Speklo
FeaturesHow it worksLocal-firstFAQAll features
Download

Privacy Policy

Effective Date: August 4, 2026

Last Updated: August 4, 2026

Speklo (“we,” “us,” or “our”) is operated by Janko Tomsic s.p. This Privacy Policy describes how we collect, use, store, and protect your information when you visit our website and when you use our desktop application for meeting on-device transcription and AI-powered summaries.

By using the website or the App, you agree to the practices described in this Privacy Policy.

1. Scope of This Policy

This policy covers two separate things:

  • The website (speklo.com) — Section 2 describes the analytics, cookies, and server infrastructure used when you browse this site
  • The desktop App (Speklo for macOS) — Sections 3 onwards describe what the App stores on your device, what leaves your device, and to whom

The short version: the App follows a local-first architecture — your recordings, transcripts, and summaries are stored on your device, not on our servers. Data leaves your device only when you use AI features with providers you configure, plus limited crash reporting and update checks. The website uses consent-based analytics to understand how visitors use it.

2. The Speklo Website (speklo.com)

2.1 Analytics (PostHog)

We use PostHog to understand how visitors use the website. Depending on your consent choices (see Section 2.3), PostHog may collect:

  • Pages you visit, referring page, and time spent on the site
  • Clicks and interactions with page elements (e.g., which download button you clicked, which FAQ questions you expanded)
  • Browser type, operating system, device type, and screen size
  • Approximate location derived from your IP address
  • Technical error reports if something on the website breaks in your browser

Analytics requests are routed through our own domain (a first-party proxy at speklo.com/ingest) and are processed by PostHog on servers in the European Union. We use analytics data solely to improve the website and the App — never for advertising, and we never sell it.

2.2 Cookies

The website uses the following cookies and browser storage:

NameCategoryPurposeDuration
cc_cookieStrictly necessaryRemembers your cookie consent choices13 months
x-speklo-geoStrictly necessaryStores your country region (derived from your IP address) so we can show the correct consent banner for your jurisdiction1 hour
ph_* / __ph* and browser localStorageAnalyticsPostHog analytics identifiers used to distinguish visitors and sessions — set only in accordance with your consent choices (Section 2.3)Up to 1 year

2.3 Consent and Your Choices

  • European Economic Area, United Kingdom, and most other regions: analytics is off by default and runs only if you click “Accept All” (opt-in)
  • United States: analytics runs by default, and you can opt out at any time via the consent banner or the cookie preferences link (opt-out)
  • We honor the Global Privacy Control (GPC) browser signal as an opt-out of analytics
  • You can change or withdraw your consent at any time using the “Cookie preferences” link in the website footer. On withdrawal, analytics cookies are cleared

2.4 Hosting and Server Logs

The website is hosted on Vercel. Like any web host, Vercel processes standard request metadata (IP address, user agent, requested URL) to serve the site and maintain security. We use the country code that Vercel derives from your IP address solely to select the correct consent banner (Section 2.3); we do not store your IP address ourselves.

2.5 Download and Update Server

App downloads and auto-updates are served from downloads.speklo.com, hosted on Cloudflare infrastructure. When you download the App or the App checks for updates, that server sees your IP address and user agent in standard access logs, like any file server on the internet. The requests themselves contain no personal data beyond this — see Section 6.5.

2.6 Legal Bases for Website Processing (GDPR)

  • Consent (Art. 6(1)(a) GDPR) — analytics cookies and analytics processing
  • Legitimate interest (Art. 6(1)(f) GDPR) — serving the website securely, strictly necessary cookies, and determining the correct consent regime from your approximate location

3. The Desktop App: Information We Collect

3.1 Google Account Information

When you connect your Google account to Speklo via OAuth 2.0, we request the following scopes:

  • openid — To verify your identity
  • email — To retrieve your email address
  • profile — To retrieve your name and profile picture
  • https://www.googleapis.com/auth/calendar.readonly — To read your Google Calendar events (read-only access)

From your Google account, we receive and store locally on your device:

  • Your email address
  • Your display name
  • Your profile picture URL
  • Your Google user identifier

3.2 Google Calendar Data

With your explicit consent via the OAuth flow, Speklo accesses your Google Calendar in read-only mode. We do not create, modify, or delete any events in your calendar. The calendar data we access includes:

  • Event titles (summary)
  • Event start and end times
  • Event attendee names, email addresses, and response statuses
  • Event organizer name and email address
  • Event descriptions
  • Event locations
  • Google Meet and conference call links
  • Recurring event identifiers and recurrence patterns
  • Event color and status

This data is stored locally on your device to match calendar events with meeting recordings and to pre-fill attendee information.

