Responsible Use

Mostly Troctor reads transcripts you already have, which moves the hard question one step back: whose transcripts are they, and were you entitled to them in the first place. There is also a live mode that captures a meeting itself, in the build you can install, and switching it on moves that question forward again, onto you, at the moment you press start.

Last updated: 19 August 2026

What it's for

Troctor is for meetings you are in. You attach the documents a meeting is about and ask questions about them and about what is said in the room, and you import the transcripts your existing tools already produced so that all of them are searchable in one place:

  • Your own client and customer calls, when you need to know what you actually committed to.
  • Standups, design reviews and planning sessions, where the document under discussion is the thing nobody has finished reading.
  • Interview loops and hiring debriefs your team ran and kept.
  • Your own recordings, notes and dictation.
  • Meeting archives your organisation holds and has given you access to for this purpose.

The common thread is not the format of the file. It is that the conversation was yours to keep.

This is the whole of the ethical surface of this product, so it gets the space.

Troctor does not join anything. What it does today is read files you point it at, which means it cannot check where a file came from, cannot tell a transcript of your own sales call from a transcript of somebody else's board meeting, and does not try. The judgement is entirely yours, and it has to be made before you import, not after.

This section used to be the whole of it, and live mode changes that

There is now a live mode that captures a meeting as it happens, sends the audio from your Mac to a transcription vendor, and keeps a recording of it on your disk. It is off unless you switch it on, and it is unproven rather than finished, which is why it sits on the roadmap. That is a statement about maturity and not a reason to read the rest of this page as hypothetical. The moment you switch it on, Troctor stops being a tool that only reads what already existed and becomes one of the tools that makes the recording. The obligation described below as belonging to "whoever pressed record" is yours, at the moment you press it. Everything in consent law applies to you directly rather than to somebody upstream, and nothing in the product will tell the other people in the room. The security page sets out the mechanics.

Two rights have to be true at once:

The right at the time
The conversation had to have been lawfully recorded, with whatever consent the law required from whoever was in the room. That obligation belonged to whoever pressed record, and if that was not you, you are relying on them having got it right.
The right now
You have to be entitled to hold the transcript and to process it today. A contract can end that entitlement without the recording ever having been unlawful. So can leaving a job, closing an engagement, or a retention policy that told you to delete it.
Importing a transcript does not launder it

If a conversation was recorded without the consent the law required, having it as Markdown in a folder you chose changes nothing about that. It is the same recording, in a form that is now easier to search. Passing it through Troctor does not reset its provenance, does not create a new lawful basis, and does not put us between you and the consequence. If you were not allowed to have the file, you are not allowed to import it.

Recording law still applies to you. It just applies at a moment that has already passed by the time Troctor sees the file.

Several US states, including California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania and Washington, require every participant to consent to a recording. Others require only one. Under GDPR, participants generally need to be informed, and there has to be a lawful basis both for making the recording and for keeping it. California's rules on virtual notetakers carry penalties per occurrence.

Those rules attach to the recording and travel with everything derived from it. A transcript is derived from it. So is your index, and so is every answer Troctor gives you out of that index.

If people on the call were in different places

Assume the strictest rule applied. That is the safe reading, and it is the one a regulator is likely to take. If you cannot establish that the recording was lawful, treat it as though it was not.

You are responsible for complying with the law that applies to you and to everyone who was on the call. We cannot do that for you, and nothing in these pages transfers that responsibility to us.

Other people's meetings

The realistic failure here is not somebody deliberately building a surveillance archive. It is a folder of transcripts that accumulated, some of which were never yours, being imported in one go because importing in one go is what the app is good at. Be direct with yourself about three cases:

A colleague forwards you a transcript
They may have had every right to that meeting and no right to redistribute it. Being sent a file is not the same as being authorised to keep it, index it and query it for years. If in doubt, ask them whether the people on that call would expect you to have it.
A client call you were not on
Access granted for one purpose, such as reviewing an account before a handover, is not general permission to fold that conversation permanently into your own searchable memory. Import what your engagement covers, and not the rest.
A recording from a previous employer
Do not. Meetings from a job you have left almost always belong to that employer, usually under a confidentiality clause you are still bound by, and often under an obligation to have returned or destroyed them. This is the case people rationalise most easily and defend worst.

A useful test before you drag a folder in: if the people speaking in that file found out it was sitting in your personal archive and you could ask it questions, would that be a conversation you would be comfortable having. If it would not, leave the file out.

