OneSay Privacy Policy
Last updated and effective: August 3, 2026
Privacy contact: support@onesay.io
1. Scope of This Policy
This Policy explains how OneSay collects, uses, stores, transmits, discloses, and deletes personal information when you visit https://onesay.io, create or use a OneSay account, use the released desktop application, or contact support. It also explains how you can exercise relevant rights.
This Policy applies to the current OneSay website, account services, free Beta, one-time 90-day non-renewing Pro benefit, released macOS application, and related services. Information processed independently by third-party websites, sign-in providers, AI services, or other third parties may also be subject to their own privacy rules and is not entirely controlled by this Policy.
The current product is available only to individuals who are at least 18 years old. Anyone under 18 must not register for or use OneSay.
2. How OneSay Works
OneSay’s core features include Dictation, Translation, Rewrite, and Ask:
- When you actively start Dictation or Translation, the application captures audio for that interaction, sends audio frames through an encrypted network connection to the OneSay gateway and a third-party speech-recognition service, and may then use a third-party AI service to refine or translate the transcript;
- When you actively start Rewrite, the application reads the text you selected and any dictionary, preference, and limited expression context needed to provide the feature, and sends it to the cloud to generate a rewrite;
- When you actively start Ask, your question, optional selected text, limited expression context, external-search setting, and other necessary input are sent to a third-party AI provider, which generates the answer;
- To insert results into another application, OneSay may read active-application, process, control, or window descriptions and temporarily use operating-system accessibility functions or the clipboard.
OneSay does not continuously record ambient audio merely because you installed or opened the application. Audio capture should begin only after you actively start the relevant voice feature and stop when that workflow ends or is canceled.
3. Personal Information We Process
The following table reflects the current technical implementation. Particular fields depend on the features, device, and settings you use.
| Category | Examples | Source | Main purpose | Required or optional |
|---|---|---|---|---|
| Account information | User ID, name, email, avatar, role, account status, referral code, and optional phone number | You, Google OAuth, account system | Account creation and management, profile display, support, benefits | Core account details are generally required; some details are optional |
| Authentication and security | Password-verification results, OAuth link, session, PKCE, access/refresh token, device UUID, IP or risk signals | You, device, Google, network | Sign-in, session maintenance, abuse prevention, security | Required for accounts and cloud features |
| Raw voice audio | 16 kHz mono PCM audio frames, duration, and connection information | Microphone, only after you start a voice feature | Speech recognition, Dictation, Translation | Required for voice features |
| Locally retained audio | Ogg audio associated with a History item, with a technical limit of 64 MiB per file | Microphone | Local History playback | Optional; saved only when Save History is enabled and a valid History item is created |
| Text and AI content | Partial/final transcript, selected text, question, instruction, translation, rewrite, answer, and possible source links | You, active application, third-party AI | Dictation, Translation, Rewrite, Ask, and result insertion | Required for the corresponding feature |
| Application and expression context | Application name, bundle ID/PID, control or window description, selected text, limited nearby text, dictionary, language, tone, and expression preferences | Device, active application, you | Selection capture, request understanding, personalization, result insertion | Some elements are required; others depend on settings and feature |
| Local personalization | History, Dictionary, Insights, AI result, favorites, corrections, and preferences | Your use and settings | Local history, dictionary, insights, and personalization | Optional or supporting features |
| Usage metering | Characters, estimated tokens, audio seconds, request/session/trace/AI-result IDs, model, provider, cost, quota, and plan snapshot | OneSay Services | Quotas, benefits, cost accounting, reliability, operations | Required to operate and manage the Services |
| Device and diagnostics | OS, version, architecture, locale, time zone, app version, network/endpoint host, request and trace IDs, performance, error stack | Device and Services | Diagnostics, stability, security, support | Basic operational data is necessary; Sentry diagnostics generally require separate enablement or voluntary submission |
| Website analytics | Page path, language, approved business events, browser and ordinary network/device information, GA cookies | Browser, Google Tag Manager/GA4 | Consented website analysis and improvement | Optional; refusal does not prevent core Services |
| Contact and feedback | Name, email, message, language, use case, feedback text, optional scrubbed diagnostics | You | Responses, troubleshooting, product improvement | Necessary when contacting support; diagnostic attachments are optional |
| Benefits and promotions | 90-day Pro grant, credits, redemption code, referral, quota, and entitlement records | Registration, promotions, Services | Issuance and administration, duplicate/fraud prevention | Required for the relevant benefit |
| Legal and risk data | Consent status, bans, rate limits, audits, abuse signals | You, Services, administrator actions | Compliance, security, investigation, disputes | Required depending on circumstances |
3.1 Product Collection Paths Not Currently Found
As of the audited version, no current product path was found that continuously captures the full screen, records the screen, or performs OCR to provide the features above. Test tools may capture OneSay’s own window, but that is not part of the ordinary user product flow.
