, its plan, how many machines it allows, when it was issued and when it expires, and how many activations it currently has. The only plan value that exists is beta. There is no payment processor, no card details, no invoice and no subscription tier, because the beta is free and there is nothing to bill.
Each Mac you activate
Activation exchanges your key for a per-device token, and creates one record per machine:
Each time you download the build
One row in an audit log: your account identifier, your email address, the licence, the version you downloaded and the time. Download links are signed and valid for ten minutes, and this log is what lets a leaked link be traced back to the account that requested it.
Usage reporting from the app
Counts, durations and short identifiers, on by default. The complete list is the next section, in full rather than in summary.
Each answer we serve, and each meeting you transcribe
Counters, all written by our backend rather than by the app: one usage record per answer holding the model name, token counts and timing, a running total of credits for the day against your licence so the allowance can be enforced, and, for live mode, the seconds of connection reported while a meeting runs plus a count of how many connections that licence has opened today. None of them has a field capable of holding anything you wrote or anything anybody said. The answer records are itemised in the next section.
Feedback you send from the dashboard
Your account identifier, your email address, the message you wrote, the kind of feedback you picked and your app version.
When you email us
Whatever you put in the email, kept so we can answer you and remember the conversation if you write again.
This website
No advertising cookies, no analytics tags and no third-party trackers on any page. Our host records standard server logs including IP address and user agent, retained briefly for security and abuse prevention. The waitlist form counts submissions per IP address to keep bots off it, in a short-lived rate-limit record.
Usage reporting in full
Every event carries the event name, your device UUID, your licence identifier, the app version and a timestamp. Beyond that, each event may carry only the properties named against it below. This is the entire list, and it is the same list that exists in the app's source.
all, person or project, never the person's or project's name), which model, and whether it was a follow-up.Four names that this page used to list are gone from it. ask_gated measured the confidence gate, and when that gate was removed in v0.1 the event was taken out of the app and out of the server's allow-list in the same change. citation_opened, insight_shown and answer_rated were listed here while nothing in the build sent them, which overstated what is collected, so they are off the list until something actually emits them.
One further event is written by our own server rather than by the app, and it is the only one the switch in Settings does not govern. chat_served is recorded once per answer, and carries our model id and the vendor model string behind it, the credits it cost, the input and output token counts, whether those were measured or estimated, how long it took, and whether it failed. It exists because every answer is money out of our pocket and we need to know how much. No client can send it, and it is stored alongside the rest with the same 90-day expiry. There is no longer a way to opt out of it while still asking questions, because there is no longer a path to a model that does not go through us.
The list is closed, which is a stronger guarantee than filtering. A property not named above is dropped rather than inspected, so question, file, speaker, title, text, email, query and vault cannot reach us on any event, and a test fails the build if any of them is ever added. The same list exists again in the server that receives events and is applied a second time on arrival, so a modified copy of the app cannot send more than an unmodified one. The security page describes how that is enforced and tested.
Events are kept for 90 days and then expire automatically. Turning reporting off in Settings also discards anything queued and not yet sent, rather than letting one last batch go.
What this data cannot tell us: what you asked, what was in any meeting, what your files are called, who you meet with, or what your vault contains. It can tell us that a question took eleven seconds, that an import of forty files produced thirty-eight meetings, and that answers are failing more often on one app version than another. That is what it is for.
How we use it
- To decide who to let into the beta, and to email you a key.
- To confirm a licence is valid and to hold it to three machines.
- To serve you the build and to know which account each download went to.
- To answer your emails and read your feedback.
- To find out where the app is slow, where imports fail, and what the answers and the transcription cost us to run.
- To keep the service from being abused, through rate limits and the hidden field on the waitlist form.
- To meet legal obligations.
We do not sell personal data. We do not share it with advertisers. We do not build advertising profiles. We do not train models on anything, and we have nothing from your meetings that we could train on.
Legal bases
If you are in the UK, EU or another region applying similar law:
On usage reporting specifically, because it is the one that deserves the argument rather than the label: our interest is knowing whether a beta product works before more people rely on it. The balance rests on what the data is. It is counts, durations and short fixed identifiers, tied to a device UUID and a licence rather than to anything you said, and it cannot contain a question, a file name, a person's name or a line of a transcript. You can object at any time by turning it off, the switch is shown at activation before the first event is sent, and turning it off discards what has not been sent.