3.3 Locally Generated Data

Through your use of the App, the following data is created and stored locally on your device:

  • Audio recordings (transient) — Captured from your microphone and system audio, or imported from audio files (MP3, WAV, M4A, FLAC, OGG, AAC, WMA). Audio is held only until transcription completes and is then deleted automatically — see Section 9
  • Transcripts — Generated from audio recordings by the on-device transcription engine running on your Mac
  • AI-generated summaries — Created using your configured AI service and API key
  • Custom cross-meeting summaries — Synthesized from multiple meeting transcripts
  • Tasks — Action items extracted from your transcripts, each with the verbatim quote that produced it, plus any owners, due dates, priorities, categories, and tags you assign
  • Vector embeddings — 1536-dimensional vectors used for semantic search across your meeting content
  • Chat conversations — Your questions and AI-generated answers in the meeting chat feature
  • Focus Board content — Kanban cards, tags, assignee assignments, attached images, source links, and AI-generated specifications
  • Meeting notes — Notes you add to meetings
  • Projects and categories — Organizational labels you create

A note on voice data: the App does not generate or store biometric identifiers. It creates no voice embeddings, no voiceprints, and no speaker profiles, and it cannot recognize a person's voice across meetings. Transcripts are separated into speaker turns labelled Speaker 1, Speaker 2, and so on; these labels are anonymous and carry no identity. Earlier versions of the App did generate voice embeddings — that capability, and the data it produced, were removed in version 0.17.0.

Recordings and transcripts still contain the personal data of other meeting participants — see Section 11.

3.4 API Keys You Provide

Speklo operates on a Bring Your Own Key (BYOK) model. You provide your own API keys for third-party services:

  • Anthropic (Claude) — For AI summaries, chat, focus board features, and specification generation
  • OpenAI — For text embeddings, query analysis, and optional AI features
  • Google (Gemini) — For optional AI features
  • Cohere — For optional reranking of chat search results

Transcription requires no API key and no third party. Speech-to-text and speaker separation run entirely on your device. Your audio is never sent to a transcription service.

Your API keys are encrypted using macOS Keychain, your operating system's native secure storage, before being stored on your device.

Your API keys are never transmitted to Speklo or any party other than the respective API service when you use the App's features.

3.5 Automatically Collected Data

Error reports (Sentry): In production builds, the App sends error reports to Sentry (a third-party error tracking service) when crashes or exceptions occur. You can turn this off at any time under Settings → Privacy & Diagnostics; the change takes effect immediately, and when disabled the App does not initialise Sentry at all. Each install is identified only by a randomly generated Support ID, which is not linked to you. These reports contain:

  • Exception stack traces (technical debugging information)
  • App version number
  • Operating system name and version
  • CPU architecture (e.g., arm64)
  • Electron framework version
  • A limited set of technical context entries (“breadcrumbs”) — these may include file names and file system paths from your device, such as the names of audio files being processed. Your operating system username is stripped from paths and email addresses are masked before transmission
  • If an App update fails to install: excerpts of the installer log and related macOS system log entries, and technical metadata about the App bundle (such as its install path and code-signing information), to diagnose the failure

As with any network request, Sentry receives your IP address when a report is transmitted; we do not use it to identify you. Error reports never include your meeting audio, transcripts, summaries, chat conversations, calendar data, or API keys. The App also does not attach screenshots or memory dumps to error reports, because either could contain that content.

Auto-update checks: The App checks downloads.speklo.com for available updates shortly after launch and about every four hours while running. The request itself contains only the current App version; like any web request, it also exposes your IP address and user agent to our download server (see Section 2.5). Updates are downloaded and installed only after you approve them in the App.

