Privacy Policy

Last updated: September 2026

Summary

Enzo, formerly Glassfox and Chirp, runs transcription, speaker recognition, and Recall collection on your Mac. Ask uses Local by default. Optional DeepSeek Flash sends your question, recent conversation, and selected text context directly to DeepSeek using your own API key. Selected text may include excerpts from recordings, Recall, documents, and your screen. Raw audio, files, screenshots, and images are not sent in that cloud request. Optional web research sends a public query directly to a search provider and retrieves selected public sources. Neither cloud answers nor web research pass through Enzo servers. Feedback and connected AI tools have their own data boundaries, described below.

What Stays on Your Mac by Default

With Local selected, the following content is processed on your Mac. Choosing a cloud answer can send selected text from these sources to DeepSeek; connecting another AI tool or submitting feedback can also share information you choose:

  • Audio, transcripts, meeting content, dictated notes, and personal conversations
  • Speaker profiles, generated documents, and files or images attached to Ask
  • Recall app, window, document, website, timing, or readable-text context
  • Temporary screen frames used for local text recognition or screen context you explicitly capture
  • Names, emails, account identifiers, filenames, speaker names, or precise location in anonymous app analytics

How Enzo Works

Transcription and Local answer generation use your Mac with Apple Silicon hardware acceleration. That means:

  • No internet connection is required for transcription
  • No audio is ever uploaded to any server
  • Transcription does not send recording content to a cloud provider. Optional cloud answers can use selected transcript text.
  • Your transcript archive is stored on your Mac. Selected excerpts sent to DeepSeek are handled under that provider's terms and privacy policy.
  • In Ask, the local model decides per question whether current public information is needed. When web research is enabled, your Mac sends one bounded query—derived from the current question and, for follow-ups, recent user questions—directly to DuckDuckGo or, if needed, Bing. It then directly opens a bounded number of selected public pages or documents so their readable text can be extracted locally. Nothing is routed through a Enzo search service. These search requests do not include recordings, attached-file contents, Recall or screen content, assistant messages, the full conversation, or the assembled prompt. Answer generation stays on your Mac with Local selected; the optional cloud answer has the separate boundary described below.
  • If you explicitly connect Enzo's local MCP server to another AI tool, that tool can read the transcript excerpts needed to answer your request. Cloud AI tools process those excerpts under their own privacy terms; local AI tools keep them on your Mac.

How Recall Works

Recall is off until you explicitly enable it. While it is on, Enzo records the foreground app and time, then adds bounded window, document, website, and readable focused-app text when macOS exposes that context safely. An app Enzo cannot safely read contributes app and time only.

  • Local protected storage: Recall uses a separate database on your Mac. Readable text, window and document titles, website details, and summaries are encrypted with a key held in the macOS Keychain; app identity and timestamps remain local structured metadata. Captured evidence expires after 30 days by default.
  • Accessibility first: Enzo reads a bounded view of the focused app through macOS Accessibility. It does not scroll, click, type into, or otherwise control that app.
  • Optional visible-text fallback: If you enable it, Enzo temporarily captures the focused window, recognizes visible text locally, and immediately discards the pixels. Recall does not keep a screenshot archive.
  • Sensitive surfaces: Passwords, secure fields, protected content, known private-browser windows, excluded apps, and Enzo's own windows are not captured as readable context.
  • Browser limitation: Some browsers do not expose a reliable private-window signal to macOS. They remain app-only unless you explicitly enable Visible browser text after a warning that private windows may be included.
  • Speak recordings: Saved recordings appear in Recall at the time they happened and open back to Speak. Their transcripts remain in Speak; Ask and daily briefs can use them locally without copying them into Recall.
  • Ask: Built-in Ask may search Recall locally and use a bounded set of relevant moments. Every source used for an answer is preserved as an inspectable evidence receipt. Choosing DeepSeek Flash can send selected Recall text as context for that question.
  • Your controls: You can pause Recall, exclude apps, export what it saved, or delete exact context, a day, or everything.

Recall's temporary OCR frames are different from screenshots you explicitly keep during a recording with Capture now or Screen timeline. Those recording screenshots and their recognized text are stored locally with the recording in Speak until you delete it. A one-shot Current screen source in Ask discards its pixels before generation and may retain the recognized text in that answer's evidence receipt.

What Can Leave Your Mac

The app makes these limited outbound requests:

  • Optional DeepSeek Flash answers: Add your own API key and select DeepSeek Flash in Chat to use cloud answer generation. Your Mac sends the question, recent conversation, and a bounded selection of text directly to DeepSeek. This can include transcript excerpts, Recall text, extracted document text, screen text, and web sources. Raw audio, files, screenshots, and images are not sent. Your API key is stored in the macOS Keychain and sent only to DeepSeek for authentication, never to Enzo. DeepSeek receives the submitted text and ordinary connection information and processes it under its own terms and privacy policy. Switch back to Local to generate subsequent answers on your Mac; this does not retract requests already sent to the provider.
  • Optional web research in Ask: The routing decision always runs locally. When web research is enabled and needed, the app creates one bounded query from the current question and, when needed to resolve a follow-up, recent user questions. Your Mac sends that query directly to DuckDuckGo or, as a fallback, Bing, then connects directly to up to four selected public source sites to retrieve readable pages or supported documents. Search providers and source sites receive the query or requested URL plus ordinary connection and request information such as your IP address. These requests use an ephemeral session without cookies, a signed-in browser session, or a URL cache, and never pass through Enzo. The app does not include recordings, attached-file contents, Recall or screen content, assistant messages, the full conversation, or the assembled model prompt in those requests. You can turn web research off in Settings → General → Privacy. Fetched excerpts are discarded after generation; citation titles and links remain only in bounded memory for up to 30 minutes and are never written to Enzo's database.
  • License activation: When you purchase and activate a license, we process your email address and license key through our payment provider (Polar) to verify your purchase. This is required to unlock your Enzo license.
  • Anonymous usage statistics (introduced in Enzo 1.5.3): This setting is enabled by default. The app sends counts of dictations and meetings, feature use, permission and setting states, app and macOS versions, Mac model and memory, and license and trial state. Country, and US state when applicable, are derived by our server from the request. The records use a random installation identifier that is not tied to your name, email, license, audio, transcripts, filenames, or speaker names. You can turn this off anytime in Settings → Privacy, which stops future usage-statistics requests.
  • Feedback you submit: The in-app form sends the description and any contact email you choose to provide. Bug and feature submissions become public GitHub issues; support and other messages are sent privately by email. A diagnostic report is optional, is previewable before submission, and is sanitized to remove common identifiers.
  • Operational requests: License checks, model downloads, and software-update checks contact Enzo, Polar, GitHub, or our hosting provider. These requests do not contain your recording content, but those services may process standard connection information such as an IP address and user agent.
  • Optional Google Ads measurement: Only after you choose Allow on the website, Google's tag may receive the page or conversion event, ad-click attribution, and standard browser, device, and connection information, and may store or read advertising data in your browser. Declining keeps the tag blocked. Your choice is saved locally in this browser.
  • Crash reports: If the app crashes, macOS may send anonymized crash reports to Apple (not to us). You can disable this in System Settings.

Third-Party Services

We use the following third-party services:

  • DeepSeek: Only when you choose DeepSeek Flash, the provider receives the text request directly from your Mac using your API key. Provider usage charges and its terms and privacy policy apply separately from Enzo.
  • DuckDuckGo and Microsoft Bing: The app sends a bounded public search query directly to DuckDuckGo and may use Bing as a fallback. Enzo does not proxy these requests or receive their contents. Each provider handles the request under its own policy: DuckDuckGo Privacy Policy and Microsoft Privacy Statement.
  • Public source websites: To answer from primary material instead of search snippets alone, your Mac may directly retrieve up to four public pages or documents selected from the results. Those sites receive the requested URL and ordinary connection information and process it under their own terms and privacy policies.
  • Polar: Payment processing and license management. Polar's privacy policy applies to purchase transactions. View Polar's Privacy Policy
  • Supabase: Stores the app's anonymous usage-statistics records for us. These records do not contain recording content or direct account identifiers.
  • GitHub: Hosts model and app-release downloads. If you submit a bug or feature request through Enzo, the form clearly identifies that it will create a public GitHub issue before you send it.
  • Resend: Delivers private support and general-feedback email submitted through the app.
  • Google Ads: Measures ad-attributed downloads and purchases only after you allow advertising measurement. You can decline before the tag loads or change the choice below. Google processes resulting data under Google's Privacy Policy.
  • Vercel Analytics: Our website (tryenzo.ai) uses Vercel's privacy-friendly, cookieless analytics to measure aggregate traffic — page views and download or checkout clicks. It collects no personal data, sets no cookies, and has no access to anything inside the app (your audio and transcriptions never reach it). View Vercel's Privacy Policy
  • First-party traffic counts: We keep our own privacy-friendly, cookieless tally of website traffic — page views, unique-visitor estimates, downloads, approximate country, device type, and referring source. It sets no cookies, stores no IP addresses or other personal data (visitor estimates use a one-way hash that resets every 24 hours), and never touches anything inside the app.

Advertising Choices

Google Ads measurement is optional and off until you allow it. Changing this setting updates the tag immediately and controls whether it loads on future pages in this browser. Enzo's separate cookieless first-party traffic counts do not depend on this choice.

Loading your saved preference…

Data Storage

Enzo continues to store transcripts, retained audio, speaker profiles, generated documents, Ask attachments, evidence receipts, recording screen captures, Recall data, and downloaded models under the legacy ~/Library/Application Support/Chirp folder so version 1.6 can find existing local data without a risky migration. Recall uses a separate database; its sensitive text and descriptive context are encrypted, and captured evidence expires after 30 days by default. Settings are stored in macOS preferences. License and Recall encryption credentials use the macOS Keychain; license recovery also uses an encrypted, device-bound fallback under that Application Support folder. Enzo is distributed outside the Mac App Store and is not App Sandbox-contained. Moving the Enzo application to Trash does not automatically erase its Application Support data; delete content from Enzo's Speak, Recall, Speakers, and Storage controls first, or remove that folder manually after quitting Enzo. A Recall export is a readable file at the location you choose and is not removed when you later clear Enzo's local database.

Your Rights

Your content is under your control on your Mac. Recall controls let you pause new capture, exclude apps, export stored data, or permanently delete exact context, a day, or everything independently from recordings in Speak. Enzo's recording deletion controls remove live transcript content immediately and retain content-free tombstones temporarily for future synchronization safety. Turning off “Share anonymous usage statistics” in Settings → Privacy stops future anonymous usage-statistics requests. For questions or requests concerning license, feedback, website, or anonymous usage records, contact us; because usage records are not linked to an account, we may need information from your installation to locate them.

Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date.

Contact

If you have questions about this privacy policy, please contact us at hello@glassfox.ai