Privacy Policy
Mates Rates Services Pty Ltd · Last updated 5 September 2026
The short version: you choose how contextual replies are prepared. Private mode uses Apple Foundation Models on your Mac and uploads no reply context. Best quality mode sends only a bounded visible-thread packet and selected facts to Chalked and Anthropic Claude after you turn it on. Dictation is a separate path: audio is processed in transit by a named transcription provider under a zero-retention agreement, and its transcript is processed without retention. Your cards are encrypted on your device before they sync, so we can't read them. Chalked inserts drafts for review and never sends on your behalf.
What we process, and what we keep
- Contextual reply text — Private mode processes the bounded visible conversation and draft on your Mac with Apple Foundation Models. Best quality mode sends that bounded packet, plus only the selected verified facts and sourced evidence, to Chalked and Anthropic Claude. It does not send a screenshot, raw Accessibility tree, window title, contact identifier, conversation identity or full message history. Best quality mode is off until you enable it, can be turned off in Settings, and neither mode silently falls back to the other. Reply content is never sent to analytics.
- Local conversation identity — a random salt and salted one-way hashes of recent speaker/text turns help Chalked avoid merging same-named conversations. The sidecar contains no name or message text, never syncs, and can be deleted in Settings.
- Voice audio — streamed from your device directly to AssemblyAI for transcription, processed in transit, never stored by us or retained by them (zero-retention agreement).
- Dictation transcripts — sent to our server and a named model provider to clean up your dictation and check whether you made a commitment, then discarded. Not stored.
- Card source text — when a card is made, Chalked reads the app you're dictating into and the conversation in the focused window, through macOS Accessibility. Never screenshots, never screen recording. The source text attached to that card stays on your Mac. Only the app name, the window or thread name and a link back travel with the encrypted card. This is separate from the bounded packet used when you enable Best quality replies.
- Your cards — the promise, the next step, the due date and where it came from. Encrypted on your device (AES-256-GCM, with a key held in your iCloud Keychain) before they sync between your devices through us. We store the encrypted blob and cannot read it.
- Calendar data — when you enable calendar grounding, Chalked uses fresh free/busy windows and does not give event titles to the reply model. Apple Calendar is read locally. Google Calendar requests pass through our server to your authorised Google account.
- Account data — an anonymous device identifier; your email only if you choose to sign in by email, Apple or Google.
- Usage analytics — counts and durations of feature use (via PostHog). Never the content of anything you say or type.
Who touches your data
AssemblyAI (transcription, in transit, zero retention) · Vercel (hosting, Sydney) · Neon (database, Sydney) · AI Gateway model providers (dictation cleanup and detection, zero-retention routing) · PostHog (usage analytics) · Apple and Google (sign-in and authorised calendar access). Apple Foundation Models prepares Private-mode replies on your Mac. Anthropic Claude receives the bounded packet only when you enable Best quality replies. We never sell data, and nothing is shared for advertising or tracking.
Permissions on the Mac
Chalked needs Accessibility so the fn key works everywhere, it can insert text and, when contextual replies are enabled, it can read a bounded conversation in a supported foreground app. It uses the Accessibility UI tree, not screenshots or screen recording, and does not log keystrokes. Password fields and anything protected by Secure Input are skipped. You can turn contextual replies off, exclude each supported app, or turn commitment and source capture off in Settings. You can switch Best quality replies off to withdraw cloud-reply consent. Microphone access is used only when you choose voice. Calendar access is optional. Full Disk Access is optional and used only for the sent-message history importer you enable separately.
Your controls
Calendar writes go only to Chalked's own calendar or to the Google calendar you explicitly authorise; your existing events are not modified by reply preparation. Rubbing out a card removes its local source text and any Chalked calendar hold linked to it. You can forget the local salted conversation identities in Settings without deleting messages or cards. Handing a card to an AI opens it in front of you; Chalked never sends anything on your behalf. Revoke calendar, Accessibility, microphone or Full Disk Access in System Settings at any time, disconnect Google Calendar in Chalked, and contact us to delete your account data entirely.