Markdrip Privacy Policy
For a shorter, plain-language overview, see ourprivacy summary.
1. Who we are
Markdrip is developed by Markdrip.
For privacy inquiries, contact us at[email protected].
This policy applies to the Markdrip desktop application for macOS and any future platforms on which it is offered.
2. On-device processing — what stays on your Mac
Markdrip is a local-first application. All core processing happens entirely on your device:
- Audio recording — microphone and system-audio capture, stored and processed locally.
- Transcription — speech-to-text runs on-device using models downloaded to your Mac.
- Speaker identification — voice fingerprinting, diarization, and name matching all run locally.
- Summarization and analysis — meeting summaries, action items, and topics are generated on-device.
- Search — full-text and semantic search run against a local index.
Tier 0 — never transmitted
Markdrip never sends your raw audio or voice fingerprints anywhere — not to us, not to anyone, in any mode. They are stored only on your device. This is a hard architectural constraint, not a setting:
- Audio — recordings are processed and stored locally; raw audio is never uploaded.
- Voice fingerprints and clips — used only to recognize speakers across your own meetings, stored locally. See theBiometric & Voice Data Notice for full details.
No setting, consent flow, or future feature can override this constraint.
(If you place your vault in a cloud-synced folder such as iCloud Drive or Dropbox, that service will sync your vault files — including recordings — under your own settings; Markdrip does not do this and cannot see it.)
Tier 1 — on-device by default
Your transcripts, notes, summaries, contact records, and search index are stored on your device by default. Tier 1 content may leave your device only if you explicitly enable an optional egress mode (each is off by default and discloses exactly what is sent and where).
3. License and commerce communications
The desktop application's license service carries a deliberately minimal payload that includes no Tier 0 or Tier 1 content:
- At activation (once, when you first activate): your license key and a machine fingerprint (a device identifier bound to your license), so your paid license can be issued and bound to your device.
- On heartbeat (at most once per 24 hours, only when your device is already online): license validation only — an activation identifier, a timestamp and anti-replay nonce, and a cryptographic signature. No usage counters, no location data, no content of any kind.
- Your IP address is seen transiently to answer the request and is not retained. The only connection-derived record is a short-lived (no more than 72 hours), one-way-hashed abuse-prevention record used for rate limiting.
This license exchange never includes your audio, transcripts, notes, summaries, voiceprints, contacts, or any Tier 0 or Tier 1 content. License validation itself does not include product-usage data.
Product-usage measurement
The app sends pseudonymous, content-free usage measurements: integer counts of product actions such as completed recordings and feature activations, and current object counts in your vault. No audio, transcripts, notes, summaries, voiceprints, speaker names, or other meeting content is included.
Regional default. Outside the EEA and UK, usage reporting is on by default. Inside the EEA and UK, it is off by default and requires your explicit opt-in.
Opt-out. Turn usage reporting off — or on — at any time under Settings → Privacy → Share usage data. Turning it off immediately stops future sends and clears any queued measurements on your device; it does not affect recording, transcription, local files, or your license. A "Delete previously shared data" button sends an authenticated deletion request for measurements already sent; a failed request remains retryable and does not re-enable reporting.
What the service receives. The app sends authenticated numeric measurements bound to an install-specific key. The server observes the connection address and derives a coarse network prefix (/24 for IPv4, /48 for IPv6) and a two-letter country code, stored alongside the measurements for aggregate product analysis. The raw connection address is never written to any database, log, or export.
IP Geolocation attribution. Country-code derivation uses a third-party IP-to-country dataset. IP Geolocation byDB-IP — licensed underCC BY 4.0.
Retention. The pseudonymous measurement series is retained for 35 days. Aggregate statistics (thresholded, not linked to any install or person) are retained for 13 months.
4. Optional Google Calendar connection
Google Calendar is an optional connection. It is off by default: we access it only after you choose to connect Google Calendar and select the calendars you want Markdrip to read. The connection requests only the read-only calendar.calendarlist.readonly andcalendar.events.readonly permissions. Markdrip cannot create, change, or delete your calendar events.
What we read and why
From the calendars you select, Markdrip reads event titles, start and end times, attendees, locations, and event descriptions (including join-link context). We use that information on your device to auto-title meetings and enrich their local meeting context. We do not read calendar data for advertising, profiling, product analytics, or any unrelated purpose.
Direct connection, local storage, and sharing
Calendar metadata travels directly from Google to your device under your Google account. Markdrip infrastructure is not in this data path, does not receive a copy of your event metadata, and does not share it with third parties. Access and refresh tokens are stored only in your operating system's keychain, not in your vault or on Markdrip servers. The event metadata used for meeting context stays locally on your device.
Retention and disconnect
You can disconnect Google Calendar at any time. Disconnecting removes local keychain tokens and purges the local remote-calendar state and derived calendar context. Markdrip also asks Google to revoke the grant; this provider request is best-effort, so you can revoke access directly in your Google Account if it does not complete. Raw audio and voiceprints never leave your device in any mode.
5. Purchases
Markdrip sells its plans directly. Stripe is our payment processor: it processes the checkout transaction on our behalf and is not the seller of the plan. Checkout is currently unavailable; this section describes the data handling that applies if you choose to purchase when checkout is enabled.
Checkout and billing data
Stripe processes your email address, billing name and address, payment-method details, browser IP address, selected plan, price, tax, currency, and recurring-charge consent. Stripe uses this information to complete the transaction, calculate tax, prevent fraud, manage a subscription, and provide a receipt. Markdrip receives and keeps the minimum commerce information needed to deliver and manage your license, provide billing support, reconcile payments, and meet accounting, tax, security, and legal obligations. We do not receive or store your full payment-card number.
