What runs on your phone
Dictation is recognized on the phone: the app carries the speech models in its bundle (SenseVoice + CT-Transformer, verified against a pinned digest at build time) and reports the engine it used (sense-voice (on-device, …)). Signed out, or on a Local plan, no audio and no transcript leaves the phone.
The app holds the microphone for a dictation window so the keyboard can start an utterance without switching apps; the window ends five minutes after the last thing you say, and you can end it sooner from the keyboard’s strip or from Home.
Tracking
None. The app’s privacy manifest declares NSPrivacyTracking false and an empty list of tracking domains. There is no advertising identifier and no analytics SDK. The only services the app calls are Tacit’s own: the account backend (a Supabase-hosted project) and the recognition and notes node.
What can leave the phone, and only then
Nothing below happens while you are signed out. Signed in, these are the only paths:
Audio of a dictation
- When
- only on a Pro plan, where the plan itself decides the route — there is no switch
- Where
- Tacit’s own
/ws - Kept
- processed in memory to be recognized and formatted; the service logs an id, timings and sizes, never the words
The words of a dictation (this session’s formatted text)
- When
- when you tap to generate an Insight digest — or, if you turn the unattended digest on, on its own daily cadence; that switch is off by default
- Where
POST /v1/insight- Kept
- answered from memory; no text kept
A meeting’s transcript
- When
- only when you ask for its AI notes
- Where
POST /v1/notes- Kept
- answered from memory; no text kept
A meeting’s transcript, while it runs
- When
- only for a meeting you agreed at the start to send
- Where
POST /v1/notes/live- Kept
- answered from memory; no text kept
Your dictionary’s terms and the suggestions you refused
- When
- on sign-in and on each launch with a session, on any plan, with no tap
- Where
PUT /v1/vocabulary- Kept
- unioned into your account’s vocabulary and kept until you delete the account
A record of use: each on-device dictation’s word count and an utterance id — never the words
- When
- while signed in, on any plan, with no tap
- Where
POST /v1/usage- Kept
- your account’s monthly word count
The AI notes of a meeting (the saved note only —
gen_idandnotes, never audio, turns or attachments)- When
- off by default; only after you turn the switch on for your account and confirm
- Where
- the account’s meeting-notes table
- Kept
- one row per meeting keeping the newest saved generation; deleting your account removes them
One request does not need an account and does not carry one. To show the icon of an app you dictated into — the same icons Tacit shows on the Mac — the phone asks Apple’s public App Store lookup for that app’s artwork: https://itunes.apple.com/lookup?bundleId=<the app’s bundle id>, once per app, with no account, no text and no identifier of yours. An app can be in one country’s App Store and not another’s, so the phone may ask up to three of them for the same app — your device’s own region first — and stops at the first that has the icon; each of those asks carries the same thing and nothing more. The picture is kept on your phone (a small, bounded directory), and deleting all local data deletes it. Apps whose icon the phone does not hold keep a neutral tile. This happens signed out too, because it is not about you; if you are offline, nothing is asked and nothing is missing but the picture.
Your e-mail address and your user id are collected when you sign in, for the account itself.
The app’s privacy manifest declares exactly these categories, each linked to you, for app functionality, and none for tracking: Audio Data · Other User Content · Email Address · User ID · Product Interaction. The manifest is checked against the app’s actual network routes in both directions before each build: a route the phone takes must be declared, and a declared route the phone does not take is a build failure.
What stays on your phone
Your dictation history, dictionary, snippets, notes, meetings (their audio and transcripts) and the queued usage counts live on the phone, per identity. Settings ▸ Account ▸ Delete all data on this device empties every one of those stores — including what was left there while signed out — and says what it did; the account itself and the device’s settings stay. A meeting’s audio is also bounded by a retention budget the app enforces on its own.
Deleting your account
Settings ▸ Account ▸ Delete account asks to confirm (“Everything of yours on the server goes with it, and it cannot be undone”) and then deletes the account. Your account’s vocabulary is deleted with it, and the opt-in meeting-notes rows are removed by the database’s own cascade.
Children
The app is not directed to children.