Last updated: October 2, 2026. Effective date: October 2, 2026.
Who is responsible
blabe is made and sold by Marcos Montalvo, an individual (“I”, “me”). I decide why and how the personal data described on this page is used, except where a company named below handles it under its own policy. Contact: support@blabe.dev.
The short version
- The app has no analytics, telemetry or crash reporting.
- The app talks to one service: blabe’s transcription service, which I run. It turns your speech into text and checks your trial or license; for a subscription, it checks the license with Polar. At most once a day, and only right after you finish a dictation, the app asks blabe.dev whether a newer version exists. If one does, the blabe menu offers it; nothing opens or downloads on its own. If you click it, Sparkle, the update library, opens its update window, and if you choose to install, the app downloads the signed update through blabe.dev from Cloudflare R2, where blabe’s downloads are stored, and installs it; installation can finish when you next quit blabe. These requests carry only what any web request does: your IP address, and a user agent naming the versions of blabe and of Sparkle. They send no license, account details, system profile or anything else about you or your Mac, and the website’s server logs the requests it receives like any other visit.
- The service runs on Cloudflare Workers, with its records in a Cloudflare D1 database. It sends your audio through OpenRouter to Microsoft’s MAI-Transcribe 2 model and returns the text. It doesn’t store your audio or your transcripts: it holds them in memory only while it passes them on. It deletes each request’s audio length and cost after 30 days.
- On your Mac, your audio is held in memory only. blabe never saves it to disk.
- Your sign-in token and this Mac’s random IDs are stored in your Mac’s login Keychain.
- I keep closed support emails and diagnostic attachments for 30 days after a case closes.
- This website sets no cookies. It counts visits to its pages with Umami, an analytics tool I run myself on the website’s server, so no analytics company receives the data. Its server keeps access logs for at most 30 days.
- I don’t sell or share your personal information.
What blabe handles
Your voice
While you hold the hotkey, blabe records from your microphone. When you let go, it encodes the recording in memory and sends it over HTTPS to blabe’s transcription service, which I run on Cloudflare Workers. The service sends the audio through OpenRouter to Microsoft’s MAI-Transcribe 2 speech model, run on Microsoft Azure, and returns the text to the app. The service processes your audio to transcribe it for you. The microphone is off when you aren’t holding the key. If you press Esc while holding it, the recording is discarded and not sent.
On your Mac, blabe never writes the recording to disk. If a transcription fails, the recording stays in memory so that Retry Transcription can send it again. It is discarded after a successful transcription or when you quit blabe.
What blabe’s transcription service keeps: not your audio, and not your words. Your audio is passed on for transcription and isn’t stored on the service: the service holds it in memory only while passing it on. The text that comes back goes straight to your Mac and isn’t stored either. So if the text is lost on its way back, for example because your connection drops, the service has no copy to send again, and you record again. For each request, the service records a one-way fingerprint of the request, so that a retry isn’t counted twice, how much audio it was, when it happened, how it turned out, what it cost, and which license or trial it belongs to. That also lets me see how much each license or trial is used. To prevent runaway use, it also counts each license’s or trial’s recent and simultaneous requests. After 30 days, the service deletes how much audio a request had and what it cost. It keeps the request’s fingerprint, time and outcome, and which license or trial it belongs to, for as long as the service keeps that license or trial, so that an old request can never be charged twice. With a subscription or a trial, each request also keeps how much of your allowance it used and which allowance period it counted against, because that’s how your remaining allowance is worked out. The counts of recent and simultaneous requests are deleted within a day.
Your words
The text that comes back is pasted where your cursor is. To paste, blabe briefly replaces your clipboard with the text, presses ⌘V, and then puts your previous clipboard contents back. If pasting fails, the text stays on your clipboard so it isn’t lost. blabe keeps your last transcript in memory for Copy Last Transcript until you quit. It does not save transcripts to disk, and it does not keep a history. If you turn on sending to coding agents, blabe may also press Return after pasting.
