Legal
Privacy Policy
Trace runs entirely on your Mac. It has no accounts and no telemetry, and your audio never leaves the device. Trace uses the network for a one-time model download, for the licence check and updates if you bought direct from us, and for anything optional you switch on yourself, such as Google Calendar or a custom AI endpoint. The Mac Calendar option reads on-device and uses no network.
The short version
Trace runs entirely on your Mac. Your audio, transcripts, summaries, and saved speaker names never leave the device. The one exception is one you set up yourself. If you point the optional AI features at a custom endpoint, the transcript text they work on goes to the server you chose, described under “Custom AI endpoint” below. The app has no accounts, no telemetry, and no meeting bots, and collects nothing about you at all. Our website uses self-hosted, cookieless analytics with no personal data, which we explain under “Website analytics” below. The one time we hold any personal data on the web is if you join our optional referral program, described under “Affiliate program” below.
Trace Companion, our optional iPhone app, records on your phone and sends each recording straight to Trace on your Mac over an encrypted connection between the two devices. It never sends anything through the internet, and it collects nothing about you either. It is described under “Trace Companion for iPhone” below.
If you downloaded Trace direct from our website rather than the Mac App Store, the app makes a licence check to confirm your purchase (described under “Licence and updates” below). That check sends a one-way fingerprint of your Mac and your licence key. It never sends your audio, transcripts, or anything you record.
Trace offers an optional calendar connection so sessions can be named after the meeting you’re in. You can use your Mac’s calendar, which Trace reads entirely on-device through macOS and which sends nothing over the network, or connect Google Calendar directly. Either way it’s off by default, you turn it on yourself, and nothing about your recordings is ever shared with Google or anyone else.
What Trace does on your device
Trace records audio (microphone and/or system audio) when you start a recording, transcribes it locally using an on-device speech recognition model, and saves the resulting audio and transcript files inside the app’s sandboxed container under ~/Library/Containers/.
Each session is its own folder containing mic.wav, system.wav, transcript.json, transcript.md, meta.json, and, once you summarise it, summary.md. If you have turned on compression, the audio files are mic.m4a and system.m4a instead. The meta.json file holds the session’s name, its start and end times, its length, and a log of transcription attempts. Like the rest of the folder, it stays on your Mac. The quickest way to open one is to right-click a session in the menu bar list and choose Reveal in Finder. You can also browse, copy, move, rename, or delete sessions directly from Finder.
If something is said in a meeting that shouldn’t have been recorded, you can erase the last few seconds while the recording is still running. Trace overwrites those samples with silence in the recording files on your Mac, so the audio is gone from the files themselves rather than hidden from the transcript. There is a short countdown you can cancel; once it finishes, the erased audio cannot be recovered.
If you turn on Spotlight indexing (off by default), Trace adds each finished recording’s title, transcript text, and named speakers to macOS’s own Spotlight index so they show up in system search. That index is part of macOS on your Mac; turning the setting off removes Trace’s entries again.
Speaker identification
After the system-audio track is transcribed, Trace runs an on-device speaker identifier so each distinct voice on the call gets its own numbered label (Speaker 1, Speaker 2, and so on). This uses two open-source models that ship alongside the speech model: a Pyannote-based segmentation model that finds speech boundaries, and a WeSpeaker embedding model that distinguishes voices. Both run locally on the Mac. No audio leaves the device for speaker identification.
Those voices start out numbered, and you can give them real names after a call. If you let Trace remember voices across calls, it stores a numeric voiceprint and the name you gave in a registry on your Mac, never any audio, so it can suggest that name when it hears the person again. You confirm every suggestion. This voice memory stays on your Mac and is never uploaded, and you can rename, merge, or forget any voice in Settings.
On-device summary (optional)
You can ask Trace to summarise a meeting. It runs Trace’s own on-device language model (an open-weights model downloaded once and run locally through MLX), and writes a summary.md next to the transcript. It is not copied to your clipboard unless you turn that on in Settings. Like everything else, this happens on your Mac. The transcript, the summary, and your audio never leave the device, and there is no cloud step. It is off until you press the button.
The same local model powers the other AI features: asking questions about a meeting, a folder of meetings, or everything you have recorded, and the optional automatic naming and tagging of recordings. Questions and answers are worked out on your Mac from your own transcripts and are never sent anywhere. Conversations are saved on your Mac alongside the recordings they are about, so you can come back to them, and you can delete any of them from the app. (If you have configured a custom endpoint, these features use it instead, described next.)
