Website and beta data flow
Privacy Notice
Effective 2026-08-26
Who this notice covers
This notice covers the SkimSpeak public-beta waitlist and the invited SkimSpeak app beta for United States users age 18 or older. It describes the current website and build, not every possible future version. During the beta, contact the person who invited you with privacy questions.
When copied text leaves your Mac
SkimSpeak does not transmit clipboard text in the background. A summarized mode sends only after you trigger it and approve the SkimSpeak Beta privacy notice. The app removes certain control data and attempts to replace common credential, Social Security number, labeled banking-detail, long-number, and payment-card patterns before sending, but this redaction is only a safety net and cannot detect every secret or personal detail.
The 100% verbatim path uses the local voice without a summarization model and does not send copied text to a provider. Numeric cleanup still replaces labeled banking details, Social Security number patterns, payment-card patterns, and standalone numbers longer than ten digits in the cleaned Original and local speech. Consult the source application for exact values. Closing the player deletes its temporary audio file through an ordinary filesystem deletion, but cannot retract text already sent for summarization.
The standard public-beta app includes its pinned on-device voice. If voice residency is set to 20 minutes or Always, SkimSpeak may initialize that bundled voice locally after launch, including before provider consent, so setup time absorbs the first-use delay. This initialization reads no source text and sends no text, summary, credential, audio, or model request over the network. Off releases it after a read; Always keeps it resident only until SkimSpeak quits.
Who processes summarized text
With included Beta access, the request passes through a SkimSpeak relay hosted by Cloudflare and then uses a server-controlled set of approved model routes. GPT-OSS can go directly to Cerebras's official API; DeepSeek and the Groq-pinned GPT-OSS route go through OpenRouter. Direct Cerebras requests fix the endpoint and model and request low reasoning and streaming. OpenRouter requests require Zero Data Retention routing, deny model-provider data collection, and enforce server-selected model/provider and price limits. Operational, abuse, security, billing, and legally required metadata may still exist under the participating third parties' policies.
If a fast route fails before producing visible summary text, the relay may send the same sanitized source once more through its privacy-qualified control route. Up to two privacy-qualified upstream routes—and potentially both Cerebras and OpenRouter—may therefore process one summary request, while it uses no more than one included Beta summary.
Those providers apply their own terms and privacy policies. Provider output can be incomplete or wrong. SkimSpeak does not claim to control third-party retention or make their commitments on their behalf.
What SkimSpeak stores
- The opaque Beta pass is stored in SkimSpeak’s private macOS Keychain item.
- Preferences, consent records, and content-free Beta status are stored in Application Support.
- Generated audio is temporary and deleted when the player closes, a new listen starts, or the app quits.
- Fresh installs keep a local, content-free timing and usage log; it is not sent to SkimSpeak.
- If you deliberately choose a text-bearing local logging mode, redacted source and summary text can remain in local history until you delete it.
- The Beta relay keeps hashed access tokens and content-free quota, timing, status, and abuse-control records. Per-request operations records can include a random request ID, requested summary detail, a coarse source-length band, routing-policy ID, selected pinned route, outcome, bounded upstream and downstream statuses, elapsed, first-body-byte and first-visible-content timing, fallback outcome, allowlisted route, model, provider and finish-reason labels, and bounded integer token counts—not request or response bodies.
- If you explicitly redeem a separately issued +100 code, the relay stores only its one-way hash, a random issuance ID, fixed unit/expiry metadata, and its redeemed subject/timestamp. It never stores or returns the raw code, and your existing Keychain pass is not replaced.
- The relay can hold a transient pre-output buffer of at most 256 KiB solely to detect visible fast-route output. It is never logged or stored and is discarded after delivery or fallback.
- For an unsupported active-window reader, the shortcut first shows a local error. If that build offers Request Feature, only a separate click sends the exact application bundle identifier or fixed source/failure category named in its confirmation. It sends no title, file name/path/extension, URL, text, screenshot, Accessibility tree, clipboard, email, Beta pass, content, device/install ID, or persistent user ID. The credential-free endpoint keeps only a UTC-day aggregate count, with a global daily ceiling on new aggregate keys. Exact unknown-app bundle identifiers make the demand actionable and can reveal which app was foreground. Cloudflare sees ordinary network metadata; short-lived one-way network rate keys are not stored in SkimSpeak's durable database, and request bodies are not logged. The direct transport does not follow redirects or use ambient proxy settings; it reports locally whether delivery was confirmed.
Website and download data
If you join the public-beta waitlist, the site stores the normalized email address you submit plus content-free confirmation claim, delivery, and retry timestamps. Resend receives the address and a one-time confirmation message so it can tell you that you are on the list. SkimSpeak will use that address to send the requested public-beta access message when the September 1 release is ready. The waitlist confirmation contains no download link, invitation, Beta pass, unlock code, source text, prompt, or summary.
If you use the separate invitation-only download flow, the site stores the normalized email address plus content-free request, delivery, and cooldown timestamps. Resend receives the address and the transactional message so it can deliver that email. The gated download flow separately stores hashed invitation and ticket values, download counts, and ordinary hosting and security metadata. An email row does not contain an invitation, download ticket, Beta pass, summary count, source text, prompt, or summary, and it has no database relationship to those records.
The app archive has no public download address. Emailed download links expire after 30 minutes and work once. The site does not sell signup emails and does not receive app clipboard text unless a user explicitly triggers a summarized read.
A beta-extension request stores only the normalized email, first and last request timestamps, and a delivery status in its own table. Network rate limiting happens outside that table. The request does not create a code automatically; if approved, an operator issues a separate code manually. Neither the email row nor the acknowledgement message is joined to a Beta pass, token, usage count, source text, prompt, model request, or summary.
Your controls
In Settings you can withdraw the Beta privacy choice, change local logging, and inspect Beta access status. You can uninstall by deleting the app, its Application Support folder, and its Keychain item. Requests about upstream-provider-held data must go to that provider.
Children, regulated data, and security
This beta is not for anyone under 18. Do not use it with protected health information, regulated data, or third-party confidential material. SkimSpeak offers no BAA or DPA for this beta. No system is perfectly secure; use your own judgment and do not send material whose disclosure would be unacceptable.
Changes
A material change to what a future build sends or retains will be reflected in an updated notice and effective date. See the Beta Terms and EULA for the license and current Beta limits.