音声認識・整形は既定で端末内だけで動作します。設定の「プライバシーモード」をオンにしている間は、音声・文字・画面の内容・その他の入力内容は一切外部に送信されません(Apple のオンデバイス音声認識・整形のみを使用)。macOS版の「ディープコンテキスト」(3-3)を併用していても、画面から読み取った内容が外部へ出ることはありません。会議モードも設定の認識エンジンに従い、オンデバイス選択時は会議の音声も端末外に出ません。
例外はひとつだけです。macOS版では、プライバシーモードがオンのときも、ライセンスが有効かどうかを確認する通信だけは行われます(3-4)。この通信に、音声・文字・辞書・画面の内容は一切含まれません。
本アプリは、文字入力機能の提供を目的に次の情報を処理します。特記なき限り端末内にのみ保存し、外部送信しません。上表の情報を当方のサーバーへ収集することはありません(macOS版のライセンス確認のみ例外=3-4。そこへ届くのはライセンスキーと端末の識別子だけで、音声・文字・辞書・画面の内容は一切送信しません)。
| 情報 | 目的 | 保存場所 |
|---|---|---|
| マイク音声 | 音声を文字に変換(文字起こし) | 認識に使用・録音履歴として端末内。既定で外部送信しない |
| 認識テキスト | 入力先へ挿入・整形 | 端末内。既定で外部送信しない |
| 辞書・定型文(スニペット)・カスタムモード・整形ルール | 表記の統一・定型文入力・整形調整 | 端末内(クラウド機能を選んだ場合の送信は 3-1・3-2) |
| 録音履歴(音声・書き起こし) | 結果の見返し・コピー | 端末内(保存期間設定・削除の対象) |
| キーボード変換学習・利用統計 | 変換精度向上・利用状況の確認 | 端末内 |
| 修正して学習の内容(入力された文と、直したあとの文)〔macOS版〕 | 同上 | 端末内。ただし「学習候補を抽出」を押したときに限り、プライバシーモードがオフなら Claude へ送信して取り出します(3-2)。オンのときは端末内の文字比較だけで行い、送信しません |
| クリップボード(文字を入力先へ挿入するときに一時的にお借りします) | 認識した文字を入力先へ貼り付ける | 端末内。挿入の前後だけ一時的に使い、元の内容は挿入後にお戻しします(3-6) |
| 診断ログ | 不具合の切り分け | 端末内。入力文章・変換内容の中身は記録しない |
| APIキー(クラウド機能利用時にユーザーが入力) | クラウドサービスへの認証 | 端末の Keychain。当方・第三者は取得しない |
| ライセンスキー・端末の識別子(macOS版の有料ライセンス登録時) | 契約が有効か、登録台数の上限内かの確認 | キーは端末の Keychain。確認のため当方のライセンスサーバーへ送信(3-4) |
本アプリから端末の外へ通信が発生する場面をすべて挙げます。3-1〜3-3 は任意のクラウド機能で、ユーザーが明示的に有効化し、自身の API キーを登録した場合にのみ動作します(オンデバイスのまま、またはプライバシーモードがオンの間は発生しません。ただし「音声ファイルの文字起こし」の「議事録にまとめる」は、認識エンジンの選択にかかわらず、ボタンを押したときだけ動きます)。3-4 は macOS版のライセンス確認で、こちらはプライバシーモードがオンでも行われます。3-6 は端末の外への送信ではありませんが、macOS の機能によって近くの端末へ渡りうるため、あわせて記載しています。
クラウド機能は、お客様が明示的に有効にしたときだけ動きます。3-1〜3-3 は、設定でクラウドを選び、ご自身の API キーを登録した場合にのみ動作します(3-3 のディープコンテキストも既定はオフです)。macOS 版には送信先ごとの同意画面はありません。クラウドへの送信を止めるには、設定でオンデバイスの認識・整形に戻すか、「プライバシーモード」をオンにしてください(第4項)。
認識エンジンに「ElevenLabs Scribe」を選び API キーを登録したとき、api.elevenlabs.io へ送信されるのは録音した音声データと、残りクレジットを表示するためのお客様の API キーだけです。
送信しないもの:辞書に登録した語(「認識ヒント」の表記も読み(かな)も)、定型文(スニペット)の合言葉と本文、音声コマンドの言い回し、「ディープコンテキスト」で画面から抽出した語、置換ルールの置換前の読みと置換後の表記(置き換えは、書き起こしが返ってきたあとに端末の中で行います)、アカウント情報(本アプリはアカウントを持ちません)。
2026年8月までは、辞書に登録した語・定型文の合言葉・音声コマンドの言い回し・ディープコンテキストで抽出した語を「認識ヒント」(keyterms)として一緒に送っていました。効きめを確かめられないまま、ご登録のお名前などが話題と関係なく毎回送られていたため、送るのをやめました。辞書も置換ルールも、書き起こしが返ってきたあとに端末の中で適用されます。
api.anthropic.com)へ送信されるものClaude へ送信されるのは次の3つの場面です。いずれもプライバシーモードがオンの間は行われません。
議事録を作るときに送信するのは、書き起こした全文と用語集です。用語集の範囲は、整形のときと同じです。音声そのものは送信しません(送るのは文字起こしのテキストだけです)。
整形のときに送信するのは、認識テキストと用語集(辞書の「認識ヒント」の表記および有効な置換ルールの置換後の表記)です。あわせて、選んでいる整形モードの指示文を送信します——ご自身で「カスタムモード」を作って選んでいる場合は、そこにお書きになった指示文がそのまま送信されます(アプリに組み込まれたモードの場合は、アプリに固定で入っている指示文です)。さらに同音異義語の照合リスト(「意向/移行」のような取り違えを直すための、2〜4字の漢字熟語だけの一覧)を送信します。この照合リストは、「ディープコンテキスト」がオンのときだけ入力先の本文から取り出します(3-3)。オフのときは送信しません。
