the fine print
Privacy Policy
Oris is built around one promise: it never sends your audio anywhere. This page is the honest, full version of what that means, and of the small amount of data the website and app do collect.
Last updated: October 2, 2026
The short version
Oris records meetings on your Mac, transcribes them on-device, and writes the result into your own notes. Your audio is never sent anywhere by Oris, your transcripts and notes are never sent to us, and the finished note lands only at the destination you picked.
The parts that do touch a server are small and separate from your content: if you sign up for product updates, or turn on Oris Pro, we store your email; if you turn on Pro we also record that a licence was issued, under a code derived from your email rather than the email itself, and the app checks that licence once a day, sending the licence and the app's version and never your email or your content; the website uses privacy-friendly, cookie-free analytics; using this website's Search + Ask sends what you type to a separate search service; and when the app checks for updates it sends anonymous, non-reversible usage counts. Each of those is spelled out below.
What Oris does not collect or see
Your recordings, transcripts, and notes
Recording happens on your Mac. The audio file is written to a local recordings folder; when your notes are files, that folder sits with them by default, so a note can link to its own recording. Transcription runs on-device with WhisperKit, so there is no network call in the transcription path. The finished transcript and summary are written into the destination you chose: plain Markdown in your Obsidian vault or local folder, or a note in Apple Notes. None of it is uploaded to us, stored by us, proxied through us, or read by us. There is no Oris account, and there is no Oris server that holds your content, because your content is never sent to us.
Your destination is your own app and your own storage, and it keeps its own sync. If your vault sits in a folder that iCloud Drive or Dropbox syncs, or your Apple Notes folder belongs to an iCloud account, that service will sync the finished note the same way it syncs everything else you keep there: to your other devices, and to anyone you share that folder with. The audio follows the same rule: it lives in whichever folder Oris actually recorded it into, and that folder depends on your setup — inside your notes folder by default for a vault or local folder, or a separate local folder under your Documents folder for Apple Notes, unchanged if you later switch destinations — so if a sync service watches that particular folder, including iCloud Drive's Desktop and Documents sync for anything under Documents, the audio syncs right along with it. That syncing runs under your account and your provider's policy; Oris is not part of it. If you want recordings out of that sync, keep the folder Oris records into somewhere your sync service doesn't watch. Oris's audio retention setting also clears recordings past your chosen age out of that folder as you keep recording; what a sync service keeps after a deletion, such as a trash bin or version history, is governed by that service.
Summarization is bring-your-own-key
By default, summaries are generated by a model running locally on your Mac, so that path is fully on-device too.
If you choose to configure a cloud model instead (for example OpenAI, Anthropic, Azure, or a self-hosted Ollama endpoint), then your transcript text is sent to your chosen provider, under your API key and account. That is a direct relationship between you and that provider. Oris does not proxy that request, does not see the text, and does not store it. When you turn on a cloud provider, that provider's privacy policy governs what happens to the text you send it, so please read theirs.
What Oris does collect, and why
These are the server-side things. None of them include your recordings, transcripts, or notes.
Newsletter and product-update signups
If you sign up for updates on the website, or turn on Oris Pro from inside the app, we store your email address and a few fields that tell us how to serve and understand the signup:
- Your email address.
- Which form you used: the newsletter, the waitlist, or a Pro signup (the Pro panel on the download page, or the app).
- Whether you told us you're on an Apple silicon Mac.
- Whether you told us you're comfortable with a developer-style install.
- The time you signed up.
- Basic attribution: the marketing parameters on the link you arrived from (UTM values), the referring site, the landing page, and a coarse country, so we know which channel a signup came from.
- If you entered one, the referral code of the person who sent you. It is a code, not their address.
- If you turned on Pro, roughly when a licence was issued to you.
We use this to email you product updates. You can unsubscribe at any time from the link in any email, and we'll stop. Unsubscribing does not affect a Pro licence you already hold, and asking the app for your licence again, on this Mac or a new one, does not put you back on the list. Email delivery and the contact list are handled by Resend (see subprocessors below).
Oris Pro licences
Oris Pro is turned on by typing your email into the app and clicking the confirmation email that arrives. That adds you to the contact list above if you are not already on it, and it writes a record of the licence to a ledger we keep. The record holds no email address. It holds:
- A licence id: a one-way code computed from your address with a secret only we hold. It can't be reversed into the address, though we can match it to one (see below).
- The licence's state (lifetime, subscription, or revoked), how it was issued, and which of our signing keys issued it.
- When it was issued, when it expires, and when the record last changed.
- When an app last checked the licence in. One time, replaced on every check, not a history.
- One entry per licence email we have sent you, with the same details and the time it was recorded.
We keep this so that support can answer what a person holds: restoring a licence, processing a refund, and answering a chargeback all start there. The lookup starts from an address: with yours in hand, we compute your licence id and find your record. The code can't be turned back into an address by itself, and someone without our secret can't test addresses against it. We can, though: we hold the secret, and the contact list holds addresses, so we can tell which record belongs to a given address. That is what makes the ledger pseudonymous rather than anonymous. It is a record about you, kept under a code instead of your address, and we treat it as personal data.
