Legal

Privacy Policy


This privacy policy explains what personal data Squibble GmbH collects when you use Saydrop or this website, and how it is processed and protected. It applies from June 2026 and complies with the Swiss Federal Act on Data Protection (revFADP) and GDPR.

01 Controller

The controller responsible for data processing on this website and the Saydrop service is:

Squibble GmbH

Rossbergstrasse 30

8310 Kemptthal, Switzerland

UID CHE-422.123.021

hello@squibble.ch

02 Data & Scope

The app (local transcription)

Saydrop transcribes with mlx-whisper on your Mac (Whisper medium by default). Audio is processed in memory and is not persisted by Saydrop. Cleanup is off by default. Optional Gemma and Qwen cleanup run locally; optional Gemini cleanup sends the transcript to Google only after you explicitly enable it.

Rotating app diagnostics are stored in ~/Library/Logs/saydrop.log and remain local by default. Optional Graylog reporting is off by default and, when configured, sends only allowlisted metadata such as timing, outcome, character count, and a run identifier; it does not send transcript text.

First-run onboarding requests Microphone, Input Monitoring, and Accessibility only after showing the matching explanation and after you choose to continue. Its resumable state is stored locally. Onboarding metrics are limited to step names, step durations, permission denials, and retries. They never contain audio, transcripts, dictated content, personal vocabulary, clipboard contents, or editor context. Transcript history, optional diagnostics, and editor-context access are presented as separate choices and default to off.

Editor context is off by default. If you enable it, Saydrop reads only a bounded selected-text or surrounding-text snapshot when you press the dictation hotkey. Secure/password fields and apps on your denylist are excluded. The snapshot is supplied only to local Gemma or Qwen cleanup as delimited, untrusted reference text, then discarded. It is never sent to Whisper, Gemini, history, diagnostics, Graylog, or metrics. Saydrop does not read URLs, window titles, screenshots, OCR, or clipboard content, and it does not poll editors in the background.

Selected-text editing uses a separate explicit hotkey or menu action. The bounded non-secure selection and spoken instruction go only to a local model. Saydrop shows the proposed replacement in an Apply/Copy/Cancel preview and never edits automatically. Apply succeeds only while the captured target and selection are still valid; otherwise the proposal is copied, or the operation fails without changing the source.

If you enable app-aware formatting, Saydrop reads the frontmost application's bundle identifier locally when you press the dictation hotkey. Exact bundle-to-mode mappings remain in your local settings. Saydrop does not read URLs or window titles, and bundle identifiers are never included in transcript history, diagnostics, metrics, or Graylog reports.

Personal vocabulary, deterministic replacement rules, and exact-trigger snippets are stored and processed locally. Rule phrases, triggers, and expansions are never included in diagnostics, metrics, or Graylog reports. Operational personalization metrics contain counts only. App-scoped rules use the same exact local bundle identifier mapping and do not inspect window titles, URLs, selections, or surrounding text.

The website & purchase

This static marketing site is hosted in Switzerland. For aggregate visitor statistics we use Umami, a privacy-friendly analytics tool we self-host in Switzerland (insights.squibble.me). It is cookieless, sets no tracking cookies, does not follow you across sites, and stores no data that identifies you personally. No analytics data leaves our Swiss infrastructure or is shared with third parties.

Purchases are processed by Paddle.com Market Ltd as Merchant of Record. When you purchase a Saydrop license, Paddle collects your name, email address, billing address, and payment information under their own payment processing service. Squibble GmbH does not receive or store this payment data. See Paddle's Privacy Policy for full details.

Optional cloud cleanup (user opt-in)

Cleanup is off by default. If you choose to enable cleanup with the cloud backend (by setting SAYDROP_CLEANUP_BACKEND=gemini and providing your own Google Gemini API key), your transcribed text is sent to Google's Gemini API under your own account and API key. This is entirely optional and must be explicitly enabled in your configuration.

Squibble does not store, process, or have access to text sent to Gemini via cloud cleanup. You control this data directly. See Google's Privacy Policy for how they handle data sent to their APIs. Personal dictionary terms are included in Gemini requests only if you separately opt in to sharing them.