送信しないもの:音声そのもの、辞書の読み(かな)。macOS版で「ディープコンテキスト」がオフのとき(既定)は画面に表示されているテキストを一切送信しません。
macOS版には、認識と整形の精度を上げるためにいま入力しようとしている場所の文脈を参考にする「ディープコンテキスト」という設定があります。既定はオフで、ユーザーが自分でオンにしたときだけ動作します。オンにすると録音を開始した瞬間に、入力先のアプリから「前面アプリの名前・ウィンドウのタイトル」「カーソル周辺のテキストの抜粋(最大 800 文字)」「そこから抽出した語(最大 40 語)と同音異義語の照合用の漢字熟語」を読み取ります。読み取りは端末内で行われ、クラウド機能を使っていなければ(またはプライバシーモードがオンなら)端末の外へは出ません。
クラウド機能を選んでいる場合の送信先は次のとおりです。Anthropic(Claude)へ:アプリ名・ウィンドウのタイトル・抜粋(最大 800 文字)・同音異義語の照合リスト。ElevenLabs(Scribe)へ:抽出した語(最大 40 語)と、アプリ名・ウィンドウのタイトルから取り出した語。
パスワード欄では読み取りません。入力先がパスワード入力欄(セキュアテキストフィールド)のときは、文脈を一切取得しません。この設定をオフにすると、これらの読み取りと送信は完全に停止します。
macOS版の有料ライセンスを登録すると、本アプリは契約が有効かどうかを当方のライセンスサーバー(wadadigitallab.com・HTTPS)に確認します(起動時や定期的なタイミング)。送信するのはライセンスキー・端末の識別子・機種名(例:MacBookPro18,3)・アプリの識別子(koetype)です。「端末の識別子」は、この Mac のハードウェア識別子から計算した不可逆な文字列(SHA-256 ハッシュ)で、元の識別子を復元することはできません。契約の登録台数の上限を数えるためだけに使います。
送信しないもの:音声・書き起こしテキスト・辞書・画面の内容・APIキー。これらがライセンスサーバーへ届くことは一切ありません。この確認はプライバシーモードがオンのときも行われます(プライバシーモードは「音声や文字を外部へ出さない」ための設定であり、契約の確認そのものを止める設定ではないためです)。オフラインでも一定期間は続けて利用できます(猶予期間)。
購入時の情報について:macOS版の購入手続きは決済代行の Stripe が処理します。クレジットカード番号などの決済情報は Stripe が取り扱い、当方が受け取ることはありません。当方は契約の管理のために、Stripe から通知される契約の状態・ライセンスキー・連絡先メールアドレスを保管します。
クラウド機能では、データはお客様ご自身が登録した API キーを用いて各社へ直接送信されます(当方のサーバーを経由しません)。当方は、送信先である ElevenLabs 社および Anthropic 社の利用規約・データ処理契約(DPA)・公開ドキュメントを確認し、両社が本ポリシーと同等以上のデータ保護を提供していることを確認しています。両社とも、EU 標準契約条項(SCC)を含む GDPR 対応の DPA を公開し、再委託先(サブプロセッサー)の一覧を公表しており、各再委託先に対して自社の DPA と実質的に同等以上の保護義務を課すことを契約上定めています。
Anthropic(AI整形・議事録/api.anthropic.com)
ElevenLabs(クラウド音声認識 Scribe/api.elevenlabs.io)
(各社に関する記述は、2026 年 7 月 31 日時点の各社公開文書に基づきます。各社が方針を変更する可能性があるため、最新の内容は各社のサイトをご確認ください。)
認識した文字を入力先へ入れるとき、本アプリは macOS のクリップボード(コピー&ペーストの置き場)を一時的にお借りすることがあります。お借りする前の内容は退避し、挿入が終わったらお戻しします(1秒とかかりません)。お借りしているあいだは、クリップボード履歴アプリに記録されないための印(nspasteboard.org の規約に基づく ConcealedType/TransientType)を付けています。ただしこの印は、規約に従うアプリにだけ効くもので、クリップボードを読むすべてのアプリに対する保証ではありません。
戻せない内容(画像・ファイル・書式付きテキストなど)が載っているときは、クリップボードに一切触れず、文字を直接打ち込む方法に切り替えます。ただし例外が3つあります——文字が入力先に入らなかったとき・音声コマンドの「アットマークコピー」を使ったとき・パスワード入力欄と判定したときは、文字をお届けする手段がクリップボードしかないため、何が載っていても上書きします(上書きしたときは、その旨を画面でお知らせします。「アットマークコピー」はご自身で選ばれた操作のため、この断りは出しません)。
これは端末内の処理で、当方や第三者のサーバーへ送信されるものではありません。ただし、macOS の「ユニバーサルクリップボード」(同じ Apple アカウントでサインインした近くの iPhone・iPad・Mac とクリップボードを共有する Apple の機能)を有効にしている場合、クリップボードに置かれた文字が、その近くの端末へ渡ることがあります。これは Apple の機能によるもので、本アプリが送信するものではありません。止めたいときは、macOS の「システム設定 → 一般 → AirDrop と Handoff」で Handoff をオフにしてください。
