Skip to content

Security

The technical companion to the Privacy Policy. It says exactly what Lip can access on your Mac, what it stores, every connection it can make, and how to check all of it yourself rather than take it on faith.

Last updated 2026-10-05.

Permissions

Lip asks for two permissions, and each exists for one narrow reason.

Accessibility. Lip uses the Accessibility API to insert transcribed text at your cursor, in whatever app is frontmost (the same effect as if you'd typed it yourself). It does not use this access to read your screen, log your keystrokes, or observe what's happening in other apps. It's a write path, not a read path.

Microphone. Lip captures audio only while you're holding the trigger key. It does not listen in the background, and it never records to a file: the audio is transcribed in memory and discarded the instant the text lands in your cursor.

What's on disk

Everything Lip keeps lives inside its own Application Support folder and its own preferences. Nothing is written anywhere else on your Mac, and your audio is never written at all — not even to a temporary file.

The Whisper model used for transcription. Your personal dictionary, which biases transcription toward the names and jargon you've taught it. Your snippets. Counters of how much you dictate, which are what the Insights page draws and which never leave the machine. A marker recording when your trial started, kept in both the Keychain and Application Support. A diagnostic log, which records what Lip did but never what you said — transcripts are redacted before anything is written. And the licence blob: a small signed file at ~/Library/Application Support/Lip/licence that records your entitlement.

That licence blob is deliberately not your licence key. It's a signed statement (this device, this email, this version ceiling) that Lip's activation server produced once and that Lip can verify locally forever after. Reading the file off disk doesn't hand anyone your key, and it isn't useful on a different Mac.

Signing and notarization

Lip is signed with a Developer ID certificate and notarized by Apple, the same requirements any Mac app distributed outside the App Store has to meet.

Gatekeeper checks the code signature before the app is allowed to run at all: that it's actually signed, that it hasn't been altered since signing, and that Apple's automated scan found nothing it flags as malicious. An unsigned or unnotarized build simply won't launch; Gatekeeper blocks it before you ever see a permission prompt.

Verify it yourself

Lip is not a no-network app, and this page is not going to tell you it is. It makes two connections and no others: it fetches model weights from huggingface.co if you pick a model that isn't the bundled one, and it contacts our activation server once when you enter a licence key. What never travels is your audio, your transcripts and your usage data — and that is the claim worth checking, because it is the one that matters.

Check it at the moment it counts. Start dictating, and while you are still holding the key, run:

lsof -i -a -p $(pgrep -x Lip)   # while dictating: no open connections

lsof -i lists every open network connection belonging to a process. Run against Lip mid-dictation it prints nothing at all, because transcription is happening on your Mac against weights already on your disk. There is no request in flight to inspect, no endpoint to point at, and nothing queued to send later. Run it again while a model is downloading and you will see exactly one connection, to huggingface.co — which is the point: the connections Lip makes are the two named above, and they are visible when they happen.

Activation is deliberately kept out of the main binary. It runs in a separate helper program bundled inside the app, which Lip launches only when you activate a key and talks to over a local pipe rather than by sharing code, so the licensing path cannot reach anything else the app is doing. See /support for how activation and licence recovery actually work, and /privacy for exactly what that one request carries.

Reporting an issue

Security issues, or anything that looks like one, go to support@mylittletools.in. Include your Lip version and macOS version, and what you observed: there's no bug tracker or account to sign into first.

Every report gets a reply directly from a person working on Lip, not a ticket queue.