Trust & Security
Last updated: July 20, 2026
Your meetings stay on your Mac
Boswell is local-first by design. Recording and transcription always run on your Mac, and on-device AI can draft your notes without anything leaving the machine. The meeting content you capture never travels to a Boswell server — there is no Boswell pipeline that sees your audio or your notes.
The one case where meeting content leaves your Mac is cloud AI, and it only happens when you ask for it. That case is described in full in the next section.
The macOS app is distributed as a Developer-ID-notarized, hardened-runtime binary. If you want to cut the app off from the network entirely, macOS lets you do that — Boswell's core recording and transcription features keep working either way.
The only server-side data Boswell holds is the account and subscription record described below.
When you use cloud AI
Boswell includes stronger cloud models for summarizing, chatting with your notes, and translation. Cloud AI is always something you choose to invoke — it never runs on its own, and the on-device path stays available. Here is exactly what happens when you do use it.
Your content goes directly from your Mac to the AI provider. It does not pass through, and is not stored on, a Boswell server. This is true both ways you can use cloud AI:
- Boswell-funded cloud AI — included, with no API key to set up. Boswell's backend issues your Mac a personal, spend-limited API key for OpenRouter, our model gateway. The key comes from us; the content does not go through us — your Mac talks to OpenRouter directly. Boswell's servers see only usage and spend against that key, never prompts, transcripts, or notes.
- Bring your own key (BYOK) — configure Anthropic, OpenAI, Ollama, or another provider in Settings → AI Services and Boswell sends the request straight to that provider using your key.
Either way, once your content reaches a provider, that provider's privacy policy governs it, not ours.
On training, be aware of the default. OpenRouter routes each request to one of many upstream providers, and by default that pool includes providers that may store or train on what you send. If you would rather not allow that, turn off Allow providers to train on my data in Settings → AI Services. Boswell then restricts routing to providers that don't store or train on prompts. The honest trade-off: that pool is smaller, so some models — free ones especially — may become unavailable and requests to them can fail.
To keep meeting content on your Mac in every case, use the on-device models and leave cloud AI unused.
What Boswell's backend stores
When you sign in to Boswell — required to use the app, including the Free tier — a small account record is created on Boswell-operated infrastructure (hosted by Supabase). That record contains:
- Your email address — used to authenticate your account and to send subscription notices.
- Your subscription status and Stripe identifiers — once you subscribe to Pro: your current plan, status (active, canceled), and the Stripe customer and subscription IDs that link your account to your payment method. Boswell uses these to verify your Pro access across your Macs. A Free-tier account has no subscription and no Stripe identifiers.
- Device sign-in entries — a salted, one-way hash of each Mac's hardware identifier (not reversible to your machine or identity), an optional device name you choose (e.g. "MacBook Air"), and the app and macOS versions last reported by that device. These let you see and sign out your Macs from your account page.
No recordings. No transcripts. No note content. Ever. This list is the complete extent of what Boswell stores server-side. There is no pipeline that processes your meeting content on Boswell's infrastructure — including when you use Boswell-funded cloud AI, where your Mac talks to the model provider directly and we hold only the usage and spend figures for your key.
Signing in is required to use Boswell, so this account record exists whether you are on the Free tier or Pro. For a Free-tier user it holds your email and device sign-in entries; the subscription fields above are populated only if you upgrade to Pro.
The processors we use
Boswell works with three processors to run the subscription and account service:
| Processor | Role |
|---|---|
| Stripe | Payment processing. Handles checkout, billing, and the Customer Portal. Stripe sees only what is necessary to take payment (email, card details, billing address). Stripe never receives recording content. Stripe's privacy policy governs data once it reaches them. |
| Supabase | Account and licensing backend. Stores the subscription record and device sign-in entries described above. |
| Resend | Transactional email. Delivers magic-link sign-in emails and subscription notices, and holds the opt-in product-update contact list if you joined it. |
Two further processors are optional — one you invoke, one you can switch off:
- OpenRouter — the model gateway behind Boswell-funded cloud AI, and the only processor that ever receives meeting content. It receives a request only when you invoke a cloud model, sent directly from your Mac, and passes it to the upstream model provider that serves it. See When you use cloud AI above, including the training default. If you use BYOK instead, your chosen provider takes this role.
- PostHog — anonymized usage analytics inside the macOS app. It is on by default and can be turned off any time from Settings → Privacy → Send anonymous usage data. Events contain no recording content, no transcripts, no file paths, and no personally identifying information.
No other external services receive your data. Boswell runs no advertising networks, tracking pixels, or behavioral analytics on the website.
Security posture
- Notarized and hardened. The Boswell app is code-signed with an Apple Developer ID certificate and notarized by Apple. Hardened runtime is enabled, which restricts the executable's access to its own entitlements.
- Keychain storage. Cloud AI API keys — both your own (BYOK) and the managed key Boswell issues for its included cloud AI — are stored in the macOS Keychain, not in a file Boswell can read after entry. A BYOK key is never sent to Boswell's servers.
- Network-off compatible. Boswell's recording, transcription, and on-device note-taking features work without a network connection. You can use macOS's built-in application firewall to block the app's network access and the core experience remains intact; only cloud AI and account sign-in need the network.
- Vulnerability disclosure. If you find a security issue, see our Vulnerability Disclosure Policy for how to reach us and what to expect. Reports go to security@meetboswell.com.
DPA available on request
A Data Processing Agreement (DPA) is available to organizations that require one for compliance purposes. Email support@meetboswell.com with the subject line "DPA request" and we will provide one.
A different approach to trust
Most cloud note-taking and meeting-recording tools ask you to trust that they protect your content in their cloud. Boswell's answer is different: we don't have a copy of your meetings. There is no stored copy on Boswell's servers that could be breached, subpoenaed, or misused. We are not asking you to trust our cloud; we are asking you to trust your own Mac.
Cloud AI is the deliberate exception, and we'd rather name it than bury it: when you invoke a cloud model, that request goes to the model provider. It still doesn't route through us, and it still doesn't get stored by us — but it does leave your Mac, and the provider's terms apply to it from that point. It is your call, every time.
We do not hold any certifications such as SOC 2, ISO 27001, or HIPAA compliance at this time. We believe the local-first architecture makes that tradeoff explicit: rather than certifying the handling of data we do not hold, we build the app so that the sensitive data never arrives at a server in the first place.
Full policies
- Privacy Policy — complete details on data collection, your rights, and how to contact us.
- Vulnerability Disclosure Policy — how to report a security issue.
Contact
Trust, privacy, or security questions: support@meetboswell.com Security vulnerability reports: security@meetboswell.com