Onvilo Privacy Policy
- Effective date: August 18, 2026
- Last updated: August 28, 2026
- Policy version: 1.0.6
- Controller/operator: Latech
- Sole proprietor’s legal name: Disclosed without delay on request before purchase through support@onvilo.app
- Geographic address: Disclosed without delay on request before purchase through support@onvilo.app
- Telephone: Disclosed without delay on request before purchase through support@onvilo.app
- Japanese Qualified Invoice Issuer registration number: T8810483333248
- Application: Onvilo (Bundle ID:
com.latech.Onvilo)
This Privacy Policy applies commonly to Onvilo’s website, purchase, licence, email, and support processing for sales in Japan, the United States, Australia, New Zealand, Hong Kong, Singapore, and any other country or region shown at checkout. Sales in countries or regions not shown at checkout are not available.
1. Scope and controller
This Privacy Policy applies to the Onvilo macOS application, the official website, free trial, purchase process, downloads, licence management, transaction email, enquiries, and support provided by the controller.
Latech, a sole proprietor in Japan, is the controller for the processing described as the operator’s processing. Contact details are in section 19.
Third-party applications or services into which you insert text, and Stripe / Link, Cloudflare, Resend, Google, Apple, or another provider acting for its own purposes, process information under their own notices and legal responsibilities.
2. Core privacy design
Onvilo processes speech recognition, text correction, and translation on your Mac.
During normal use, Onvilo does not send recorded audio, transcripts, corrected text, translated text, translations, or registered vocabulary to the operator’s servers.
The application does not include usage analytics, an advertising SDK, or an external crash-reporting service.
Onvilo connects to the operator’s licensing API on Cloudflare to automatically start and validate the cumulative 20-minute free quota on first launch, and to activate, validate, and deactivate a licence. It connects to the operator’s update distribution on Cloudflare (updates.onvilo.app) to check for and download software updates. These connections do not include recorded audio, transcripts, corrected text, translated text, translations, or registered vocabulary.
Onvilo uses the general macOS pasteboard for automatic paste and copy. The operating system or other software may store, read, process, or synchronise pasteboard content. Section 3.3 explains this distinction.
3. Information processed locally on your Mac
3.1 Recorded audio
Onvilo accesses the microphone only while dictation is active.
It uses the captured audio for on-device transcription with Apple Speech.
The public Release build deletes temporary audio files after transcription and does not retain audio in history.
A temporary file may remain in an operating-system temporary location after a crash, forced termination, power failure, or another exceptional event.
3.2 Transcripts, corrected text, translation, and destination
Onvilo corrects transcripts on the Mac using Apple Foundation Models where available. It translates selected or editable-field text on the Mac using Apple’s Translation framework.
Onvilo uses the resulting text to insert or copy it to the destination you choose. It does not send this text to the operator’s servers.
If the destination is Slack, email, a web browser, or another cloud-connected application, that application or service processes the inserted text under its own terms and privacy notice.
3.3 General pasteboard
Onvilo writes corrected or translated text to the general macOS pasteboard for copy and automatic paste.
The general pasteboard is not storage dedicated to Onvilo. Other applications may read it, and content may remain until you or another application replaces it.
Depending on your settings, macOS pasteboard history, Handoff’s Universal Clipboard, or a third-party pasteboard manager may store, read, process, or synchronise the content to another device.
This processing is performed by macOS or third-party software; it does not mean that Onvilo sends pasteboard content to the operator.
Review Handoff, pasteboard history, and pasteboard-manager settings before inserting confidential information.
3.4 Input-field context
If you expressly enable context assistance, Onvilo may use Accessibility to read up to 300 characters immediately before the cursor in the current editable field.
Onvilo uses this text only for the current on-device correction. It does not save the context in history, diagnostic logs, or settings and does not send it to the operator.
3.5 History
History is disabled by default.
If you enable it, Onvilo saves the following in a local SQLite database:
- creation time and recording duration;
- the transcript before correction;
- corrected text;
- a correction you entered and the correction time;
- recognition language and applied profile;
- the destination application’s Bundle ID;
- identifiers for the speech-recognition and processing providers; and
- processing status, error reason, and text-processing guard result and reason.
