Security and architecture
There is no cloud to trust. There is no cloud.
Most privacy claims are policies. This one is an architecture. Here's exactly how it works, so you don't have to take our word for it.
What “local-first” actually means here
Safeclip runs Whisper and a local language model directly on your device. Your audio is captured, transcribed, summarized, and clipped entirely on your own hardware. Nothing is ever uploaded, streamed, or transmitted to a Safeclip server or any third party, at any point in that pipeline. This isn't a setting you can misconfigure. It's the only way the app works.
The only data that ever leaves
- Account or installation identifier
- App version number
- Update channel
What never leaves your device
- Audio or video data
- Transcripts or text content
- Recording metadata
- Filenames or file paths
How this compares
Most AI note-taking tools, including well-funded ones with strong reputations, capture audio locally but store the transcript in the cloud. Some route your audio through a private inference API instead of storing it. Both of those are meaningfully better than fully cloud-native tools, but both still involve a server somewhere holding your words. Safeclip has no such server for your content. It's a different category, not a more careful version of the same category.
What this means in practice
- No BAA required for regulated professionals, because nothing protected is transmitted.
- No data breach surface for your recordings, because there’s no database to breach.
- No policy to change on you later, because there’s no server-side retention decision to make.
- Works with no internet connection at all, because it was never designed to need one.
The trade
Every tool here involves trade-offs. Here is ours, plainly.
| Safeclip | Cloud notesGranola, Otter, Fireflies | Therapy scribesMentalyc, Upheal, Blueprint | |
|---|---|---|---|
| Where the recording lives | On your machine. Never uploaded. | Their servers. | Their servers. |
| Who can read it | You. We couldn’t access it if we wanted to. | The vendor, and whoever they process with. | The vendor, and whoever they process with. |
| Joins the meeting for you | No. You start the recording yourself via the menu bar or in-app. This is the trade. | Usually yes: a bot or desktop agent. | Usually yes: a bot or dedicated recorder. |
| Clinical notes / EHR | SOAP/DAP draft, on-device (Founding License). You paste it into whichever system you already use. Not a chart replacement. | Meeting notes. Not clinical. | Session notes aimed at documentation. Closer to the chart, still not the EHR. |
| Clip or audiogram on disk | Yes. Waveform file and captions saved locally. | Not the focus, or a cloud render. | No. |
Where the recording lives
- Safeclip
- On your machine. Never uploaded.
- Cloud notes
- Their servers.
- Therapy scribes
- Their servers.
Who can read it
- Safeclip
- You. We couldn’t access it if we wanted to.
- Cloud notes
- The vendor, and whoever they process with.
- Therapy scribes
- The vendor, and whoever they process with.
Joins the meeting for you
- Safeclip
- No. You start the recording yourself via the menu bar or in-app. This is the trade.
- Cloud notes
- Usually yes: a bot or desktop agent.
- Therapy scribes
- Usually yes: a bot or dedicated recorder.
Clinical notes / EHR
- Safeclip
- SOAP/DAP draft, on-device (Founding License). You paste it into whichever system you already use. Not a chart replacement.
- Cloud notes
- Meeting notes. Not clinical.
- Therapy scribes
- Session notes aimed at documentation. Closer to the chart, still not the EHR.
Clip or audiogram on disk
- Safeclip
- Yes. Waveform file and captions saved locally.
- Cloud notes
- Not the focus, or a cloud render.
- Therapy scribes
- No.