Privacy Policy
What Fluent does with your data.
Fluent listens to your microphone and reads your screen. That makes this policy unusually important, so it is written to be read rather than to be defensible.
- 9 minute policy
- Last reviewed
- Effective August 18, 2026
- Speech is transcribed on your device
- Contact: privacy@fluentforall.com
What does Fluent collect, and what leaves my computer?
Speech recognition, dictation, text-to-speech, hotkeys and screen-reader navigation run entirely on your device: they need no account and send us nothing. Only an AI agent run transmits anything, because that is where the reasoning happens, and what it sends is your instruction plus the accessibility tree of the focused window, falling back to a masked screenshot only when the accessibility tree is not enough. We do not sell your data, ever, to anyone. Product analytics are off until you switch them on, and are anonymous when you do. Fluent can also be pointed at a model endpoint on your own machine or network, in which case no screen content or speech leaves your premises at all.
What never leaves your computer
Speech recognition, dictation, text-to-speech, hotkeys and screen-reader navigation run on your device. They do not require an account and they do not send anything to us.
Audio captured for speech recognition, the Windows accessibility tree, window titles, your settings and the local activity log all stay on your computer. Uninstalling Fluent removes them.
What is sent, and only during an agent run
When you ask Fluent to do something rather than type something, it sends a model what it needs to plan the next step. This is the only feature that transmits your screen or your words off the device.
- Your instruction, on every agent run: the words you spoke or typed.
- The accessibility tree of the focused window on most runs: control names, roles and structure. It is preferred over screenshots because it is cheaper, more reliable and smaller.
- A screenshot, only when the accessibility tree is insufficient, and only after masking.
- Tool results during a run: what happened after each step.
A screenshot that cannot be masked is discarded rather than sent
Before any screenshot leaves your device, Fluent plans masked regions from the OCR word rectangles in that same image and from the accessibility bounds of fields whose label marks their contents as sensitive, then paints over them.
If masking cannot be completed, the screenshot is discarded and the run continues on the accessibility tree instead. We do not send the unmasked image.
Masking is a risk-reduction measure and not de-identification. No automated detector reliably finds a personal name. Do not rely on it as a compliance control.
Account, billing, analytics and stored credentials
For an account we hold your email address, your subscription status and an opaque licence identifier. Card details go directly to Stripe and are never seen or stored by us. A licence token deliberately contains no email, no name and no machine fingerprint.
Product analytics inside the Windows app are disabled by default. If you turn them on, we receive a fixed, closed list of product events with an install identifier that is random and unrelated to your machine or your operating system account. Free text cannot be sent: every value is filtered to short identifier-shaped tokens, numbers or booleans, so a window title or a transcript line is rejected on its shape rather than on somebody remembering to think about it. The app uses no third-party analytics SDK and no crash reporter. Withdrawing consent rotates the install identifier, and analytics are unavailable entirely in HIPAA mode.
This website is measured separately and does use PostHog. Page views and deliberate clicks are counted for every visitor, and by default nothing is written to your device to do it: the identifier lives in memory and is gone when you close the tab, so a second visit cannot be recognised as the same person. Accepting on the notice stores that identifier in your browser instead, which is the only thing the notice changes. Nothing is collected at all if your browser sends Do Not Track or Global Privacy Control, and your IP address is not sent as a property. Session replay is disabled, so no recording of your screen is ever made. Autocapture is disabled too, which is the setting that would otherwise record the text of everything you click; what is recorded instead is a fixed list of deliberate events, plus click and scroll positions with no element or text attached.
Passwords you save to Fluent's vault are sealed using the Windows credential store. There is no API that reads them back: Fluent can type a secret into a login form but cannot return it to a model, a log, a transcript or a tool result. If the credential store is unavailable, saving is refused rather than falling back to plaintext.
When you contact support
We process what is needed to answer you: your email address, your name if you give it, your message, the topic, the impact, your reply preference, optional callback details, and basic source and app-version context. The support form sends this through Vercel and Resend to a private Google Workspace inbox.
The abuse control on that form stores only a server-keyed hash of the request address and a count in Supabase, never the message itself, and expires that record after 24 hours.
The support form does not accept attachments. Do not include patient or health information, passwords, API keys, payment card numbers, screen captures or confidential files.
Who else receives data, and how to avoid all of them
The Evidence status tab on this page lists every current subprocessor, what it is for, and what reaches it. That list is the authoritative one, and we will update it before adding a recipient.
You can avoid all of them. Fluent can be configured to use a model endpoint on your own machine or your own network, in which case no screen content and no speech leaves your premises. This is how it is intended to be deployed in clinical settings.
