Website and beta data flow

Privacy Notice

Who this notice covers

This notice covers the SkimSpeak public-beta waitlist and the invited SkimSpeak app beta for United States users age 18 or older. It describes the current website and build, not every possible future version. During the beta, contact the person who invited you with privacy questions.

When copied text leaves your Mac

SkimSpeak does not transmit clipboard text in the background. A summarized mode sends only after you trigger it and approve the SkimSpeak Beta privacy notice. The app removes certain control data and attempts to replace common credential, Social Security number, labeled banking-detail, long-number, and payment-card patterns before sending, but this redaction is only a safety net and cannot detect every secret or personal detail.

The 100% verbatim path uses the local voice without a summarization model and does not send copied text to a provider. Numeric cleanup still replaces labeled banking details, Social Security number patterns, payment-card patterns, and standalone numbers longer than ten digits in the cleaned Original and local speech. Consult the source application for exact values. Closing the player deletes its temporary audio file through an ordinary filesystem deletion, but cannot retract text already sent for summarization.

The standard public-beta app includes its pinned on-device voice. If voice residency is set to 20 minutes or Always, SkimSpeak may initialize that bundled voice locally after launch, including before provider consent, so setup time absorbs the first-use delay. This initialization reads no source text and sends no text, summary, credential, audio, or model request over the network. Off releases it after a read; Always keeps it resident only until SkimSpeak quits.

Who processes summarized text

With included Beta access, the request passes through a SkimSpeak relay hosted by Cloudflare and then uses a server-controlled set of approved model routes. GPT-OSS can go directly to Cerebras's official API; DeepSeek and the Groq-pinned GPT-OSS route go through OpenRouter. Direct Cerebras requests fix the endpoint and model and request low reasoning and streaming. OpenRouter requests require Zero Data Retention routing, deny model-provider data collection, and enforce server-selected model/provider and price limits. Operational, abuse, security, billing, and legally required metadata may still exist under the participating third parties' policies.

If a fast route fails before producing visible summary text, the relay may send the same sanitized source once more through its privacy-qualified control route. Up to two privacy-qualified upstream routes—and potentially both Cerebras and OpenRouter—may therefore process one summary request, while it uses no more than one included Beta summary.

Those providers apply their own terms and privacy policies. Provider output can be incomplete or wrong. SkimSpeak does not claim to control third-party retention or make their commitments on their behalf.

What SkimSpeak stores

Website and download data

If you join the public-beta waitlist, the site stores the normalized email address you submit plus content-free confirmation claim, delivery, and retry timestamps. Resend receives the address and a one-time confirmation message so it can tell you that you are on the list. SkimSpeak will use that address to send the requested public-beta access message when the September 1 release is ready. The waitlist confirmation contains no download link, invitation, Beta pass, unlock code, source text, prompt, or summary.

If you use the separate invitation-only download flow, the site stores the normalized email address plus content-free request, delivery, and cooldown timestamps. Resend receives the address and the transactional message so it can deliver that email. The gated download flow separately stores hashed invitation and ticket values, download counts, and ordinary hosting and security metadata. An email row does not contain an invitation, download ticket, Beta pass, summary count, source text, prompt, or summary, and it has no database relationship to those records.

The app archive has no public download address. Emailed download links expire after 30 minutes and work once. The site does not sell signup emails and does not receive app clipboard text unless a user explicitly triggers a summarized read.

A beta-extension request stores only the normalized email, first and last request timestamps, and a delivery status in its own table. Network rate limiting happens outside that table. The request does not create a code automatically; if approved, an operator issues a separate code manually. Neither the email row nor the acknowledgement message is joined to a Beta pass, token, usage count, source text, prompt, model request, or summary.

Your controls

In Settings you can withdraw the Beta privacy choice, change local logging, and inspect Beta access status. You can uninstall by deleting the app, its Application Support folder, and its Keychain item. Requests about upstream-provider-held data must go to that provider.

Children, regulated data, and security

This beta is not for anyone under 18. Do not use it with protected health information, regulated data, or third-party confidential material. SkimSpeak offers no BAA or DPA for this beta. No system is perfectly secure; use your own judgment and do not send material whose disclosure would be unacceptable.

Changes

A material change to what a future build sends or retains will be reflected in an updated notice and effective date. See the Beta Terms and EULA for the license and current Beta limits.