Hints that travel with your audio
Each request also carries your language setting (if you pinned one), the cleanup option, and the list of keywords blabe asks the model to favour: your own words from Settings and, if you keep them on, blabe’s built-in developer terms. The list has at most 50 entries. The service passes them to the model with your audio.
Your license
When you sign in with your license key, blabe sends it, with your Mac's model name (for example “Mac15,3”) and a random ID for this Mac, to blabe's transcription service. The service activates this Mac with Polar as one of your 3 and gives blabe a sign-in token. Your Mac keeps only that token and the random ID in your login Keychain, not the license key.
Each request to blabe’s transcription service carries that token. For a subscription, the service stores your license key, the activation ID, your Polar customer ID and the random ID for this Mac, so that it can check with Polar that your subscription is still active before it transcribes. It also stores your Polar subscription ID and when that subscription started, and, for each monthly allowance period, the period’s start and end dates and how much audio was transcribed in it. Each request record notes which period it counted against. Past periods are kept rather than overwritten, so your usage stays the same if you change Macs or sign in again. None of these records contain audio or your words. The free trial needs no signup and no email address. When you start the free trial, blabe creates a random identifier and keeps it in your login Keychain on this Mac only; it doesn’t sync through iCloud, and it isn’t derived from your Mac’s hardware or from anything about you. blabe sends it, with your Mac’s model name (for example “Mac15,3”), to the transcription service, which stores only a one-way hash of the identifier, when the trial started and how much it has been used. That is how each Mac is limited to one trial, and why reinstalling blabe doesn’t restart it.
Your settings
Your hotkey, language, microphone, sound and sending choices, and your keyword list are stored on your Mac. Only the language, the cleanup option and the keyword list leave it, with your audio, as described above.
What blabe looks at on your Mac
To decide whether it is safe to press Return after a paste, blabe checks which app is in front and, for terminals, which program is running in the tab. This happens on your Mac and none of it is sent anywhere.
Support
If you write to me, I receive your email address and whatever you tell me, and the emails are stored with my email provider. Please don’t send recordings, transcripts or passwords, and don’t send card details. For billing questions, I may ask for your Polar order reference. blabe never uploads logs or diagnostics by itself. In Help → Export Support Bundle…, you can save a file that summarizes blabe’s own logs from the last 24 hours and its recent crash reports, with message text and file paths left out and without audio, transcripts or keys, along with your blabe settings and permission states (not your vocabulary words), and choose whether to email it to me.
Purchases
Polar sells the subscription and is the merchant of record. That means Polar, not I, collects your payment details, billing address and email, and handles payment, tax and receipts. Polar is a controller of the payment data it processes and handles it under its privacy policy. I don’t receive your card details.
As the seller, I can see your customer record in Polar. According to Polar’s documentation, it includes your email address, name, billing name and address (including your country), any tax ID you enter, and your orders and subscriptions. I use it to run the subscription, to send you notices about it, such as a price change, and to answer support questions.
This website
The website sets no cookies and has no third-party scripts, fonts or embeds. To count visits, it uses Umami, an analytics tool I run myself on the same server as the website, so no analytics company receives the data. When you open a page, your browser loads a small script from blabe.dev, which sends back the address of the page you opened, without anything after a “?” or “#”. It sends nothing else from the page: no page title and no referring site. If your browser sends Do Not Track or Global Privacy Control, the script doesn’t load and your visit isn’t counted. Like any request, the script’s request carries your IP address and your browser’s user agent. Umami uses them to work out your browser, operating system, device type and approximate location (country, region and city), and to recognize repeat visits: it combines them, with a secret value that changes every month, into a scrambled visitor ID. It stores that ID, the page, the time and those details, but not your IP address. Umami sets no cookies, stores nothing in your browser and doesn’t follow you to other sites. I use it only to see how many people visit which pages. It is served from a Hostinger VPS in Lithuania. The reverse proxy in front of it logs each request, with your IP address, the time, the page you asked for and your browser’s user agent, for security and troubleshooting. These logs are deleted after at most 30 days. Downloads are served from Cloudflare R2, under Cloudflare’s privacy policy and website terms.
