Privacy Policy
Lozenge runs on your Mac. There is no account, and we operate no server that your sessions, transcripts, or scripts pass through. This page says so in detail, and is honest about the third parties you can choose to involve.
Last updated September 8, 2026. Effective September 8, 2026.
1. Who this covers
This policy applies to the Lozenge macOS application and to lozenge.ai. Both are operated by Michael Lynn (“we”, “us”). Contact us at privacy@lozenge.ai.
2. The website
This site is a set of static pages. It sets no cookies, embeds no analytics, and runs no advertising or tracking scripts. We do not build a profile of you and we have no data about you to sell, because we do not collect any.
The site is hosted by Vercel Inc., which processes standard request logs (IP address, user agent, requested path, timestamp) to serve pages and protect against abuse. We do not use those logs for analytics and we do not join them to anything else. See the cookie notice for the full account.
Fonts are served from our own domain rather than a font CDN, so rendering this page contacts no third party.
3. The application
3.1 What we collect
Nothing. Lozenge has no user accounts, no telemetry, no crash reporting service, and no update check that reports who you are. We do not receive your scripts, your transcripts, your research cards, your bookmarks, your templates, or the fact that you opened the app.
3.2 What stays on your Mac
Everything the app produces is stored locally:
- Sessions, scripts, and templates are files you save where you choose, plus a bundled set inside the app.
- Transcripts, research cards, and bookmarks live in the open session until you save or export them.
- Preferences (appearance, speech locale, presenter profile, model id, toggles) are in macOS UserDefaults.
- Slide thumbnails imported from a deck are written to Application Support.
- API keys and OAuth tokens are stored in the macOS Keychain under
com.mrlynn.Lozenge. They are never written to preferences, never included in an export, and never logged.
Deleting the app and its container removes all of it. We cannot delete it for you, and we cannot recover it for you, because we never had it.
3.3 Microphone, speech, and camera
The app opens at rest. It does not listen and does not open a network port until you start a session. macOS asks for microphone and speech recognition permission the first time you use Listen or Listening Sync, and for camera the first time you record. You can withdraw any of these in System Settings at any time, and the app will tell you plainly that the feature is unavailable rather than working around it.
With the default Local Listen engine, audio is processed on device by Apple Speech and a locally cached speaker model. Audio is not sent to us and is not sent to any third party.
4. Third parties you can choose to involve
Several features call a service using credentials you supply. None of them are enabled by default with your data, none of them route through us, and each is listed here with what is sent.
| Service | When it is used | What is sent |
|---|---|---|
| OpenAI or Anthropic | Only if you select that provider and store a key. Powers Ask, research, interview assist, and intelligent import. | The relevant excerpt: your question, the current script beat and nearby outline, or a clipped transcript, plus your presenter profile and template prompt. |
| OpenAI transcription | Only if you switch the Listen engine from Local to OpenAI. | Audio chunks from the session, as WAV. |
| Ollama | Only if you select it. Runs on your machine or a host you name. | The same excerpts as above, to the base URL you configured. By default that is your own computer. |
| Google Slides | Only if you import a deck or sign in. | An OAuth request scoped to read only, then a request for the presentation you named and its thumbnails. |
| FluidInference model files | Once, on first local Listen. | A download request for the speaker model. No audio and no account. |
These providers handle that data under their own terms and privacy policies, and your relationship is with them, not with us. Their retention and training practices are theirs to state. If that matters for the conversation you are in, use the Local engine and leave the model features off. The app works without any of them.
5. The Google Slides bridge
The optional presenter bridge binds a port on 127.0.0.1 and speaks only to a Chrome extension on the same machine, using a six character pair code minted when the bridge starts. It carries next and previous, nothing else. It is off by default, it binds only while a session is running, and it is not reachable from your network or from the internet.
6. Recording other people
Lozenge is a notetaking tool for the person in the conversation. It is not a monitoring product and it should not be used as one. Laws on recording and transcribing a conversation differ by state and country, and some require every party to agree. You are responsible for having that conversation and for any consent it requires. Say plainly that you are taking notes. It costs nothing and it is the right thing to do.
7. Children
Lozenge is a tool for work. It is not directed at children under 13, and we do not knowingly collect anything from them. Since we collect nothing from anyone, there is nothing to delete, but write to us if you believe otherwise.
8. Your rights
Privacy laws including the GDPR, the UK GDPR, and the CCPA give you rights to access, correct, delete, and port your personal data, and to object to its processing. We can honour every one of those requests immediately for the simple reason that we hold no personal data about you. Your app data is on your own disk and is entirely under your control. We do not sell or share personal information, and we never have.
If you want to exercise a right, or you think we have something of yours, write to privacy@lozenge.ai and we will answer within 30 days.
9. Security
Credentials use the macOS Keychain. Network calls the app makes use TLS. The app is signed with an Apple Developer ID and notarized, so macOS can verify it has not been altered since we built it. No system is perfect, and we will tell you promptly and specifically if something goes wrong that affects you.
10. Changes
If this policy changes we will update the date above. A change that materially affects how your data is handled will be called out on this page rather than slipped in quietly.