1. Hypervibe
  2. Privacy Policy

What stays on your Mac, and what leaves it.

Hypervibe is a local-first desktop application operated by Lucio Sianca, LLC ("Hypervibe", "we", or "us"), the controller of the account and service data described here. Contact: contact@hypervibe.so. This policy explains what data the app handles on your Mac, what reaches our servers and the services behind them, what we keep and for how long. Plain language, no surprises.

Stays on your Mac

  • Microphone audiotranscribed on-device
  • Your repositories and coderead locally
  • Workspaces, memory, loops, preferenceslocal files
  • Cache of spoken replieslocal, clearable

Leaves your Mac

  • Sign-inFirebase Authentication
  • Planner command and board snapshotour gateway, then Groq
  • Text of the replies the app speaksour gateway, then Inworld
  • Account and usage identifiersour gateway
  • PaymentPaddle

1. Summary

Your microphone audio, your repositories and your agent sessions stay on your machine. Four things leave it: your sign-in, which goes through Firebase Authentication; the commands you give the planner, together with a snapshot of your board, which our planner service sends to a hosted model to turn into a plan; the short lines the app speaks back to you, which our gateway sends as text to Inworld to generate the audio; and your payment, which Paddle processes as our merchant of record. Our gateway verifies your account and counts usage against its subscription. Device and request identifiers also support session security and duplicate-request prevention. We do not run analytics or telemetry inside the app.

2. Data Hypervibe processes on your Mac

To do its job, the app handles the following locally:

  • Your voice. The current Mac release transcribes microphone audio locally using Parakeet, an on-device speech model downloaded on first use from Hugging Face. We do not receive your microphone audio, and the current release does not send it to an Apple Speech or Whisper fallback. The transcribed commands you send to the hosted planner are treated as described below.
  • Spoken replies. The audio the app plays back is generated by our voice service, described in section 3, and cached on your Mac so a line that was generated once replays without a new request. The cache lives in the app's Application Support folder, is limited to 100 MiB per account, drops entries unused for 30 days, and can be cleared from Settings.
  • Source code. The agent CLIs you connect run as real terminals on your machine. The app reads the repos you open to build the studios, project memory and previews.
  • Session state. Workspaces, console layouts, memory, loops and preferences are stored on your local disk as files you can inspect and delete.

3. Data that reaches us

  • Account. When you sign in with Google or email and password, Firebase Authentication (a Google service) manages your identity, verification, recovery and secure session. The web and Mac use the same Firebase account UID but maintain separate sessions. We receive your UID, email, verification state and available profile details. Billing ownership uses the verified UID, not a matching email. An avatar selected on your Mac stays local; this account does not synchronize boards or files.
  • Sessions and usage. The gateway uses your verified Firebase UID, service session and request identifiers to authorize access, enforce the shared credit allowance and avoid billing a repeated request twice. Older service routes may also use a salted device identifier. These identifiers are not your files or microphone audio.
  • Planner commands. When you give the planner a spoken or typed command, the app sends our planner service the text of the command and its language, plus a snapshot of your board: the names, types, roles, activity and current orders of your consoles; groups and their members; recent orders and their status; the repo folder name, workspace names, selection, zoom, active tool, open panel, figure counts and the names and states of loops; up to 60 relative paths of Markdown files; and the last eight messages of the orchestrator thread, with your turns trimmed to 220 characters and agent reports to a 140-character excerpt. Our service forwards this to Groq, which runs OpenAI's gpt-oss-120b model, and returns a plan as prepared prompts that wait for your Enter. Microphone audio is never sent, and file contents are not attached. But the command, the recent messages and the agent excerpts inside them can contain code or other information you or an agent wrote, so treat the planner like any hosted model.
  • Spoken replies. When the app confirms a command or narrates a mission out loud, it sends our gateway the text of that line (at most 500 characters), its language, the chosen voice and a request identifier. Our gateway forwards the text, voice and language to Inworld, which generates the audio with its TTS-2 Flash model and streams it back through our gateway to the app. Generated audio, including audio containing your words or console names, can be cached for five minutes on our server, scoped to your account and a hash of the request. It is not shared with other accounts. Older voice routes may share only predefined generic audio with no user content. Inworld receives text only: it never receives your microphone audio or your transcripts.
  • Billing. If you subscribe, Paddle processes your payment details, name, email and billing address as merchant of record. Our server stores your Firebase UID association with Paddle customer, transaction, subscription and adjustment identifiers, paid periods and signed billing notifications in Upstash. These records support access verification, accounting and recovery from missed notifications. Card details stay in Paddle checkout; we never receive full card numbers. Billing portal links are temporary and are not stored by our application.
  • Contact. If you email us, we receive the address and message you provide.
  • Website. hypervibe.so is hosted on Vercel and uses Vercel Web Analytics to count visits. It uses aggregated measurements without analytics cookies. Measurements may include the page path, referrer, browser, device and approximate country. We remove query strings and fragments from analytics URLs and do not send account, checkout or email-action events to public analytics. Hosting and security services also process request metadata such as IP addresses. Authentication uses browser storage to keep you signed in; that is separate from analytics.

