1. Who we are
Offrun is made by Founderly, Inc., a corporation organised under the laws of the State of Delaware, United States. In this policy, “Offrun” means the Mac application, “this site” means offrun.dev, and “we” and “us” mean Founderly, Inc.
Founderly, Inc. is the controller of the personal data described in section 3. For anything ordinary (a question, a problem, a request), write to hello@founderly.xyz. For privacy requests, data-protection matters and formal written notices, use legal@founderly.xyz.
2. What happens on your Mac
Offrun listens to what you say, reads the screen you are looking at, and types clean text where your cursor is. Speech recognition, the vision model that reads the screen and the language model that cleans up the result are all small models that run on your Mac. There is no server in that dictation processing path. Content you later submit to an AI agent is covered in section 6.
- Your voice
- Held in memory while the hotkey is down and released the moment you let go. No recording is written to disk and none is transmitted.
- Your screen
- A single frame, read as you speak and freed immediately afterwards. It is never written to disk and never leaves the machine.
- Your text
- Typed at your cursor, in the application you were already using. If you submit it to an AI agent, it is shared with that provider.
- What Offrun keeps
- Your custom dictionary and vocabulary used for dictation, including library names and shorthand. This is stored on your own disk so that it is there next time. It stays on your Mac and is not synced, backed up to us, or used to train anything.
None of this is personal data we hold, because we never hold it. It is yours, on your machine, and section 10 explains how to remove it.
Two honest qualifications, rather than hedging every row above. Measurements about your dictation do travel (how many words, how long it took, how much you edited), and section 5 sets those out. And if the app crashes, the report it sends can include a snapshot of its memory, which section 3 explains.
3. What we receive
Section 2 is about the material Offrun handles, which stays with you. This section is about the limited service data we receive:
- Account details. We store your name and email. If you use email sign-in, your password is stored only as a one-way scrypt hash. If you use Google sign-in, Google verifies your identity and gives us your name and email. Signing in does not grant access to Gmail or Calendar; those optional connections require separate permission, as described in section 6.
- Subscription details. We store your plan, subscription status, billing-period end, cancellation state, and the provider identifiers needed to manage Pro access.
- Aggregate usage. To apply account limits and show product history, the app may sync daily word and dictation counts, editing totals, the time of your latest completed dictation, app version, plan status, and related non-content service data.
- Support requests. If you contact support through Offrun, we store your account name and email, ticket subject and message, category, priority, status, timestamps, and any image you choose to attach.
- Product analytics. The app may report bounded events such as which control was clicked, the app surface, app version, a random per-install identifier, and the country from your Mac's region setting. Amplitude does not receive your account ID, email, username, clicked text, input values, pointer coordinates, transcripts, clipboard content, or screen content.
- Crash reports, when the app fails. A crash report contains the state of the program at the moment it stopped: the sequence of function calls that led to the failure, the version of Offrun and of macOS, and the type of Mac. Reports are sent directly to Offrun and stored on our behalf by Amazon Web Services (AWS) in private, encrypted storage for up to 90 days. Where the operating system produces one, a native crash minidump may be uploaded with it; read on.
- Session tokens. Staying signed in means access and refresh tokens accompany authenticated requests.
- Referrals. A referral code at signup, and your account token when the app checks your referral status.
- Catalog, updates, statistics and dictionary downloads. Usually only an API key or your account token and simple parameters, such as how many days of statistics to return.
- Connection information. As with any internet request, your source IP address, the time, the route and standard network headers appear in our AWS service logs.
Technical crash and error reporting is on by default and can be turned off at any time in Settings. Product analytics does not have a separate switch: the anonymised events described above are sent automatically while you use the app. They are tied to an installation identifier rather than to your name or email, and they never carry the material in section 2.
What none of it contains is the material in section 2. No analytics event, and no ordinary crash or error report, carries your speech, a frame of your screen, the text Offrun typed, your custom dictionary, or what the app has learned about your projects. Those never leave the device at all, so there is no path by which they could reach an analytics provider. Those reports describe what you did with the app, not what you said to it.