Search index (on your Mac)
To find recordings quickly, Trace keeps a search index on your Mac: one file in Trace’s own storage holding the words of each transcript, the recording’s name, and its speakers and tags. It is built and read locally and never uploaded. With AI features on, search can also match on meaning. That uses a second, smaller open-weights model, downloaded once from the same public model repository as the speech model and run locally, to turn each transcript into numbers the index can compare. Those numbers stay in the same local file. Deleting a recording removes it from the index.
Translation (optional)
Trace can translate the live recap and finished transcripts into your language. This uses Apple’s translation framework, which runs its models on your Mac; the words being translated are not sent to Apple or anywhere else. The first translation to or from a language downloads that language’s pack from Apple through macOS’s own consent sheet, and after that translation works offline. A translated transcript is saved next to the original on your Mac, and the original is never modified. Translation needs macOS 15 or later.
Custom AI endpoint (optional)
If you would rather run the AI features through a model of your own, you can point them at any OpenAI-compatible server in Settings under AI. That can be a local server like LM Studio or Ollama, or a hosted API you have an account with. It is off by default and only ever set up by you.
While a custom endpoint is selected, the text the AI features work on is sent to that server. The transcript (and, for questions, your question) goes to the base URL you entered, and the summary, name, tags, or answer comes back. Nothing else is sent. No audio ever leaves your Mac, and live transcription always runs on-device regardless. Who operates that server, and what they do with the text, is between you and them. With a local server the text never leaves your machine at all; a hosted provider handles it under their own privacy terms.
The API key, if the server needs one, is stored in your Mac’s Keychain, never in a plain file. Switch the model setting back and the endpoint is no longer contacted.
Required network requests
Before any transcription happens, Trace downloads your chosen speech model and its speaker-identification model (roughly 220 MB to 950 MB, depending on the model you pick) from Hugging Face on first use. The live recap fetches its own streaming model (about 640 MB) the first time you record, the optional summary feature downloads its language model (a few GB) the first time you summarise, and translating to or from a language for the first time downloads that language’s pack from Apple. After that, everything runs entirely offline. These downloads are the only network requests Trace must make to work.
That download is the only reason the Mac App Store version of Trace declares the network.client entitlement. No audio, no transcripts, and no metadata are ever sent anywhere, unless you have deliberately pointed the AI features at a custom endpoint (above), in which case transcript text goes to the server you chose.
There is also an Offline mode switch in Settings. While it is on, Trace declines to start any network request of its own, including these downloads and calendar syncs, until you turn it back off.
Licence and updates (website download only)
This section applies only if you downloaded Trace direct from our website. The Mac App Store version has no licence check and no update server; for it, the store is the gate, and everything above still describes the whole story.
The website version is sold direct, so it needs to do two things the store used to do for us: tell a paid copy apart from a free trial, and update itself. Both involve talking to a small Trace service.
What the licence check sends. To start your free trial, activate your key, or re-check an active licence, the app contacts our licence service over HTTPS and sends:
- a one-way fingerprint of your Mac: a hashed value derived from a stable hardware id. It is hashed on your Mac with a Trace-specific salt before it is sent, so it can’t be tied back to your hardware or to any other product, and we never receive the raw id; and
- your licence key (once you have one), and a name for the Mac you choose, so you can recognise your activations.
It never sends your audio, transcripts, summaries, calendar data, or anything you record. The fingerprint exists only to bind your trial and your two-Mac limit to actual machines; it is not used for advertising, profiling, analytics, or tracking you across the web.
How often it checks. Your trial start is confirmed once, online. A paid copy re-checks occasionally during its first 30 days (the refund window), and after that it stops checking and runs fully offline forever. So a bought copy of Trace settles back into living entirely on your Mac.
Your purchase. Payment is taken by our reseller, Paddle, who is the merchant of record. Your card details go to Paddle, never to us; we receive only your email and a record that a purchase happened, which is what lets us email you your key. Recovering a lost key sends an email to the address you bought with.
Updates. The website version updates itself with Sparkle, an open-source updater for Mac apps. It checks our update server for a newer signed build and installs it when you agree. The update check sends only what’s needed to ask “is there a newer version”, no audio and no transcripts.
The licence and update servers are run by us (Trace), not a third party, on our own infrastructure.