4. Services we rely on

  • Firebase Authentication (Google LLC) for sign-in.
  • Paddle (the Paddle entity identified in your checkout and receipt) as merchant of record for checkout, invoicing, taxes and the customer portal.
  • Vercel for hosting the website, its cookieless analytics, and the gateway behind the planner and the spoken replies.
  • Upstash (hosted Redis) for server-only billing ownership, paid periods and notification history, in addition to the gateway's usage counters, short-lived planner response cache and account-scoped generated audio cache.
  • Groq (Groq, Inc.) running OpenAI's gpt-oss-120b model behind our planner service, which receives your planner commands and board snapshot as described above. The current release uses the included service rather than personal Groq or Cerebras keys.
  • Inworld (Inworld AI) generating the audio of the spoken replies from the text our gateway sends, with its TTS-2 Flash model.
  • Hugging Face as the download source of the on-device speech models.

These providers process data to supply their services; Paddle also processes billing information as merchant of record. See Firebase, Paddle, Vercel, Upstash, Groq, Inworld and Hugging Face for their privacy information. Provider retention may differ from the short caches we operate. Data may be processed in the United States and other countries where these providers operate. Contact us for information about the transfer arrangements applicable to your data; mandatory international-transfer protections continue to apply.

5. Third-party coding agents

Hypervibe orchestrates agents you connect, such as Claude Code or Codex. Those agents are independent software and send your prompts or code to their own providers under their own policies and under your own account with them. Hypervibe surfaces which agents are active, but it does not control their network behavior. Review the privacy terms of each agent you use.

6. How we use what we receive

Account, device, planner, voice, billing and contact data is used solely to sign you in, produce your plans, generate the spoken replies, count usage against the limits of your subscription, deliver the product, fulfill purchases and answer you. Hypervibe does not use this data to train models; processing by model providers is subject to their service terms. We do not sell data, and we do not share it for advertising.

7. Storage, security and retention

Local data lives in your Mac's standard application support directory and is protected by your device's security. Firebase manages account sessions. Billing records and original signed notifications are retained server-side for account operation, recovery and applicable accounting requirements; they are not automatically deleted when you sign out or uninstall. Access and deletion requests are reviewed separately from subscription cancellation. Secret keys and payment portal URLs are not included in our application logs.

On our gateway:

  • Planner. The command and the board snapshot are not stored. The gateway keeps a hash of the request, under which the model's response is cached for five minutes so a repeated command costs nothing. Each cached response is scoped to your account and a hash of the request. It is not shared with other accounts.
  • Spoken replies. The text of a line is not stored. In the account-based service, generated audio may be cached on our servers for five minutes, scoped to your account and a hash of the request. It is not shared with other accounts. The app also caches audio locally. Usage records contain character counts, cost, timestamps and an account identifier, without the spoken text. Account usage records and counters are retained for service operation; older voice-service records expire after 90 days.
  • Usage counters. Credit balances, character counts and spend totals are kept per account and subscription period. They currently have no automatic expiry. We review them on account-deletion requests and retain only what is necessary for account operation, fraud prevention, disputes or applicable recordkeeping obligations; cancellation alone does not delete them. Short-lived rate-limit counters expire within days.
  • Logs. Our gateway logs counts, latency, outcomes and an account identifier for each request, never the command, the board or the spoken text. Those logs are held by Vercel under its log retention.

What Groq and Inworld retain of the text they receive is governed by their own policies.

8. Your rights

Write to contact@hypervibe.so to request access, correction or deletion. Depending on your location, you may also have rights to portability, restriction, objection, withdrawal of consent and a complaint to your local data-protection authority. We may ask for reasonable proof that the account is yours; never send us your password or full card details. We respond within the time required by applicable law and explain any records we must retain. Subscription cancellation and data deletion are separate requests.

Removing the app from Applications does not remove its Application Support files, preferences or Keychain entries. Your repositories remain wherever you saved them under your macOS user. Local workspaces belong to that macOS profile and are not a cloud repository account: another person using the same unlocked macOS profile can access its local files. Use separate macOS users for separate people. You can clear spoken-reply caches in Settings and contact us for help removing Hypervibe local data without deleting your projects.

9. Children

Hypervibe is a developer tool and is not directed at anyone under 16.

10. Changes

We may update this policy as the product evolves. Changes are identified by the effective date above. We provide any additional notice or obtain consent required by applicable law before a material change takes effect.

11. Contact

Questions about privacy: contact@hypervibe.so.