You may select seven days, 30 days, 90 days, or no automatic expiry. The initial period after enabling history is 30 days.
Expired history is deleted the next time Onvilo runs. Data whose period expires while Onvilo is not running remains until the next launch.
Turning history off does not delete existing history. You can delete history and correction-learning data together in Settings.
When you run history-based suggestions, Onvilo reads only examples that you explicitly corrected or approved, filtered to the same target app and speech language, on your Mac.
Onvilo does not send the suggestion Prompt, selected history text, or generated candidates to the operator.
When you turn off history use in the Suggestions screen, Onvilo does not read the history database and uses only the Prompt, selected app, and registered vocabulary on your Mac.
3.6 Vocabulary, correction rules, and settings
Registered vocabulary, correction rules you expressly approve, ignored correction suggestions, hotkeys, display language, and other settings are stored locally on your Mac.
Onvilo does not send this information to the operator.
If you export vocabulary and explicitly approved correction rules from Settings and import them on another Mac, you choose how the file is stored, moved, or synchronized.
The file does not contain audio, history text, or Prompts, but it does contain the vocabulary and correction rules you registered, so review its destination and sharing permissions.
3.7 Developer evaluation features
Features for saving, replaying, scoring, or storing evaluation audio are excluded from the public Release build.
When a developer uses a Debug build for quality evaluation, evaluation data stays on a developer-controlled Mac and that build is not distributed to general users.
3.8 Diagnostics
Onvilo exports diagnostics to a file or the general pasteboard only when you expressly perform the export action.
Diagnostics may include Onvilo and macOS versions, general Mac model information, permission states, speech-model state, settings state, history counts, aggregate processing results, and recent application logs.
Diagnostics do not include utterance contents, transcripts, corrected text, translated text, translations, or registered vocabulary.
Onvilo does not send diagnostics automatically. If you attach diagnostics to a support request, section 4.4 applies.
3.9 Trial and licence connections
Onvilo connects to the operator’s licensing API on Cloudflare to automatically start and validate the cumulative 20-minute free quota on first launch and to activate, validate, or deactivate a one-time-purchase licence with a maximum of three Macs.
These requests process a licence key, activation or trial token, a randomly generated installation ID or its HMAC, product and major version, the generic device label “Mac,” IP address, request time, and User-Agent. Onvilo does not send the Mac name selected by the user.
Onvilo does not collect a Mac serial number, IOPlatformUUID, MAC address, or another permanent hardware identifier. These requests do not include recorded audio, transcripts, corrected text, translated text, translations, input-field context, vocabulary, history, or correction-learning data.
4. Website, purchase, and support information
4.1 Website access and analytics
When you visit the official website, Cloudflare may process IP address, access time, requested URL, referrer, User-Agent, device and browser information, and security identifiers for hosting, delivery, security, and abuse prevention.
The production website uses Google Analytics 4 to understand aggregate website use and improve the site. Google Analytics may process user and session statistics, approximate region, browser and device information, and online identifiers such as the _ga cookie. Onvilo does not intentionally send names, email addresses, audio, transcripts, payment-card information, or other directly identifying customer data to Google Analytics. Google Signals and advertising personalisation are disabled.
The Google Analytics tag loads only after you allow Analytics in the website consent interface. It does not load before a choice, and it remains disabled after refusal. The choice is stored in first-party storage under onvilo.analytics-consent.v1 and can be changed through Privacy settings in the footer.
When you withdraw consent, the current page updates Google’s consent state to denied and removes Google Analytics cookies visible to the site. This action cannot by itself delete information already sent to or retained by a browser or Google.
The consent interface is shown to production-site visitors regardless of country. Development and staging sites do not use Google Analytics when no measurement ID is configured.
When a visitor who has consented to analytics proceeds to purchase, Onvilo may send a GA4 purchase event through the Measurement Protocol after payment has been confirmed by a Stripe webhook. The event uses the Stripe Checkout Session ID, purchase amount, currency, product identifier, and the consented GA4 client and session IDs. It does not send names, email addresses, addresses, card information, audio, transcripts, or other directly identifying information. The GA4 client and session IDs are handled in a temporary Cloudflare D1 outbox for delivery and are deleted after delivery or seven days after creation. A sent row retains only the Checkout Session ID and status for 30 days to prevent duplicates.