Calendar (optional)
Trace can optionally read your calendar to name sessions automatically (using the current meeting’s title) and nudge you one minute before a meeting starts. This is off by default. You pick a source once during onboarding or any time from Preferences, and you can turn it off whenever you want. There are two sources, and you choose which one (if any) to use:
Mac Calendar (on-device)
If you choose Mac Calendar, Trace reads your upcoming events through Apple’s EventKit framework, which is part of macOS. This covers every account you have set up in the Calendar app (iCloud, Google, Exchange, and others) without connecting anything yourself. It is entirely on-device: there is no sign-in, no token, and no network request. Trace asks macOS for read-only calendar access the first time you select this source, and you can revoke it any time in System Settings → Privacy & Security → Calendars. Calendar data read this way is never written back, never stored to disk, and never leaves your Mac.
Google Calendar (optional)
Alternatively, you can connect Google Calendar directly so Trace can name your sessions and fire the one-minute reminder. This is off by default. You enable it once during onboarding or any time from Preferences, and you can disconnect whenever you want.
The rest of this section is the full disclosure of how Trace uses Google user data, as required by the Google API Services User Data Policy.
OAuth scopes Trace requests
When you connect the integration, Trace asks Google for three scopes:
https://www.googleapis.com/auth/calendar.readonly: read-only access to your calendars and events. Trace uses this to name sessions and to time the one-minute reminder. Trace cannot create, update, or delete anything on your calendar.openid: standard OpenID Connect sign-in, so Google can identify which account you connected.email: so Trace can show you the email of the connected Google account in Preferences, which lets you confirm you authorised the right one before you start using it.
Trace does not request, and has never requested, any other Google scope. These three are the minimum set that the integration needs to function.
Data Trace accesses
From the Calendar API, for events in a short window around the current time (roughly the next 15 minutes and the last few minutes of a running meeting), Trace reads:
- Event title
- Event start and end times
- Calendar name and ID
From the OpenID Connect userinfo endpoint, once at connection time, Trace reads:
- The Google account email address
That is it. Trace does not read event descriptions, attendee lists, locations, conferencing URLs, attachments, free/busy data, contacts, Drive files, Gmail, or anything else.
How Trace uses that data
- Event title: used as the default name for a recording session that overlaps the event, and shown in the one-minute reminder so you can see what’s about to start.
- Event start and end times: used to decide when to fire the one-minute reminder and which event a recording should be named after.
- Calendar name and ID: shown in the Preferences calendar picker so you can choose which calendars to include.
- Account email: shown in Preferences so you know which Google account is connected.
Trace uses this data only for the features above. It is never used for advertising, profiling, training AI models, analytics, or any secondary purpose.
Data sharing
Trace does not share Google user data with anyone. No Trace server ever receives your Google data (the website version’s licence server handles licence keys, machine fingerprints, and, if you join the referral program, your affiliate details, never calendar data), there is no third-party analytics or error-reporting SDK, and no human (including the developer of Trace) can see your Google data. All Google API calls go directly from your Mac to Google over HTTPS.
Trace does not sell, rent, trade, or transfer Google user data to any third party under any circumstances.
Data storage and protection
- OAuth tokens (access token and refresh token) are stored in the macOS Keychain under Trace’s bundle ID (
info.traceapp.trace), protected by the operating system’s standard Keychain access controls. - Calendar events are never written to disk. They live only in Trace’s in-memory cache for the short look-ahead window described above, and are discarded when the app quits.
- Account email is stored once in user defaults inside Trace’s sandboxed container, for display only.
- Trace runs inside the macOS App Sandbox, so no other app on your Mac can reach the tokens or the cached events through Trace.
- All requests to Google’s OAuth and Calendar endpoints are made over HTTPS with TLS 1.2+, and the OAuth flow uses PKCE so the authorisation code cannot be intercepted.
Data retention and deletion
- Calendar events: not retained. They live in memory only and vanish as the window rolls forward or the app quits.
- OAuth tokens: retained on your Mac in the Keychain until you disconnect. When you click Disconnect in Preferences, Trace deletes both the access and refresh tokens from the Keychain immediately.
- Account email: deleted from user defaults when you disconnect.
- You can also revoke Trace’s access at any time from your Google account’s Connected apps page. The next time Trace tries to use its token, Google will reject it and Trace will clear its local copy.
- Uninstalling Trace removes its container, which removes all locally stored Google data (tokens and email). The Keychain item is removed alongside the container.
- Because no Google user data ever leaves your Mac, there is no server-side copy for anyone to delete. If you want to confirm a full wipe, disconnect in Preferences, then revoke access on Google’s Connected apps page, then delete Trace’s container under
~/Library/Containers/info.traceapp.trace/.
