Privacy Policy
Nublet is on-device by design: the things you do with it happen on your Mac, and we go out of our way not to see your content.
Last updated: not set
This document is a draft pending review.
The legal entity, effective date and governing law are not yet set, and the source drafts ask for a lawyer’s review before publication. Fill in legal in components/data/site-config.ts and this notice disappears.
Nublet (“we”, “us”) is a macOS app made by [legal entity not set].
The short version
- What you do in the app stays on your Mac. Your dictation audio and transcripts, clipboard history, stashed files, notes and camera images are processed and stored locally. They are never uploaded to us.
- No analytics, no tracking, no ads, no third-party SDKs. We do not operate a server that receives your content.
- Some features are about things on the internet — a YouTube video, the lyrics to the song you’re playing, a model you chose to download. Those make ordinary web requests, listed in full below. Every one is triggered by something you do, and none sends us your content.
What stays entirely on your device
- Voice dictation — audio is transcribed on-device. We set
requiresOnDeviceRecognition, so it cannot fall back to a speech server. The Whisper tokenizer ships inside the app, so dictation works with the Wi-Fi off. - Clipboard history — a local database on your Mac only.
- Stashed files — references to your own files, on your Mac.
- Camera mirror, Photo Booth, screen recordings — processed locally and saved to the folder you choose.
- AI rewriting and summarising — runs on-device. Your text is not sent to any AI service.
- Notes — read and written directly to your own Apple Notes library through macOS. It syncs the way Notes already syncs for you; Nublet keeps no copy and is not part of that sync.
- Agent companion — reads coding-agent transcripts already on your disk. Nothing is uploaded, and cost figures are estimated locally.
Every request Nublet can make
| When | Where it goes | What is sent | Why |
|---|---|---|---|
| You summarise a YouTube link | youtube.com, and googlevideo.com if the video has no captions | The video ID, and your IP as with any web request. If there are no captions the app downloads the audio to transcribe on-device. Nothing of yours is uploaded. | To fetch the transcript the summary is made from. |
| A YouTube link's preview card is shown | i.ytimg.com (inside an embedded web view) | The video ID and your IP, to load the thumbnail. | To show a preview instead of a bare URL. |
| Something is playing and synced lyrics are on | lrclib.net | The track title, artist and duration of whatever is playing — including titles picked up from a browser tab. In effect your listening history, one lookup per track. No account, no identifier. | To fetch time-synced lyrics. Turn it off in Settings ▸ Media ▸ Synced lyrics, or with Fully offline. |
| Album art is missing locally | Spotify's image CDN (i.scdn.co) | An image request and your IP. | To show cover art for the current track. |
| You download a language model | models.nublet.app | A plain file request (IP, user-agent). No account, no personal data. | To deliver the model file. |
| A copied link is previewed | The site the link points to | Your Mac requests that page — first for its title and image, then, when the preview card opens, as a full page load with that site's own scripts and cookies. | To show a rich preview instead of a bare URL. Turn it off in Settings ▸ Clipboard if you copy sensitive links. |
| You check for updates (or turn on automatic checks — off by default) | GitHub (raw.githubusercontent.com for the appcast, github.com for the download) | Your app version and macOS version, as Sparkle sends them. Anonymous — we do not enable Sparkle's system profiling. | To tell you a new version exists. |
| You activate a licence | Polar (api.polar.sh) | Your licence key and your Mac's name, which Polar shows you so you can tell your activations apart. Payment details go to Polar as merchant of record — we never see your card. | To activate your licence on this Mac. |
| The app re-checks your licence at launch | Polar (api.polar.sh) | Your licence key and activation id. This one is automatic once you have a licence — it is how a refunded or revoked key stops working. Turned off by Fully offline. | To confirm the licence is still valid. |
| You send feedback | Currently your email app (a mailto: to support@nublet.dev) | Whatever you write. | So we can read and act on it. |
| You email us | Our email provider | Whatever you write. | To answer you. |
We do not control YouTube, LRCLIB, Spotify, GitHub, Polar, or the sites behind links you copy. When your Mac talks to them it is an ordinary web request from your IP address and their own privacy policies apply. We do not receive a copy.
There is no telemetry, no crash reporting, no usage analytics, and no ad or attribution SDK. We do not know how many times you open the app or which features you use.
Turning the network off
Settings ▸ General ▸ Fully offline stops the licence check, album-art lookups and lyrics. It does not currently cover update checks, link previews, YouTube requests or model downloads — all things you explicitly ask for. Update checks can be turned off separately in Settings ▸ About, and link previews in Settings ▸ Clipboard. We would rather write that down plainly than let “Fully offline” imply more than it does.
Payments
Purchases are handled by Polar, which acts as merchant of record and processes your payment information under its own privacy policy. We do not see or store your card details.
Data retention and your rights
- Feedback or email you send us is kept until we’ve acted on it, then may be deleted.
- You can ask us to access or delete anything you’ve sent us at support@nublet.dev, and we’ll do it within a reasonable time.
- Everything else lives on your Mac, where you can delete it yourself. We don’t sell your data — we don’t have any to sell.
Children
Nublet isn’t directed at children under 13 (or the age of digital consent in your country) and we don’t knowingly collect their information.
Changes
If we change this policy we’ll update the date above and, for material changes, note it in the app or on the website. The request table was last verified against v0.19.0 (build 205).
Questions? support@nublet.dev