Cloudflare may use cookies or similar technologies that are necessary to deliver and protect the site.
4.2 Software updates
Onvilo uses Sparkle to check the operator’s update distribution (updates.onvilo.app) for updates after launch and periodically. It downloads an update from the same distribution when you request or permit it. The distribution runs on Cloudflare infrastructure.
Cloudflare may process IP address, connection time, requested URL, and a User-Agent containing Onvilo and Sparkle versions.
Onvilo does not send recorded audio, transcripts, corrected text, translated text, translations, input-field context, vocabulary, history, or correction-learning data during update checks or downloads. Sparkle system-profile submission is disabled.
4.3 Purchase, consent, and licence records
For purchases in countries and regions shown at checkout, Stripe or Link may process the purchaser’s name, email, billing information, country or region, tax information required by the payment flow, product, purchase time, amount, currency, tax, invoice, transaction identifiers, payment status, refund status, and dispute information. Onvilo starts every Checkout session with Managed Payments. For eligible products, countries, and transactions, Stripe Managed Payments may process the information as an independent transaction-level controller under its own privacy notice and applicable responsibility allocation.
Onvilo is offered only to a natural person contracting in their own name and responsibility; the named individual’s private, business, and professional use is permitted. An employer or another third party may reimburse or pay the purchase price without changing the contract if the named purchaser remains the contracting person and the only licensed user. Purchases by or on behalf of a company, organisation, team, or other entity, company-specific agreements, multi-user purchases, sharing, and resale are not available.
For licence fulfilment, the three-device limit, refund synchronisation, and evidence of the purchase choices, the operator stores in Cloudflare D1:
- Stripe Checkout Session, Payment Intent, and Customer identifiers;
- product and price identifiers, amount, currency, purchase locale, and billing country or region;
- payment, refund, dispute, fulfilment, and sales-country-review status, reason, and notification state;
- HMACs of the licence key and activation token;
- the type, displayed language, version, SHA-256, and immutable object key of each legal document shown at purchase; and
- the time of acceptance and the immediate-supply consent and acknowledgement.
For purchases where analytics consent was given, the operator also temporarily stores the consented GA4 client ID and session ID, delivery status, attempt count, and timestamps in Cloudflare D1 so that the server-confirmed purchase event can be sent to GA4. The GA4 identifiers are deleted after delivery, and unsent rows are deleted seven days after creation.
For a free trial, the operator stores HMACs of the randomly generated installation ID and trial token, the generic device label, major version, trial mode, quota seconds, start time, a compatibility date, last validation time, and status. Plaintext installation IDs and trial tokens are not stored. The app stores the local quota usage meter in this Mac’s Keychain and does not send it to the licensing API.
The operator does not copy the purchaser’s name, email, or billing address from Stripe into the licence database. An authorised person may consult Stripe when needed to confirm a purchase.
Stripe / Link processes the full card number, card security code, and other complete payment credentials. The operator does not store them.
After payment, the operator uses Resend to process the email address, purchase locale, message contents, attached legal-document copies, and sending, delivery, or bounce information for the licence and transaction email.
Purchases by or on behalf of a company, organisation, team, or other entity are not available. Employer reimbursement or payment is allowed when the named purchaser remains the contracting natural person and the only licensed user. Organisation details and B2B VAT numbers are not handled within the current sales scope. If a purchaser enters business or tax information in Checkout, Stripe or Link processes that information; the operator does not copy it into the licence database. A natural person who needs an invoice for their own business or professional use may provide their legal name, transaction ID, and invoice request through Stripe or support. For Managed Payments transactions, Stripe or Link sends transaction-level invoices, receipts, and refund notifications and may make them available again in the Dashboard. The operator retains the Invoice ID and the legal-name, address, or telephone disclosure request record in a restricted private tax and operations ledger.