Compliance with Google’s Limited Use requirements
Trace’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Trace does not:
- use Google user data to serve advertisements,
- transfer Google user data to any third party except as necessary to provide or improve the user-facing features of Trace (which, since Google data never touches a Trace server, means it does not transfer Google user data to anyone),
- use Google user data to train generalised or personalised AI or machine-learning models, or
- allow humans to read Google user data, except with your explicit consent, to comply with applicable law, or to investigate abuse in line with Google’s policy.
What Trace does NOT do
- Trace does not create user accounts. There is no login, ever. The website version uses a licence key instead, and recovery is by your purchase email.
- Trace does not upload your audio, transcripts, or any derived data, not to us, not to anyone (completely firewall it off if you want!). The website version’s licence check sends a hashed fingerprint of your Mac and your key to confirm your purchase, never your audio or transcripts, as described under “Licence and updates” above.
- The Trace app does not include analytics, telemetry, or any third-party crash-reporting SDK. See “Apple system diagnostics” below for the one platform-level exception. (The website’s cookieless analytics are described under “Website analytics” and never touch the app.)
- Trace does not use advertising, tracking, or third-party SDKs.
- Trace does not access or read any files other than the session recordings it creates itself. The optional
traceclicommand-line tool reads those same session files and makes no network calls of its own. - Trace does not record video and never captures your screen continuously. The optional screenshots feature captures a still image of one screen region, and only at the moment you ask for it (⌘⇧S while recording). Each screenshot is saved with that session on your Mac, the same as the audio and transcript. The “System Audio Recording” permission macOS requires is used solely to capture the system audio stream via Core Audio taps.
- Trace does not watch keystrokes. Its global shortcuts are registered through the Mac App Store safe Carbon API, which notifies Trace only when one of its own shortcuts is pressed.
Trace Companion for iPhone
Trace Companion is an optional iPhone app that records in-person meetings and sends them to Trace on your Mac to be transcribed. The iPhone transcribes nothing itself. The app has no accounts, no analytics, no advertising, and no third-party SDKs, and it collects no data about you.
What the app stores on your iPhone
When you record, the app saves the audio and a small record of the recording in its own storage on your iPhone. The record holds the recording’s name, start time, length, and any key moments and notes you added. That storage is excluded from iPhone backups, so your recordings are never copied to iCloud Backup or to a computer backup. You can delete a recording in the app at any time.
How recordings get to your Mac
You pair the app with one Mac by scanning a code that Trace shows on that Mac. After that, whenever you open the app near your Mac, it finds the Mac over your local network or a direct Wi-Fi link between the two devices, and sends any recordings that are waiting. The connection is encrypted end to end with keys that only your iPhone and your paired Mac hold. Recordings never go through the internet, iCloud, or any server of ours.
Each recording stays on your iPhone until your Mac confirms that it has a complete copy and that the copy matches the original. The app then deletes the audio from your iPhone. It keeps the small record, so the list still shows what you recorded and which Mac it was sent to.
The pairing keys are stored in your iPhone’s Keychain. Unpairing removes the pairing from your iPhone. Recordings that haven’t been sent yet stay on your iPhone until you pair again or delete them.
Permissions the app requests
| Permission | Why |
|---|---|
| Microphone | To record meetings. The microphone is used only while a recording is running. |
| Camera | Only to scan the pairing code your Mac shows. Nothing from the camera is saved. |
| Local Network | Only to find your paired Mac and send it your recordings. |
The Lock Screen and Dynamic Island controls, the Control Center button, and the Shortcuts actions start and control recordings on your iPhone. They send nothing anywhere.
If you share analytics with app developers in your iPhone’s settings, iOS may forward anonymised crash reports to us, the same way macOS does under “Apple system diagnostics” below.
Apple system diagnostics
If you’ve opted into Apple’s system-wide developer diagnostics in System Settings → Privacy & Security → Analytics & Improvements → Share with App Developers, macOS may forward anonymised crash reports to us via App Store Connect. This pipeline is handled by macOS itself, not by Trace, and you control it per-device in System Settings.
These reports contain stack traces and device metadata only. They never include your audio, transcripts, session content, or any field that identifies you. We use them only to spot crashes that need fixing.
Permissions Trace requests
| Permission | Why |
|---|---|
| Microphone | To record your voice for transcription |
| System Audio Recording | Required by macOS to capture system audio via Core Audio taps (no video is ever captured) |
| Screen Recording | Only for the optional screenshots feature, to capture the screen region you choose. Requested when you first use screenshots, and used for nothing else. |
Trace does not request Accessibility permission. Global shortcuts use Carbon’s Mac App Store safe hotkey API, which does not need it.
