What leaves your Mac
While recording, microphone audio is sent over an encrypted connection to a third-party cloud speech-recognition service, which returns transcript text to the app. Formidable obtains a short-lived, transcription-only token from its service. The reusable production key is never included in the app.
Formidable applies temporary request limits and an aggregate daily service ceiling to protect transcription access. This access service receives no audio or transcript text and stores only an irreversible account-subject hash, hashed Formidable sessions, random account/session IDs, and coarse usage counters. The service does not store your name, email, identity-provider tokens, or password. Each sign-in receives a revocable session. Retired sessions are removed in bounded batches, and an account keeps no more than its 10 newest session records. The app periodically checks a public feed for updates.
Speech-service data handling
The speech-recognition service may process and retain audio and generated text under its own data policies. Formidable does not currently promise zero provider retention or no model training. Do not dictate confidential, regulated, or highly sensitive material.
What stays on your Mac
- A revocable Formidable account session is stored in an owner-only, backup-excluded file. Your basic account label (name and email) is stored in a separate owner-only, backup-excluded file so the app can show which account is active. Signing out removes both local files.
- Temporary provider tokens live only in memory and expire after two minutes.
- Recovery audio is stored temporarily as AES-GCM encrypted ciphertext and is removed after success, Discard, or the next launch after a crash.
- To insert text, Formidable briefly places the transcript on the macOS clipboard for Command-V and restores the previous clipboard when it has not been replaced by a newer copy. Clipboard-history, synchronization, or device-continuity tools may observe or retain that temporary value.
- Diagnostic logs contain state, timing, permission, and error metadata—not intentional transcript text, credentials, or raw audio.
Support and deletion
Formidable automatically sends privacy-filtered crash and performance reports to a third-party diagnostics service. Anonymous diagnostics are always on and cannot be turned off in Settings. Reports exclude transcripts, audio, credentials, field contents, app or website identity, process and provider request IDs, URLs, screenshots, and cursor locations. Random IDs may correlate one app launch or dictation attempt, but are not reused as a device or account identity. The diagnostics provider may derive and retain an approximate city, region, and country from the network request that delivers a report, even though it is configured not to store the source address. Formidable does not request precise device location or send coordinates or an explicit location field. An exported support ZIP is never uploaded automatically and contains no recovery audio.
Share pseudonymous product usage is on by default and can be switched off in Settings. It sends a random installation ID and simple feature-use events such as an app open or confirmed dictation to a third-party analytics service. The service is configured to discard source IP addresses; each event also disables location enrichment and person-profile creation. It never sends words, audio, app or website names, URLs, cursor data, exact duration, or exact word count. Switching it off deletes the local ID.