Privacy & safety
Freehand sends audio and text to the services you configure. Their own privacy and retention policies apply, whether they run locally, on your network, or with a hosted provider.
Audio & text
Microphone and selected-file audio goes to the transcription endpoint. Optional cleanup sends the transcript to a separate chat endpoint. Speech generation sends the text you enter or select to the speech endpoint.
Captured audio is released when the request ends, including failure or cancellation. Selecting an existing audio file does not change or delete the original.
Results & history
Current results remain available in memory until cleared, replaced, or Freehand exits. Recovery and explicit copying do not require history.
History is off by default. When enabled, it is memory-only, limited to 20 entries and 2 MiB, and cleared on exit. It does not contain audio or credentials.
Generated speech
Generated audio stays in memory until cleared or replaced, a recording begins, or Freehand exits. Saving the generated audio to a file is an explicit action.
Keys & settings
Saved API keys use Windows Credential Manager or macOS Keychain. Freehand does not display stored keys or write them to the settings database.
Your saved connections, vocabulary, and other settings are stored in a local database. That database is not encrypted; treat it and its backups as private configuration.
Connections
HTTPS is required by default. You can explicitly allow HTTP for a trusted local or network endpoint, but it sends data without transport encryption. Transcription, cleanup, speech, and connection-check requests do not follow redirects.
Text insertion
Freehand captures the destination before recording. Windows checks the original application, process, and focused control. macOS checks the application and window; moving between fields in that same window is allowed.
If validation fails, Freehand does not activate another app and leaves the result ready to copy. Delivery can be partial, so check for existing text before copying again. Automatic delivery does not silently replace the clipboard.
macOS Secure Input blocks delivery when active, but not every custom secure field can be detected.
Checks & updates
Connection checks read health or model metadata without running inference. Automatic update checks contact GitHub release metadata and can be disabled in Settings. They do not send recordings or transcripts to GitHub.
Diagnostics
Operational logs exclude audio, transcript text, credentials, private headers, full paths, model IDs, URL paths and queries, and destination-window identity.
Managed runtime output is separate: Freehand keeps a bounded rolling tail in private memory, even with history off and the output viewer closed. Upstream output can contain transcripts, prompts, paths, or other sensitive text. Embedded Runtime output displays immediately when opened; the standalone Process output window asks for consent each time. Hiding a viewer clears its displayed text and stops reads, but does not erase the private tail. Clear, the next runtime start attempt, removal, or Quit discards it. It is not saved as a log file.
Update helper log
Restarting into an app update creates a temporary helper log containing installation paths and replacement errors. Paths can reveal your account name. The helper does not receive recordings, transcripts, or inference API keys, and it does not delete this log afterward. Review it before sharing it for support.