VoxaFlow

What VoxaFlow sends

Your voice and your text stay on your Mac. Here is every connection the app makes, with real example requests.

Last updated: October 6, 2026

In short: VoxaFlow talks to two of our servers today, both at Hetzner in Germany: once to download the models, then once a day to check for updates. No account, no device ID, no usage data. Speech recognition and the AI cleanup run on your Mac, so dictation works with Wi-Fi turned off.

The servers the app may contact

The app has a fixed list of hosts (Endpoints.allowedHosts). An automated test fails as soon as the source code or one of the libraries contacts anything else.

HostPurposeSince
models.voxaflow.aiSpeech and language models (mirror, fixed versions)0.6.4
updates.voxaflow.aiUpdate check and downloads0.6.4
license.voxaflow.aiBeta and license checkplanned for 0.8
packs.voxaflow.aiSigned vocabulary packs (Coding)planned for 0.9

The website voxaflow.ai is only ever opened in your browser (for example the beta notice), never loaded by the app.

1. Model download

When: once after installing, and when you switch models. About 2.2 to 2.8 GB, depending on the model. A finished model starts without any network request.

The app first asks for the file list, then fetches the files in pieces (so an interrupted download can resume) and checks each file against its size and checksum. A real request for the language model:

GET /mlx-community/Qwen3.5-2B-MLX-4bit/resolve/main/model.safetensors
Host: models.voxaflow.ai
Range: bytes=0-4194303
User-Agent: VoxaFlow/0.7.0
Accept-Language: *
Accept: */*
Accept-Encoding: gzip, deflate

That is the complete request: no cookie, no token, no identifier. One exception: the speech recognition model (Parakeet, plus the detector that checks whether anyone is speaking) is downloaded by the open-source library FluidAudio, which uses the macOS defaults, a user agent such as VoxaFlow/13 CFNetwork/3896.100.1.1.1 Darwin/27.0.0 and your preferred languages (Accept-Language: en-US,en;q=0.9). The Darwin version tells which macOS version you use. Up to version 0.6.6 the language models were downloaded the same way; from 0.7.0 they send the request above.

2. Update check

When: once a day. You can turn it off under Settings › About. VoxaFlow uses Sparkle, with updates signed by our own key and notarized by Apple.

GET /beta/appcast.xml
Host: updates.voxaflow.ai
User-Agent: VoxaFlow/0.6.6 Sparkle/2.10.0
Accept: application/rss+xml,*/*;q=0.1
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, br

No system profile (Sparkle can send one; it is switched off), no query parameters. The preferred languages are added by macOS to every request. If there is an update and you install it, the app downloads the file named in the feed, a delta of a few MB or the full archive of about 40 MB.

3. Optional: sync via iCloud

When: only if you turn on sync under “iCloud & Data” (from 0.7.0). The app then puts dictionary, snippets, settings and statistics, and optionally the history, into the “VoxaFlow” folder in your iCloud Drive.

This is not a connection of the app: it writes files to a folder on your Mac, and macOS uploads them to your iCloud. A network monitor shows macOS processes such as bird or cloudd for this, not VoxaFlow. Every file is encrypted with AES-256-GCM on your Mac first; this is how a file starts:

VoxaFlow/devices/9DCB2FAD-…/profile.vxenc
56 58 46 31 01 40 25 d2 46 28 1b ec 78 bc 0d f8   VXF1.@%.F(..x...

Only your devices have the key: in the keychain and as a recovery code that you enter on further Macs. Neither Apple nor we can read the contents.

4. Coming with version 0.8: beta and license check

From 0.8 the beta license, and from 1.0 a bought license, is checked on license.voxaflow.ai: when you activate, then about every 30 days. The planned request:

POST /v1/beta
Host: license.voxaflow.ai
User-Agent: VoxaFlow/0.8.0
Content-Type: application/json

{"device_hash": "3f9a…", "platform": "mac", "app_version": "0.8.0"}

The device hash is a SHA-256 of a fixed prefix and the hardware UUID of your Mac. The UUID itself is never sent, and the hash cannot be turned back into it. It lets one license cover two devices. We will update this page with real requests before 0.8 ships.

Never sent to us

“Report a Problem …” in the menu creates a text file with version, Mac model, settings, log entries and the latest crash report (no dictated text, no audio) and opens an email in your mail app. It only leaves your Mac if you click Send.

What our servers keep

The full legal text is in the privacy policy.

Check it yourself

Found something that does not match this page? Write to hello@voxaflow.ai.