All permissions are requested at first launch and can be revoked at any time from System Settings → Privacy & Security.
Default global shortcuts
Every shortcut is configurable in Settings → Shortcuts.
| Shortcut | Action |
|---|---|
⌘⇧R | Start or stop recording |
⌘⇧K | Flag a key moment |
⌘⇧P | Pause or resume the current recording |
⌘⇧H | Show or hide the floating pill |
⌘⇧? | Reveal the recap of the last few minutes |
⌘⇧E | Erase the last few seconds of the recording |
Trace also exposes actions to Apple’s Shortcuts app and Spotlight (such as Start, Stop, Capture key moment, Get last transcript, and Get last summary), and it can run a Shortcut of your choice when a transcription finishes. The read actions hand your own on-device transcript or summary to a Shortcut you build, and make no network request of their own. If a Shortcut you write then sends that text somewhere, that copy leaves your Mac, but that is your Shortcut’s doing, not Trace’s.
Website analytics
Our website (traceapp.info) uses self-hosted, cookieless analytics that we run on our own infrastructure. It counts page views and roughly where visitors came from, for example which newsletter linked to us, so we can tell which write-ups actually reach people. It stores no personal data, sets no cookies, and does not track you across other sites. Because we host it ourselves, the data never goes to a third-party analytics company.
This is about the website only. The Trace app still collects nothing, sends nothing, and has no analytics of any kind, exactly as described above.
Affiliate program (optional)
If you join our referral program at traceapp.info/refer, we keep a small amount of data so we can run it and pay you. You sign in with your email, so we store that email, and we keep the payout email you give us (a PayPal or Wise address) so we can send your commission. For each referred sale your link brings in, we record the Paddle transaction it came from, the amount, and the commission you have earned. Your payment always goes through Paddle, so we never see the buyer’s card details.
You need to own Trace to take part, so when you sign in we check your email against our record of website purchases. If you bought on the Mac App Store or on Setapp there is nothing for us to check, because neither store tells us who bought. You can ask us to approve you by hand, and if you do, we store which store you named and whatever note you write for us, so we can check it and keep a record of why we let you in.
Signing in to your dashboard sets one cookie. It is a private session cookie that keeps you logged in, it is not used for analytics or advertising, and it is shared with no one. That is the only cookie our website sets, and only for affiliates who have signed in.
Joining is optional and separate from buying or using Trace. If you want your affiliate data deleted, email us and we will remove it. The affiliate terms at traceapp.info/affiliate-terms describe the program in full.
Third-party services
Trace talks to these third-party services, all described above:
- Hugging Face, once, for the speech model download on first launch. Required for transcription to work.
- Google, only when you explicitly connect the Google Calendar integration. Read-only, off by default, and you can disconnect at any time from Preferences.
- Paddle, only if you buy Trace direct from our website. Paddle is our reseller and merchant of record and handles your payment; your card details go to Paddle, not to us.
- Your custom AI endpoint, only if you configure one in Settings under AI. Trace sends transcript text there for summaries, naming, tags, and questions. You choose the server, and you can switch it off at any time.
The Mac App Store version talks to none of these except Hugging Face (plus Google, if you connect it, and a custom AI endpoint, if you configure one). The licence and update servers used by the website version are run by us, not a third party.
Trace Companion for iPhone talks to none of these, and to no other third-party service.
Nothing else. The optional Mac Calendar source is not a third-party service: it reads events on-device through macOS and contacts no server at all.
Children
Trace is not directed at children under 13 and does not knowingly collect any information from anyone (of any age).
Data retention and deletion
All recordings and transcripts remain on your Mac until you delete them. The raw audio is the one thing Trace can tidy for you, and in Preferences you can keep it, delete it as soon as the transcript is ready, or clear it after a window you set. That cleanup happens locally. By default it removes only the audio, and you can set it to clear the whole recording instead, transcript and summary included, if you would rather nothing lingered. You can delete individual sessions from the menu bar (right-click, Delete) or by removing their folder in Finder. To wipe everything, find Trace’s container in ~/Library/Containers/ and remove it. Uninstalling Trace does not automatically delete your recordings. This is intentional, so your data isn’t lost if you reinstall.
Changes to this policy
If this policy ever changes, the new version will appear at the same URL and the “Last updated” date at the top will change. Because Trace collects so little, material changes are unlikely.
Contact
Questions, concerns, or privacy-related requests: