Boswell Privacy Policy
Last updated: July 20, 2026
TL;DR
Boswell is local-first: your recordings, notes, and transcripts never touch a Boswell server. Notes sync across your own Macs through your own private iCloud, not ours. The things that reach us are your email address — signing in is required to use Boswell, and your email is also used if you join the waitlist or opt in to product updates — and a hashed device identifier so we can tell your Macs apart. Cloud AI is the one feature that sends your content off your Mac, and only when you invoke it — it goes straight to the AI provider, not through us. Google Calendar only contacts the network if you connect it; app-usage analytics is on by default and can be turned off any time in Settings → Privacy (see How We May Disclose Your Personal Data).
What This Privacy Policy Covers
This policy covers the Boswell macOS app and the meetboswell.com website — together, "Boswell" or "the Service." It explains what personal data we collect, where it comes from, how we use and disclose it, how long we keep it, and the rights you have over it.
A standalone Boswell for iOS app also exists. It shares the same account backend but has its own, sandboxed permission model and a separate Google Calendar connection flow. This policy is written for the Mac app unless stated; an iOS-specific addendum will be added if the practices diverge in a way that matters.
Personal Data
Categories of Personal Data We Collect
From your recordings and notes, mostly none reaches us.
- Audio (voice memos, meeting recordings). Stays on the Mac that recorded it, in your local
~/Library/Application Support/Boswell/directory. Audio does not sync across your devices and is never uploaded to a Boswell server — only sent elsewhere if you export it, or if you invoke cloud AI on it (see How We May Disclose Your Personal Data). - Notes, transcripts, and summaries. Also live in that local directory, but — unlike audio — they sync across your own Macs through your own private iCloud account (Apple's CloudKit), on by default. This is a real design choice, not an oversight: see Data Storage and Security for exactly what that means and how to turn it off.
- Account & subscription data. If you subscribe to Pro or sign in, we hold: your email address; your payment processor's customer and subscription identifiers; your plan and status (e.g.
active,canceled); a salted, one-way hash of each signed-in Mac's hardware identifier (not reversible to your machine or identity); an optional device name you choose; and the app/macOS version and last-check-in time for each device. No IP address, location, or geolocation is collected as part of your account or subscription data (the website's waitlist and download-link forms use your IP transiently for abuse rate-limiting — see below). - Google Calendar data, if you connect it. Calendar names, and for events: title, start/end time, all-day flag, location, description, and the meeting-join link. Read-only; never sent to a Boswell server. See How We May Disclose Your Personal Data for the full disclosure.
- Waitlist email, if you join it. Just your email address, plus whether you've confirmed and been invited — and, only if you check the optional box, a marketing preference.
- Product-update email, if you opt in. Just your email address, on a list you can leave in one click.
- App usage events. Feature-interaction events (e.g. "user opened the Voice Memo screen") — never the contents of your recordings, transcripts, file paths, or anything personally identifying. Sent automatically today; see How We May Disclose Your Personal Data for opt-out status.
- Nothing else. Boswell does not collect internet/network activity data, precise geolocation, biometric identifiers, or build inferred profiles about you.
Categories of Sources of Personal Data
- Directly from you — when you subscribe, sign in, connect Google Calendar, join the waitlist, opt into product updates, or contact support.
- Automatically, from your device — the check-in telemetry each signed-in Mac sends (app/OS version, last-seen time).
- From Google — if you use Sign in with Google or connect Google Calendar, Google is the source of your account email and (if connected) your calendar data.
- From our payment processor — transaction confirmations and billing status updates after you subscribe.
Our Business Purposes for Collecting or Disclosing Personal Data
We collect and use personal data to: provide and maintain the subscription service; process payments and prevent fraud; let you manage which Macs are signed in; send you transactional email (sign-in links, billing notices) and, if you opt in, product updates; show upcoming meetings and detect when one is starting, if you connect a calendar; measure app usage in aggregate, if you opt into analytics; and comply with legal obligations.
Other Permitted Purposes for Processing Personal Data
We may also process personal data to enforce our Terms of Service, to investigate and prevent fraud or security incidents, and as otherwise required or permitted by law.
De-Identified Data
The device-sign-in identifier we hold is a salted, one-way hash of your Mac's hardware identifier — not the raw identifier, and not reversible back to your machine or your identity. We use it only to let the backend tell your signed-in Macs apart.