3.6 Other Network Connections

  • Google Fonts: The App's interface loads its fonts from Google Fonts servers when it starts. Google receives your IP address and a standard font request; no other data is sent
  • Hugging Face: If you choose to use local (on-device) transcription, the App downloads the required speech-recognition models from Hugging Face once. Only the model download request is made; none of your data is uploaded

4. How We Use Your Information

4.1 Google User Data

We use the Google account information and calendar data we access exclusively to:

  • Display your name, email, and profile picture within the App
  • Retrieve and display your upcoming and recent calendar events
  • Match calendar events with meeting recordings based on timing and attendees
  • Pre-fill attendee lists for meetings using calendar event participant data
  • Display attendee names and avatars in the meetings interface

We do not use your Google user data to:

  • Serve or target advertisements
  • Conduct market research or profiling
  • Sell or transfer data to third parties
  • Train artificial intelligence or machine learning models
  • Send you marketing communications

4.2 Locally Stored Data

All locally generated data is used exclusively to provide the App's core features:

  • Transcription — Converting audio recordings to text on your device, and separating them into anonymous speaker turns
  • Summarization — Generating AI-powered meeting summaries. Transcripts are sent to your AI provider with speakers tagged [S1], [S2], and so on; participant names are not included
  • Action item extraction — Identifying tasks in a transcript, each with the verbatim quote supporting it. This is the only feature that receives your attendee list, so that a task can be assigned an owner
  • Semantic search — Searching across your meeting history using natural language
  • Focus Board — Turning meeting content into kanban cards
  • Chat — Answering your questions about your meetings using retrieval-augmented generation

5. Data Storage and Security

5.1 Local-First Architecture

All your data is stored locally on your device. Speklo does not operate remote servers that store your data. Your data resides in:

  • SQLite database: Contains meeting metadata, transcripts, summaries, tasks, chat history, focus board content, calendar events, and attendee information, at ~/Library/Application Support/Speklo/desktop.db
  • LanceDB: Contains vector embeddings for semantic search, stored in the same user data directory
  • Audio files (transient): Held in an app-internal working directory inside the same user data directory, and deleted automatically once the transcript has been written. The App keeps no audio library and provides no audio playback
  • Focus Board images: Stored in the user data directory under ticket-img/

5.2 Encryption and Security Measures

  • OAuth tokens are encrypted using the Electron safeStorage API, which delegates to the macOS Keychain
  • API keys are encrypted using the same OS-level encryption before being stored in the local database
  • Context isolation is enabled in the App's architecture, preventing the user interface from directly accessing system-level functions
  • Node.js integration is disabled in the renderer process, providing an additional security boundary

5.3 No Remote Data Storage

Speklo does not maintain servers that store your personal data, meeting recordings, transcripts, summaries, or any other user content. Your data lives on your device and under your control.

5.4 macOS Permissions

The App requests the following macOS permissions:

  • Microphone — To record your voice during meetings
  • Screen & System Audio Recording — macOS requires this permission to capture system audio (the voices of other meeting participants coming through your speakers). Speklo captures audio only — no video, screenshots, or screen content is ever captured, processed, or stored

A camera permission entry may appear in the App's technical metadata, but Speklo has no camera feature and never accesses your camera.

6. Third-Party Services

6.1 Services Accessed With Your API Keys (BYOK)

When you use features that require AI processing, Speklo sends data to third-party services using the API keys you provide. You establish a direct relationship with these service providers by obtaining and using your own API keys:

ServiceData SentPurpose
OpenAISummary text, chat queriesText embeddings for semantic search, query analysis, and optional AI completions
Anthropic (Claude)Transcript text (speakers anonymised), chat context, focus board content, and — for action item extraction only — attendee namesAI-generated summaries, action item extraction, chat responses, focus board card processing, specification generation
Google (Gemini)Transcript text, chat contextOptional AI completions
CohereChat search query and retrieved meeting excerptsOptional reranking of chat search results

Each service's processing of your data is governed by their respective privacy policies:

  • OpenAI Privacy Policy
  • Anthropic Privacy Policy
  • Google Cloud Privacy Policy
  • Cohere Privacy Policy

You control which services are used by choosing which API keys to provide. If you do not provide an API key for a service, no data is sent to that service.