なお、パスワード入力欄と判定した場所へは、本アプリは文字を入力しません。そのときの文章はクリップボードに残しますが、上記の記録させない印を付けたうえで、約1分後に自動的に消去します。
録音履歴は設定「履歴の保存期間」(日数・「ずっと」も可)に従い、期間超過分は自動削除されます。履歴画面から個別削除も可能です。辞書・設定・統計も端末内にあり編集・削除できます。アンインストールで端末内データ(Keychain の API キーを含む)は削除されます。ライセンスの記録(3-4。ライセンスキー・端末の識別子・連絡先メールアドレス・契約の状態)は、契約が続く間および法令上必要な期間、当方のライセンスサーバーに保管します。削除をご希望の場合は第7項の連絡先までお申し付けください。
macOS 版には送信先ごとの同意画面がありません。クラウドへの送信は、設定でオンデバイスの認識・整形に戻すか、「プライバシーモード」をオンにすることで、その時点でただちに停止します。進行中の処理も中止します。停止しても本アプリはそのままお使いいただけます(端末内での認識・整形に切り替わります)。
進行中の処理(長い文章を分割して順に送信するもの)も中止します。クラウドへの送信を止めても、本アプリはそのままお使いいただけます。
端末内のデータの削除は上記のとおりです(録音履歴=「履歴の保存期間」の設定と履歴画面からの個別削除、辞書・定型文・設定・統計=各画面から編集・削除、すべてまとめて=本アプリのアンインストール)。ライセンスの記録の削除をご希望の場合は第7項の連絡先までお申し付けください。
すでに送信済みのデータの削除は、送信先各社側で行っていただく必要があります(当方は各社のサーバーに保管されたデータを削除する権限を持ちません)。Anthropic:お客様が送信した入力と出力は、受信または生成から 30 日以内に自動的に削除されます(例外は 3-5 に記載)。ElevenLabs:保持された音声・書き起こしは、ElevenLabs の API またはアカウント設定からいつでも削除でき、アカウントごと削除することもできます。あわせて、今後の学習への利用は「Terms and privacy」→「Data use」→「Improve the models for everyone」をオフにすることで停止できます(3-5)。
データを第三者に販売・提供しません(第3項でユーザーが選んだ送信先へ機能提供目的で送る場合、および決済処理のために Stripe を利用する場合を除く)。広告表示なし、アプリ・ウェブをまたぐトラッキングなし。第三者の解析・広告・トラッキング SDK を組み込んでいません。
本アプリはお子様を対象としません。API キーと macOS版のライセンスキーは Keychain に保管し、クラウド通信および macOS版のライセンス確認の通信は HTTPS で行います(ただしインターネット送信・保管の安全性を完全には保証できません)。法令変更・機能追加に応じて本ポリシーを改定することがあり、重要な変更はアプリ・公開ページで告知します。本ポリシーは日本法(個人情報保護法/APPI を含む)に準拠します。現時点の配信地域は日本を予定しており、将来 GDPR・CCPA 等の対象地域を含める場合は当該法令に応じた開示を追記します。
事業者名:和田デジタルラボ / 連絡先:wadadigitallab@gmail.com
Recognition and formatting run only on your device by default. While "Privacy Mode" is enabled, your audio, text, on-screen content, and other input are never transmitted externally (only Apple's on-device recognition/formatting is used) — this holds even if the macOS "Deep Context" feature (3-3) is enabled. Meeting Mode follows the selected engine; if you chose on-device, meeting audio also stays on your device.
There is exactly one exception. On the macOS version, even while Privacy Mode is on, the App still contacts our server to verify that your licence is valid (3-4). That request contains no audio, no text, no dictionary entries, and nothing read from your screen.
The App processes the following to provide text-input functionality. Unless otherwise noted it is stored only on your device and not transmitted externally. We do not collect the information below on our servers — with one exception, licence verification on the macOS version (3-4), which receives only a licence key and a device identifier and never any audio, text, dictionary entries, or on-screen content.