4.4 Enquiries and support
When you contact support, the operator may process your name or display name, email address, message, information needed to verify a purchase, and diagnostics or files you choose to attach.
Do not include utterance contents, transcripts, passwords, payment-card numbers, or other confidential information unless it is necessary and you understand the risk.
5. Purposes and legal bases
The operator uses information for the purposes and, where the EU GDPR or UK GDPR applies, the legal bases below. The exact basis depends on the context and applicable law.
| Processing | Purpose | EU/UK legal basis |
|---|---|---|
| Purchase, checkout, licence issue, activation, validation, transaction email, refund | Enter into and perform the purchase and licence contract | Contract; steps at your request before contract |
| Trial issue and validation | Provide the requested trial and enforce its stated one-per-device/per-major-version limit | Contract or steps at your request; legitimate interests in preventing abuse |
| Tax, accounting, payment records, sanctions, and legally required disclosures | Comply with legal and regulatory duties | Legal obligation |
| Website delivery, licensing security, rate limits, fraud prevention, incident response | Keep the website, checkout, trial, and licensing systems secure and available | Legitimate interests in secure and reliable operation; legal obligation where applicable |
| Support, complaint handling, establishment or defence of claims | Respond to requests and maintain necessary evidence | Contract; legitimate interests; legal obligation where applicable |
| Essential product, security, legal-document, or discontinuation notices | Administer the contract and protect users | Contract; legal obligation; legitimate interests depending on the notice |
| Google Analytics on the website | Measure aggregate site use and improve the website | Consent |
The legitimate interests relied on are secure and reliable service operation, licence enforcement, preventing fraud and abuse, handling support and disputes, and maintaining necessary business records. The operator must not rely on those interests where your rights and interests override them.
The operator does not use this information for behavioural advertising, sell it, or train an AI model on recorded audio or text content.
Where processing is based on consent, you may withdraw that consent at any time for the future. Withdrawal does not affect processing already carried out lawfully.
6. Recipients and service providers
The operator uses the following providers. A provider may be an independent controller, processor, or both for different activities. Final role allocations must be confirmed against the applicable contract and service configuration.
| Provider | Purpose | Main information |
|---|---|---|
| Stripe / Link | Checkout, payment, applicable transaction-level indirect taxes, receipts, invoices, refund notifications, disputes, and transaction support for eligible Managed Payments products, countries, and transactions | Purchaser, billing, payment, and transaction information |
| Cloudflare | Website, CDN, DNS, security, checkout API, trial and licence management, webhooks, database, legal snapshots, update metadata and update-file delivery | IP and request data, device and browser data, Stripe identifiers, licence and trial records, consent evidence, security logs, Onvilo/Sparkle User-Agent |
| Resend | Licence and transaction email with legal-document attachments | Email address, purchase locale, message and attachments, delivery and bounce data |
| Google Analytics | Consent-based production-site analytics | Aggregate use, approximate region, browser/device data, cookies and online identifiers |
Stripe or Link may act as an independent controller when it determines purposes and means for payment, tax, fraud prevention, legal compliance, disputes, and transaction support for a Managed Payments transaction. The applicable Stripe contract, eligibility determination for the product, country, and transaction, and Dashboard configuration govern the allocation.
For New Zealand, the Privacy Officer is Daiki Sekiguchi. For Singapore, the Data Protection Officer is Daiki Sekiguchi. Access and correction requests for Hong Kong personal data may be sent to support@onvilo.app; the responsible person’s address is disclosed without delay on request before purchase. The regional residual risk concerning those contact details is recorded in the sales approval ledger.
Cloudflare, Resend, and Google use global infrastructure, so information may be processed outside Japan, the EEA, or the United Kingdom.
The operator configures the licence database and legal-snapshot bucket with Cloudflare’s EU jurisdiction. This does not mean every network, security, support, or log-processing activity remains in the EU.
macOS may obtain speech, Foundation Models, translation, or update data from Apple. Apple’s privacy notice applies to Apple’s connection data. Onvilo does not implement a transfer of recorded audio, transcripts, corrected text, or translated text to Apple for Onvilo processing.
