Privacy Policy
Last updated: July 2026
1. About This Policy
This policy covers two OneKey products, which handle your data differently:
- OneKey for Mac — a desktop dictation app that transcribes speech on your device by default. Your voice and notes stay local unless you turn on optional cloud features or sign in.
- OneKey Notes (iOS and Android) — a voice-notes app that requires an account and processes your voice notes in the cloud so they can be transcribed, enhanced, and synced across your devices.
Where a practice applies to only one product, we say so. Otherwise it applies to both.
2. Information We Collect
Account information (OneKey Notes). Signing in is required to use OneKey Notes. When you sign in with Google or Apple, we collect and store your account profile so we can create and sync your account: your email address, your name, your profile photo, which sign-in provider you used, whether your email is verified, and your device platform (iOS or Android). On the Mac app, sign-in is optional; if you use it, we store the same basic identity fields.
Onboarding and personalization answers (OneKey Notes). During setup we ask a few questions — your preferred language, what you do for work (for example student, founder/CEO, or manager), the note-taking challenges you identify with, and how often you revisit your notes. We store these answers on your profile to personalize your experience and to group you into a general “persona,” which is included in the context we send to our AI provider when composing your notifications.
Voice recordings and transcriptions. On OneKey for Mac, voice is transcribed on-device and stays on your device by default. On OneKey Notes, your audio is sent to our cloud transcription provider, transcribed, and then discarded — we never store the audio on our servers. The resulting text transcription is saved to your account.
Notes and related content (OneKey Notes). We store the content you create — transcriptions and AI-enhanced text, note titles, tasks, tags, your custom dictionary (vocabulary terms), templates, and app settings — in your account so it syncs across your devices. We also store usage statistics such as streaks and counts.
Device and technical information. To operate the service we collect basic device and app data, such as your platform, app version, time zone, sign-in and activity timestamps, your IP address, and — once you allow notifications — a push notification token for your device. Our cloud, AI, analytics, advertising, and crash-reporting providers also receive your IP address when the app communicates with them.
Purchase and subscription information. For OneKey Pro (Mac), our payment processor (Polar.sh) collects your email and payment details, and license activation sends your license key along with a device identifier and your computer's name to bind the license to your Mac. For OneKey Notes subscriptions, purchases are handled by the Apple App Store or Google Play and managed through RevenueCat, which receives your account identifier and subscription status.
Analytics and diagnostics. We collect product-usage events, performance data, and crash reports to run and improve the app. See Section 6 for the specific providers and what they receive.
Invite and referral information (OneKey Notes). If you install OneKey Notes from an invite or referral link, we capture the invite code so we can credit whoever referred you. On Android we read the Google Play install referrer; on iOS, the first time you open the app, we check your clipboard once for a OneKey invite link (which may prompt you to allow pasting). We use the clipboard content only if it is a OneKey invite link — anything else is ignored and is never stored or sent. We keep the invite code on your device until you sign in, then send it to our servers to apply the referral.
Bug reports (optional). If you submit a bug report from within the app, we collect what you type plus basic device information (and, in OneKey Notes, your account ID and email) to diagnose the issue.
3. How We Use Your Information
- Provide, sync, and maintain the OneKey apps and your account
- Transcribe your voice notes and power AI features (enhancement, titles, tasks, templates, the note assistant, and reminders)
- Process payments and manage subscriptions and licenses
- Send you notifications and important service updates
- Measure usage, diagnose crashes, and improve our products
- Respond to support and bug reports
- Protect our users and comply with legal obligations
4. Local Processing (OneKey for Mac)
On the OneKey Mac app, core voice recognition operates entirely on your local device:
- Voice recordings are processed locally using on-device machine learning models (whisper.cpp)
- Transcribed text and your custom vocabulary are stored locally on your device (they are not synced to the cloud)
- No voice data is transmitted to external servers for on-device transcription
- Local processing works completely offline
Optional cloud features (Mac). The Mac app also offers features that are off by default and only send data when you enable them and configure a third-party provider (typically with your own API key):
- Cloud transcription — your recorded audio and custom dictionary terms are sent to the transcription provider you choose
- Cloud AI enhancement — your transcript is sent to the AI provider you choose, along with context you opt to include (such as selected text, clipboard contents, active-window text, and your custom vocabulary)
- Webhook export — completed transcriptions can be sent to a URL you configure
Supported providers include OpenAI, Anthropic, Groq, Google (Gemini), Deepgram, AssemblyAI, ElevenLabs, Mistral, OpenRouter, Cerebras, and others, or a custom endpoint. Local AI options such as Ollama send nothing off your device when pointed at a local endpoint; if you configure a remote server URL, your transcript is sent to that server. When you first use a speech model, the app downloads it from a third-party model host (Hugging Face); this reveals your IP address to that host but sends no voice, note, or usage data. The app also periodically checks our servers for software updates and announcements; these are simple downloads and do not send your usage data.
