Your words, on the record.
Rhema exists to turn what you say into text. That only works if you can trust where your voice goes. This page says exactly where — no summary gloss, no “we care about your privacy” filler.
Effective July 14, 2026 · Last updated July 14, 2026
The short version. Your recordings are processed to produce your text, and then the text comes back to your Mac. Rhema's servers do not keep a copy of your dictations, and we never use your words to train AI models. Your transcript history lives in a local database on your own computer.
What we do keep: your account, your subscription state, the things you deliberately save to your account (vocabulary, macros, style profiles, voice captures), support conversations you send us, and operational metadata — counts, timings, error codes — that never includes what you said.
Who we are
Rhema is made by 1 Source Medicine, LLC, a Kansas limited liability company doing business as Rhema. When this policy says “we,” that's who it means. You can reach us at talk@rhema.black.
What happens when you dictate
Recording happens entirely on your Mac. Audio is captured locally and nothing leaves your machine until you finish a dictation. When you do, here is the full journey:
- Audio → transcription. Your recording is sent over an encrypted connection to our servers, which pass it to OpenAI's speech-to-text API to be transcribed. The text comes back to your Mac and lands at your cursor. Recordings under 4 MB — nearly all dictations — are processed in memory and never written to our storage. Longer recordings are staged in a private, access-controlled storage bucket just long enough to be transcribed, and the staged file is deleted as soon as the transcription attempt finishes, whether it succeeded or failed. If an upload never reaches processing (say, your connection drops mid-request) or a deletion fails, the leftover file stays in that private bucket until we purge it — and you can request deletion at any time.
- AI commands → language models. When you use the hot word (“Rhema email,” “Rhema clean this up”), the transcript text — plus, for some commands, the name of the active app and any text you had selected — is sent to Anthropic's Claude models to produce the result. The result comes back to your Mac. Our servers record that a command ran (its type, model tier, token counts, and timing) — not what it said.
- Your history stays home. Your transcript history is stored in a local database on your Mac. If you opt in to keeping audio recordings, those audio files are also stored locally, not on our servers.
We do not use your audio, transcripts, or command text to train AI models. Our AI providers process your content solely to return results to you; we use their business APIs, which under their terms do not use API content to train their models.
What you choose to save
Some Rhema features only work if we store content for you. Everything in this list exists because you created it, and it stays in your account until you delete it or your account is deleted:
- Custom vocabulary — the words, names, and jargon you teach Rhema. Vocabulary entries may be sent to Anthropic to generate correction rules.
- Macros and custom instructions — your saved voice workflows and the personal instructions you attach to AI modes. If you explicitly share a macro, the shared copy becomes visible to people you share it with.
- Style profiles — when you upload writing samples, the raw upload is sent to Anthropic for analysis and is not stored on our servers. What we keep is the derived profile: its name, the synthesized style rules, and the anonymized example snippets the analysis extracts.
- Voice captures — to-dos and journal entries you capture by voice sync to your account, including their full text, so they can be stored durably and follow you across devices.
Account, billing, and devices
- Account — your email address and authentication state, managed through Supabase.
- Billing — payments run through Stripe Checkout, hosted by Stripe. Your card number goes directly to Stripe; our servers never see or store it. We store your Stripe customer and subscription identifiers, your plan, and usage counters (commands used this period, transcription minutes this period).
- Devices — to enforce per-plan device limits we store each registered device's name, OS version, app version, and when it was last seen. You can deactivate devices from your dashboard.
Diagnostics and telemetry
The app reports operational events so we can find and fix problems: errors, crashes, performance timings, paste failures, and a re-dictation signal (whether you re-spoke a recent dictation — measured as similarity scores, time gaps, and text lengths, never the words themselves).
Every telemetry payload passes through a scrubbing layer on our servers before it is stored. Fields whose names suggest spoken content — transcript, text, prompt, clipboard, selected text, and similar — are dropped entirely, log lines that look like transcription output are removed, and remaining strings are truncated. What survives is metadata: event type, error code, app and engine version, timings.
If the app is not signed in, telemetry is tied to a device identifier rather than an account.
Support conversations
When you contact support, we store your message, your contact email if you provide one, and — if you attach diagnostics — a log bundle that has been through the same scrubbing layer as telemetry and is capped at 64 KB. Support requests are first read by an automated triage system that helps stage fixes; a human may also read them. Support threads are retained so we can follow up on them.
The website
- Questions you ask on the landing page or through the site chat are sent to Anthropic to generate an answer, which streams back to your browser. We do not store the question or the answer.
- To rate-limit anonymous traffic we keep counters keyed by IP address; these are deleted automatically within about two days.
- The site chat uses Cloudflare Turnstile to verify you are human. Our hosting provider, Vercel, produces standard server logs as part of operating the site.
- We do not run advertising trackers, and we do not sell or share your personal information for advertising.
Who processes your data
We use a small set of service providers, each for one job:
- OpenAI — speech-to-text transcription of your recordings.
- Anthropic — the language models behind AI commands, style analysis, vocabulary rules, and site Q&A.
- Stripe — payments, subscriptions, and card storage.
- Supabase — our database, authentication, and file storage.
- Vercel — hosting for rhema.black and its APIs.
- Cloudflare — bot verification (Turnstile) on the site chat.
Each provider receives only what its job requires, and none of them is permitted to use your content for anything other than providing their service to us.
Retention
- Dictation transcripts and AI command text — returned to your device, not stored on our servers.
- Staged audio for long recordings — deleted automatically when the transcription attempt finishes; leftovers from interrupted uploads or failed deletions are purged on request.
- Account content (vocabulary, macros, style profiles, captures) — until you delete it or your account is deleted.
- Usage and telemetry metadata — retained while we need it to operate and improve the service.
- Support threads — retained so we can follow up.
- Rate-limit IP counters — deleted within about two days.
- Billing records — retained as required for accounting and tax purposes.
Your rights and choices
Email talk@rhema.black to access, correct, export, or delete your data. There is no self-serve delete button yet, so deletion is handled by request: when you ask, we delete your account and the data tied to it, except records we are legally required to keep (such as billing records).
If you live in California, you have the right to know what personal information we collect (this page is that disclosure), to request deletion, and to not be discriminated against for exercising those rights. We do not sell personal information. If you live in the European Economic Area or the United Kingdom, we process your data to perform our contract with you and for our legitimate interest in operating and securing the service; you additionally have rights to access, rectify, erase, restrict, and port your data, and to complain to your local supervisory authority.
Security
Data moves over encrypted connections (TLS). Stored data lives in access-controlled infrastructure, audio staging uses a private bucket with signed, expiring upload URLs, and payment details never touch our servers. No system is perfectly secure, and we won't pretend otherwise — but the fastest way to keep your words safe is our default: not keeping them.
Children
Rhema is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
If we change this policy, we will update this page and the date at the top. If a change meaningfully reduces your privacy, we will tell you before it takes effect.
Contact
1 Source Medicine, LLC, doing business as Rhema · Kansas, USA
talk@rhema.black
See also our Terms of Service.