03 Purpose & Legal Basis

Data Purpose Legal basis
Purchase email (via Paddle) License activation, receipts, support Contract (revFADP Art. 6 / GDPR Art. 6(1)(b))
Local app logs Debugging, troubleshooting (on your machine only) Legitimate interest
Text sent to Gemini (optional, if enabled) Cloud-based text cleanup (you control via your API key) Explicit consent / Your instruction
Diagnostic metadata sent to Graylog (optional, if configured) Operational troubleshooting without transcript text Explicit opt-in / Legitimate interest

04 Storage & Retention

Saydrop is designed to minimize data retention and centralized storage:

  • Settings and license data: Stored as plaintext under ~/Library/Application Support/Saydrop/. Existing installations can retain dictionary or transcript-history data under legacy ~/.config/saydrop/ paths.
  • Personalization data: Vocabulary and versioned replacement/snippet data are plaintext local files. Saydrop-managed directories use user-only 0700 permissions and files use 0600, with atomic writes and symlink refusal. Terms, triggers, preferred phrases, and expansions are not sent to diagnostics or Graylog. Gemini receives vocabulary only under the separate dictionary-sharing opt-in; replacements and snippets are never sent for cleanup.
  • Transcript history: Plaintext, opt-in, and off by default. The configured retention period is applied while history is enabled. Disabling history stops new entries but preserves existing files; use the app's explicit delete action to remove history. Persistent rows contain only final recoverable text, timestamp, detected language, formatting mode, and cleanup and delivery outcomes. Audio, raw transcripts, personal vocabulary, app identifiers, and selection or surrounding context are never stored in history. Session-only history remains available until Saydrop quits even when persistence is disabled; rejected, silent, and textless errors are not added.
  • Local protection and uninstall: Saydrop-owned files use user-only permissions where managed by the app, but are not application-level encrypted. Deleting Saydrop.app does not delete these user-data files.
  • Local logs: Stored in ~/Library/Logs/saydrop.log and automatically rotated. They remain local unless optional metadata-only Graylog reporting is configured or you share them for support.
  • Purchase data (via Paddle): Retained by Paddle per their standard retention policies (typically for tax/legal compliance, 7 years).
  • Cloud cleanup requests (if enabled): Sent to Google's Gemini API. See Google's Privacy Policy for their retention period — Squibble has no copies of this data.
  • Website analytics: Aggregate, cookieless statistics via self-hosted Umami (Switzerland). This website analytics system is separate from desktop-app diagnostics.

05 Optional Cloud Services

Saydrop can optionally integrate with cloud services if you explicitly enable them:

Service Purpose Activation
Paddle.com Purchase processing, payment, license management When you buy
Google Gemini API Optional cloud text cleanup (you provide API key) Opt-in, config setting
Graylog Optional metadata-only app diagnostics Off by default; explicit configuration

Transcription remains local regardless of these optional integrations. Umami analytics applies to this website, not the desktop app.

06 Your Rights

Under the revFADP and GDPR you have the following rights regarding your personal data:

  • Access (Art. 25 revFADP / GDPR Art. 15): request a copy of all personal data we hold about you.
  • Rectification (GDPR Art. 16): request correction of inaccurate data.
  • Erasure (GDPR Art. 17): request deletion of your data where there is no overriding legal obligation to retain it.
  • Restriction (GDPR Art. 18): request that we restrict processing while a dispute is resolved.
  • Portability (GDPR Art. 20): receive your data in a structured, machine-readable format.
  • Objection (GDPR Art. 21): object to processing based on legitimate interest.

We respond to all data requests within 30 days. To exercise any of these rights, email hello@squibble.ch with the subject line Data Request and a description of your request.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

07 Changes to this Policy

We may update this privacy policy as the service evolves or as legal requirements change. Material changes will be communicated to registered users by email at least 14 days before they take effect. The current version is always published at saydrop.squibble.ch/privacy.

Last updated: June 2026

08 Contact

For privacy questions, data requests, or DPA enquiries:

Squibble GmbH — Privacy

Rossbergstrasse 30

8310 Kemptthal, Switzerland

hello@squibble.ch