Security and privacy

Useful assistance needs clear boundaries.

A plain-language overview of what the current beta processes, what it retains, which providers are involved, and where its protection claims stop.

Default retentionRaw audio is streamed, not recorded by the app.

Transcript and answer text remain in current-session memory by default.

macOS first evidence-grounded user-controlled permitted use only

Lyrebird processes sensitive interview context. The product therefore separates selected audio, transient transcript and answer content, locally stored preparation material, and account or billing records.

This page summarizes the current implementation for the controlled beta. The complete legal descriptions remain in the privacy, terms, security, and permitted-use page.

Data flow by purpose

Selected audio is sent to Deepgram for streaming transcription. Transcript or typed questions, answer controls, and optional labeled evidence are sent to OpenAI for response generation. Supabase supports authentication, metering, aggregate reliability reports, and account controls. Stripe is sandbox-only.

  • Raw audio: streamed for transcription; not recorded by the app.
  • Transcript and answers: current-process memory by default.
  • Résumé, role, and evidence: stored locally until cleared.
  • Coding screenshot: sent only after a user action in the relevant mode.
  • Account export and deletion: available to authenticated users.

Protection is not invisibility

The desktop app includes visibility controls and best-effort content protection for supported capture paths. It does not promise protection from external cameras, all monitoring software, proctoring, policy controls, or unsupported screen-capture methods.

Responsible disclosure

A public security inbox has not yet been established. Until it exists, avoid sending secrets, interview content, provider keys, or personal records through an unverified channel. The contact page will be updated when a dedicated route is available.

Questions, answered plainly.

Does Lyrebird store recordings?

The current app does not record raw audio. Selected audio is streamed for transcription.

Can I delete my account data?

Authenticated users have export and permanent deletion paths. Deletion removes the sandbox Stripe customer and subscription, licenses, and Supabase identity.

Are API keys stored in the browser?

Provider secrets belong on trusted backend or native boundaries. Signed-out BYO keys are kept in app memory rather than browser local storage.

Bring the experience. Find the words.

Explore the working demonstration and see how Lyrebird shapes a clearer place to begin without upgrading the evidence.

Try the demo →