5. Cloud Transcription and AI (OneKey Notes)
Unlike the Mac app, OneKey Notes transcribes and processes your notes in the cloud by default — this is how the mobile app works, not an optional add-on. Your data is encrypted in transit.
- Transcription. Your audio recording — along with any custom dictionary terms you've added, which are sent as text to improve accuracy — is sent to our third-party transcription provider (OpenAI). The audio is transcribed and then discarded; it is never stored on our servers.
- AI features. Your note text is processed by third-party AI providers (currently Groq and OpenAI) to enhance and format your transcript, render it in the output language you select, generate content from templates, answer questions in the note assistant, evaluate the trigger conditions for automations you set up, and — after you complete onboarding — extract topics and entities and compose your notifications. When a feature runs, the relevant content (your transcript or note text, text you type, note and task titles, note topics, and any dictionary terms, tags, or usage context involved) is sent to the provider solely to perform that operation and return the result. Transcript enhancement is on by default and cannot be turned off individually; the other features run when you use them or after onboarding sets them up.
Before you create an account. During onboarding, OneKey Notes offers an optional demo where you can record a short voice sample. If you choose to record it, that audio and the text derived from it are sent to our third-party AI providers (OpenAI and Groq) to transcribe and process it — this happens before you sign in. It is the only feature that works without an account; if you skip the demo, no recording is made or sent.
6. Analytics, Advertising, and Crash Reporting
OneKey Notes uses third-party analytics, advertising, and diagnostics services. In the production app these are active by default; they do not run in development builds, and we can disable them remotely — except that basic native crash reports (Sentry) may still be sent, because crash diagnostics are captured at the device level before the remote switch applies. There is currently no in-app toggle to turn analytics off, but you can exercise the data rights in Section 11.
- Mixpanel and Google (Firebase Analytics) — product analytics. We send app events (for example, recording, editing, sharing, subscribing, and onboarding actions) tied to your account identifier. Mixpanel also stores profile attributes such as your email, name, avatar, sign-in provider, and subscription status. Your note or transcript text is not sent to these services.
- Microsoft Clarity — session analytics that records how you interact with the app (screen views, taps, and gestures) with text and images masked, to help us improve usability.
- Meta (Facebook) — advertising and attribution. We share app events (such as registration, checkout, and purchase) and identifiers including your email, name, account identifier, and mobile advertising ID to measure and improve our ads. On iOS, advertising identifiers are used only if you allow tracking when prompted (App Tracking Transparency).
- Sentry — crash and error reporting (stack traces and diagnostic context). We configure Sentry to minimize the personal information in reports and mask on-screen content; some diagnostic reports (for example, an error during account deletion) may still include an account reference.
The OneKey Mac app does not include any analytics, advertising, or crash-reporting SDKs.
7. How We Share Your Information
We do not sell your personal information for money, and we share it only as described below. Note that sharing data with our advertising partner for ads and attribution (see the advertising bullet below and Section 6) may be considered a “sale” or “share” of personal information under some U.S. state privacy laws (such as California's CCPA/CPRA); see your choices in Section 11.
- Service providers we use to run OneKey Notes: our cloud provider (Google Firebase / Google Cloud) for authentication, database storage, and push notifications; OpenAI and Groq for transcription and AI features; Apple, Google Play, and RevenueCat for subscriptions; and the analytics and crash-reporting providers listed in Section 6.
- Advertising and attribution partners: we share app events and identifiers (including your email, name, account identifier, and mobile advertising ID) with Meta (Facebook) to measure and improve our ads. This is a distinct advertising relationship, not a service-provider one.
- Payment processors: Polar.sh for OneKey for Mac license purchases.
- Internal automation and processing services we operate: when a note is created we may route note identifiers and metadata (your account ID, the note's ID, and its creation time) to an internal automation service; the note's text and content are not sent.
- Bug-report tooling (GitHub): if you submit a bug report, its contents, basic device information, and your account ID (but not your email) may be copied into an issue in our engineering issue tracker on GitHub, a third-party code-hosting service.
- Legal and safety: when required by law or to protect our rights and users.
- Business transfers: in connection with a merger, acquisition, or sale of assets.