No current path was found by which OneSay’s servers receive complete payment-card numbers; production payments are not currently enabled.
4. Device Permissions and the Clipboard
OneSay may request:
- Microphone: to capture audio for an interaction after you actively start a voice feature;
- Accessibility: to obtain text you deliberately select and insert results into a target application;
- Input Monitoring: to recognize global Fn gestures and OneSay shortcuts, not to upload complete keystroke content;
- Clipboard: as a temporary insertion or copy mechanism, which may involve temporarily preserving and attempting to restore the previous clipboard content; and
- Notifications, background operation, and launch at login: to show status or provide quick access; launch at login is currently off by default.
Granting a system permission does not mean that OneSay reads everything accessible through that permission. We should limit access to the feature you initiate and what is necessary for it. You can revoke permissions through the operating-system settings, although the corresponding feature may stop working.
5. History, Insights, Dictionary, and Local Audio
5.1 When Save History Is Enabled
When Save History is enabled, OneSay may keep up to 200 History items in the current account’s local data directory. An item may contain a transcript, selected text, output, target application or window description, device information, and trace metadata. Older items may be removed when the numerical limit is reached.
If a workflow creates a valid History item, the application may also retain associated Ogg audio locally. That Ogg file is not automatically uploaded as a separate field to OneSay or an AI provider, although raw PCM audio has already been processed through the cloud for speech recognition.
5.2 When Save History Is Disabled
When Save History is disabled, the current four workflows do not create new History items or associated Ogg files. Turning it off does not automatically delete content that was saved previously; you can delete individual items or use Delete All.
Save History controls only History and associated Ogg files. It does not disable Insights, Dictionary, settings, usage metering, necessary diagnostics, or cloud processing required for a requested feature. Insights may continue to be stored, and an AI result referenced by Insights may be retained.
5.3 Delete All History
Delete All removes all local History and associated Ogg files for the current account and clears related AI results that are not referenced by Insights at that time. It does not remove Insights, Dictionary, settings, diagnostics, the account, server-side usage/trace data, backups, or third-party records.
Deleting an account on the website does not currently send an instruction to installed Electron applications to delete their local data. Before deleting your account or uninstalling OneSay, clear local content on each device if you want it removed.
6. How We Use Personal Information
We may process personal information to:
- provide Dictation, Translation, Rewrite, Ask, sign-in, result insertion, status, and other features you request;
- authenticate you, maintain sessions, and manage the 90-day Pro benefit, credits, redemptions, and quotas;
- retain local History, audio, dictionaries, insights, and preferences that you choose to keep;
- measure usage, apply quotas, diagnose performance, improve reliability, and plan capacity;
- analyze website use after you consent;
- receive and respond to contact, feedback, and technical-support requests;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of the Terms;
- comply with legal obligations and government orders and protect the lawful rights of users, OneSay, and others; and
- process information for another purpose to which you separately and expressly agree.
Where processing is based on consent, you may withdraw that consent. Withdrawal does not affect processing that occurred before withdrawal and does not prevent processing necessary to perform our agreement with you, comply with law, or provide a core feature you explicitly request.
