1. Who we are
Offloop is made by Founderly, Inc., a corporation organised under the laws of the State of Delaware, United States. In this policy, “Offloop” means the Mac application, “this site” means offloop.work, and “we” and “us” mean Founderly, Inc.
Founderly, Inc. is the controller of the personal data described in section 3. For anything ordinary (a question, a problem, a request), write to hello@founderly.xyz. For privacy requests, data-protection matters and formal written notices, use legal@founderly.xyz.
2. What happens on your Mac
Offloop listens to what you say, reads the screen you are looking at, and types clean text where your cursor is. Speech recognition, the vision model that reads the screen and the language model that cleans up the result are all small models that run on your Mac. There is no server in that path, which is why none of the following is ever sent anywhere:
- Your voice
- Held in memory while the hotkey is down and released the moment you let go. No recording is written to disk and none is transmitted.
- Your screen
- A single frame, read as you speak and freed immediately afterwards. It is never written to disk and never leaves the machine.
- Your text
- Typed at your cursor, in the application you were already using. That is the only place it goes.
- What Offloop keeps
- Your custom dictionary and what the app has learned about the projects you work on: library names, shorthand, the vocabulary you use. This is stored on your own disk so that it is there next time. It stays on your Mac and is not synced, backed up to us, or used to train anything.
None of this is personal data we hold, because we never hold it. It is yours, on your machine, and section 10 explains how to remove it.
Two honest qualifications, rather than hedging every row above. Measurements about your dictation do travel (how many words, how long it took, how much you edited), and section 5 sets those out. And if the app crashes, the report it sends can include a snapshot of its memory, which section 3 explains.
3. What we receive
Section 2 is about the material Offloop handles, which stays with you. This section is about the limited service data we receive:
- Account details. We store your name and email. If you use email sign-in, your password is stored only as a one-way scrypt hash. If you use Google sign-in, Google verifies your identity and gives us your name and email.
- Google Calendar connector. If you choose to connect one or more Google accounts, we store each account's Google identifier, name and email; the identifiers, names and access roles of calendars available to that account; which calendars you selected; and encrypted OAuth access and refresh tokens. Offloop reads upcoming events from the selected calendars and returns only the event title, start and end times, response status, calendar and account identifiers, and Google Meet link needed to show a reminder. The connector has read-only access and cannot create, change or delete a calendar or event.
- Subscription details. We store your plan, subscription status, billing-period end, cancellation state, and the provider identifiers needed to manage Pro access.
- Aggregate usage. To apply account limits and show product history, the app may sync daily word and dictation counts, editing totals, the time of your latest completed dictation, app version, plan status, and related non-content service data.
- Support requests. If you contact support through Offloop, we store your account name and email, ticket subject and message, category, priority, status, timestamps, and any image you choose to attach.
- Product analytics. The app may report bounded events such as which control was clicked, the app surface, app version, a random per-install identifier, and the country from your Mac's region setting. Amplitude does not receive your account ID, email, username, clicked text, input values, pointer coordinates, transcripts, clipboard content, or screen content.
- Crash reports, when the app fails. A crash report contains the state of the program at the moment it stopped: the sequence of function calls that led to the failure, the version of Offloop and of macOS, and the type of Mac. Reports are sent directly to Offloop and stored on our behalf by Amazon Web Services (AWS) in private, encrypted storage for up to 90 days. Where the operating system produces one, a native crash minidump may be uploaded with it; read on.
- Session tokens. Staying signed in means access and refresh tokens accompany authenticated requests.
- Referrals. A referral code at signup, and your account token when the app checks your referral status.
- Catalog, updates, statistics and dictionary downloads. Usually only an API key or your account token and simple parameters, such as how many days of statistics to return.
- Connection information. As with any internet request, your source IP address, the time, the route and standard network headers appear in our AWS service logs.
Technical crash and error reporting is on by default and can be turned off at any time in Settings. Product analytics does not have a separate switch: the anonymised events described above are sent automatically while you use the app. They are tied to an installation identifier rather than to your name or email, and they never carry the material in section 2.
What none of it contains is the material in section 2. No analytics event, and no ordinary crash or error report, carries your speech, a frame of your screen, the text Offloop typed, your custom dictionary, or what the app has learned about your projects. Those never leave the device at all, so there is no path by which they could reach an analytics provider. Those reports describe what you did with the app, not what you said to it.
The native crash minidump is the exception, and we would rather say so than let you discover it. A minidump is a snapshot of the app's memory at the instant it failed. We do not put your dictation into it deliberately, and we do not go looking for it, but because it captures memory rather than a curated list of fields, it may incidentally contain fragments of whatever the app was working on at that moment, which can include audio or text in flight. It is produced only by a crash, it is read only to diagnose that crash, it is never used for analytics or any other purpose, and it is held in the same private, encrypted storage for the same 90 days. Turning off crash and error reporting in Settings stops it being sent at all.