Who else handles your data
I use these companies. Each has its own privacy policy, and I don’t control what they do with data they receive.
- Microsoft (privacy statement) runs the MAI-Transcribe 2 model on Microsoft Azure. It receives your audio and the hints above through OpenRouter and returns the transcript. Microsoft describes how it handles speech data in its documentation on data, privacy and security for speech to text. That page doesn’t name MAI-Transcribe 2.
- OpenRouter (privacy policy, terms) routes the request from blabe’s transcription service to Microsoft, through my OpenRouter account. It sees the audio, the transcript and the hints. Its policy says it doesn’t persist audio beyond the time needed to route the request, except for abuse detection, security, billing or legal compliance.
- Cloudflare (privacy policy, website terms) hosts blabe’s transcription service on Cloudflare Workers, with its records in a Cloudflare D1 database, in my Cloudflare account. Your audio and the returned text pass through the service on Cloudflare. It also hosts the downloads on R2. It sees your IP address and request details when you use the service or download blabe. Where it processes and keeps data is covered by its own policy.
- Polar (privacy policy, buyer terms) is the merchant of record. It processes your payment, tax and receipts, and issues and checks license keys. It uses Stripe to process card payments.
- Hostinger (privacy policy) hosts the server in Lithuania that runs this website. It also hosts the support mailbox; where it keeps that mail is covered by its own policy.
The companies that carry or transcribe your audio (Cloudflare, OpenRouter and Microsoft) decide how long they keep it and where they process it, under the policies linked above, and I don’t promise that they keep nothing. These companies may process data in the United States and other countries.
How long data is kept
- Audio on your Mac: in memory only, until it is transcribed successfully or you quit blabe. Never on disk.
- Transcripts on your Mac: the last one in memory until you quit. Never on disk. Whatever you paste stays in the app you pasted it into.
- Audio, transcripts and request records on blabe’s transcription service: audio and transcript text are not stored; the service holds them in memory only while passing them on. The Mac, request and usage records described above are kept on the service, as are any license, subscription, allowance-period and trial records. Mac records stay while the service keeps the license or trial they belong to; when a Mac’s place is freed, its record is deleted. Each request’s audio length and cost are deleted after 30 days; its fingerprint, time and outcome stay while the service keeps the license or trial it belongs to, so that a retry is never charged twice. With a subscription, the allowance each request used and the period it counted against are deleted 400 days after the request, long enough to cover a yearly billing period. For a trial or a subscription, some of these records can’t be deleted early without letting a Mac start a second trial, or a license be charged twice or get a fresh allowance. Those stay for the periods above, even if you ask me to delete them. Deleted records can remain in Cloudflare’s automatic database recovery history for up to 7 days. License and subscription records (the license and customer IDs from Polar and the Macs activated on them) stay while the license is in use and are deleted 12 months after it was last used, with these exceptions. They stay longer while a Mac’s activation or a request’s outcome is unconfirmed, for example when the service never learned whether a dictation went through, so that nothing is charged twice. The service doesn’t settle an unconfirmed outcome on its own, so those records have no automatic deletion date. After they’re deleted, a minimal record of the license, holding only a one-way hash of it and no license ID, customer ID or sign-in token, stays with its request records until every one of those requests is confirmed and 400 days old; a request that’s never confirmed keeps it with no end date. If I have turned a license off, that minimal record and its request records stay while it remains off, so that signing in again can’t turn it back on. For a license already in use before this schedule began, the 12 months count from no earlier than the day it began, because earlier use wasn’t recorded, so its records can stay up to a year longer. Sign-in sessions are deleted 30 days after they expire or are signed out. A trial’s start and end, with a scrambled form of the Mac’s trial ID, stay for as long as I offer trials, so each Mac gets one trial; the allowance a trial used is deleted 30 days after it ends.