The native crash minidump is the exception, and we would rather say so than let you discover it. A minidump is a snapshot of the app's memory at the instant it failed. We do not put your dictation into it deliberately, and we do not go looking for it, but because it captures memory rather than a curated list of fields, it may incidentally contain fragments of whatever the app was working on at that moment, which can include audio or text in flight. It is produced only by a crash, it is read only to diagnose that crash, it is never used for analytics or any other purpose, and it is held in the same private, encrypted storage for the same 90 days. Turning off crash and error reporting in Settings stops it being sent at all.
We do not sell personal data, and we do not share it with anyone for advertising. There is no advertising in the app.
4. Payments
Offrun is free, so there is nothing to pay and no payment data to collect. We do not ask for a card anywhere in the app or on this site, we hold no card details, and no payment processor receives anything about you today.
If a paid plan is introduced, payments will be handled by Stripe: card details would be entered into Stripe's own payment form and go directly to Stripe, never reaching our servers and never seen or stored by us. We would keep the Stripe customer and subscription identifiers, plan, subscription status, billing-period end, and cancellation state needed to manage that plan. Stripe would process that data as an independent controller under its own privacy policy, which you can read at stripe.com/privacy. This policy and the date at the top of the page will change before any of that begins.
5. Usage and allowances
Nothing you dictate is metered. There is no word allowance to enforce, so no usage count is kept in order to ration what you can do. Where the app does send aggregate counts, they are the bounded product analytics described in section 3, under the consent choice set out there.
Whatever is sent, these records never include audio, transcript text, formatted text, clipboard content, or screen context.
6. When the app uses the network
Dictation itself is designed to work offline, and after setup it does. The app uses the network for these service functions:
- Once, at setup, to download the models it runs on. After that download completes, dictation works with no connection at all.
- To create and access your account, including email verification and optional Google sign-in.
- To access services you connect, including Gmail and Calendar, and to process requests through your chosen AI agents.
- To check your account, which today carries no plan, subscription or allowance for the app to apply.
- To send bounded product analytics, as described in section 3.
- To send a crash report, if the app has failed and you have not turned reporting off.
- To create and view support requests, including an image only when you choose to attach one.
- To open the billing portal or change your plan.
- To check your referral status, if you have a referral code.
- To fetch the catalog, updates, your statistics or dictionary downloads.
- To check for updates, so you can be told when a new version is available.
Speech recognition and dictation formatting run locally. Submitting content to an AI agent shares it with the provider you choose.
Optional Google connections and AI agents
With your permission, Offrun reads Gmail messages and attachments, saves drafts for your review, and reads selected calendars and events for scheduling and meeting reminders. The Gmail connector does not send email. Connections call Google directly from your Mac; authorization tokens are stored locally using macOS Keychain-backed encryption and are not given to agents.
You choose which connected accounts an agent can use. Requested content is shared with the AI provider used for that task and may be retained in chat history, project memory and files. Enabling a connection does not automatically send your mailbox to every agent. The provider's terms and your account settings govern its processing and retention. Content included in shared project memory may also be used by other agents working in that project.
Our use of Google user data is subject to the Google Workspace user data policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models.
You can disconnect an account in Connectors or revoke access in your Google Account. This stops future connector access; it does not remove existing drafts, chat history, project memory or saved files. Remove those separately, and use your AI provider's controls for data it has already received.
Any request over the internet reveals your IP address to the server receiving it, and that is true of every one of these. We do not use IP addresses to build a location history; they appear in ordinary server logs, which are kept for a short period for security and debugging and then discarded.
The single exception to the line above is the crash minidump in section 3, which is why it is spelled out there rather than left to be found.
7. This website and cookies
The website is a separate thing from the app, and it is measured differently. offrun.dev uses Google Analytics to understand how people find and read the site: which pages are visited, in what order, how long they are on screen, what referred you, and the browser, device type and approximate location that Google derives from your IP address.
Google Analytics sets cookies in your browser to recognise a returning visit and to hold the identifier that ties those page views into a single session. That is the ordinary case; if you send the signal described below, it sets no cookie and holds no identifier at all. Google processes this data as described in its own privacy policy, and may process it outside the country you are in.