We do not sell personal data, and we do not share it with anyone for advertising. There is no advertising in the app.
4. Payments
Payments for Offloop Pro are handled by Stripe. When you subscribe, your card details are entered into Stripe's own payment form and go directly to Stripe. They never reach our servers and we never see or store them. We keep the Stripe customer and subscription identifiers, plan, subscription status, billing-period end, and cancellation state needed to manage your plan.
Stripe processes this data as an independent controller under its own privacy policy, which you can read at stripe.com/privacy.
5. Your word count
The Free plan includes 2,000 words in each fixed seven-day allowance period. Daily aggregate counts may be synced to your account so the same allowance can be applied across your signed-in devices. These records never include audio, transcript text, formatted text, clipboard content, or screen context.
6. When the app uses the network
Dictation itself is designed to work offline, and after setup it does. The app uses the network for these service functions:
- Once, at setup, to download the models it runs on. After that download completes, dictation works with no connection at all.
- To create and access your account, including email verification and optional Google sign-in.
- To sync Google Calendar, if you connect it. Offloop asks Google for your calendar list and upcoming events on the calendars you select, then shows reminders for events that contain a Google Meet link.
- To check your subscription and sync aggregate usage, so the app can apply your plan and account allowance.
- To send bounded product analytics, as described in section 3.
- To send a crash report, if the app has failed and you have not turned reporting off.
- To create and view support requests, including an image only when you choose to attach one.
- To open the billing portal or change your plan.
- To check your referral status, if you have a referral code.
- To fetch the catalog, updates, your statistics or dictionary downloads.
- To check for updates, so you can be told when a new version is available.
Dictation content is not on this list at any setting. Your speech, screen context, transcript, and finished text have no normal network path.
Any request over the internet reveals your IP address to the server receiving it, and that is true of every one of these. We do not use IP addresses to build a location history; they appear in ordinary server logs, which are kept for a short period for security and debugging and then discarded.
The single exception to the line above is the crash minidump in section 3, which is why it is spelled out there rather than left to be found.
7. This website and cookies
The website is a separate thing from the app, and it is measured differently. offloop.work uses Google Analytics to understand how people find and read the site: which pages are visited, in what order, how long they are on screen, what referred you, and the browser, device type and approximate location that Google derives from your IP address.
Google Analytics sets cookies in your browser to recognise a returning visit and to hold the identifier that ties those page views into a single session. Google processes this data as described in its own privacy policy, and may process it outside the country you are in.
We do not put a cookie banner in front of you, so it is only fair to say plainly what that means: analytics loads when the page loads, and we treat it as our legitimate interest in understanding how the site is read rather than as something you have agreed to. Section 11 sets out that basis. The exception is the first item below, which we act on before anything loads.
You can opt out in any of these ways:
- Send a Global Privacy Control signal. This is the one we act on ourselves, and it is the most complete: when your browser sends it, this site does not load Google Analytics at all. The tag is never requested, no cookie is set, and no request reaches Google. There is nothing to opt out of afterwards. Brave and DuckDuckGo send it by default; Firefox has a setting for it, and several extensions add it. We honour it everywhere, not only where the law obliges us to.
- Install Google’s opt-out browser add-on, which blocks it on every site.
- Turn on your browser’s tracker blocking, or use one that blocks it by default.
Nothing else on the site is third-party. There is no advertising network, no pixel, no embedded video player and no font CDN: the typefaces and every other asset are served from this domain. The site does not ask you to sign in, and nothing you type into it is stored by it.
Our hosting provider also keeps standard server logs, including IP addresses, for security and to keep the site running. We do not analyse them to identify visitors.
8. Who else handles your data
We use a small number of companies to run parts of the service. Each one only receives what it needs for its own job, and none of them receives the material in section 2:
- Stripe
- Payments and subscriptions. Receives your payment details directly and your email address.
- Optional sign-in and Google Calendar connection. Google verifies your identity and provides the calendar data you ask Offloop to read.
- Resend
- Account, security, billing, and support email delivery. Receives the recipient address and email content needed for delivery.
- Amplitude
- Product analytics for the Mac app. Receives the usage events in section 3 and your installation identifier.
- Google Analytics
- Website measurement only. Receives the page-view data in section 7. It is not used in the app.
- Amazon Web Services (AWS)
- Hosts Offloop's backend and privately stores account, aggregate usage, subscription, support, Google Calendar connector, and sanitized crash-report data.