7. International transfers
The operator is established in Japan. Where the EU GDPR applies, a transfer from the EEA to an eligible Japanese private-sector recipient may be covered by the European Commission’s adequacy decision for Japan. Personal data received in Japan under that decision is handled subject to the applicable Japanese supplementary rules.
Where the UK GDPR applies, an eligible transfer to Japan may be covered by the United Kingdom’s adequacy regulations within their scope.
A provider may process or onward-transfer information in another country. Before opening EU or UK sales, the operator must map each transfer and confirm an applicable mechanism, such as:
- an EU or UK adequacy decision or regulation within its scope;
- the European Commission’s Standard Contractual Clauses with any required transfer assessment and supplementary measures;
- the UK International Data Transfer Agreement or UK Addendum with the required data-protection test; or
- another valid mechanism under applicable law.
You may request information about the safeguard relevant to your data from the contact in section 19. Any request for a copy may be subject to proportionate redaction of confidential commercial information.
EU and UK sales are not available. Before opening either market, the operator will document provider processing countries, role allocation, data-processing agreements, subprocessors, transfer mechanisms, and the required assessment record.
8. Disclosure to third parties
The operator does not disclose personal information to another party except:
- with your consent;
- to the providers in section 6 as necessary for the described services;
- when required by law;
- where necessary to protect life, physical safety, or property and consent is impracticable; or
- as part of a business transfer, subject to applicable safeguards.
Because the operator does not collect your ordinary Onvilo audio, transcript, corrected text, translated text, translations, or vocabulary, it cannot disclose that content, except where you choose to send it in a support request.
The operator does not sell personal information or share it for cross-context behavioural advertising.
9. Retention
The operator uses the following target periods, then deletes or anonymises information unless a longer period is required for a legal obligation, unresolved dispute, security incident, or legal claim:
- purchase, refund, billing, and tax records: seven years after the end of the financial year containing the transaction;
- records needed to prove a licence right: while the licence is active and seven years after it ends;
- records used to prevent repeated trial use: three years after trial issue;
- enquiries and support records: two years after resolution;
- data-rights request records: three years after completion;
- Workers operational logs obtained by the operator: no more than seven days;
- website security logs obtained or stored by the operator: no more than 90 days, except records needed for an incident or dispute until resolution;
- periodic D1 backups: no more than 12 months; and
- GA4 client and session IDs used for purchase-event delivery: after delivery or no more than seven days after creation; sent outbox rows with identifiers removed: no more than 30 days; and
- Google Analytics data: the period configured in the Google Analytics property and controlled by Google’s retention settings.
Stripe / Link, Cloudflare, Resend, Google, and Apple apply their own retention policies to information they control independently.
Sections 3 and 11 explain retention and deletion of local Mac data.
10. macOS permissions
Onvilo uses:
- Microphone to capture audio during dictation;
- Accessibility to inspect the active field, insert text, and provide context assistance; and
- Input Monitoring to send a paste keystroke when direct insertion is unavailable.
You can revoke permissions in macOS System Settings. The related feature may stop working after revocation.
11. Local storage and protection
Principal local locations include:
- history:
~/Library/Application Support/Onvilo/database.sqlite; and - settings: macOS UserDefaults for Bundle ID
com.latech.Onvilo.
The history database does not add application-level encryption. It relies on the macOS user account, file permissions, and disk encryption such as FileVault.
On a shared Mac, review whether history should be enabled and select an appropriate retention period.
12. Security for operator-controlled information
The operator uses reasonable organisational and technical measures, including limiting access, protecting credentials, encrypting data in transit, managing providers, monitoring logs, and deleting records according to retention periods.
- Person responsible for privacy management: Latech Onvilo operator
- Summary of measures: least-privilege access, protected credentials, encrypted transport, provider management, logging, monitoring, backup control, and scheduled deletion
No security measure can guarantee absolute security. If a breach requires notice under applicable law, the operator will notify the competent authority and affected individuals as required.
13. Your data-protection rights
Subject to applicable law and exceptions, you may request:
- confirmation and access to personal information held about you;
- correction of inaccurate or incomplete information;
- deletion or erasure;
- restriction or suspension of processing;
- objection to processing based on legitimate interests;
- portability of information you provided where the legal conditions apply;
- withdrawal of consent for future processing; and
- information concerning recipients or international-transfer safeguards.
