Privacy
What leaves your Mac.
Privacy claims are cheap. Here is the whole picture, row by row, so you can check it. Turn on Local-only mode and the right-hand column becomes “nothing”.
| What | Where it lives | Over the network |
|---|---|---|
| Your notes and attachments | Plain files in a folder on your Mac | Never sent by the app, unless you ask a cloud AI provider you set up to work on them. |
| Search | A local SQLite index | None. The search index is built and kept on your Mac. |
| Meeting audio | Recorded to your Mac | None by default. Only if you choose cloud transcription with your own OpenAI key. |
| Transcription | On-device Whisper | A one-time model download when you pick a model. After that, none. |
| Summaries and Ask | Ollama on your Mac, or a provider you choose | None with Ollama. With your own Anthropic or OpenAI key, the text you ask about goes to that provider. |
| Link previews | Fetched for links you paste | A request to that link’s website. Blocked in Local-only mode. |
| Usage stats and crash reports | Off by default | None unless you turn them on. Never note content. |
| Account | None during the beta | None. There is nothing to sign in to. |
Local-only mode
One switch in Settings blocks every network path above. It is enforced twice: in the app window and in the background process that does file and model work, so nothing can slip past through a side door. Updates are skipped while it is on.How to use Local-only mode.
The egress log
When something does go over the network (a cloud AI call you made with your own key, for example), the app records when, which provider, which feature and how many bytes. Never the content. You can read it in Settings and export it as CSV.
Keys and telemetry
- API keys for Anthropic or OpenAI are stored in the macOS Keychain, never in a settings file.
- Usage statistics and crash reports are off until you turn them on. Crash reports are scrubbed of paths, emails and keys, and never include note content.
- The app includes no third-party analytics SDK. A build check rejects one if anyone adds it.
This website
This site sets no tracking cookies and loads no ad or analytics scripts from third parties. We count visits with Cloudflare Web Analytics, which is cookieless. If you join the beta, we store your email, your platform and which page you signed up from, not your IP address. See the privacy policy.
What isn’t built yet
There is no cloud sync, no account and no hosted AI today. If we build them, they will be opt-in, and this page will say exactly what they send before they ship.
Questions
Does Oyma send my notes to its servers?
No. There are no Oyma servers in the path of your notes, recordings or transcripts. Content only leaves your Mac if you set up a cloud AI provider with your own key and ask it to work on something.
What does Local-only mode block?
Every network request the app could make: cloud AI, cloud transcription, link previews, model downloads and update checks. It is enforced in both the window and the background process.
Is my data end-to-end encrypted?
There is nothing to encrypt in transit to us, because nothing is sent to us. Your files sit on your Mac under your own disk encryption (FileVault). We have not built cloud sync yet.
Has the app been independently audited?
Not yet. We will publish dated audit reports here when we commission one. Until then, the egress log lets you check for yourself.
Private by default. Checkable by you.
Free during the private beta. Apple silicon Macs, macOS 14 or later.