Google Calendar data moves only between Google, Offloop's AWS backend and your Mac. We do not sell it, use it for advertising, use it to train models, or give it to another company. Offloop's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
If we add or replace one of these we will update this section, and the date at the top of the page will change with it.
9. The permissions macOS asks for
macOS will ask you to grant Offloop three permissions. Each one is needed for a specific part of the app to work, and each is used for that and nothing else:
- Microphone
- To hear you. The microphone is opened when you hold or double-tap the hotkey and closed when you finish. Offloop does not listen in the background and has no wake word.
- Screen Recording
- To read the single frame it uses for context: the names, identifiers and terms visible in front of you, so it can spell them correctly. It captures at the moment you dictate, not continuously, and nothing is recorded.
- Accessibility
- To type the finished text into the application you are using, and to know which application that is. It is not used to read the contents of other applications.
You can review or revoke any of these at any time in System Settings → Privacy & Security. Revoking one disables the part of Offloop that depends on it; it does not affect the rest.
10. How long things are kept
On your Mac
Your custom dictionary and what Offloop has learned about your projects stay on your disk until you remove them. You can clear them from Settings, and deleting the application and its support folder removes everything Offloop has stored locally.
On our side
We keep your account record (name, email, password hash and subscription status) for as long as the account exists, and for a short period afterwards for accounting and tax records. Your aggregate usage is kept while the account is active so the allowance can be applied, and is removed with the account. Crash and error reports, including any native minidump, are kept for up to 90 days and then deleted. Product analytics events are kept for up to 24 months. AWS service logs, which hold the connection information in section 3, are kept for a short period for security and debugging. Google Analytics data is retained on Google’s own schedule for the website. Support images expire automatically after 180 days. Support ticket text is kept as needed to respond, maintain support history, and meet legal or security obligations.
Google Calendar connection data is kept while that Google account is connected to Offloop. Disconnecting the account asks Google to revoke the token and deletes the account identity, encrypted tokens, calendar list and calendar selections from Offloop. Upcoming event results are fetched for reminders and are not kept as a calendar archive.
Ask us to delete your account and we will remove your account record, your aggregate usage and your support tickets, except where we are required to keep transaction records by law.
11. Your rights and your choices
The switches
The quickest controls are the ones in the product itself, and they do not require you to write to anybody:
- In the app: Settings lets you turn crash and error sharing off. It is the only in-app switch: the anonymised product analytics in section 3 have no separate toggle.
- For Google Calendar: Connectors lets you choose which calendars Offloop reads, connect more than one Google account, or disconnect an account and delete its connector data.
- On the website: the opt-outs in section 7. Those cover this site's Google Analytics, which is separate from the analytics the app sends.
The legal rights
Depending on where you live, you have rights over the personal data we hold. Those rights generally include asking us for a copy of it, asking us to correct it, asking us to delete it, asking us to restrict or stop a particular use, and asking for it in a portable form. If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority. If you are in California, you have the right to know what we collect, to have it deleted, and to opt out of sharing for cross-context behavioural advertising; we do not sell personal information for money, and the section 7 opt-outs cover the sharing question for the website.
Write to legal@founderly.xyz to exercise any of these and we will respond within 30 days. We will never charge you for making a request or treat you differently for having made one.
Legal bases, if you are in the EEA or UK
We process your email and subscription status to perform our contract with you.
We process Google Calendar data only after you connect an account and approve Google's consent screen. That consent can be withdrawn by disconnecting the account in Offloop or removing Offloop from your Google Account permissions.
We process crash and error reports on the basis of our legitimate interest in finding and fixing faults, and you can override that at any time with the switch in Settings. We process the anonymised product analytics in section 3 on the same basis; as section 3 says, those have no separate switch, so if you want them stopped, write to us and we will act on it.
The website's Google Analytics cookies rest on the same legitimate interest in understanding how the site is read. We do not ask you to accept cookies before they are set, so we do not claim to be relying on your consent for them. The controls that do work are the browser-side opt-outs in section 7. You can also object to this processing by writing to us.
12. Children
Offloop is a professional tool and is not directed at children under 13. We do not knowingly collect personal data from them. If you believe a child has given us their information, write to us and we will delete it.
13. Changes to this policy
If we change this policy we will update the date at the top of the page. If a change materially affects what we collect or what we do with it, we will tell account holders by email before it takes effect, rather than relying on you to notice.
14. Contact
Questions about this policy, or about anything in it, go to hello@founderly.xyz. Privacy requests and formal written notices go to legal@founderly.xyz. We would rather answer a question than have you guess.
Founderly, Inc.
Delaware, United States