The right to object to direct marketing is absolute. The operator does not currently use personal information for direct marketing or behavioural advertising.
To exercise a right, contact section 19 and identify the request and relevant information. The operator may verify identity using the purchase email, transaction ID, or another proportionate method.
EU and UK requests are generally answered without undue delay and within one month, subject to a lawful extension for complexity or number of requests. A request is normally free, but a manifestly unfounded or excessive request may be refused or charged as permitted by law. If the operator refuses a request, it will explain the reason and available complaint route.
Stripe, Cloudflare, Google, Apple, or another independent controller may require you to exercise a right directly with it.
14. EU and UK representatives
Because EU and UK sales are unavailable, no EU or UK representative is used for the current sales scope. The need to appoint representatives under EU GDPR Article 27 and UK GDPR will be confirmed before either market is opened.
- EU representative: Not applicable while EU sales are unavailable.
- UK representative: Not applicable while UK sales are unavailable.
No exception is assumed merely because Onvilo does not upload dictation content. Purchase, trial, licence validation, transaction email, and support processing may be recurrent rather than occasional.
15. Complaints to supervisory authorities
Contact the operator first if you wish, but doing so does not remove your right to complain to a supervisory authority.
If the EU GDPR applies, you may lodge a complaint with the data-protection authority in the EU or EEA country of your habitual residence, place of work, or the alleged infringement. Authorities are listed by the European Data Protection Board.
If the UK GDPR applies, you may complain to the Information Commissioner’s Office.
You may also have a right to a judicial remedy under applicable law.
16. Local deletion and uninstall
You can use “Delete history and correction learning data” in Settings to remove saved history and correction-learning data.
The SQLite database uses secure-delete settings so deleted history content is overwritten in database free space. This does not guarantee that forensic recovery is impossible from storage media, an operating-system snapshot, or backup.
The action does not delete vocabulary, hotkeys, display language, or other settings.
Deleting the application alone may leave settings or Application Support data.
To remove the principal Onvilo data and settings from the Mac:
- Delete history and correction-learning data in Settings.
- Quit Onvilo and delete
~/Library/Application Support/Onvilo. - Run
defaults delete com.latech.Onviloto remove UserDefaults. - Delete
/Applications/Onvilo.appor the Onvilo.app at the location you selected.
Onvilo cannot delete general pasteboard content, pasteboard history, Time Machine or another backup, an APFS snapshot, a temporary file left after a crash, an exported diagnostic file, or content retained by another application. Delete those through the relevant system or application.
17. Children
Onvilo is not directed to a child who cannot enter into the contract under applicable law. The operator does not knowingly use the website, purchase, or licence systems to collect a child’s information without legally valid involvement of a parent or guardian.
If you believe a child provided personal information improperly, contact section 19.
18. Changes to this Policy
The operator may revise this Policy when features, providers, or law change.
The revised text and effective date will be published on the official website. Versioned copies will be preserved for a reasonable period.
Material changes will receive reasonable advance notice through the distribution page or application.
Where a new purpose or disclosure requires fresh consent, publication of a revised notice does not replace that consent; it will be obtained before the new processing begins.
19. Contact
Questions, complaints, and rights requests may be sent to:
- Controller/operator: Latech
- Sole proprietor’s legal name: Disclosed without delay on request before purchase through support@onvilo.app
- Geographic address: Disclosed without delay on request before purchase through support@onvilo.app
- Telephone: Disclosed without delay on request before purchase through support@onvilo.app
- Japanese Qualified Invoice Issuer registration number: T8810483333248
- Email: support@onvilo.app
- Support hours: weekdays, 10:00–17:00 Japan Standard Time, excluding Japanese public holidays and announced closures
- EU representative: Not applicable while EU sales are unavailable.
- UK representative: Not applicable while UK sales are unavailable.
The operator will not ask you to send a payment-card security code, account password, recorded audio, or transcript contents merely to identify a routine privacy request.