| Information | Purpose | Where stored |
|---|---|---|
| Microphone audio | Transcribe speech into text | Used for recognition; saved as history on device. Not sent externally by default |
| Recognized text | Insert / format the result | On device. Not sent externally by default |
| Dictionary, snippets, custom modes, formatting rules | Consistent spelling, fixed phrases, formatting tuning | On device (for what is sent when you enable a cloud feature, see 3-1 and 3-2) |
| Recording history (audio, transcripts) | Review / copy results later | On device (retention setting & deletion apply) |
| Keyboard learning & usage statistics | Conversion accuracy, self-review of usage | On device |
| "Correct and learn" content (the inserted text and your corrected version of it) [macOS] | Same as above | On device. However, only when you press "Extract learning candidates", it is sent to Claude if Privacy Mode is off (3-2). With Privacy Mode on, the pairs are derived on device and nothing is sent |
| Clipboard (borrowed briefly when inserting text into the target app) | Paste the recognized text into the app you are typing in | On device. Used only around the moment of insertion; the previous contents are restored afterwards (see 3-6) |
| Diagnostic logs | Troubleshooting | On device. Typed text / conversion content is not logged |
| API keys (entered by you for cloud features) | Authenticate to cloud services | Device Keychain. We and third parties never obtain them |
| Licence key and device identifier (if you register a paid licence on macOS) | Verify the subscription is active and within the device limit | The key is in the device Keychain; sent to our licence server for verification (3-4) |
This section lists every situation in which the App communicates outside your device. 3-1 to 3-3 are optional cloud features and operate only when you explicitly enable them and register your own API key (nothing is sent while you stay on-device or while Privacy Mode is on — except "Summarize into minutes" on the "Transcribe an audio file" screen, which runs regardless of the recognition engine you chose, and only when you press the button). 3-4 is licence verification on the macOS version, which runs even while Privacy Mode is on. 3-6 is not a transmission off your device, but is documented here because macOS itself may pass the content to nearby devices.