7. Artificial Intelligence, Third-Party Models, and Training
7.1 Ask and Other AI Features
Answers from Ask come from a third-party AI provider. Your question, selected text, expression context, dictionary/preferences, optional external-search settings, and other necessary inputs may be sent to that provider to generate and return an answer.
Dictation, Translation, and Rewrite may also use third-party speech-recognition or AI services. AI output may be inaccurate, outdated, incomplete, or fabricated and does not represent OneSay’s views, warranty, or professional advice. See Section 7 of the OneSay Terms of Service for your verification responsibilities and situations in which these features are not appropriate.
7.2 Training of OneSay-Owned Models
The current product design does not show a production path by which OneSay writes user raw audio, transcripts, selected text, questions, answers, or other substantive content into a training set for a OneSay-owned model.
Unless we separately provide a clear explanation of the content, purpose, and effect and obtain any express consent required by law, OneSay will not use that content to train its own AI models. Usage, performance, and trace metadata that does not contain substantive request or response text may be used for operations, reliability, and product improvement.
7.3 No “Zero Retention” or “No Training” Warranty for Providers
The current audit could not verify, through effective contracts, DPAs, or provider control panels, that every third-party speech and AI provider applies zero retention, no training, or no human review. We therefore do not make those absolute promises on their behalf.
A provider may process requests under its agreement with OneSay, account configuration, terms, and applicable law. We will use vendor review, configuration, and contractual measures to limit the processing. If more specific commitments become supportable, we will update this Policy.
8. Cookies, Website Analytics, and Local Storage
8.1 Necessary Technologies
The website may use authentication and security cookies, including Better Auth session and cross-subdomain cookies. Blocking necessary technologies may prevent account or website functions from working.
The website uses onesay_cookie_consent_v1 local storage to record your analytics choice. The current record may not contain the date, region, or policy version associated with that choice.
8.2 Google Tag Manager and GA4
OneSay should not load GTM/GA4 analytics tags before you expressly consent to website analytics. Current GA4 events may include:
- a virtual page view;
- CTA, download, lead-generation, and language-change events; and
- page path, locale, and ordinary network/device information visible to Google through your browser.
The current data layer blocks parameters with known sensitive names, including email, name, token, transcript, audio, clipboard, prompt, response, window, user, or device identifiers. This safeguard does not constitute anonymization.
You can refuse or withdraw consent in Cookie Settings. After refusal, the website stops loading the controlled analytics tags and attempts to remove accessible _ga* cookies. This does not automatically delete data that Google previously received on its servers.
No currently enabled Meta Pixel, Google Ads remarketing, third-party advertising ID, or other advertising pixel was found. If we introduce advertising or remarketing, we will update the explanation before enabling it and obtain consent where required.
9. Recipients and Processors
We do not sell personal information solely for monetary consideration. To provide the Services, we may disclose information to or engage the following recipients and processors:
| Recipient/category | Current purpose | Information that may be processed |
|---|---|---|
| Alibaba Cloud infrastructure, container registry, CDN, and related hosting | Service hosting, update distribution, network operations | Account, service, network, and operational data depending on the service |
| Alibaba Cloud Bailian/DashScope | Speech recognition, text generation, Translation, Rewrite, Ask, optional search | PCM audio, transcript, selected text, question, prompt/context, preferences, output |
| Google OAuth | Google account sign-in | Name, email, avatar, OAuth identifier, authorization information |
| Google Tag Manager/GA4 | Consented website analytics | Page, locale, approved events, cookies, ordinary network/device information |
| Sentry | Website contact feedback; consented app errors and optional diagnostics | Feedback text, contact details, scrubbed error/device/trace information |
| Resend | Verification, reset, and other transactional emails | Email, name, transactional email content and events |
| Apple and update-distribution services | macOS signing, notarization, update checks and distribution | Application and update-request device/network metadata |
| Professional advisers, auditors, and authorities | Legal, audit, security, disputes, legal obligations | Information necessary for the relevant matter |
| Transaction recipient | Merger, financing, reorganization, or business transfer | Necessary information subject to notice, safeguards, and purpose limitation required by law |
Payment providers, additional sign-in options, or an OpenAI fallback that exist in code but are not enabled are not described as current routine recipients. Before enabling a material new recipient, we will update this Policy as appropriate and complete any required notice or consent process.