How We May Disclose Your Personal Data
Apart from the optional waitlist and product-updates email lists, the only server-side data Boswell holds is your subscription record (see Categories of Personal Data We Collect). Here is exactly who touches it, and the optional integrations that may touch other data:
Payments. Payment is handled by our payment processor's hosted checkout. It collects what it needs to process the transaction: your email address, card details, and billing address. It acts purely as a payment-processing conduit — Boswell does not send it any recording content, transcript text, recording or meeting titles, file paths, or usage data, only what's intrinsically necessary to take payment. It never sees your notes. Our payment processor's privacy policy governs the data once it reaches them. You manage billing (receipts, invoices, payment method, plan changes, cancellation) through its hosted billing portal from Settings → Billing in the app.
Subscription backend. When you sign in — required to use Boswell — Boswell's backend stores your account record; if you subscribe to Pro, it also stores your subscription record (see above). You sign in from Settings → Account in the app (Google sign-in or a magic-link email).
Sign-in & account emails. Magic-link sign-in emails, and any account or subscription notices, are sent through our email provider, from
hello@meetboswell.com. The same provider holds the opt-in product-updates contact list, if you joined it — the download-link form's checkbox is unchecked by default, and every product-update email carries a one-click unsubscribe link.Waitlist (opt-in). If you join the waitlist to be invited to Boswell, we store your email address with our email provider and send you a confirmation email to verify it's really you. Once your spot is ready, we email you an invite with the download link. If you also check the optional "send me updates" box on the waitlist form — unchecked by default — we add you to the same product-updates contact list described above; leaving it unchecked means your email is used only for the waitlist itself. You can unsubscribe from any waitlist or update email with its one-click link, or ask to be removed at any time by emailing support@meetboswell.com. Submitting the waitlist or download-link form also sends your IP address to our backend, used transiently to rate-limit abuse and not stored beyond that.
Google Calendar (opt-in, direct connection). If you connect a Google account for calendar detection — from Settings → Record Meetings → Calendars, or by choosing Sign in with Google during onboarding — Boswell talks directly to the Google Calendar API. It requests three OAuth scopes:
openid,email, andhttps://www.googleapis.com/auth/calendar.readonly— read-only; Boswell cannot create, edit, or delete anything in your calendar, and does not read attendee lists, guest emails, attachments, or conference metadata beyond the meeting-join link. It's used only to show upcoming meetings and to notice when one is starting (by matching an event's location, join link, or description against known meeting platforms — Zoom, Google Meet, Microsoft Teams, and others). Calendar events and the OAuth token are never sent to a Boswell server or any third party; they travel directly between Google and the app on your Mac. Identity is the one thing that is shared: if you use Sign in with Google, your account email reaches our backend to create or link your Boswell account (no calendar content included). Boswell's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See Data Storage and Security for where the token lives, and Data Retention for how long.Cloud AI (opt-in per use — the one path that sends your content off your Mac). Boswell can summarize, chat with your notes, translate, and transcribe using cloud models instead of the on-device ones. This only happens when you invoke it; the on-device path remains available and nothing is sent in the background. In every case Boswell sends the relevant audio or text directly from your Mac to the AI provider — it does not pass through, and is not stored on, a Boswell server, and we do not log the contents of these requests. There are two ways it can be set up:
- Included cloud AI (no API key to set up). Boswell's backend issues your Mac a personal, spend-limited API key for our model gateway, which routes each request to the upstream model provider that serves it. The key is issued by us; the content does not travel through us. Our backend records only usage and spend against that key — never prompts, transcripts, or notes.
- Bring your own key (BYOK). If you configure a provider of your choice in Settings → AI Services, Boswell uses your own API key, stored in your Keychain and never sent to Boswell's servers. Once your content reaches a provider, that provider's own privacy policy governs it, and it acts as an independent controller for it. On training: our model gateway's default routing pool includes upstream providers that may store or train on what you send. To exclude them, turn off Allow providers to train on my data in Settings → AI Services; note that this narrows the pool, so some models (free ones especially) may become unavailable. You can stop using cloud AI, or revoke any provider configuration, at any time from Settings → AI Services.
Analytics. Boswell sends anonymized usage events (e.g. "user opened the Voice Memo screen") to our analytics provider in non-debug builds. Events never include the contents of your recordings, transcripts, file paths, or any personally identifying information. Analytics is on by default and can be turned off any time in Settings → Privacy → Send anonymous usage data. Our analytics provider's own privacy policy applies to data once it reaches their service.
App updates (direct-distribution path only). If you installed via the direct DMG download, the app uses an update-check framework that pings Boswell's own appcast URL (
https://meetboswell.com/appcast.xml) — anonymous, no user identifier, purely to show an "Update Available" prompt. Disable in Settings → Updates. Mac App Store builds update through the App Store instead.Legal process, safety, and business transfers. We may disclose personal data if we believe it's necessary to comply with a legal obligation (such as a subpoena or court order), to protect the rights, property, or safety of Boswell, our users, or the public, or in connection with a merger, acquisition, or sale of assets — in which case we'd tell you before your personal data becomes subject to a different privacy policy.
Boswell does not sell or share your personal information, and does not sell or share it for cross-context behavioral advertising. We have no advertising business, run no ad trackers, and don't disclose your personal information to third parties for their own marketing. The processors above act on our instructions to provide the service, not for their own advertising purposes.
Cookies & Site Analytics
This section is about the website, https://meetboswell.com, as distinct from the app.
No analytics or advertising cookies
The Boswell marketing site does not set advertising or analytics cookies, and it runs no third-party analytics, tracking pixels, or fingerprinting scripts of any kind. Because the site sets no tracking cookies, there is no cookie-consent banner to dismiss.
Your browser may make ordinary requests to load the pages, fonts, and images, and our host (Netlify) processes those requests to serve the site and may keep standard server logs for security and reliability. The site also loads one small scroll-animation script from a third-party content-delivery network (unpkg.com), which sees the same ordinary request data any CDN does — but Boswell does not place tracking cookies or run client-side analytics on the marketing site.
No browser storage at all
The website sets no cookies and no localStorage of any kind. Signing in, viewing your subscription, and managing billing all happen inside the Boswell app now (Settings → Account, Settings → Billing) — there is no website session to remember.
App analytics is separate
The app analytics described under How We May Disclose Your Personal Data is a feature of the macOS app, not the website. If we ever add analytics or a cookie banner to the website itself, we will update this section before doing so.
Data Storage and Security
- Local files. Audio, notes, transcripts, and exports live in
~/Library/Application Support/Boswell/, protected by standard macOS file permissions (and by FileVault, if you have it enabled). - Notes sync via your own private iCloud. Note text, transcripts, and summaries sync across your Macs through a private CloudKit database scoped to your own iCloud account — never a Boswell-hosted store. Apple gives developers no access to records in a user's private database, so Boswell cannot read your synced notes any more than it can read your local ones. This is on by default; turn it off in Settings → Privacy to keep everything strictly local to each Mac. Data in your private iCloud is encrypted under Apple's standard iCloud encryption; if you've turned on Advanced Data Protection in your Apple Account settings, it's end-to-end encrypted (Apple itself can't read it either) — without ADP, Apple holds the encryption keys per its standard iCloud posture. Audio does not sync via iCloud; it stays local to the recording device.
- Keychain-protected secrets. OAuth tokens (Google Calendar) and cloud AI API keys — both your own (BYOK) and the managed key issued for the included cloud AI — are stored in your Mac's Keychain, accessible only while the Mac is unlocked, and never synced to iCloud Keychain or any other device. A BYOK key is never sent to Boswell's servers.
- Backend & payment processor. Our backend and payment processor both encrypt data in transit (TLS) and follow their own industry-standard practices for data at rest; our payment processor is a PCI-DSS compliant platform. Neither ever receives your recordings, transcripts, or notes.
System Permissions
Boswell asks for the following macOS permissions at the moment you first use the feature that needs them:
- Microphone: when you start a voice memo, dictation, or meeting mic track.
- System audio recording: when you start a meeting capture, so Boswell can transcribe the other participants' audio from the call. This uses macOS's narrow "System Audio Recording Only" permission — not Screen Recording. No video or screen access is involved.
- Accessibility: only if you enable auto-record detection. Boswell reads meeting-app window titles so it only offers to record when you're actually in a call, rather than just because Zoom or Teams is open.
- Input Monitoring: only if you enable system-wide dictation. Boswell watches for your dictation hotkey so you can dictate into any app. Boswell does not log your keystrokes.
- Contacts: only if you opt into speaker-name resolution. Boswell looks up contacts so you can pick a name for each speaker; contact data never leaves your Mac.
- Calendars: only if you opt into upcoming-meeting auto-detection from calendars already added to your Mac (System Settings → Internet Accounts). This is separate from directly connecting a Google account for the same purpose — see Google Calendar under How We May Disclose Your Personal Data for what that reads, stores, and shares.
Each prompt is the standard macOS prompt; you can revoke any permission later in System Settings → Privacy & Security. Boswell gracefully degrades when permissions are revoked: the relevant feature stops working, but the app continues to run.
Data Retention
Because Boswell is local-first, most of your data has no retention schedule on our side — it lives on your Mac (and, for notes, your own private iCloud), under your control, for as long as you keep it. The table below covers the limited data that does reach a server, or leaves the recording device.
| Data | Where it lives | How long it's kept |
|---|---|---|
| Voice memo & meeting audio (recordings) | Your Mac only — the device that recorded it; never synced | As long as you keep it; deleted when you delete the recording |
| Notes, transcripts, and summaries | Your Mac, plus your own private iCloud (if sync is on) — never a Boswell server | As long as you keep them; turn off sync in Settings → Privacy to keep future notes local-only |
| Subscription record (email, payment-processor IDs, plan/status) | Boswell backend | While your subscription is active, and for a limited period afterward for support and accounting; deleted or anonymized after that period, or sooner on request |
| Device sign-in hashes + device names | Boswell backend | While the device is signed in; removed when you sign the device out, or when the subscription record is deleted |
| Check-in telemetry (app/OS version, last-seen time) | Boswell backend | Kept as the current status for each signed-in device; removed with the device or the account |
| Sign-in / license emails | Email provider (processor) | Per our email provider's retention for transactional email logs |
| Opt-in product-updates contact (email only) | Email provider (processor) | While you're opted in; removed when you unsubscribe or ask to be removed |
| Waitlist entry (email + confirmed/invited status) | Email provider (processor) | Until you unsubscribe or ask to be removed — invited entries are not currently deleted automatically after your invite is sent |
| Payment & transaction records | Payment processor (independent controller) | Retained by our payment processor as required for tax, accounting, and anti-fraud purposes — Boswell does not control this schedule |
| Usage analytics (on by default; opt out in Settings → Privacy — see above) | Analytics provider (processor) | Per our analytics provider's retention for these events; deletable via their request flow |
| Cloud AI requests (only when you invoke cloud AI) | Sent from your Mac straight to the AI provider — never stored on a Boswell server | Per the serving provider's own retention policy; Boswell keeps no copy. For the included cloud AI we retain only usage and spend figures for your key, not content |
| Google Calendar OAuth token (only if you connect an account) | Your Mac's Keychain only — never a Boswell server | Until you disconnect the account in Boswell, or revoke access from your Google Account |
| Google Calendar events (only if you connect an account) | Not stored — fetched live from Google in a rolling window, held only in memory | Cleared when Boswell closes; never written to disk |
Post-cancellation window. The precise retention period for the subscription record after cancellation is while the account is active and for a limited period afterward (on the order of months, not years), to cover support requests, charge-back windows, and accounting. A specific number will be set here once established. You can request deletion at any time — see Your Data Rights below — and we will act on it subject only to our payment processor's legally required retention of transaction records.
Personal Data of Children
Boswell is a professional productivity tool not directed at users under 13. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact support@meetboswell.com and we'll delete it.
Your Data Rights
Your rights depend on where you live, but Boswell's local-first design means the practical answer is usually the same: most of your data is already on your Mac (or your own private iCloud) and under your direct control; the only data we hold server-side is your subscription record, plus your waitlist or product-updates email entry if you joined one of those lists.
The basics (everyone)
Local & iCloud data. Everything Boswell creates from your recordings lives on your Mac; notes/transcripts also live in your own private iCloud if sync is on. To erase it: quit Boswell, uninstall the app, and delete ~/Library/Application Support/Boswell/; turning off sync in Settings → Privacy first also removes the CloudKit copy going forward. There is no Boswell server holding your notes, so there is nothing on our side to delete.
Subscription & account data (subscribers only). If you have or had a Boswell Pro subscription, Boswell holds the server-side data listed under Personal Data: your email, your subscription record, your machines' salted sign-in hashes, and the check-in telemetry. You can:
- See your plan and manage billing any time from Settings → Billing in the app.
- Request its deletion by emailing support@meetboswell.com. We will cancel any active subscription and delete your subscription record and all associated device sign-ins. (Note: deleting your account removes your ability to use Pro until you subscribe again; our payment processor separately retains transaction records as described below.)
State Law Privacy Rights
California and Other US State Rights
If you live in California, or another US state with a comprehensive consumer-privacy law (Colorado, Connecticut, Virginia, Utah, Texas, Montana, and others), you have rights over the personal information Boswell holds, subject to that law's limits:
- Know / access what personal information we have collected about you, the categories of sources, the business purposes for collecting it, the categories of third parties with whom it is shared, and the specific pieces of personal information we hold.
- Delete the personal information we hold about you (subject to limited exceptions, such as completing a transaction in progress or complying with a legal obligation).
- Correct inaccurate personal information.
- Opt out of any sale or sharing of personal information for cross-context behavioral advertising — see How We May Disclose Your Personal Data: we don't do this.
- Limit use of sensitive personal information (Boswell collects none, as defined by CCPA/CPRA).
- Non-discrimination for exercising any of these rights.
How to submit a request. Email support@meetboswell.com from the address associated with your account. We will verify your request against the account email on file, respond within 45 days (extendable by a further 45 days with notice), and will not charge a fee for up to two requests per 12-month period.
Nevada Resident Rights
Nevada law (NRS 603A) gives Nevada residents the right to opt out of the "sale" of certain personal information — narrowly defined as a transfer for monetary consideration to a third party for that party's own use in advertising or reselling. Boswell does not sell personal information under this definition. You may still submit a verified request by emailing support@meetboswell.com, though there is currently nothing to opt out of.
European Union, United Kingdom, and Swiss Data Subject Rights
Where the GDPR, UK GDPR, or the Swiss Federal Act on Data Protection (FADP) applies, you have rights over the personal data Boswell holds (principally, the subscription record).
Personal Data Use and Processing Grounds
- Performance of a contract (Article 6(1)(b) GDPR) — holding your subscription record (email, plan, payment-processor IDs), delivering and verifying your Pro subscription, and sending magic-link sign-in emails and subscription notices.
- Legitimate interests (Article 6(1)(f) GDPR) — recording device sign-in hashes and check-in telemetry to detect unauthorised sharing of a subscription, and app-usage analytics to understand feature usage (on by default, with a working opt-out — see How We May Disclose Your Personal Data for where). This is the minimum data needed to protect your Pro access and improve the product.
- Consent (Article 6(1)(a) GDPR) — connecting Google Calendar for meeting detection, and joining the waitlist or product-updates list on the website. Each is specific and controllable (Settings → Record Meetings → Calendars, or your Google Account directly, for calendar access; unsubscribe links or support@meetboswell.com for the waitlist/product-updates lists). Syncing notes via your own private iCloud is on by default, but Boswell itself never receives or processes that data — it travels solely between your Macs and your personal iCloud account, so no Boswell lawful basis applies to it.
- Legal obligation / legitimate interests (Article 6(1)(c)/(f) GDPR) — our payment processor's retention of transaction records for tax and anti-fraud purposes. It is an independent controller for this data; Boswell does not control or extend its retention.
Data Subject Rights
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data (your email is editable via support).
- Erasure ("right to be forgotten") — have your subscription record and device sign-ins deleted.
- Restriction — ask us to limit how we use your data while a question about it is resolved.
- Portability — receive the data you gave us in a structured, machine-readable form (typically JSON or CSV on request).
- Objection — object to processing we carry out on the basis of legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time (see the Consent basis above for exactly where), with no effect on processing already carried out.
To exercise any of these rights, email support@meetboswell.com. We will respond within one calendar month (extendable by a further two months for complex requests, with notice). You also have the right to lodge a complaint with your local supervisory authority — the relevant authority depends on where you are located in the EU/EEA, the Information Commissioner's Office (ICO) if you are in the UK, or the Federal Data Protection and Information Commissioner (FDPIC) if you are in Switzerland.
Transfers of Personal Data
Boswell's processors (payments, backend hosting, email delivery, and — unless you opt out — analytics) operate infrastructure in the United States and potentially other countries outside the EEA/UK/Switzerland. Where personal data is transferred to a country without an adequacy decision, each processor relies on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms under GDPR Chapter V, the UK International Data Transfer Addendum, and the Swiss FADP's equivalent framework, as applicable. Boswell does not itself transfer your data outside the context of these processor relationships.
Processor-held data
Some data sits with our processors, each of which offers its own rights flow:
- Payment records. Our payment processor retains transaction records and may be legally required to keep them for tax and anti-fraud purposes. It is the controller for that data; see our payment processor's privacy policy.
- Usage analytics. Anonymized event data may live on our analytics provider's servers (see How We May Disclose Your Personal Data for current opt-out status), which provides its own data-subject request flow at its privacy policy.
- Cloud AI providers. If you used cloud AI, the provider that served the request is the data controller for anything you sent to it — the upstream provider our model gateway routed to, or the provider you chose if you brought your own key. Each has its own GDPR/CCPA flow. Boswell holds no copy of these requests, so there is nothing on our side to produce or delete.
- Your own iCloud. Synced notes live in your private iCloud account; Apple's own privacy policy and data-subject rights flow govern that data, since Boswell has no access to it.
Changes to This Policy
Material changes to this policy will be reflected here, with the "Last updated" date at the top updated accordingly. If that date matches what you remember from your last visit, nothing has changed.
Contact Information
Questions about this policy or your data: support@meetboswell.com.