Privacy Policy
Minutehand is a macOS application made by TWO Design ("we"). The short version: Minutehand runs entirely on your Mac, we operate no servers, and we never see your recordings, transcripts, calendar, or keys. The longer version follows.
What Minutehand does
Minutehand records meeting audio (your microphone and your Mac's system audio), sends that audio to Deepgram for transcription using an API key you provide, and saves the resulting transcript as a Markdown file in a folder on your Mac that you choose. It can also read your Google Calendar to prompt you before meetings begin.
Data stored on your Mac
Audio recordings are written to your local disk and automatically deleted after a retention period you configure in Settings. They are never uploaded anywhere except to Deepgram, once, for transcription.
Transcripts are plain Markdown files saved to a folder you choose. They stay there until you move or delete them. We have no access to them.
Secrets — your Deepgram API key and Google sign-in tokens — are encrypted at rest using macOS secure storage (Keychain-backed). If secure storage is unavailable, Minutehand refuses to save them in plaintext.
Transcription (Deepgram)
Transcription is performed by Deepgram under your own Deepgram account and API key. Meeting audio is sent to Deepgram solely to produce the transcript. Your relationship with Deepgram — including how they handle audio — is governed by Deepgram's privacy policy. We are not a party to it and receive nothing from it.
Google Calendar
If you connect Google Calendar, Minutehand requests read-only calendar access (the calendar.readonly scope). It uses this on your Mac, and only to check for upcoming events so it can offer to record and to tag transcripts with meeting details (title, time, attendees).
Sharing. We do not share, sell, transfer, or disclose your Google Calendar data to any third party, or to ourselves. Minutehand runs entirely on your Mac and we operate no servers, so calendar data is never sent to TWO Design, never sent to Deepgram, and never sent anywhere except directly between your Mac and Google's own API, over TLS, using your own Google account's credentials.
Data protection. Your Google OAuth access and refresh tokens are encrypted at rest on your Mac using macOS's secure, Keychain-backed storage (safeStorage); if secure storage is unavailable on your Mac, Minutehand refuses to save them in plaintext at all rather than falling back to an unprotected file. Calendar event data (titles, times, attendee lists) fetched from Google is held only in memory for the duration of each look-ahead check — it is written to disk only for the specific event you choose to record, and even then only as part of the local transcript file you already control.
Retention & deletion. Encrypted access/refresh tokens are retained locally only until you disconnect Google in Settings, at which point they are deleted from your Mac immediately. Calendar event data fetched while checking for upcoming meetings is discarded automatically after each check (roughly every 60 seconds) and is never separately stored; any of it that was written into a transcript persists only as long as you keep that file, and is gone as soon as you delete it. Disconnecting in Minutehand removes the app's local copy of your tokens; to fully revoke Minutehand's access on Google's side, visit myaccount.google.com/permissions. Minutehand's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we never collect
Minutehand has no accounts, no analytics, no telemetry, and no crash reporting that phones home. The application makes network requests to exactly two services: Deepgram (with your key) and Google (with your consent). That's the complete list.
Purchases
Purchases are processed by Polar, our merchant of record. Polar handles payment details and issues your licence key; we receive your order information (name, email, licence key) from Polar to provide support and licence activation. Payment card details never reach us. Licence activation checks send only your licence key to Polar's API — no meeting data, ever.
This website
This site is a set of static pages. It sets no cookies, loads no third-party scripts, and makes no requests to anyone else — fonts, images, video and the one small script on the home page are all served from this domain. Our host, Netlify, counts page views from its own server logs so we can see whether anyone is reading this; that counting happens entirely server-side, involves no cookies and no tracking script, and tells us nothing that identifies you.
If you give us your email address on the updates form, it is stored by Netlify and used for one thing: occasional emails about Minutehand releases. We don't sell it, share it, or add it to anything else, and every email we send carries an unsubscribe link. Ask us at support@minutehand-app.com and we'll delete it.
Changes & contact
If this policy changes, the date above will change with it. Questions: support@minutehand-app.com.