Security and governance

This page is the one we would want if we were the ones vetting a dictation tool: what actually happens to the audio, who can change that, and what we do and do not claim yet.

Where things stand today. On-device transcription, optional cleanup that stays on the Mac unless you connect a cloud model, and no training on your dictation are true right now, for every user. The team postures described below come with Tulpa Teams, which is not available yet. Request team access to hear when it opens. We would rather tell you exactly what has shipped than round up.
01

Transcription happens on the device, under every posture

Speech-to-text runs locally, using open, widely used speech models (Whisper, Parakeet and Moonshine) or, if you choose it on macOS 26, Apple's built-in on-device recognizer. None of them is a black box on someone else's server. Audio is not a network request waiting to happen; it is processed where it was spoken, and it is never saved.

02

Only the optional polish pass can send your words off the machine

Tulpa separates transcription, which is always local, from an optional cleanup pass that rewrites your dictation. Cleanup is off by default, and with Apple Intelligence it runs on the Mac. Filler word removal and custom words run on the Mac with no AI. The only thing that ever sends your dictation off the device is cleanup with a cloud model you connect with your own API key, after a warning you confirm. It sends text only, never audio, straight from the Mac to that provider and never through us. Checking for updates, downloading a speech model and, if you sign in, account and license checks reach the network too; none of them carries your audio or your transcripts.

03

Posture is enforced, not suggested

Tulpa Teams, coming soon, is built around three postures. Under Local-only, no external endpoint can be configured by anyone; the option does not exist. Under Org-managed, one endpoint is set centrally and individual overrides are refused. Open lets people choose for themselves, which is how Solo works today.

04

Nothing trains on you by default

Tulpa does not use your audio or transcripts to train or improve any model. If you connect a cloud model and turn cleanup on with it, text goes to that provider under its own terms, and Tulpa tells you so before you connect. That is a deliberate choice, not a default anyone opted you into.

05

Deployed fleet-wide, not configured seat by seat

With Tulpa Teams, policy is meant to be set once and picked up by every seat, including new hires, with nothing for an admin to chase down machine by machine. Today Tulpa ships for Macs with Apple Silicon; Windows and Linux share the same codebase and are on the roadmap.

Does audio ever leave the device?

Raw audio is never transmitted or saved under any posture; there is no code path that uploads it. Transcript text leaves only if you connect a cloud model with your own key and turn cleanup on with it. It then goes straight from your Mac to that provider, under that provider's own terms, and never through us.

Can one person turn off the org's policy for themselves?

Team policies come with Tulpa Teams, which is not available yet. Under Local-only or Org-managed the relevant settings are locked, and the app is designed to refuse the override outright rather than simply hide the control. The distinction matters, because a hidden setting can still be reached by anyone who knows where to look.

What platforms does Tulpa run on today?

Macs with Apple Silicon, an M1 or later, today. Intel Macs are not supported: the ONNX Runtime package Tulpa uses ships no prebuilt Intel build for macOS, so supporting Intel would mean compiling it ourselves. The codebase is otherwise cross-platform by design, and Windows and Linux support is on the roadmap. We would rather ship those well than announce them early.

Is Tulpa open source?

No. Tulpa is a proprietary commercial product. Its speech models are open and widely used (Whisper, Parakeet, Moonshine), so the core transcription behaviour is not a mystery even though the app itself is closed-source. On macOS 26 you can also choose Apple Speech, Apple's closed recognizer, which also runs on the Mac.

Do you train on our audio or text?

No. The only way your text could reach a third-party model is if you connect one for cleanup with your own key, and what that provider may do with it is governed by its own terms. Tulpa warns you of that and asks you to confirm before it connects.

How is this different from a "privacy mode" toggle in other dictation apps?

A per-user toggle depends on every single person remembering to turn it on, it can usually be turned back off just as easily, there is nothing to audit, and nothing stops drift across a team. With Tulpa Teams, coming soon, posture is set by whoever owns the fleet and enforced at the app layer, rather than left to individual judgment.

Talk to us

Have a longer security questionnaire?

Send it over and we will walk through the architecture directly. Happy to go deeper than a landing page can.