The Privacy Ledger, explained
The Privacy Ledger is a list, kept by the app, of every network request it has ever made: when, to which host, how many bytes, and why. It exists so that “nothing leaves your machine” is something you can check rather than something you take our word for.
What a normal ledger looks like
On the default setup, with a local model for notes and update checks on:
2026-09-02 media.recordist.app 0.2 KB update check (version, platform)
2026-09-02 whisper.cpp release mirror - model download: large-v3-turbo (fetched, nothing sent)
2026-09-02 github.com - download: notes engine runtime (fetched, nothing sent)
2026-09-02 registry.ollama.ai - download: notes model Qwen2.5 1.5B (fetched, nothing sent)
2026-09-02 media.recordist.app 0.2 KB update check (version, platform)
The update check repeats at launch and every six hours while the app runs. Turn off update checks and, after the three downloads, nothing further is added. Audio is never on this list, because there is no code path that uploads it.
With a cloud key
If you use Anthropic or an OpenAI-compatible provider, each generation adds a line:
2026-09-16 api.anthropic.com 41.2 KB notes: "Pricing sync" (transcript + template)
That is the transcript text of one meeting and your template, nothing else. Delete the provider and the lines stop.
What it does not include
Traffic between the app and things on your own machine: the local model, and the AI assistants you connect. Those never leave the machine. Where an assistant you connected sends what it read is that assistant’s business; the ledger only covers Recordist.
Exporting it
Settings → Privacy → Export ledger writes JSON. It is also included in Export all, and it is part of the database, so it moves with you to a new Mac.
Check it against the Trust Center
The public version of this table, with every possible request explained, is on the Trust Center. If you see a host in your ledger that is not on that page, that is a bug; report it to [email protected].