Cloud features run only when you explicitly enable them. 3-1 to 3-3 operate only if you select a cloud engine in Settings and register your own API key (Deep Context in 3-3 is also off by default). The macOS version has no per-recipient consent screen; to stop transmission to the cloud, switch recognition/formatting back to on-device or turn on "Privacy Mode" (section 4).
When you select "ElevenLabs Scribe" and register a key, the only things sent to api.elevenlabs.io are the recorded audio and your API key (used to display your remaining credit).
Not sent: anything from your dictionary (neither the written forms under "recognition hints" nor their readings/kana), snippet triggers and their body text, voice-command phrases, terms extracted from the screen by "Deep Context", neither the spoken side nor the replacement text of your replacement rules (replacement happens on your Mac, after the transcript comes back), and account information (the App has no account).
Until August 2026 we also sent the items above as recognition hints (keyterms). We stopped: we could not confirm any benefit, while names you had registered were being sent on every recording regardless of the topic. Your dictionary and replacement rules are applied on your Mac, after the transcript comes back.
api.anthropic.com)There are three triggers. None of them occur while Privacy Mode is on.
For meeting minutes, what is sent is the full transcript and a glossary. The glossary is the same as the one used for formatting. The audio itself is never sent — only the transcribed text.
For formatting, what is sent is the recognized text and a glossary (written forms registered under "recognition hints", plus the replacement text of enabled replacement rules). The instructions of the selected formatting mode are also sent — if you have created and selected a "custom mode", the instructions you wrote are sent verbatim (for built-in modes, these are instructions fixed inside the App). A homophone reference list is also sent — a list containing only 2–4 character kanji compounds, used to correct confusions between same-sounding words. That list is extracted from the body text of the field you are typing into only when "Deep Context" is enabled (3-3); nothing is sent when it is off.
Not sent: the audio itself; the readings (kana) of dictionary terms. With "Deep Context" off (the default), no on-screen text is sent at all.
The macOS version has a setting called "Deep Context" that improves recognition and formatting by referring to the context of where you are about to type. It is off by default. When enabled, the App reads the following from the target app at the moment recording starts: the frontmost app's name and window title; an excerpt of the text around the cursor (up to 800 characters); terms extracted from those (up to 40) plus kanji compounds for homophone reference. The reading happens on your device, and nothing leaves it unless you are using a cloud feature (and nothing leaves it at all while Privacy Mode is on).
If you are using cloud features: to Anthropic (Claude) — the app name, window title, the excerpt (up to 800 characters), and the homophone reference list; to ElevenLabs (Scribe) — the extracted terms (up to 40), including terms taken from the app name and window title.
Password fields are never read. If the target is a secure text field, no context is captured at all. Turning the setting off stops this reading and transmission completely.
Once you register a paid licence on macOS, the App asks our licence server (wadadigitallab.com, over HTTPS) whether your subscription is active (at launch and periodically). It sends the licence key, a device identifier, the model name (e.g. MacBookPro18,3), and an app identifier (koetype). The device identifier is an irreversible string (a SHA-256 hash) computed from this Mac's hardware identifier; the original cannot be recovered from it, and it is used solely to count devices against your plan's device limit.
Not sent: audio, transcripts, dictionary entries, on-screen content, or API keys — none of these ever reach the licence server. This check runs even while Privacy Mode is on (Privacy Mode is about not sending your audio or text outside the device; it is not a setting that stops us from verifying your subscription). If the server is unreachable, you can continue using the App offline for a grace period.
About purchase information: purchases of the macOS version are processed by Stripe. Payment details such as card numbers are handled by Stripe and never reach us. To manage your subscription, we store the subscription status, licence key, and contact email address reported to us by Stripe.
