Privacy Policy

Effective date: September 18, 2026

Handy is an open-source, local-first speech-to-text application maintained by CJ Pais and contributors. This policy explains how the official Handy desktop application and the handy.computer website handle information.

This policy applies to official Handy releases and services operated for the Handy project. Modified or redistributed versions of Handy may have different practices.

The short version

Local speech processing and storage

Handy’s speech-recognition models run on your device. When you use Handy, the application may process and store the following information locally:

By default, Handy retains a limited number of recent history entries and their audio recordings. Entries that you mark as saved may remain until you delete them. You can delete individual entries, change the retention period, or set the history limit to zero.

Official release builds redact transcription content from diagnostic logs. Development or self-compiled debug builds may produce more detailed logs.

Handy uses operating-system permissions for features such as microphone access, global keyboard shortcuts, accessibility-assisted pasting, and clipboard access. These permissions are used to provide the features you request.

Network connections

Handy may make the following network connections.

Software updates

When update checking is enabled, Handy contacts GitHub Releases to determine whether a new version is available and to download updates. Update checking is enabled by default and can be disabled in Handy’s settings.

Model downloads

When you download a speech-recognition model, Handy may contact Hugging Face and its content-delivery providers. If a Hugging Face download fails, Handy may retrieve the model from blob.handy.computer, which is delivered using Cloudflare.

These services may receive ordinary technical request information, such as your IP address, request time, requested model or file, application or device information conveyed by HTTP headers, and download status. Model download and update requests do not include your microphone audio or transcription content.

Optional post-processing

Handy offers optional post-processing through user-selected AI providers, local services, or custom endpoints. Cloud post-processing is disabled unless you configure and invoke it.

When you invoke cloud post-processing, Handy sends the transcription, selected prompt, model information, and the authentication credential required for the request directly from your device to the provider you selected. Handy’s maintainers do not receive or proxy this content.

Processing by a selected provider is governed by that provider’s privacy policy and terms. Supported providers may include OpenAI, Anthropic, OpenRouter, Groq, Cerebras, Z.AI, and AWS Bedrock. A custom endpoint is governed by the operator of that endpoint. If you do not want transcription content sent to another service, leave cloud post-processing disabled or use an on-device or local endpoint.

Website

The Handy website does not currently embed advertising, behavioral analytics, or first-party tracking cookies. It may use browser information locally to show the appropriate download option for your operating system.

The website and model-download infrastructure use Cloudflare for hosting, content delivery, security, and reliability. Cloudflare may process technical information such as IP addresses, browser and device information, requested pages or files, timestamps, and security signals. Cloudflare may use essential security mechanisms when necessary to protect the service.

The website contains links to GitHub, donation providers, sponsors, and other third-party websites. When you follow those links, the third party receives your request and handles information under its own privacy policy.

Communications, community participation, and donations

If you contact the Handy maintainers by email or through GitHub, Discord, or another community platform, we may use the information you voluntarily provide to respond, investigate a problem, or maintain the project. Information submitted to a public GitHub issue, discussion, or other public community is public.

Donations are handled by third-party providers such as Stripe or GitHub Sponsors. Handy does not receive complete payment-card details, although the provider may share transaction, contact, or supporter information with the project maintainer.

Sharing and sale of information

Handy does not sell personal information and does not share personal information for targeted advertising.

Information may be disclosed only:

Retention and deletion

The Handy maintainers do not retain copies of locally processed audio, recordings, or transcription history because that information is not received by the maintainers.

Local information remains on your device according to your retention settings and until you delete it. Uninstalling Handy may not automatically remove its application data directory. Handy’s About and Debug pages provide shortcuts to the relevant data, recordings, and log directories.

Infrastructure providers may retain technical request logs according to their own policies and configured retention periods. Support communications and donation records may be retained as reasonably necessary to respond, maintain project records, prevent abuse, or comply with legal obligations.

Security

Handy is designed to minimize data transmission by processing speech locally. Local application data is protected by your operating-system account and filesystem controls. Handy does not currently add separate application-level encryption to its local history or settings files. You are responsible for securing your device and credentials entered for external services.

Where applicable law requires a legal basis, technical website and download data is processed as necessary for the legitimate interests of operating, securing, and improving the project; communications are processed to respond to your request; and records may be processed to comply with legal obligations. Optional third-party processing occurs when you choose and direct Handy to use that service.

Cloudflare, GitHub, Hugging Face, community platforms, and optional providers may process information in countries other than your own. Their handling of international transfers is described in their respective privacy policies.

Your choices and rights

You can:

Because Handy does not operate user accounts or receive your local transcription content, the maintainers generally cannot access, export, or delete information stored only on your device.

Depending on where you live, you may have rights concerning personal information held by the project maintainer, such as support correspondence or donation records. To make a request, contact us using the address below. You may also have the right to complain to your local data-protection authority.

Third-party privacy policies

Relevant third-party policies include:

Optional post-processing, donation, community, and custom service providers are governed by the policies of the services you select or visit.

Changes to this policy

We may update this policy when Handy’s functionality or data practices change. The effective date at the top of this page will be updated when material revisions are published.

Contact

For privacy questions or requests, contact:

CJ Pais
contact@handy.computer