InkSpoke
FeaturesUse casesCompareGuidesBlogPricing
Sign inDownload ↓
Privacy

Privacy policy.

The short version: we built InkSpoke offline-first so the vast majority of your usage never touches our servers.

Last updated · July 27, 2026

PMT Labs, LLC ("PMT Labs", "we", "us", or "our") operates the InkSpoke desktop, mobile, and web applications (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. We respect your privacy and have built InkSpoke around an offline-first model so the vast majority of your usage never touches our servers.

1. Information You Provide Directly

We collect information you give us when you create an account or contact us:

  • Account information: email address and a hashed password (Argon2id). We never store passwords in plaintext.
  • Profile information you choose to add: display name and avatar (optional).
  • Communications: the contents of messages you send us through support channels.

2. Information Processed Locally on Your Device

By default, InkSpoke processes audio and transcription on your device. The following data never leaves your device unless you explicitly enable a feature that requires it:

  • Audio recordings captured for transcription.
  • Transcripts produced by the local speech-to-text engine.
  • Custom dictionaries, vocabulary, and command definitions.
  • Wake-word audio captures used for local detection.

3. Information Processed When You Enable Cloud Features

Some optional features require sending data outside your device. We tell you at the point of opt-in and you can disable them at any time:

  • Cross-device sync: we store your workspaces, entries, dictionaries, and settings on our servers so you can reach them from your other signed-in devices. All sync traffic is encrypted in transit (TLS 1.2+) and the storage volumes are encrypted at rest. Beyond that, how your entry content is protected depends on which sync mode you choose. You can switch modes at any time in the desktop app's settings.
    • Standard sync (the default): entry content and dictionary terms are stored on our servers in a form we are able to read. We hold the keys to the transit and at-rest encryption, so that encryption protects your data from third parties — it does not prevent us from accessing it. We access this content only where necessary to operate the Service, to act on a support request you make, or where we are legally required to.
    • Private sync (optional, available on every plan): if you turn it on, entry content and dictionary terms are end-to-end encrypted on your device before upload, using a recovery key that only you hold. We never receive that key, so we cannot read this content — and we cannot recover it for you if you lose the key.
    In both modes, some sync data is always stored as readable plain text: workspace names, workspace tags, and entry titles. Private sync does not encrypt these fields, so please do not put sensitive information in them.
  • Cloud-based transcription / LLM refinement (BYOK): audio or text is sent directly from your device to the third-party provider (OpenAI, Anthropic, Google, etc.) using your own API key. InkSpoke does not intercept, log, or proxy this content.
  • Wake-word custom model training: audio samples you choose to upload are processed in our build pipeline to produce a personalized model, then deleted within 30 days.

4. Information Collected Automatically

When you use the Service, we automatically collect a small amount of technical and usage information for service operation, security, and improvement:

  • Device & app information: operating system, app version, locale, and a device-scoped anonymous identifier used to apply per-device free-tier limits.
  • Usage analytics: aggregate, anonymized counts of feature usage and crash reports. This data contains no audio, no transcription content, and no personal information. You can disable analytics in Settings → Privacy.
  • Server logs: when you connect to our API, we record request metadata (IP address, user agent, endpoint, response status) for up to 30 days for security and abuse prevention.

5. How We Use Information

  • To provide, maintain, and improve the Service.
  • To authenticate you, secure your account, and enforce usage limits.
  • To process payments and manage subscriptions (via Stripe).
  • To respond to your support requests.
  • To detect, prevent, and address technical issues, fraud, or abuse.
  • To send service-related communications (security alerts, billing notices). We do not send marketing email without your opt-in.

6. Sharing of Information

We do not sell your personal information. We share data only with service providers acting on our behalf, and only as needed to operate the Service:

  • Stripe — payment processing.
  • Cloudflare — DNS, CDN, DDoS protection.
  • Hosting providers (Contabo) — server infrastructure for the API and sync layer.
  • Third-party AI providers only when you supply your own API key (BYOK) and connect directly from your device.

We may also disclose information if required by law, to protect the rights and safety of our users, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you beforehand).

7. Data Retention

  • Account data is kept for as long as your account is active.
  • Sync data is kept for as long as you keep the corresponding workspace.
  • Anonymous usage analytics are retained for up to 12 months.
  • Server logs are kept for up to 30 days.
  • You may request deletion at any time (see Your Rights below).

8. Your Rights

Depending on your location, you have rights regarding your personal information. We honor these requests for all users globally:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate information.
  • Deletion — request that we delete your account and all associated data.
  • Portability — request an export of your data in a machine-readable format.
  • Opt-out of analytics — toggle analytics off in Settings → Privacy.
  • EU/UK residents (GDPR): you also have the right to object to processing, restrict processing, and lodge a complaint with your supervisory authority.
  • California residents (CCPA/CPRA): we do not sell or share personal information for cross-context behavioral advertising. You may exercise your rights to know, delete, correct, and limit processing of sensitive personal information.

To exercise any right, email [email protected] from the address on your account.

9. Security

We use industry-standard security measures to protect your data: TLS 1.2+ for all network traffic, Argon2id for password hashing, authenticated encryption for stored API keys, and isolated containers for service execution. No method of transmission or storage is 100% secure; we work to continuously improve our defenses and to disclose any incidents promptly.

10. International Data Transfers

Our infrastructure is currently hosted in Germany (Contabo) and on Cloudflare's global network. If you access the Service from outside these regions, your data is transferred internationally. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

11. Children's Privacy

The Service is not directed to children under 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email (if you have an account) or via a prominent notice in the app. The "Last updated" date at the top of this page reflects the latest revision.

13. Contact Us

PMT Labs, LLC
5900 Balcones Drive, STE 100
Austin, TX 78731
United States

Email: [email protected]
General inquiries: [email protected]

InkSpoke

You spoke. It's inked.
Voice-first writing for every app you live in.

© 2026 PMT Labs
Product
FeaturesWorkspacesWake-wordComparePricingMobile
Resources
GuidesBlogVoice commandsContact
Company
Use casesAboutPrivacyTerms