Lucy is designed so that your recordings never leave your device. This policy explains exactly what that means, what data (if any) is involved, and your rights.

1. What data Lucy collects

Lucy does not collect, transmit, or store any user data on external servers. All audio recordings, transcripts, and notes are stored exclusively on your device, in your device’s local app storage (sandboxed to Lucy).

Lucy does not require an account. Lucy uses no advertising networks and no advertising or marketing analytics: it does not build a profile of you, does not track you across apps or websites, and does not measure your usage for any commercial purpose. The only usage information it records is described in the next section — anonymous counts of what the app did, so that we can find where it fails.

To be explicit: no audio, no transcript, no summary, and no session metadata is ever sent to Xymex, to any third-party service, or to any cloud infrastructure operated by anyone.

The one exception: crash, performance and usage diagnostics

Lucy sends anonymous crash, performance and usage diagnostics to Sentry (Functional Software, Inc.), acting as our data processor, so that we can find and fix bugs and see where the app lets people down. This is the only data that leaves your device.

  • What is sent: the type of crash and the sequence of code that led to it; the app version, device model and OS version; timing measurements for slow operations; and anonymous usage events — for example that a recording was started, that a transcription finished or failed and why (as a category such as “low disk space”), which on-device model was downloaded, which export format was used, or that a purchase was completed for a given tier. Every value is a fixed category or a coarse range (such as “2–10 minutes”); free text is never sent.
  • What is never sent: your audio, transcripts, summaries, meeting or session names, speaker names, or the contents of any file. File paths inside your documents are redacted before sending, and interface labels — which in this app contain transcript text — are discarded entirely.
  • Not linked to you: reports carry no account, e-mail, device identifier or user ID; we create no install identifier, and IP address storage is disabled on both of our Sentry projects (iOS and macOS). Where a coarse country-level region is inferred at the moment a report arrives, we never use it to identify anyone and never combine it with other data. We hold nothing that lets us tie a report back to a person or a device.
  • Only from App Store and TestFlight builds, capped: at most 300 usage events are recorded per launch; development builds send nothing.
  • It cannot be turned off: these diagnostics are the single exception to Lucy’s on-device rule, and they are what makes it possible to fix bugs that would otherwise be invisible. Settings › Privacy & Data › Crash reports describes exactly what is sent.

The App Store privacy label for Lucy reads Diagnostics — Crash Data, Performance Data and Other Diagnostic Data; Usage Data — Product Interaction; all Not Linked to You, and states that this data is not used for tracking. That label is cross-checked by Apple against actual app behavior.

2. How AI model downloads work

To provide transcription features, Lucy downloads AI model files from Argmax’s distribution network (hosted on huggingface.co) on first launch. The download size is approximately 600 MB to 1.6 GB depending on which models you select.

This download is a one-way file transfer to your device. No audio, no transcript, no personal information, and no usage data is transmitted to Argmax, HuggingFace, or any other party during or after this download. Your device makes an outbound HTTPS request to a content delivery network (CDN) to fetch the model file — the same mechanism used by every app that fetches an image or file from the internet. The CDN delivers the file. No user data travels in the other direction.

After the model is downloaded, all transcription processing runs locally. No further network requests related to transcription are made.

3. Microphone access

Lucy requests microphone access (the NSMicrophoneUsageDescription permission) to record audio sessions. Microphone access is only used when you actively start a recording inside the app. The iOS system recording indicator (the orange dot in the status bar) is always visible when Lucy is recording — this is enforced at the operating system level and cannot be suppressed.

Audio is processed entirely on your device and is never transmitted to any external server. When you delete a session, the audio file is deleted from your device’s local storage.

4. Data retention and deletion

All data — recordings, transcripts, and notes — is stored locally on your device in Lucy’s sandboxed app storage. You can delete any session at any time from the app’s session library. The delete action is immediate and permanent; there is no server-side backup to recover from.

Deleting the Lucy app from your device removes all data stored by Lucy, including recordings, transcripts, and preferences. Lucy has no access to your data once the app is deleted.

Downloaded AI model files are stored in Lucy’s local storage. You can delete downloaded models from Lucy’s Settings screen to free up storage space. Models can be re-downloaded at any time over Wi-Fi.

5. At-rest encryption for locked sessions

Lucy includes an optional session-lock feature. When you lock a session, the transcript and audio file are envelope-encrypted at rest using a key that is bound to your device’s biometric enclave (Face ID or Touch ID) via the iOS Secure Enclave.

What this means in practice:

  • A locked session’s transcript and audio cannot be read without biometric authentication on your device.
  • The encryption key never leaves the Secure Enclave and is never transmitted to Xymex or any third party.
  • There is no recovery path. If biometric authentication is permanently unavailable on your device, a locked session cannot be decrypted. Keep unlocked backups of any session you cannot afford to lose.
  • Unlocked sessions are stored in sandboxed local app storage as described in Section 4. Encryption is an additional layer you opt into per session — it is not applied by default.

This feature is entirely local. No key material, no encrypted data, and no metadata about locked sessions is ever transmitted off your device.

6. Third-party open-source libraries

Lucy is built using the following open-source libraries. None of these libraries transmit data off your device when used inside Lucy:

  • WhisperKit by Argmax, Inc. (Apache 2.0 license) — on-device speech transcription. github.com/argmaxinc/WhisperKit
  • FluidAudio (open-source) — on-device speaker diarization (voice attribution). All processing is local.
  • MLX Swift by Apple (Apache 2.0 license) — on-device machine learning inference framework for Apple Silicon. No data leaves the device.

Apart from the Sentry diagnostics described in section 1, Lucy does not integrate advertising SDKs, analytics platforms, or any other service that collects or transmits user data.

7. Children’s privacy

Lucy is a professional tool designed for adults. It is not directed at children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal data from children. Because Lucy collects no data at all, this risk is structurally absent — but we state it explicitly for completeness.

8. Contact and policy updates

For privacy questions or data deletion requests (though Lucy has no server-side data to delete), contact us at:

support@xymex.com

We will notify users of any material changes to this policy via an in-app notice in the next app update. This policy was last updated on September 6, 2026.