Information collected independently through a third party’s own product may also be subject to that party’s privacy policy. To the extent required by law, OneSay will agree with its processors on the purpose, duration, method, categories, and safeguards and reasonably supervise their processing.
10. Storage Locations and Cross-Border Processing
OneSay’s current primary infrastructure includes servers and container-registry services in Hong Kong and global third-party services that may process data in other locations. Code contains a Shanghai OSS configuration, but the audit could not establish whether it is actually used for user data.
Your information may therefore be processed outside the country or region where you are located, including Hong Kong and other locations in which providers operate. Data-protection law varies by jurisdiction.
For transfers of personal information from mainland China to a location outside mainland China, OneSay should complete any required personal-information protection impact assessment, contract, certification, security assessment, or other transfer mechanism. Where required, we should separately inform you of the overseas recipient, purposes, methods, categories, and rights procedures and obtain separate consent.
11. Retention
We generally retain personal information only for the shortest period necessary for the processing purpose, except where law requires retention or limited retention is necessary for disputes, security, audit, or fraud prevention. Current details are:
| Location/category | Current period or method | Deletion or expiry |
|---|---|---|
| Local History | Up to 200 items; no uniform time-based TTL | Individual deletion, Delete All, or removal of older items when the limit is reached |
| Local Ogg audio | Retained only when Save History is enabled; no uniform time-based TTL | Deleted with the related History item, orphan cleanup, or Delete All |
| Insights, Dictionary, settings, some AI results | No uniform time-based TTL | Managed through the relevant local feature; deleting History does not necessarily remove an AI result referenced by Insights |
| macOS Keychain refresh token | While signed in or until replacement | Deleted on sign-out; third-party OAuth grants may require separate revocation |
| Real-time Session | Production currently processes the main session in process memory | Released with the process/container lifecycle; this does not establish simultaneous provider deletion |
| Redis hot state and idempotency | Defaults of approximately one hour and 15 minutes | TTL expiry; configuration may change |
| Account, session, 90-day Pro, credits, entitlements | Account duration and the period necessary for Services, law, and disputes | Account deletion and some database cascades; see Section 12 for scope limitations |
| Usage metering, quotas, voice traces, administration audit | Retained for the period needed to administer benefits and quotas, support reliability and security, conduct audits, and resolve disputes | Deleted, aggregated, or de-identified when no longer needed and not legally required |
| Docker service logs | Size-based rotation, currently approximately 25 MiB × 5 per container, not a fixed number of days | Rotation and overwrite; logs may contain an email or referrer and require further minimization |
| Backups | Database or environment backups may be created before deployments | Overwritten or deleted through normal backup rotation; deletion requirements apply again if a backup is restored |
| Sentry | Retained under project and provider settings for the period needed to diagnose errors or handle feedback | Deleted or anonymized under project settings, provider mechanisms, and applicable law |
| GA4 | Retained under Google control-panel settings for consented website analytics | Expired, deleted, or aggregated under Google settings and applicable law; withdrawal stops future controlled collection |
| Resend | Retained for the period needed to send transactional email, protect account security, and handle related requests | Deleted or restricted under provider mechanisms, ordinary email-record cycles, and applicable law |
| Contact and feedback | Period needed to handle the request, resolve the issue, and comply with law | Deleted or de-identified under the finalized support-retention schedule |
If a legally required retention period has not expired or deletion is temporarily technically infeasible, we will stop processing other than storage and necessary security protection and delete or anonymize the information when permitted.
12. Account and Data Deletion
You can use available account-deletion functionality or contact support@onesay.io. We may verify your identity to protect the account.