Health information
Fluent is used on clinical workstations. Where we process protected health information on behalf of a covered entity or a business associate, we do so only under a signed Business Associate Agreement, and only in a configuration whose model inference stays inside the customer network.
Without a BAA in place, do not use hosted inference on a workstation displaying patient information. We cannot lawfully receive that data, and HIPAA mode exists so that you do not have to.
Logs and audit records
Fluent keeps a local, tamper-evident audit record of what it did. Values pass through a redaction step before being written. As with masking, this is defence in depth rather than de-identification, and it is not HIPAA Safe Harbor.
Audit records stay on your device unless you export them.
How long each kind of record is kept
Most of what Fluent processes never reaches us at all, so most of this list describes something already on your own computer.
- Model requests: not retained by us. The provider you configured governs its own retention through its terms.
- Gateway usage counters: 60 days, and only a device identifier and integers.
- Account and billing: the life of the account, then as long as tax law requires.
- Analytics events: 24 months.
- Support conversations: 24 months, unless law, a dispute or a security investigation requires longer.
- Support-form abuse hashes: 24 hours.
- Local logs and audit records: on your device, until you delete them.
Your rights, and transfers out of your country
Depending on where you live, you may have rights to access, correct, delete, port or object to the processing of your personal data, and to withdraw consent. Email privacy@fluentforall.com. We will not charge you for exercising them and will not degrade your service because you did. Because most of what Fluent processes never reaches us, an access request will often be answered by pointing you at data already on your own machine.
We are a US entity, our founder and operations are in Singapore, and our subprocessors operate in the United States and China. If you are in the UK or the EEA, transfers rely on the Standard Contractual Clauses. If your data cannot lawfully leave a jurisdiction, use the on-premises inference configuration — that is what it is for.
Fluent is not directed at children under 13 and we do not knowingly collect their data.
Changes, and the accessibility of this policy
We will post changes here and, for anything that materially widens what we collect, notify you in the app before it takes effect. The effective date at the top of this page is revised when an update is published.
If any part of this document is inaccessible to you, email privacy@fluentforall.com and we will provide it in a format that works. That is not a courtesy: this is an assistive product, and a policy you cannot read is not a policy you agreed to.
| Recipient | Purpose | What reaches it |
|---|---|---|
| DeepSeek | Agent planning | Your instruction, the accessibility tree, and tool results |
| OpenAI | Screenshot interpretation | Masked screenshots only |
| Stripe | Payments | Email and billing details. Card numbers go to Stripe directly and are never seen or stored by us |
| Railway | Gateway hosting | Requests in transit |
| Vercel | Website and support-form hosting | Contact details, message, reply preference, and callback details |
| Resend | Support-form email delivery | Contact details, message, reply preference, and callback details |
| Google Workspace | Private support inbox | Support conversations and contact details |
| Supabase | Support-form abuse prevention | A server-keyed hash of the request address, a request count, and an expiry time. Never the message |
| PostHog | Optional analytics on this website only | Page views, intentional link and button events, campaign attribution, browser and device metadata, click and scroll positions, page performance timings, JavaScript errors, and the accessibility preferences your browser advertises to every website (reduced motion, high contrast, colour scheme, pointer type). No identifier is stored on your device unless you accept, and nothing at all is collected if your browser sends Do Not Track or Global Privacy Control |
Questions
Does Fluent send my microphone audio to the cloud?
No. Command audio is transcribed on the Windows device and no cloud speech service receives the recording. What can leave the device is the resulting text, and only during an agent run.
Can I use Fluent without anything leaving my network?
Yes. Point Fluent at a model endpoint on your own machine or inside your own network. Loopback and on-premises inference are not egress, and no screen content or speech leaves your premises in that configuration.
Do you sell my data?
No. Not to anyone, in any circumstance. There is no advertising business here to sell it to.
How do I exercise a data right, or ask a question about this policy?
Email privacy@fluentforall.com. Exercising a right costs you nothing and will not degrade your service. For an access request, expect us to point you at data already on your own machine, because that is where most of it is.
Keep reading
- What do these terms cover?These terms explain the rules, responsibilities, and limits that apply when you use Fluent and its connected services.
- Can voice control be used on a workstation that displays PHI?The interesting question is not what the software can do. It is what it refuses to send, and whether you can prove it afterwards.
Sources
- Fluent Privacy and Safety — The input-by-input evidence record this policy is the binding form of.
- Clinical deployment and HIPAA mode — The configuration that keeps inference inside a hospital network.
- Terms of Service — The terms this policy sits alongside.
- Privacy contact — Data rights requests and questions about this policy.
Fluent For All, Inc. · Last reviewed