When cloud features are used, data is sent directly to each provider using the API key you registered; it does not pass through our servers. We have reviewed the terms of service, Data Processing Addenda (DPAs), and public documentation of both ElevenLabs and Anthropic, and we confirm that both provide data protection equal to or greater than that described in this Privacy Policy. Both publish a GDPR-compliant DPA incorporating the EU Standard Contractual Clauses (SCCs), publish a list of their subprocessors, and contractually require each subprocessor to accept data protection obligations substantially as protective as their own DPA.
Anthropic (AI formatting and meeting minutes / api.anthropic.com)
ElevenLabs (cloud speech recognition, Scribe / api.elevenlabs.io)
(Statements about these providers reflect their published documents as of 31 July 2026. Providers may change their policies; please check their sites for the latest information.)
To place recognized text into the app you are typing in, the App may briefly borrow the macOS clipboard. Whatever was on it is saved first and restored once the insertion finishes (this takes well under a second). While borrowed, the App marks the content so clipboard-history apps do not record it (the ConcealedType / TransientType markers defined by nspasteboard.org). Those markers only work with apps that honour that convention; they are not a guarantee against every app that reads the clipboard.
If the clipboard holds something that cannot be restored (an image, a file, rich text, and so on), the App does not touch it at all and types the characters directly instead. There are three exceptions: when the text could not be inserted into the target, when you use the "at-mark copy" voice command, and when the target is determined to be a password field. In those cases the clipboard is the only way to deliver the text, so it is overwritten regardless of what it held (the App tells you on screen when it does — except for "at-mark copy", which you chose deliberately).
This is on-device processing and is not sent to us or to any third-party server. However, if you have Apple's Universal Clipboard enabled (the macOS feature that shares the clipboard with nearby iPhones, iPads, and Macs signed in to the same Apple Account), text placed on the clipboard may reach those nearby devices. That transfer is performed by Apple's feature, not by this App. To stop it, turn Handoff off in System Settings → General → AirDrop & Handoff.
Where the App determines the target is a password field, it does not type into it. The text is left on the clipboard with the markers above and is cleared automatically after about one minute.
Recording history is auto-deleted after the "History retention" period (days, or "Forever"); items can be deleted individually. Dictionary, settings, and statistics are on device and editable/deletable. Uninstalling deletes on-device data (including Keychain API keys). Licence records (3-4: licence key, device identifier, contact email address, subscription status) are retained on our licence server for the duration of your subscription and for any period required by law; to request deletion, contact us using the details in Section 7.
The macOS version has no per-recipient consent screen. Transmission to the cloud stops immediately when you switch recognition/formatting back to on-device or turn on "Privacy Mode"; anything in progress is cancelled. The App remains fully usable (it falls back to on-device processing).
Anything in progress (such as a long transcript being sent in chunks) is cancelled as well. The App remains fully usable after you stop cloud transmission.
Deleting data held on your device works as described above (recording history — the "History retention" setting plus per-item deletion on the history screen; dictionary, snippets, settings, and statistics — editable and deletable on their own screens; everything at once — uninstall the App). To request deletion of your licence records, contact us using the details in Section 7.
Deleting data that has already been sent must be done on the recipient's side (we have no ability to delete data held on their servers). Anthropic: the inputs and outputs you sent are deleted automatically within 30 days of receipt or generation (exceptions are listed in 3-5). ElevenLabs: retained audio and transcripts can be deleted at any time via the ElevenLabs API or your account settings, and you can delete your account entirely. You can also stop any future training use by turning off "Improve the models for everyone" under "Terms and privacy" > "Data use" (see 3-5).
We do not sell or provide your data to third parties (except sending it, to provide the feature, to the recipient you chose in Section 3, and except our use of Stripe to process payments). No ads, no cross-app/website tracking, no third-party analytics/ad/tracking SDKs.
The App is not directed to children. API keys and the macOS licence key are stored in the Keychain; cloud communication and macOS licence verification both use HTTPS (no Internet transmission/storage can be guaranteed fully secure). We may revise this policy for legal/feature changes and will give notice for material changes. Governed by the laws of Japan (including APPI). Currently intended for distribution in Japan; if we later include regions such as the EU (GDPR) or California (CCPA/CPRA), we will add the required disclosures.
Provider: Wada Digital Lab (和田デジタルラボ) / Contact: wadadigitallab@gmail.com