Privacy Policy

Privacy Policy

This page states what this website and the SayIt app come into contact with, and what they do not. It is written from the actual code and updated when the code changes.

Last updated 2026-10-12 · Version 1.1

1. This website

This website (sayit.plutokeating.beer) is purely static: no server-side database, no cookies, no analytics scripts, no advertising, no third-party fonts.

  • Your language preference is kept in your browser’s localStorage (key sayit.lang); whether the home page’s opening animation has played is kept in sessionStorage (key sayit.intro, cleared when the tab closes). Both stay on your device and can be cleared in the browser at any time.
  • The download page has your browser read Android release information from this site’s version endpoint (/api/version). The request carries no identity, and the site does not record who you are.
  • The site is hosted on Cloudflare. As the hosting and network provider, Cloudflare may process connection logs (such as IP addresses) under its own privacy policy; this project does not read or keep those logs.
  • The typefaces (Inter and a subset of Noto Sans CJK) are self-hosted; nothing is requested from third parties.

2. Data on your phone

Recordings, text, photos, rough drafts and final drafts all live in the app’s private directory on your phone. They are excluded from system cloud backup and device transfer. The author runs no server that keeps any of this.

  • Recording starts only after you hold the power button or tap Speak. Audio is written to the phone in 10-second chunks and merged into one WAV file when you stop. The app has no wake word and never listens in the background.
  • The rough draft is produced offline by a speech-recognition model (sherpa-onnx) on the phone. The model files are downloaded from GitHub Releases on first use, so GitHub sees your IP address at that point. The model catalogue comes from this site’s /api/models without any identity; if unreachable, the app uses its built-in copy.
  • Photos you pick are compressed and stored on the phone. The originals are neither kept nor uploaded.
  • Permissions: microphone (required to record), notifications (the persistent notice while recording), camera and photo library (only when you choose the photo mode), network (only for the final draft, the model catalogue and model downloads). The app does not read your location, contacts or other apps’ data.
  • Settings (sound, draft language, Wi-Fi-only final drafts and so on) stay on the phone. The app includes no analytics SDK and does not measure your usage.

3. Account

Recording, the rough draft, reading back and export need no account. Only the final draft requires signing in with a PlutoKeating account (id.plutokeating.beer ), the single account run by the author and shared with the author’s other products.

  • Sign-in uses the standard OIDC authorization-code flow. The app is the public client sayit-app and requests only openid, profile, email and offline refresh. Tokens are kept in the phone’s secure storage and removed when you sign out.
  • The account service keeps your email, your sign-in methods and sign-in records. What exactly it stores and how to delete the account is described by id.plutokeating.beer itself.
  • On every final-draft request this site’s server verifies the token and reads from it the account id (sub), the client id, and the email and display name if present. The server has no user table and keeps no account data.

4. The final draft and third-party language models

To produce a final draft, the app sends that one entry’s material over HTTPS to https://sayit.plutokeating.beer/api/entries/finalize: the audio (WAV, up to 25 MB), the on-device rough draft, any text you typed, photos (up to 4, each up to 10 MB) and a language hint. After verifying your sign-in, the server forwards them to a third-party language-model provider configured by the operator, together with instructions that allow clean-up only and forbid continuing or commenting, then returns the cleaned text and the name of the model that handled it to the app.

  • The server stores no content. Audio, text and photos exist in memory only while that request is being handled and are discarded when it ends. The server has no database or object storage for this content.
  • The server writes a metadata-only log: time, account id, client id, entry kind, audio size in bytes, number and size of photos, character counts of the draft and text, outcome (success, failure or rejected), the model used and its token usage, and each attempted provider with its duration. These logs are kept by Cloudflare’s Workers logging; retention is set by Cloudflare, and this project does not export or analyse them further.
  • The third-party provider receives that entry’s audio (if it supports audio), photos (if it supports images), the rough draft and the text, and handles them under its own privacy policy. Providers are configured by the operator and may change; they are tried in the configured order, moving to the next on failure. You can ask by email which providers are currently in use.
  • A provider may reject content it deems to violate its rules. The app then marks the entry as failed; the audio and the rough draft are unaffected.
  • The final draft is clean-up only: punctuation, paragraphs, filler words removed, misheard words fixed. This project trains no models and uses your content for nothing else; whether a provider trains on it is governed by that provider’s own policy.

5. What is not collected

  • Neither the website nor the app has advertising, third-party analytics, browser fingerprinting or behavioural profiling.
  • Your content is given to no one except the language-model providers in section 4. It is never sold or rented.
  • No location, contacts, messages or other apps’ data are read.
  • There is no wake word.

6. Retention and deletion

  • In the app: Delete on an entry removes its audio, photos and text together. Settings lets you export everything as a zip and see storage usage. Uninstalling the app removes all local data.
  • On the server: your content is not stored, so there is nothing to delete. Retention of the metadata log is set by Cloudflare.
  • Account: managed at id.plutokeating.beer. To delete the account or ask what it holds, send an email.

7. Minors

This website and app are not directed at children under 16, and we do not knowingly collect their information.

8. Changes

When features change, the data flow is re-checked before this page is updated. Updates take effect when published here, with the date and version shown at the top.

9. Contact

Privacy questions go to PlutoKeating by email: PlutoKeating@outlook.com.