We keep commerce records only for as long as needed for those purposes. Some purchase, payment, tax, fraud-prevention, and dispute records may be retained longer where law, regulation, or a valid legal request requires it. Closing an account or cancelling a subscription does not necessarily erase records that Markdrip or Stripe must retain for those purposes.
Recipients and international transfers
Stripe receives checkout and payment data as Markdrip's payment processor. Stripe may process that data in the United States and other countries and uses service providers to operate its services. Stripe publishes information about its data-processing terms,international-transfer safeguards, andservice providers. We will keep our processor and transfer records current before checkout is enabled.
Your choices and rights
For questions, access, correction, deletion, restriction, objection, or portability requests concerning commerce data, contact[email protected]. We will respond under applicable law and explain any record we cannot delete because of a legal, tax, accounting, security, or dispute-retention obligation. These requests do not affect your local meeting data, which remains on your device.
Commercial measurement
We do not collect a role field or segment commercial measurement by role at this launch. We do not infer a role from meeting, contact, support, license, or product-use data.
Optional refund feedback
If you choose to select a refund reason, the selected reason and any additional text you provide are saved only on your Mac. This feedback does not affect a refund, is not sent to Markdrip, Stripe, or the licensing service, and is not used for central measurement. It becomes eligible for deletion 47 days after it is saved. The App removes eligible feedback the next time it starts or you save additional refund feedback. You can delete all saved refund feedback in the App's Settings at any time. Do not include meeting content or other sensitive personal information in additional text.
6. Model downloads
The only other network use is explicit, user-initiated downloads of on-device models (for example, the first time you enable a feature that needs a model you do not have yet). These are downloads to your machine. They send none of your data out. You can see and control them from the Models settings panel; once a model is downloaded, using it requires no network connection.
7. What Markdrip does not do
- No meeting content sent. Audio, transcripts, notes, summaries, voiceprints, and speaker names never leave your device.
- No crash reporting that phones home.
- No hosted or third-party search — search runs against a local index.
- No account required to use the application.
This public marketing site uses first-party, privacy-respecting website analytics to understand page popularity. The account portal, billing site, documentation, and founder console do not load analytics. Marketing page-view data is not linked to your identity, license, or desktop application usage, and sets no tracking cookies.
8. Voice and biometric data
Markdrip creates and stores voice fingerprints (mathematical representations of a person's voice) and short voice clips (up to approximately ten seconds) to recognize speakers across your meetings. This data may constitute biometric information under applicable law.
For complete details — including what is stored, why, how automatic recognition works, your controls, retention terms, consent, and the no-sale guarantee — see theBiometric & Voice Data Notice.
Retention
Voice data is retained on your device until you delete it. There is no automatic expiration. You control retention entirely through in-app actions (forget a person, erase all voice data, or discard individual samples).
Permanent destruction and uninstall
Deleting (uninstalling) the Markdrip application does not automatically delete your voice data or your meeting vault. The voice-data database and your vault remain on your Mac in their respective application-support and vault directories.
To permanently destroy all voice data before uninstalling:
- Open Markdrip → Settings → Privacy.
- Select “Erase all voice data” and confirm.
- Uninstall the application.
Alternatively, you can manually delete the Markdrip application-support directory after uninstalling. The application provides an “Erase all voice data” control so that you can verify destruction before removing the app.
9. Data-subject rights
Because your data lives on your device, you exercise your rights directly in the application — no request to Markdrip is needed:
| Right | How to exercise it |
|---|---|
| Access / review | View and play back your stored voice clips, transcripts, and notes at any time. |
| Rectification | Rename speakers, correct transcripts, and edit notes directly. |
| Erasure | Forget a person's voice, erase all voice data, or delete individual meetings and notes. |
| Portability | Export your vault (Markdown files), voice-consent records (Markdown or JSON), and contact data at any time. Your vault is already stored as plain Markdown and SQLite — standard, non-proprietary formats. |
| Restrict processing | Turn off speaker identification in Settings to stop future voice matching. |
| Object | Turn off any feature (speaker identification, summarization, etc.) at any time in Settings. |
If you believe Markdrip is not honoring these commitments, contact us at [email protected].
10. Children's privacy
Markdrip is not directed at children under 13 (or under 16 in jurisdictions where that threshold applies). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the use of Markdrip, please contact us at [email protected].
11. Changes to this policy
Any change that would introduce a new egress mode in the desktop application — new telemetry, product analytics, content sync, or a user-directed integration — will be reflected in a published update to this policy before that change ships. Material changes will be communicated through the application and on our website.
First-party website analytics on public marketing pages are governed by this policy and do not affect the desktop application's zero-exfil guarantee (§2).
We will not retroactively weaken the Tier 0 guarantee (§2) without updating this policy and obtaining any consent required by applicable law.
App Store privacy nutrition labels
For the purposes of App Store privacy disclosures:
- Data Not Collected — audio, transcripts, notes, contacts, voice data, and search queries. Markdrip does not collect or transmit this content.
- Data Not Linked to You — pseudonymous usage data (integer product-action counts and vault-object counts, linked to an install-specific key, not to your name, Apple ID, or account).
- Data Linked to You — license identifiers and purchase history; Stripe processes payment details for checkout.
This policy is published alongside theBiometric & Voice Data Notice and linked from the Markdrip application.