Current account deletion does not mean that every copy is deleted immediately and simultaneously:
- website account deletion does not automatically clear local History, Ogg, Insights, Dictionary, settings, or diagnostics on each installed device;
- some referral, entitlement, and account-linked tables support cascading deletion, but usage metering, voice traces, logs, backups, Sentry, GA4, Resend, and third-party OAuth grants have not been verified through a unified end-to-end deletion workflow;
- legal, financial, security, fraud-prevention, dispute, and audit requirements may permit or require limited records to be retained; and
- backup copies may remain until normal rotation and should be subject to renewed deletion controls if restored.
We will delete, anonymize, or restrict processing to the extent required by applicable law. Before deleting your account, clear local content on each device and revoke unneeded grants in Google or other third-party accounts if you want those items removed.
13. Your Rights and Choices
Depending on applicable law, you may have the right to:
- know and request an explanation of our processing rules;
- access, copy, or, where applicable, transfer personal information;
- correct or complete inaccurate or incomplete information;
- delete personal information or close your account;
- restrict or refuse certain processing;
- withdraw consent-based processing;
- refuse website analytics cookies;
- question or complain about decisions affecting your rights; and
- where legally available, permit close relatives to exercise relevant rights for a deceased user.
Existing product controls include managing or clearing local History, Dictionary, and Insights; disabling new History/Ogg storage; managing App Sentry; refusing or withdrawing website analytics consent; and editing certain account and preference information.
OneSay does not currently provide a single self-service export for all account, server-side usage, and trace data. Submit a request to support@onesay.io. We will verify identity, respond within the applicable period, and explain any request that cannot lawfully be fulfilled in full.
14. Security
OneSay applies reasonable technical and organizational measures appropriate to data type and risk. Current measures include HTTPS/WSS/TLS in transit, operating-system credential storage for refresh tokens on supported platforms, per-account separation of new-generation local data, restricted filesystem permissions, signed and notarized updates, sensitive analytics-field filtering, controlled diagnostics, and log rotation.
The released desktop application stores new-generation local data in ordinary SQLite databases separated by account. OneSay applies restricted filesystem permissions to the local-data root, account directories, SQLite/WAL/SHM files, account JSON, Ogg audio, diagnostics, and manifests. This local data is protected by the security boundary of your operating-system user account. OneSay does not claim that full-disk encryption such as FileVault or BitLocker is enabled on your device.
No internet transmission or electronic storage is completely secure. We do not claim that all OneSay data is end-to-end encrypted or encrypted at rest.
Protect your device and account, install trusted updates, and do not send support staff passwords, complete access tokens, or unrelated sensitive content.
If a personal-information security incident may affect your rights, we will take remedial measures and notify authorities and affected individuals to the extent required by law.
15. Automated Decisions and High-Impact Uses
The current audit found no dedicated OneSay module that makes employment, credit, insurance, medical, admissions, or other high-impact automated decisions about users.
AI-generated content may influence a decision you later make, but it is not verified or endorsed by OneSay. Do not use Output as the sole basis for medical, mental-health, legal, financial, tax, insurance, employment, admissions, safety, or other high-impact matters. If you cannot independently assess and verify information, do not use Ask. If you cannot reasonably assess output from OneSay’s other AI features, do not use OneSay.
16. Minors
OneSay is available only to individuals who are at least 18 years old. We do not knowingly provide accounts to or collect personal information from anyone under 18.
If you believe a person under 18 submitted personal information to OneSay, contact support@onesay.io. We will investigate and act as required by law.
17. Changes to This Policy
We may update this Policy because of changes to the product, technology, providers, law, or commercial status and will revise the “Last updated” date.
If a change materially affects your personal-information rights, we will provide prominent notice through the website, an in-app notice, your account email, or another reasonable method and obtain renewed consent where required. Changes generally will not apply retroactively.
18. Contact
To exercise personal-information rights or ask a question, submit a complaint, or provide a suggestion about this Policy, contact:
- Email: support@onesay.io
- Website: https://onesay.io
We may request information matching your request to verify identity, but we will not ask for your password or complete access token.
If the Chinese and English versions conflict, the Chinese version controls to the extent permitted by applicable law.