Sharing you direct. Some features send your content to destinations you choose:
- Automations and webhooks. If you set up an automation (webhook) that connects your notes to a third-party service or URL you choose (for example Zapier, Make, n8n, or a custom endpoint), then when it triggers — automatically when a note matches conditions you set, or when you confirm it — OneKey sends the content you configured (your note's transcribed text and its AI-enhanced version) to the destination you specified. Once your data reaches a service outside OneKey, that service's own terms and privacy policy govern its use.
- Public share links. If you tap Share on a note to create a link, OneKey Notes stores a copy of that note's shared content — its title, the text you're viewing (the transcript or an AI-generated version), its tags, and your display name — and generates a public link. Anyone who has the link can view that content without signing in, and shared copies do not automatically expire. Only notes you explicitly choose to share are made available this way.
8. Where Your Data Is Stored
OneKey Notes account data is stored and processed on Google Cloud / Firebase servers in the United States, and our AI and analytics providers may also process data in the United States. If you use OneKey Notes from outside the United States, your information is transferred to and processed in the United States. OneKey for Mac data stays on your Mac unless you enable a cloud feature or sign in.
9. Data Retention
We keep your account data for as long as your account exists; when you delete your account it is removed as described in Section 12. Some operational and diagnostic records have their own limited retention windows — for example, notification decision traces are kept for about 30 days, notification delivery logs for about 90 days, and internal notification-system diagnostic logs for up to about a year — after which they are automatically deleted. Analytics and crash providers retain data under their own policies. On the Mac app, transcriptions and recordings you keep locally remain until you delete them or uninstall the app.
10. Data Security
- Encryption in transit for data sent to our servers and providers
- Storage of personal information with industry-standard security controls
- Access to personal data limited on a need-to-know basis
- Ongoing security updates
11. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You can:
- Delete your OneKey Notes account and data from within the app (see Section 12), or request deletion by email
- On the Mac app, turn off optional cloud features at any time (on OneKey Notes, cloud transcription and AI enhancement are required to create notes and cannot be turned off individually)
- On iOS, decline app tracking when prompted, which limits advertising identifiers
- Opt out of the sharing of your information for advertising (a “Do Not Sell or Share My Personal Information” request) by emailing privacy@useonekey.com
- Manage notifications through your device settings
- Request access, correction, portability, or deletion of your data by emailing privacy@useonekey.com
12. Deleting Your Account
You can permanently delete your OneKey Notes account and all of its data directly from within the mobile app — no email or waiting period required. To do so:
- Open the OneKey Notes app (iOS or Android).
- Tap your profile picture (or the circle showing your initial) in the top-left corner of the notes screen to open Settings.
- Scroll to the bottom and tap Delete Account.
- Confirm the warning, then re-authenticate with the same Google or Apple account you signed in with (this security step confirms it's really you).
Once confirmed, deletion is immediate and permanent — it cannot be undone. Your account and your data are removed from our servers right away, including your notes and transcriptions, templates, tags, custom dictionary, tasks, app settings, usage statistics, subscription records, and your notification inbox and delivery records, along with the sign-in account itself.
A few things are handled slightly differently, for accuracy:
- Separate, aggregate notification-system diagnostic logs (distinct from your own notification records above, and keeping only a redacted reference to you) are removed or de-identified by a background process afterward, with any remaining entries cleared on our normal log-retention schedule.
- Information already shared with the third-party analytics, advertising, crash-reporting, and subscription providers listed in Section 6 is retained by them under their own policies and is not purged by the in-app deletion step. To request its deletion, use the options in Section 11.
- If you sent us a bug report from within the app, we keep the report itself — including anything you typed in it and basic device information — for engineering and quality purposes, and we remove or redact the details that identify you (such as your account ID) from our records. A copy may also exist as an issue in our engineering tracker on GitHub, where we redact those identifiers on a best-effort basis.
- If you created public share links, those shared copies are part of your account data and are removed with it; however, we cannot recall copies others may have already saved.
Voice recordings are never stored on our servers in the first place — they are transcribed and then discarded. On your device, the app clears its stored data and settings, including your saved sign-in. Audio recording files saved by the app are the one exception — they are removed when you delete the note or uninstall the app, not by the account-deletion step itself.
Prefer not to use the app? You can also request account and data deletion by emailing us at privacy@useonekey.com and we'll process it for you.
13. Cookies and Website Tracking
Our website (useonekey.com) uses minimal tracking technologies:
- Essential cookies for website functionality
- Analytics cookies to understand website usage
- No third-party advertising cookies on the website
You can disable cookies in your browser settings, though this may affect website functionality.
14. Children's Privacy
OneKey is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website, updating the date above, and — for significant changes — through email or in-app notices. Your continued use of OneKey after changes take effect constitutes acceptance of the revised policy.
16. Contact Us
- Email: privacy@useonekey.com
- Support: OneKey Support Center