That is the constraint Keeti was built from, not a box ticked afterwards. Here is exactly what stays with you, what goes out, and why the difference matters.
The microphone records the room. The audio file is written to a local folder and is never transmitted.
Transcription and speaker separation run on the machine's neural engine. No network needed: it works on a plane.
To write, Keeti sends the text of the transcript, with your key. The sound does not go. The answer comes straight back to your Mac.
There is no step in between for your content: the exchange happens between your Mac and the AI provider, on your account with them. We see neither your meetings nor your key. What the app does send us is anonymous usage counts (how many recordings make it to notes, never what they contain), spelled out in the privacy policy.
A board meeting, a legal review, an acquisition file, a performance conversation: these are the meetings where a tool that uploads the audio somewhere never makes it through the door. They are also the ones whose notes are missed the most.
Connecting a Google account is optional and Keeti works without it. If you do connect it, every permission is read-only, each one can be declined on its own at the consent screen, and everything read stays on your Mac. None of it is ever sent to us.
| Permission | What Keeti does with it |
|---|---|
calendar.events.readonly | Reads your upcoming events to spot the meeting that is starting and pre-fill its title, its attendees and the number of people who will speak. That count is what lets the local engine separate the voices correctly. |
directory.readonly | On a Google Workspace account, turns a colleague's email address into their full name using your organisation's directory, so the notes credit a person. |
contacts.readonly | Same lookup, against the contacts you have saved yourself. This is what covers clients and partners outside your organisation. |
contacts.other.readonly | Same lookup again, against the people you have corresponded with without ever saving them as contacts. In practice that is most external attendees. |
The three lookup permissions do one single job: turning an email address into a name. Keeti queries one address at a time, at the moment a meeting arrives with an attendee it cannot name, and only keeps a result whose address matches exactly the one asked for. It never exports your address book, never syncs your contacts, and never browses your directory. Decline all three and Keeti simply keeps the email address, with no error and no nagging.
The content of your events is not sent to the AI provider. Only the names and email addresses of the attendees you confirmed can be included in the text sent for writing, so that the notes attribute what was said to the right person. You can disconnect at any time from Keeti's settings, and revoke access on Google's side at myaccount.google.com/permissions.
Keeti's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
In France, recording a conversation without the knowledge of the people in it is a criminal offence, and most countries have equivalent rules. One sentence at the start of the meeting is enough to be in the clear, and Keeti can remind you every time you record. The announcement itself stays your responsibility: no tool can make it for you.
The detail of what the app handles is in the privacy policy, and the rules of use are in the terms.
No. Recording, transcription and speaker separation all happen on your Mac, and the audio file never leaves it. To write the notes, Keeti sends the text of the transcript to the AI provider you picked, using the key you supplied. Your meetings never pass through us and we keep no copy: the exchange happens between your Mac and that provider. The only thing Keeti sends us is anonymous usage measurements, never content.
Only what it needs to prepare a meeting, and only if you connect it. Keeti reads your upcoming calendar events read-only, to pre-fill the title, the attendees and the number of speakers. It then turns attendee email addresses into full names through the Google People API, one address at a time, so the notes credit a person rather than an inbox. Keeti cannot create, edit or delete anything in your Google account, none of it reaches a server of ours, and each permission can be declined on its own. The detail is on the privacy page.
Yes. Recording a conversation is regulated, and the rules vary by country. Keeti reminds you when you start a recording, but making the announcement is your responsibility. One sentence at the top of the meeting is usually enough.
Free during the public beta. Nothing to create, nothing to upload.