Security
What the desktop app contacts, how to stop it, where recordings live, and what to ask us. Written for a security or IT review.
The short version
amlistening records and transcribes on the computer it runs on. Capture, transcription, review and export need no network, and the app has no telemetry. It uploads no recording and no transcript. The only calls it makes are to check for updates, to refresh a licence after you sign in, to sign in, and to download a transcription model. Two of those happen unasked, and one switch stops both.
What the app contacts
This is every network call the app can make.
- Update checkreleases.amlistening.app
- At launch, and when you press Check for updates. With Update automatically on, every six hours, and the download too. A request for the update file. The server sees your IP address. The app starts this itself, so Work offline stops it.
- Licence refreshamlistening.app
- Only after you sign in. At launch and every six hours, once the licence is past half its life. The cached licence and the random installation ID. The app starts this itself, so Work offline stops it.
- Sign-inamlistening.app
- When you press Sign in. It opens your browser. The random installation ID and a one-way hash of the computer, user and platform names. The app listens only on 127.0.0.1 for the answer.
- Model downloadhuggingface.co
- When you press Download in Settings → Transcription. Hugging Face may redirect the file to its own download hosts. A request for the model file. The server sees your IP address.
The app also talks to its own transcription process on 127.0.0.1, and listens on 127.0.0.1 while you sign in. Neither is reachable from another computer.
What to allow on a firewall
Recording and transcription work with all of these blocked. Block them and the app loses only the call each one serves.
- releases.amlistening.app
- amlistening.app
- huggingface.co
All calls use HTTPS. The model host may send the file from its own download servers, so allow the redirect or download the model once on an open connection.
Turning the background calls off
Work offline, in Settings → App → Network, stops the update check and the licence refresh. It does not affect recording. Sign-in and the model download still work, because each waits for a button.
To set it for every user of a computer, deploy a policy file with your management tool. The app reads it when it starts. While it is present, the switch shows as set by the organisation and cannot be changed.
- macOS
- /Library/Application Support/amlistening/policy.json
- Windows
- %ProgramData%\amlistening\policy.json
{
"offlineMode": true
}Use false to pin it off. A file that is missing or cannot be read is ignored and never stops the app from starting. Remove the file and the person's own choice applies again.
Where recordings are kept
Each take is a plain folder of audio and text files under the Documents folder, in a folder named amlistening. Anything that backs up or syncs Documents, such as OneDrive or iCloud, will copy recordings too. The app does not encrypt them itself. Rely on the disk encryption your organisation already requires, such as FileVault or BitLocker.
The licence is a small signed file in the app's own data folder. It holds an account id, a plan, an email address, the random installation id and dates. It holds no recording.
The installers
The macOS app is signed with a Developer ID certificate and notarized by Apple. The Windows installer is not code-signed yet: signing is waiting on identity validation, so Windows may show an unknown publisher warning until it is. Updates come from the release server in the list above and install only when the app quits, never during a take.
The app asks the operating system for access to the microphone.
Accounts and payment
An account is needed only for a Pro licence. The website holds a name, an email address and a plan, and card details go straight to Stripe. The privacy policy lists each provider that handles that data and what it handles.
Contact
Security questions, a vulnerability report, or a questionnaire: support@amlistening.app. The docs describe the same calls from a user's side.