We do not rely on consent anywhere in this policy, and there is no cookie banner on this site, because nothing here runs on consent.
Who we share with
Four, and what each one receives. The first two are infrastructure providers, bound by contract to process data only on our instructions. The last two are the vendors that do the work a question or a meeting needs, under their own terms as well as ours:
What we do not share is anything from your vault, because we do not have it. The passages a question retrieves reach a model vendor by way of our backend and are not written down on either side of that hop by us. Everything else on your Mac, including any recording live mode wrote, stays there.
The current list of providers is available on request from privacy@troctor.com, and we will give notice before adding a new one. We may also disclose information where the law requires it, or to protect our rights, safety or property. If a valid legal request arrives, we will tell you unless we are prohibited from doing so.
How long we keep it
chat_served records our server writes are ordinary events and expire on the same schedule.What you can do yourself
There is no single button in Troctor that erases everything, and we would rather say that plainly than let you go hunting for one. Here is what actually exists:
- Delete the vault. It is your own folder of your own files. Drag it to the bin like anything else. Nothing of ours has to agree, and nothing breaks elsewhere.
- Delete the app's folder. Troctor's folder under
~/Library/Application Supportholds the search index, the device UUID, the stored licence, any queued usage events and any recordings live mode has written. Removing it removes all of them. - Remove the licence from a Mac. Settings, then Licence, then "Remove from this Mac". Your vault and index stay exactly where they are. Note that this does not free the seat: releasing a machine so the seat can be reused is a separate action in your dashboard.
- Leave live mode off. It arrives off and stays off until you switch it on for a particular meeting. Revoking the microphone and system audio permissions in System Settings, under Privacy and Security, takes the capability away from the app entirely, whatever it is asked to do.
- Delete a recording, or never make one. Open the meeting, and each recording is listed with its size beside Show in Finder and Delete. The switch beside them stops the audio being written for future meetings, in which case only the transcript is saved.
- Decide what a meeting may spend. The assistant in a live meeting has three settings, and off means no model call is made for any reason, including a question you type into the panel. That is the control that stops a meeting reaching a model at all.
- Turn usage reporting off. Settings, then Usage reporting. Anything queued and unsent is discarded at the same time.
For anything we hold on our side, email privacy@troctor.com and we will do it.
Your rights
Depending on where you live, you may have the right to see the data we hold about you, correct it, delete it, receive a copy in a portable format, or object to certain processing. You also have the right to complain to your data protection authority.
If you're a California resident, you have rights under the CCPA and CPRA to know, delete, correct and opt out of sale or sharing. We don't sell or share personal information as those terms are defined, and we won't discriminate against you for exercising any right.
To make a request, email privacy@troctor.com. We'll reply within 30 days and may need to verify who you are first.
Worth knowing what such a request can and cannot reach. Most of what you would want deleted was never ours to hold: your meetings, your questions, the answers you got and any recording of a call all live on your own disk. Questions passed through our backend, but they were relayed rather than stored, so there is no copy of them for us to delete and none for us to produce. A request to us covers the waitlist entry, the account and licence, the activation records for your Macs, the download log, the usage events and the allowance counters. It cannot reach a recording on your Mac, which is yours to delete in the app. Audio sent to Soniox during a meeting never passed through us, so there is nothing here to delete; what they hold is governed by their terms, and we will pass on a request if you send us one.
International transfers
We're based in the United States and our providers may process data there or elsewhere. Where data moves out of the UK or EEA we rely on Standard Contractual Clauses or another approved safeguard.
Children
Troctor isn't intended for anyone under 16, and we don't knowingly collect their data. If you believe a child has given us information, write to us and we'll remove it.
Changes
If we make a material change we'll update the date at the top of this page and, for anything significant, email account holders before it takes effect. If we ever start collecting something new, it will appear in the lists above before it is collected, not after.
Contact
Questions about any of this go to privacy@troctor.com, or by post to Globyskytek LLC, #2150, 207 W Millbrook Road, Suite 210, Raleigh, NC 27609, United States.