- Support emails: 30 days after the case is closed.
- Diagnostic attachments: 30 days after the case is closed.
- Website server logs: deleted after at most 30 days.
- Website visit statistics: kept for 12 months, then deleted. They don’t include your IP address.
- Payment and tax records: kept, by Polar and in my own records, for as long as tax law requires, generally up to seven years. The 30-day period does not apply to these.
- Sign-in and IDs on your Mac: your sign-in token and this Mac’s random IDs stay in your Keychain until you delete them. Freeing a Mac's place in your Polar customer portal releases its seat. The trial identifier stays in your Keychain, and the service keeps its hashed trial record, so that each Mac is limited to one trial. See the uninstall guide.
- Data held by the other companies named above: under their own policies.
If a dispute or a legal obligation needs a support case kept longer, I keep only what is needed until it is resolved. Copies of deleted email may remain in my email provider’s backups for a while after I delete them.
Security
blabe sends your audio and license details only over HTTPS, and it keeps your license record in the Keychain. No system is completely secure, and I can’t promise that nothing will go wrong.
Your choices
- Press Esc while holding the hotkey to cancel a dictation before anything is sent.
- Free a Mac's place and cancel your subscription in your Polar customer portal.
- Delete blabe and its Keychain entries by following the uninstall guide.
- Choose whether to send me a support bundle.
- Turn on Global Privacy Control or Do Not Track in your browser, and this website won’t count your visits.
Your rights
To use any of the rights below, email support@blabe.dev. I will reply within the time the law requires. To find your data, I may ask for your Polar order reference or the email address you used at checkout. I never need your full license key, so don’t send it. If you only used the free trial, its records on the service aren’t linked to your name or email, so I can’t match them to you; they’re kept only for the periods under How long data is kept. I will handle your request for any personal data I hold, including any that blabe’s transcription service keeps. What the service keeps is described above. For data the other companies named above hold under their own policies, you may need to ask them too.
California
I don’t sell or share your personal information. If you live in California, the California Consumer Privacy Act gives you these rights:
- to know what personal information I collect, use and disclose about you;
- to delete the personal information I hold about you;
- to correct inaccurate personal information;
- not to be treated differently for using these rights.
EU and UK
If you are in the EU or UK, the GDPR or UK GDPR gives you the right to access your data, to have it erased or rectified, to object to how I use it, and to complain to your supervisory authority. I handle these requests the same way, by email. If you ask me to delete your data, I delete what I can. I keep only the records described under How long data is kept that stop a Mac from starting a second trial, a payment from being counted twice or a license I turned off from being turned back on, and anything the law requires me to keep.
Legal bases
Where the GDPR applies, I rely on these legal bases: contract (transcribing your audio through blabe’s transcription service when you use a trial or a subscription, the license and your subscription, and answering your support emails), legitimate interests (security logs on this website, and keeping the transcription service secure and preventing its abuse), and legal obligation (payment and tax records). The service’s Mac, request, license, trial and usage records rely on contract (checking your access and applying any limit) and legitimate interests (preventing abuse and counting a retry only once). The service’s own request logging at Cloudflare is turned off, so I keep no access logs from it. Cloudflare processes connection data, such as your IP address, to deliver and protect the service under its own privacy policy; that relies on my legitimate interest in running the service securely. Counting visits to this website with Umami relies on my legitimate interest in knowing which pages people use.
Children
blabe is not meant for children under 16, and I don’t knowingly collect data from them. If you think a child has sent me data, email me and I will delete it.
Changes to this policy
If I change this policy, I will post the new version here with a new date. For a significant change, I will say so at the top of this page.
Contact
Marcos Montalvo, support@blabe.dev. I aim to reply within two business days. This is a goal, not a guarantee.