6.2 Focus Board Specification Generator

The Focus Board includes an optional specification generator that can read code repositories on your device to produce implementation specifications. If you use this feature:

  • You explicitly select which local repositories the feature may access
  • The App reads files from those repositories in read-only mode — it never modifies, creates, or deletes files in them
  • Relevant file contents are sent to Anthropic to generate the specification, authenticated through your own Anthropic account (your API key or your Claude subscription)
  • Repository contents are not stored by Speklo and are not sent to any party other than Anthropic

6.3 Google Calendar API

Speklo accesses your Google Calendar using OAuth 2.0 with the PKCE (Proof Key for Code Exchange) protocol. The OAuth flow opens your system's default browser for authentication — Speklo never sees or handles your Google password.

  • Access is read-only (calendar.readonly scope)
  • No data is written to your Google Calendar
  • When you disconnect your Google account in the App's settings, your OAuth tokens are revoked at Google's servers and deleted from local storage

6.4 Sentry (Error Reporting)

Production builds of Speklo use Sentry for error monitoring and crash reporting. Section 3.5 describes exactly what these reports contain — including diagnostic log context that may reference file names and paths on your device — and what they never contain (your meeting content, transcripts, summaries, or API keys). Sentry may process this data in the United States, subject to the safeguards described in its Privacy Policy (including EU Standard Contractual Clauses).

6.5 Auto-Update Server

The App checks downloads.speklo.com (Cloudflare-hosted; see Section 2.5) for available updates on launch and about every four hours. The request contains only the current App version number; the server additionally sees your IP address and user agent in standard access logs, as with any web request. Updates are only downloaded and installed with your approval.

7. Google API Services Limited Use Disclosure

Speklo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Speklo:

  1. Only uses Google user data to provide and improve user-facing features that are prominent in the App's user interface (calendar event display, attendee matching, meeting scheduling context)
  2. Does not transfer Google user data to third parties, except as necessary to provide the App's user-facing features, to comply with applicable laws, or as part of a merger, acquisition, or asset sale (with prior user consent)
  3. Does not use Google user data for advertising purposes, including retargeting, personalized advertising, or interest-based advertising
  4. Does not use Google user data to train artificial intelligence or machine learning models other than personalized models used solely to provide features to the specific user
  5. Does not sell Google user data to any party, under any circumstances
  6. Allows users to revoke access at any time via the App's settings or through the Google Account permissions page

8. Data Sharing

  • We do not sell your personal data or meeting content to any third party
  • We do not share your data with third parties for their own marketing or business purposes
  • We do not use your data for advertising, or sell or share it for cross-context behavioral advertising
  • When you use BYOK API services (Section 6.1) or the specification generator (Section 6.2), you are sending your data directly to those services under your own credentials and their privacy policies. Speklo facilitates this connection but does not independently share your data with these providers
  • Technical error reports are sent to Sentry (Sections 3.5 and 6.4) for the sole purpose of improving App stability
  • Website analytics data is processed by PostHog (Section 2.1) solely on our behalf

9. Data Retention and Deletion

Since all App data is stored locally on your device, you maintain full control over data retention:

Data TypeHow to Delete
Audio recordingsDeleted automatically as soon as the transcript is written — no action needed. If transcription never completes, the audio is discarded after 30 days
Individual meetingsDelete from the meetings list in the App
Transcripts and summariesDeleted automatically when the associated meeting is deleted. You can also enable a retention rule in Settings to delete transcripts older than 1 day, 1 week, 1 month, 6 months, or 1 year — off by default
TasksDelete individual tasks on the Tasks page; tasks are also removed when their source meeting is deleted
Google account dataDisconnect your Google account in Settings; OAuth tokens are revoked and local data is removed
Chat conversationsDelete individual conversations in the Chat interface
Focus Board cardsArchive or delete individual cards
API keysDelete individual API keys in Settings
Website analyticsWithdraw consent via “Cookie preferences” in the website footer (clears analytics cookies), or email us to request deletion of analytics data
All App dataUninstall the App and delete the user data directory (see Section 5.1 for location)

When you disconnect your Google account:

