Security and data handling

Understand where your meeting data goes.

NoteHand transcribes meeting audio on your Mac. The AI provider you choose determines where Coach suggestions and meeting notes are generated. Here's how processing, storage and permissions work.

Processing options

Set it the way you would use it, and see what is processed where.

Transcription always runs on your Mac. The setting below decides where Coach and notes are generated, and the table changes with it.

AI provider for Coach and notes
The default. Transcription, Coach and notes all run on this Mac. Transcript text is sent to the provider or custom endpoint you chose, authenticated with your API key. Audio is not sent.
Your Mac
  • AudioMeeting app and your microphone
  • TranscriptWhisper, on the device
  • NotesSummary, decisions, actions
  • Your API keyStored in the macOS Keychain
  • Usage dataNone is collected
Outside your Mac
OpenAI or Anthropic Transcript text for Coach and notes, plus any agenda or notes you typed, under your own account and their terms. The request is authenticated with your API key. Audio is not sent.

Nothing from the app. Audio, transcript and notes stay on this Mac.

DataWhere it goes
Audio from the meeting and your microphoneStays on the Mac in every setting
TranscriptStays on the Mac
NotesWritten on the Mac
Your API keyStored in the macOS Keychain; sent only to the provider it belongs to, to authenticate requests
Exported Markdown filesYour export folder. If that folder is synced by iCloud Drive, Dropbox or a company service, that service handles the copies
Usage data, analytics, crash reportsNot collected
Speech model downloadDownloaded from Hugging Face when you choose a model; local language models are pulled through Ollama on the Mac
PurchaseHandled by Apple through the App Store; BITSUMMIT receives no payment details
A message to BITSUMMITOnly when you send the in-app feedback form (your message and, for bug reports, the app and macOS versions, provider names and recent logs if you opt in) or write to us

Permissions

Permissions support the features you turn on.

For each one: what the permission is, why NoteHand requests it, and how the app uses it. macOS asks the first time a feature needs it.

Why NoteHand asks

To record your side of a call and to hear you when you dictate.

How the app uses it

The microphone is opened only while a recording or a dictation is running. The menu bar shows when the app is capturing.

Asked

The first time you record or dictate. Both builds.

For your security team

Technical facts about the released build.

Mac App Store version 1.0 (8), released 1 September 2026. Documented behaviour, not a certification.

How it is built

  • App Sandbox and hardened runtimeThe app runs sandboxed with the hardened runtime and ships a privacy manifest. App Store review is a distribution review by Apple, not an independent security audit.
  • StorageRecordings, the meetings database, the search index and downloaded models live in the app's sandboxed container. The export folder you choose is the one location outside it the app can write to, through a security-scoped bookmark. A diagnostic log with 14-day rotation lives in the container too, and an optional setting removes completed meetings' audio after a chosen period.
  • API key in the KeychainIf you add an OpenAI, Anthropic or custom-endpoint key, it is stored in the macOS Keychain on this device only, without iCloud Keychain sync, and used to authenticate requests to that provider. Requests do not pass through BITSUMMIT.
  • Network destinationsDuring a meeting with the local model: none, apart from Ollama on your own Mac. Otherwise: your chosen AI provider or custom endpoint when you select one; Hugging Face when you download a speech model, and Ollama's registry when Ollama pulls a language model; Apple's App Store for purchase and updates; BITSUMMIT's feedback service on Supabase only when you send the form.

How it behaves

  • Consent is yours to getRecording laws differ by region. During setup the app asks you to confirm that consent from the other people on a call is your responsibility. Recording starts automatically when a supported meeting is detected, and the app does not announce itself to them.
  • Built for one personNo team workspace and no share link. Each person has their own copy and shares exported files the way they already share files.
  • DeletionDeleting a meeting in the Library removes its recording, transcript, notes, search entries and the exported file from your Mac. Deleting the app does not remove its container; remove ~/Library/Containers/ca.bitsummit.CallIntelligence as well. Copies in synced or backed-up folders are governed by those services.
  • This websiteSets no cookies and runs no analytics. Fonts load from Google Fonts, and the hosting provider, Microsoft Azure Static Web Apps, receives standard request data such as IP address to serve the page.

The privacy policy covers the same handling in policy terms. For an evaluation, send your security questions or questionnaire to sales@bitsummit.ca; we answer from the documented behaviour above.

Need details for an evaluation?

Ask us about your intended setup.

We can clarify processing options, permissions and deployment requirements for your security review, and answer specific questions about the released build.