Records are kept rather than deleted. A refund or a revocation updates the record and adds an entry; nothing is removed as a matter of routine, because the history is what settles a later dispute over a charge. Unsubscribing from our emails leaves it in place. How a deletion request is handled is under Your rights below.
Once you have a licence, the app checks it when it starts and once a day while it runs. It sends the licence it already holds and its own version number to the same service, which answers with a current copy of the licence. That is how a cancellation or a refund reaches your Mac without you doing anything. The check carries no email address, no device identifier, nothing about how you use Oris, and nothing from your recordings or notes. Like any request from your Mac, it also carries your IP address and the standard request headers macOS adds, which name the macOS version. A Mac without a licence never makes it. The only lasting record of the check is its time, as above, alongside the short-lived counters below, and if the check can't get through, nothing on your Mac changes.
To keep the licence email from being abused, the service that sends it also keeps short-lived counters of how many licence requests have come from an address and from a network connection. The address counter is keyed by the same licence id; the connection counter by a hashed IP address that is never stored in the clear. Both expire on their own when their window ends, the longest being thirty days. The daily licence check keeps its own counters of the same kind, keyed by the licence id, plus a per-connection limit that lasts a minute; the longest of them lasts a day.
Website analytics
The website uses GoatCounter, a privacy-friendly analytics tool. It sets no cookies, collects no personal data, and is hosted in the EU. It records aggregate page views only, enough to know which pages people read, nothing that identifies you.
Anonymous install and update telemetry
When the app checks for updates, it sends a small, anonymous measurement so we can count active installs and know which operating systems and hardware to support. It contains:
- A non-reversible, salted hash that acts as an install identifier. It can't be tied back to you or reversed into anything personal; it only lets us avoid counting the same install twice.
- The app version.
- Your macOS version.
- Your Mac model, CPU architecture, and core count.
- How much RAM the Mac has.
- Your language and country.
There is no account, no name, and none of your content in this. It exists to answer one question: how many people are running Oris, and on what?
Download counts
When you download the app, our host records anonymous request metadata. It lets us count downloads and understand which channel they came from:
- The date (the calendar day, never a finer timestamp).
- The request method, so we can filter out automated probes.
- A coarse country.
-
The campaign labels on the link you arrived from (UTM values) and
the site that referred you, by name only — never the address
of the page you came from. These are short labels we write into our
own links, such as
blogorengine-rewrite. We only keep values matching that simple format — short, plain lowercase labels — and discard anything else, so a crafted link can't smuggle an email address, a web address, or free text into our records. It is a bound on what can be stored, not a guarantee that a determined person couldn't put some short label of their own choosing against their own visit. - A salted hash that changes every day, used only so that downloading twice isn't counted as two people. It isn't stored with your address and can't follow you from one day to the next. We keep the secret that produces it private, because that secret is what stands between the hash and the address behind it.
We don't store your IP address or your browser's user agent, and the website sets no cookies to do any of this.
Who else is involved (subprocessors)
A few third parties help run the parts above. We keep the list short and name them plainly:
- Resend — sends our emails, including the Pro licence email, and holds the contact list. Like any email service it keeps its own log of what it has sent, under its own retention.
- Cloudflare — hosts the website, stores the app downloads, serves the update feed, holds the licence ledger, and provides the supporting analytics and delivery infrastructure.
- GoatCounter — provides the cookie-free website analytics.
- Your chosen LLM provider — only if you opt into cloud summarization. This is a direct relationship between you and that provider under your own key; Oris isn't in the middle.
- askdocs — powers the ⌘K Search + Ask command bar on this website, for finding and asking about the Oris docs. What you type there (search terms and questions) is sent to the askdocs service, which we also run, to return results and generate answers. This is a website-only feature and has nothing to do with your recordings, transcripts, or notes.
How long we keep things
We keep your email on the contact list until you unsubscribe, at which point you're removed. A Pro licence record is kept, as described above, and unsubscribing does not remove it; like your contact entry, it can be looked up starting from your address. The install, update, and download telemetry is anonymous and aggregate; it isn't tied to you and isn't something we can look up by person.
Your rights
You can ask what we hold about you (in practice, your email on the contact list and, if you turned on Pro, your licence record), and you can ask us to delete it. Email [email protected] and we'll take care of it. By default a deletion request removes your address from the contact list and leaves the licence record in place, because the record holds no address and is what a later refund or chargeback for that licence is checked against. If you want the record gone too, say so and we delete it and its history. We do that deliberately rather than by routine, because once it is gone there is nothing left in the ledger to say a licence was ever issued to you. Your recordings and notes live on your own Mac or in the notes app and account you chose, so deleting them happens there, in your own apps and accounts; Oris never had a copy, so there is nothing on our side to delete.
Children
Oris isn't directed at children, and it isn't intended for use by anyone under 13 (or the minimum age required in your country, such as 16 in parts of the EU). We don't knowingly collect data from children.
Changes to this policy
As Oris grows, this policy may change. When it does, we'll update the date at the top of this page. Significant changes will be reflected here rather than buried.
Contact
Questions about privacy, or a request about your data? Email [email protected].