Confidential material

Importing a transcript is a local act. Nothing leaves your Mac when you import, index or search, and your vault never reaches us at any point. That is true regardless of how sensitive the material is.

The disclosure boundary is somewhere else, and it is worth locating precisely. When you ask a question, your question and that meeting's own material travel through our backend to a model vendor, on our account with that vendor rather than one of yours. That is real disclosure of real excerpts of real conversations, to Groq, Google or OpenAI depending on which model you picked. We relay it and store none of it, and their terms govern what happens next.

This part of the page has changed, and not in your favour. It used to say the request went from your Mac to a provider you held the account with, and that choosing a local model kept everything on the device. Both of those options have been removed. The app holds no vendor key and there is no local model, so every question about a confidential transcript is a question that leaves your machine.

So the question for confidential material is not which model to pick. It is whether to ask at all.

  • Search without asking. Importing, indexing and searching are entirely local, and so is opening a citation. You can find the passage you need without any of it reaching a model, and for privileged material that is the configuration that keeps it on the device.
  • Check what your obligations allow. If client or employer material may not leave the machine, then asking a question about it in Troctor is not permitted by those obligations, whatever the setting says, because there is no setting.
  • Assume the excerpt, not the vault. What travels is the question and up to eight passages, not the meeting and not the archive. That bounds the disclosure; it does not remove it.

The security page lists every byte that crosses the network, and the privacy policy describes exactly what is in that one request.

Assessment and exams

Troctor is not a tool for circumventing assessment, and this paragraph has been rewritten twice because the old versions stopped being true. It used to say there was no overlay and nothing that runs live, and then that neither could capture anything in a build you can install. There is now an overlay, and a live mode that captures a meeting and puts suggestions on that overlay while it happens, in the build you can install today. Nothing reads your screen, in any version, and that is not planned.

So the honest statement of the position is this. Live mode is designed for a meeting you are a participant in, where the material it draws on is your own past conversations. It is not designed for an examination, an interview you were told to sit unassisted, or any assessment whose rules forbid outside help, and we will not build features aimed at making it harder to detect. The overlay window asks to be excluded from screen sharing, and does so by default, so a private note is not broadcast to a room by accident on the versions of macOS that still honour it, which is 12 through 14; it is a switch you can turn the other way when you want people to see the panel, and that is the extent of it.

That said, examinations, certification bodies, licensing boards and employers set their own rules about outside assistance, and those rules are theirs to interpret, not ours. Read the rules of whatever you are sitting. If outside help is not permitted, do not use Troctor for it. Preparing beforehand, rehearsing, and reviewing your own past conversations are all ordinary uses and we are happy to support them.

Trusting the output

Troctor is built to be careful with your own history, because a plausible invention about what you said gets repeated out loud in the next meeting. Two things follow from that:

  • It shows you what it was working from. Every claim carries a citation into a real passage, and the citations are built from what retrieval returned rather than parsed out of the model's reply, so a source that was never retrieved cannot be cited. Troctor used to go further and refuse outright below a confidence floor. That gate was removed in v0.1 because it refused far too often on a small vault, and what is left is a prompt rule telling the model to answer with what it has and say how thin it is. A prompt rule is weaker than a refusal, which is exactly why the citation is worth opening.
  • Insights are not generated. The contradictions, unresolved commitments and recurring themes Troctor surfaces come from queries over your own index, not from a model, so they cannot be hallucinated. When Troctor says you told two people two different dates, both quotes are shown and both are real.

None of that makes an answer right. A cited passage can be read out of context, a summary can compress away the qualification that mattered, and the citation only proves that somebody said those words, not that the words were true. Transcripts are wrong too: speakers get misattributed, numbers get mangled, and automatic transcription confuses names it has never seen.

So before you act on something Troctor tells you, open the citation and read the passage yourself. That is what citations are for, and it takes a few seconds. Do not state a figure it produced as though you verified it, and do not rely on it for legal, medical, financial or other regulated advice. Your judgement stays in the loop.

How we handle misuse

We never receive your vault or your transcripts, we never receive a recording, and we keep no copy of anything you ask. Every question passes through our backend on its way to the model vendor, but it is relayed rather than stored, so there is still nothing on our side to review after the answer has been delivered. The honest consequence is that enforcement here is thin. We can act on what is reported to us and on nothing else.

Where we receive a credible report of use that breaks our Terms of Use, we may suspend or terminate the account and revoke the licence. Where we are legally required to act, we will. Revoking a licence does not delete anything from anyone's Mac, because we have no reach into it.

If you think Troctor is being used against you, write to contact@troctor.com and tell us what you know.