Security and data handling
Understand where your meeting data goes.
NoteHand transcribes meeting audio on your Mac. The AI provider you choose determines where Coach suggestions and meeting notes are generated. Here's how processing, storage and permissions work.
Processing options
Set it the way you would use it, and see what is processed where.
Transcription always runs on your Mac. The setting below decides where Coach and notes are generated, and the table changes with it.
- AudioMeeting app and your microphone
- TranscriptWhisper, on the device
- NotesSummary, decisions, actions
- Your API keyStored in the macOS Keychain
- Usage dataNone is collected
Nothing from the app. Audio, transcript and notes stay on this Mac.
| Data | Where it goes |
|---|---|
| Audio from the meeting and your microphone | Stays on the Mac in every setting |
| Transcript | Stays on the Mac |
| Notes | Written on the Mac |
| Your API key | Stored in the macOS Keychain; sent only to the provider it belongs to, to authenticate requests |
| Exported Markdown files | Your export folder. If that folder is synced by iCloud Drive, Dropbox or a company service, that service handles the copies |
| Usage data, analytics, crash reports | Not collected |
| Speech model download | Downloaded from Hugging Face when you choose a model; local language models are pulled through Ollama on the Mac |
| Purchase | Handled by Apple through the App Store; BITSUMMIT receives no payment details |
| A message to BITSUMMIT | Only when you send the in-app feedback form (your message and, for bug reports, the app and macOS versions, provider names and recent logs if you opt in) or write to us |
Permissions
Permissions support the features you turn on.
For each one: what the permission is, why NoteHand requests it, and how the app uses it. macOS asks the first time a feature needs it.
To record your side of a call and to hear you when you dictate.
The microphone is opened only while a recording or a dictation is running. The menu bar shows when the app is capturing.
The first time you record or dictate. Both builds.
To capture the audio another app is playing, which is how the other people on a call get into the recording. On macOS 14.2 and later, Core Audio system capture in Settings › Recording is an alternative path that macOS approves separately; the app also switches to it for apps such as new Teams.
NoteHand captures call audio and reads supported meeting-app window titles to detect meetings and start recording automatically. It does not capture, store or send images of your screen.
The first time you record a call. Both builds. After granting Screen Recording, quit and reopen the app; macOS applies it on the next launch.
Direct-download build only: to insert dictated text into the app you are using instead of leaving it on the clipboard.
To place text and send a single paste keystroke. The App Store build does not request or use this permission; there, dictation copies to the clipboard and you press ⌘V.
Direct download only, when you turn on automatic insertion. The direct-download build has not shipped yet.
For your security team
Technical facts about the released build.
Mac App Store version 1.0 (8), released 1 September 2026. Documented behaviour, not a certification.
How it is built
- App Sandbox and hardened runtimeThe app runs sandboxed with the hardened runtime and ships a privacy manifest. App Store review is a distribution review by Apple, not an independent security audit.
- StorageRecordings, the meetings database, the search index and downloaded models live in the app's sandboxed container. The export folder you choose is the one location outside it the app can write to, through a security-scoped bookmark. A diagnostic log with 14-day rotation lives in the container too, and an optional setting removes completed meetings' audio after a chosen period.
- API key in the KeychainIf you add an OpenAI, Anthropic or custom-endpoint key, it is stored in the macOS Keychain on this device only, without iCloud Keychain sync, and used to authenticate requests to that provider. Requests do not pass through BITSUMMIT.
- Network destinationsDuring a meeting with the local model: none, apart from Ollama on your own Mac. Otherwise: your chosen AI provider or custom endpoint when you select one; Hugging Face when you download a speech model, and Ollama's registry when Ollama pulls a language model; Apple's App Store for purchase and updates; BITSUMMIT's feedback service on Supabase only when you send the form.
How it behaves
- Consent is yours to getRecording laws differ by region. During setup the app asks you to confirm that consent from the other people on a call is your responsibility. Recording starts automatically when a supported meeting is detected, and the app does not announce itself to them.
- Built for one personNo team workspace and no share link. Each person has their own copy and shares exported files the way they already share files.
- DeletionDeleting a meeting in the Library removes its recording, transcript, notes, search entries and the exported file from your Mac. Deleting the app does not remove its container; remove ~/Library/Containers/ca.bitsummit.CallIntelligence as well. Copies in synced or backed-up folders are governed by those services.
- This websiteSets no cookies and runs no analytics. Fonts load from Google Fonts, and the hosting provider, Microsoft Azure Static Web Apps, receives standard request data such as IP address to serve the page.
The privacy policy covers the same handling in policy terms. For an evaluation, send your security questions or questionnaire to sales@bitsummit.ca; we answer from the documented behaviour above.
Need details for an evaluation?
Ask us about your intended setup.
We can clarify processing options, permissions and deployment requirements for your security review, and answer specific questions about the released build.