What VoxaFlow sends
Your voice and your text stay on your Mac. Here is every connection the app makes, with real example requests.
Last updated: October 6, 2026
In short: VoxaFlow talks to two of our servers today, both at Hetzner in Germany: once to download the models, then once a day to check for updates. No account, no device ID, no usage data. Speech recognition and the AI cleanup run on your Mac, so dictation works with Wi-Fi turned off.
The servers the app may contact
The app has a fixed list of hosts (Endpoints.allowedHosts). An automated test fails as soon as the source code or one of the libraries contacts anything else.
| Host | Purpose | Since |
|---|---|---|
models.voxaflow.ai | Speech and language models (mirror, fixed versions) | 0.6.4 |
updates.voxaflow.ai | Update check and downloads | 0.6.4 |
license.voxaflow.ai | Beta and license check | planned for 0.8 |
packs.voxaflow.ai | Signed vocabulary packs (Coding) | planned for 0.9 |
The website voxaflow.ai is only ever opened in your browser (for example the beta notice), never loaded by the app.
1. Model download
When: once after installing, and when you switch models. About 2.2 to 2.8 GB, depending on the model. A finished model starts without any network request.
The app first asks for the file list, then fetches the files in pieces (so an interrupted download can resume) and checks each file against its size and checksum. A real request for the language model:
GET /mlx-community/Qwen3.5-2B-MLX-4bit/resolve/main/model.safetensors
Host: models.voxaflow.ai
Range: bytes=0-4194303
User-Agent: VoxaFlow/0.7.0
Accept-Language: *
Accept: */*
Accept-Encoding: gzip, deflateThat is the complete request: no cookie, no token, no identifier. One exception: the speech recognition model (Parakeet, plus the detector that checks whether anyone is speaking) is downloaded by the open-source library FluidAudio, which uses the macOS defaults, a user agent such as VoxaFlow/13 CFNetwork/3896.100.1.1.1 Darwin/27.0.0 and your preferred languages (Accept-Language: en-US,en;q=0.9). The Darwin version tells which macOS version you use. Up to version 0.6.6 the language models were downloaded the same way; from 0.7.0 they send the request above.
2. Update check
When: once a day. You can turn it off under Settings › About. VoxaFlow uses Sparkle, with updates signed by our own key and notarized by Apple.
GET /beta/appcast.xml
Host: updates.voxaflow.ai
User-Agent: VoxaFlow/0.6.6 Sparkle/2.10.0
Accept: application/rss+xml,*/*;q=0.1
Accept-Language: en-US,en;q=0.9
Accept-Encoding: gzip, deflate, brNo system profile (Sparkle can send one; it is switched off), no query parameters. The preferred languages are added by macOS to every request. If there is an update and you install it, the app downloads the file named in the feed, a delta of a few MB or the full archive of about 40 MB.
3. Optional: sync via iCloud
When: only if you turn on sync under “iCloud & Data” (from 0.7.0). The app then puts dictionary, snippets, settings and statistics, and optionally the history, into the “VoxaFlow” folder in your iCloud Drive.
This is not a connection of the app: it writes files to a folder on your Mac, and macOS uploads them to your iCloud. A network monitor shows macOS processes such as bird or cloudd for this, not VoxaFlow. Every file is encrypted with AES-256-GCM on your Mac first; this is how a file starts:
VoxaFlow/devices/9DCB2FAD-…/profile.vxenc
56 58 46 31 01 40 25 d2 46 28 1b ec 78 bc 0d f8 VXF1.@%.F(..x...Only your devices have the key: in the keychain and as a recovery code that you enter on further Macs. Neither Apple nor we can read the contents.
4. Coming with version 0.8: beta and license check
From 0.8 the beta license, and from 1.0 a bought license, is checked on license.voxaflow.ai: when you activate, then about every 30 days. The planned request:
POST /v1/beta
Host: license.voxaflow.ai
User-Agent: VoxaFlow/0.8.0
Content-Type: application/json
{"device_hash": "3f9a…", "platform": "mac", "app_version": "0.8.0"}The device hash is a SHA-256 of a fixed prefix and the hardware UUID of your Mac. The UUID itself is never sent, and the hash cannot be turned back into it. It lets one license cover two devices. We will update this page with real requests before 0.8 ships.
Never sent to us
- Your voice, your dictated text, your history (with iCloud sync only encrypted into your own iCloud)
- What you select or copy, the names of apps, windows or documents
- Dictionary entries and snippets (the same)
- Name, email address, user name, device name, serial number, hardware model
- Usage statistics, word counts, crash reports, analytics of any kind. The overview in the app is computed only on your Mac.
- Anything to third parties: no Hugging Face, no cloud AI, no analytics service
“Report a Problem …” in the menu creates a text file with version, Mac model, settings, log entries and the latest crash report (no dictated text, no audio) and opens an email in your mail app. It only leaves your Mac if you click Send.
What our servers keep
- Access logs with shortened IP addresses (IPv4 /16, IPv6 /32), without user agent and languages, deleted after 7 days.
- Anonymous counts: from each update check our statistics derive country, region and city, the app version and a checksum that changes every day, so we can see how many installations are active. The IP address is not stored.
- Servers at Hetzner in Germany, under a data processing agreement. No US cloud services.
The full legal text is in the privacy policy.
Check it yourself
- With a network monitor such as Little Snitch or LuLu you see every connection VoxaFlow makes. Expect
models.voxaflow.aion first launch andupdates.voxaflow.aionce a day, nothing else. - Turn off Wi-Fi after the models are downloaded: dictation keeps working.
- An automated test in the app's test suite (
NetworkAuditTests) hooks into every network session of the app and its libraries and fails on any host not on the list above. Our measurement for 0.6.6 with empty caches and an update check due: 68 requests tomodels.voxaflow.ai, 1 toupdates.voxaflow.ai, no other hosts.
Found something that does not match this page? Write to hello@voxaflow.ai.