Whether we ask you first depends on where you are. If you are in the European Economic Area or the United Kingdom, nothing is stored in your browser until you answer the banner: analytics starts switched off, and it stays off unless you choose otherwise. Everywhere else there is no banner, analytics loads with the page, and we treat it as our legitimate interest in understanding how the site is read rather than as something you have agreed to. Section 11 sets out both bases.
Alongside those cookies, when you click a Download link we note which one it was in your browser's session storage, so that if you go on to download the app we can tell which link brought you there. It holds one short word, the name of the button you clicked, and nothing that describes you. Your browser discards it when you close the tab. It is not written at all unless analytics is switched on for you.
Wherever you are, you can change your mind at any time with the Cookie choices link at the bottom of every page. Declining there does not only stop new cookies. It deletes the Google Analytics cookies already in your browser, and clears the note described above.
You can opt out in any of these ways:
- Use the Cookie choices link in the footer. It is on every page, for every visitor, whether or not you were shown a banner. Choosing Decline switches analytics off and removes the cookies it has already set.
- Decline the banner, if you are shown one. In the EEA and the UK it appears before anything is stored, and declining it means nothing ever is.
- Send a Global Privacy Control signal. This is the one we act on ourselves, and it is the one that needs the most honest description. When your browser sends it, Google Analytics is held in a restricted mode from the moment it starts: no cookie is set or read, no identifier is stored on your device or assigned to you, and nothing about your visit can be tied to any other visit you make. What still happens is that Google receives a request with no identifier in it, which it may use only to estimate totals in aggregate. Like any request your browser makes, it carries your IP address. We would rather say that than claim nothing is sent. Brave and DuckDuckGo send the signal by default; Firefox has a setting for it, and several extensions add it. We honour it everywhere, not only where the law obliges us to, and we will never show you a banner asking you to reverse it. If you open Cookie choices yourself we will tell you what the signal did, and leave it at that.
- Install Google’s opt-out browser add-on, which blocks it on every site.
- Turn on your browser’s tracker blocking, or use one that blocks it by default.
Nothing else on the site is third-party. There is no advertising network, no pixel, no embedded video player and no font CDN: the typefaces and every other asset are served from this domain. The site does not ask you to sign in, and nothing you type into it is stored by it.
Our hosting provider also keeps standard server logs, including IP addresses, for security and to keep the site running. We do not analyse them to identify visitors.
8. Who else handles your data
We use a small number of companies to run parts of the service. The data they receive depends on the features you use:
- Stripe
- Payments and subscriptions. Receives nothing today, because Offrun is free and takes no payments. If a paid plan is introduced it would receive your payment details directly and your email address, as section 4 describes.
- Optional sign-in, Gmail and Calendar connections. Verifies your identity, supplies the data you authorize, and stores drafts you ask Offrun to create.
- Your chosen AI providers
- Process agent requests and the content included with them, including authorized Google content, as described in section 6.
- Resend
- Account, security, billing, and support email delivery. Receives the recipient address and email content needed for delivery.
- Amplitude
- Product analytics for the Mac app. Receives the usage events in section 3 and your installation identifier.
- Google Analytics
- Website measurement only. Receives the page-view data in section 7. It is not used in the app.
- Amazon Web Services (AWS)
- Hosts Offrun's backend and privately stores account, aggregate usage, subscription, support, and sanitized crash-report data.
If we add or replace one of these we will update this section, and the date at the top of the page will change with it.
9. The permissions macOS asks for
macOS will ask you to grant Offrun three permissions. Each one is needed for a specific part of the app to work, and each is used for that and nothing else:
- Microphone
- To hear you. The microphone is opened when you hold or double-tap the hotkey and closed when you finish. Offrun does not listen in the background and has no wake word.
- Screen Recording
- To read the single frame it uses for context: the names, identifiers and terms visible in front of you, so it can spell them correctly. It captures at the moment you dictate, not continuously, and nothing is recorded.
