Privacy

What leaves your Mac.

Privacy claims are cheap. Here is the whole picture, row by row, so you can check it. Turn on Local-only mode and the right-hand column becomes “nothing”.

WhatWhere it livesOver the network
Your notes and attachmentsPlain files in a folder on your MacNever sent by the app, unless you ask a cloud AI provider you set up to work on them.
SearchA local SQLite indexNone. The search index is built and kept on your Mac.
Meeting audioRecorded to your MacNone by default. Only if you choose cloud transcription with your own OpenAI key.
TranscriptionOn-device WhisperA one-time model download when you pick a model. After that, none.
Summaries and AskOllama on your Mac, or a provider you chooseNone with Ollama. With your own Anthropic or OpenAI key, the text you ask about goes to that provider.
Link previewsFetched for links you pasteA request to that link’s website. Blocked in Local-only mode.
Usage stats and crash reportsOff by defaultNone unless you turn them on. Never note content.
AccountNone during the betaNone. There is nothing to sign in to.

Local-only mode

One switch in Settings blocks every network path above. It is enforced twice: in the app window and in the background process that does file and model work, so nothing can slip past through a side door. Updates are skipped while it is on.How to use Local-only mode.

The egress log

When something does go over the network (a cloud AI call you made with your own key, for example), the app records when, which provider, which feature and how many bytes. Never the content. You can read it in Settings and export it as CSV.

Keys and telemetry

  • API keys for Anthropic or OpenAI are stored in the macOS Keychain, never in a settings file.
  • Usage statistics and crash reports are off until you turn them on. Crash reports are scrubbed of paths, emails and keys, and never include note content.
  • The app includes no third-party analytics SDK. A build check rejects one if anyone adds it.

This website

This site sets no tracking cookies and loads no ad or analytics scripts from third parties. We count visits with Cloudflare Web Analytics, which is cookieless. If you join the beta, we store your email, your platform and which page you signed up from, not your IP address. See the privacy policy.

What isn’t built yet

There is no cloud sync, no account and no hosted AI today. If we build them, they will be opt-in, and this page will say exactly what they send before they ship.

Questions

Does Oyma send my notes to its servers?

No. There are no Oyma servers in the path of your notes, recordings or transcripts. Content only leaves your Mac if you set up a cloud AI provider with your own key and ask it to work on something.

What does Local-only mode block?

Every network request the app could make: cloud AI, cloud transcription, link previews, model downloads and update checks. It is enforced in both the window and the background process.

Is my data end-to-end encrypted?

There is nothing to encrypt in transit to us, because nothing is sent to us. Your files sit on your Mac under your own disk encryption (FileVault). We have not built cloud sync yet.

Has the app been independently audited?

Not yet. We will publish dated audit reports here when we commission one. Until then, the egress log lets you check for yourself.

Private by default. Checkable by you.

Free during the private beta. Apple silicon Macs, macOS 14 or later.

One email when your invite is ready. No newsletter.