  1. Your OAuth access and refresh tokens are revoked at Google's servers
  2. Your encrypted tokens are deleted from the local database
  3. Previously synced calendar events remain in the local database until you delete them manually

Two App features move or copy data at your direction:

  • Watched folder imports: if you configure a watched folder, audio files placed there are imported for transcription and the original file is moved into a .speklo-imported subfolder after a successful import, rather than left in place. The imported copy is deleted once its transcript is written; the moved original is yours to keep or remove
  • Folder sync: if you enable folder sync, the App continuously exports your meeting summaries, custom summaries, transcripts, recaps, and focus board content as Markdown files to a folder you choose. If that folder is synced to a cloud service (e.g., iCloud, Dropbox) or a shared location, your content will leave your device under your control and that service's terms

We do not retain any of your meeting data on remote servers. There is no server-side meeting content to delete.

10. Your Rights

Because Speklo stores all App data locally on your device, you inherently maintain full control over your data:

  • Access: All your data is visible and accessible within the App's user interface. The underlying SQLite database is a standard format that can be opened with any SQLite-compatible tool
  • Modification: You can edit transcripts, summaries, meeting details, tasks, and focus board content directly within the App
  • Deletion: You can delete any data through the App's interface (see Section 9) or by directly removing the database file
  • Portability: Meeting summaries can be copied as text or exported via folder sync as Markdown. The SQLite database is a portable, standard format
  • Revocation: You can disconnect your Google account or delete API keys at any time through the App's settings
  • Restriction: You can choose not to connect Google Calendar or not to provide specific API keys, limiting data collection and processing accordingly

Rights Under GDPR (European Economic Area)

For the limited processing where Janko Tomsic s.p. acts as data controller — website analytics (Section 2) and App error reports (Section 3.5) — you have the rights granted by the General Data Protection Regulation: access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent at any time. To exercise them, use the “Cookie preferences” link in the website footer or contact us at hello@speklo.com. You also have the right to lodge a complaint with a supervisory authority — in Slovenia, the Information Commissioner (Informacijski pooblaščenec), or the authority of your country of residence.

For data the App stores locally, Speklo's local-first architecture means all personal data remains exclusively on your device — you exercise these rights directly by managing your data through the App or your device's file system.

The legal bases for processing are your consent (website analytics; connecting your Google account) and legitimate interest (App stability via error reporting; providing the App's core functionality on your device).

11. Recordings and Other People's Data

Meeting recordings and transcripts inevitably contain the personal data — including voices — of other meeting participants. For this data, you, as the person making the recording, are responsible for having a lawful basis: obtain any consents required by the recording laws of the relevant jurisdictions and inform participants that the recording may be processed by the AI services you have configured. See our Terms of Service (Section 5) for details. Participants' data is handled exactly like your own: stored locally on your device and sent only to the AI providers you choose to use.

12. Children's Privacy

Speklo is not directed at children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has used the App, please contact us at hello@speklo.com.

13. International Users

Your App data is stored locally on your device regardless of your geographic location. When you use third-party API services (Section 6.1), your data may be processed in locations determined by those service providers, which may include countries outside your jurisdiction — review the respective provider's privacy policy for details. Website analytics data is processed by PostHog in the European Union. Error reports may be processed by Sentry in the United States under EU-approved safeguards such as Standard Contractual Clauses.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the App's functionality or applicable laws. When we make material changes:

  • The updated policy will be posted at speklo.com/privacy
  • The “Last Updated” date at the top of this policy will be revised
  • Material changes will be communicated through App update release notes

Your continued use of Speklo after changes to this Privacy Policy constitutes your acceptance of the updated policy.

15. Contact Us

If you have questions about this Privacy Policy or your data, please contact us:

  • Email: hello@speklo.com
  • Website: speklo.com
  • Operator: Janko Tomsic s.p.
Speklo

AI meeting assistant for Mac. Records, transcribes, and summarizes meetings — free. Transcription runs on-device.

Product

  • Features
  • Download
  • FAQ

Connect with me

  • LinkedIn
  • X (Twitter)

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Speklo. All rights reserved.

Operated by Janko Tomsic s.p., Slovenia · hello@speklo.com

Built for macOS · Apple Silicon native