Engineering
Privacy you can verify, not just a promise.
Saying “we care about privacy” is easy. Here's what it actually means technically, point by point: what really happens behind the scenes.
Audio is never written to disk
Microphone audio only ever lives in memory, as raw PCM. No recording is saved to a file.
The recognition server only listens on 127.0.0.1
Speech-to-text runs as a separate background server on your computer and only answers requests from your own machine (loopback, 127.0.0.1). Nothing outside can reach it.
Local speech recognition with whisper.cpp
Speech is transcribed entirely on your computer by whisper.cpp, an open-source local runtime for OpenAI’s Whisper model. The default model is “small” (q5_1); with an NVIDIA graphics card you can optionally use “medium”.
SHA-256 verification
Model and engine files downloaded on first run are checked against SHA-256 hashes. An unexpected file is never silently used.
The clipboard is never used
Text isn’t copied and pasted. It’s typed directly at your cursor with real keystroke simulation (Windows SendInput + Unicode), so whatever you had on your clipboard stays untouched.
sandbox + contextIsolation
The app’s interface layer (the Electron renderer) runs isolated: it has no direct access to Node.js APIs, and every system operation goes through a narrow, typed bridge (preload/IPC).
Transcripts are never logged
What you say and the text it becomes never end up in a log, a file or a remote server.
Target window protection
Runora remembers which window was active when you started speaking. If you’ve switched to another one by the time it types (say, a password field), typing is cancelled automatically.