- Accessibility
- To type the finished text into the application you are using, and to know which application that is. It is not used to read the contents of other applications.
You can review or revoke any of these at any time in System Settings → Privacy & Security. Revoking one disables the part of Offrun that depends on it; it does not affect the rest.
10. How long things are kept
On your Mac
Your custom dictionary and what Offrun has learned about your projects stay on your disk until you remove them. You can clear them from Settings. Agent chats, project memory and saved files can also live in project folders; deleting the app and its support folder does not remove those. Connector attachments use temporary local files, normally cleared on disconnect, sign-out or shutdown. An interrupted app can leave temporary files behind.
On our side
We keep your account record (name, email and password hash) for as long as the account exists, and for a short period afterwards for accounting and tax records. Any aggregate usage we hold is removed with the account. Crash and error reports, including any native minidump, are kept for up to 90 days and then deleted. Product analytics events are kept for up to 24 months. AWS service logs, which hold the connection information in section 3, are kept for a short period for security and debugging. Google Analytics data is retained on Google’s own schedule for the website. Support images expire automatically after 180 days. Support ticket text is kept as needed to respond, maintain support history, and meet legal or security obligations.
Ask us to delete your account and we will remove your account record, your aggregate usage and your support tickets, except where we are required to keep transaction records by law.
11. Your rights and your choices
The switches
The quickest controls are the ones in the product itself, and they do not require you to write to anybody:
- In the app: Settings lets you turn crash and error sharing off. It is the only in-app switch: the anonymised product analytics in section 3 have no separate toggle.
- On the website: the opt-outs in section 7. Those cover this site's Google Analytics, which is separate from the analytics the app sends.
The legal rights
Depending on where you live, you have rights over the personal data we hold. Those rights generally include asking us for a copy of it, asking us to correct it, asking us to delete it, asking us to restrict or stop a particular use, and asking for it in a portable form. If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority. If you are in California, you have the right to know what we collect, to have it deleted, and to opt out of sharing for cross-context behavioural advertising. We do not sell personal information for money. On the sharing question, there is nothing to opt out of: advertising features are switched off in our analytics for every visitor, all of the time, so no data from this site is used for advertising personalisation or passed to an advertising network. There is no advertising in the app either. Section 7 sets out the further controls over analytics itself.
Write to legal@founderly.xyz to exercise any of these and we will respond within 30 days. We will never charge you for making a request or treat you differently for having made one.
Legal bases, if you are in the EEA or UK
We process your email and subscription status to perform our contract with you.
We process crash and error reports on the basis of our legitimate interest in finding and fixing faults, and you can override that at any time with the switch in Settings. We process the anonymised product analytics in section 3 on the same basis; as section 3 says, those have no separate switch, so if you want them stopped, write to us and we will act on it.
The basis for the website's Google Analytics cookies depends on where you are. In the European Economic Area and the United Kingdom we rely on your consent: nothing is stored until you answer the banner, and you can withdraw at any time through the Cookie choices link in the footer, which also deletes the cookies already set. Withdrawing is as easy as agreeing was, and it does not affect anything we did while consent was in place.
Everywhere else we rely on the same legitimate interest in understanding how the site is read. There we do not ask before setting the cookies, so we do not claim to be relying on your consent for them, and we say so rather than implying otherwise. The Cookie choices link works just the same, and section 7 lists the browser-side controls as well. You can also object to this processing by writing to us. No cookie is set for anyone whose browser sends a Global Privacy Control signal, wherever they are.
12. Children
Offrun is a professional tool and is not directed at children under 13. We do not knowingly collect personal data from them. If you believe a child has given us their information, write to us and we will delete it.
13. Changes to this policy
If we change this policy we will update the date at the top of the page. If a change materially affects what we collect or what we do with it, we will tell account holders by email before it takes effect, rather than relying on you to notice.
14. Contact
Questions about this policy, or about anything in it, go to hello@founderly.xyz. Privacy requests and formal written notices go to legal@founderly.xyz. We would rather answer a question than have you guess.
Founderly, Inc.
Delaware, United States