Visage
Visage Specifications Download Support

Visage — Privacy Policy

Version 1.3 — in effect from 1 October 2026 (Version 1.2: 28 September 2026; Version 1.1: 21 September 2026; Version 1.0: 19 August 2026).

Last updated: 1 October 2026 (Version 1.3 — dictation and your words: the words you teach Visage live in the memory file and never leave this computer; nothing you dictate is stored. Version 1.2 — conversations are kept by default, encrypted and local, with a switch to turn that off; the memory wording brought up to date. Version 1.1: the controller is now RAPHS LTD; data-protection contact privacy@raphs.app; hosting moved to Google Cloud)

Change of controller, 21 September 2026. The Visage software, website and licensing service are now operated by RAPHS LTD, the limited company of Visage's developer, in place of Raphael Saeed as an individual. What we collect has not changed — see “The short version” below. What changed: who is responsible (RAPHS LTD), where you write to exercise your rights (privacy@raphs.app), and where the website and licensing service run (Google Cloud, with the licence record stored in London — §11). Shown here prominently as §12 promises.

The short version

Visage is built to need as little of your data as possible, and to ask before it uses any of it. There is no Visage account. There is no Visage server that your conversations pass through. Visage does not run analytics or telemetry of any kind. Everything the Software does — understanding your speech, generating a reply, watching for your face through the camera — happens on your own computer, using its own processing power, unless you deliberately turn on one specific optional feature (§3) that sends your messages to a cloud AI provider of your choice. The sections below are the complete, detailed version of that same statement.

1. Who this is

This Privacy Policy is issued by RAPHS LTD, a company registered in England and Wales (company number 17358041) with its registered office at 167-169 Great Portland Street, London, England, W1W 5PF, the developer and publisher of Visage (“we”, “us”, “the Licensor”). Support: support@raphs.app. Data-protection requests (access, deletion and the other rights described in §11): privacy@raphs.app.

2. What we do not collect

We do not operate a backend server for the Software's core function, do not require or offer a user account, and do not run telemetry, crash reporting, or usage analytics of any kind inside the Software. We do not know how many people use Visage, what they say to it, or how they use it, because nothing about your usage is sent to us. The two narrow, disclosed exceptions to “nothing is sent anywhere” are the update check (§5) and licence activation (§6) below — both are deliberately minimal and are described in full.

3. Local processing, by default

Conversations (text). By default, Visage generates its replies using an AI model that runs entirely on your computer (via a local inference process the Software manages). Your messages never leave your machine in this mode. Cloud AI providers are opt-in only — see §4.

Microphone (hold-to-talk). Visage's microphone permission explanation, shown when your operating system first asks your permission, states our commitment plainly (the wording varies slightly by platform; the commitment does not): “Visage listens only while you hold the talk button; audio never leaves this Mac.” Concretely: audio is captured only for the duration of an explicit press-and-hold; it is held in memory only (never written to a file by Visage's own code) and is sent to a transcription process that runs on your own computer and is not reachable from the network; when the hold ends (including if you cancel it), the audio is discarded from memory immediately after transcription. Nothing about what you say to Visage by voice is stored or transmitted off your machine.

Camera (Presence, off by default). Presence — the optional feature that lets Visage's face follow your gaze through the camera — is off until you turn it on yourself, either from the chat overlay's camera button or in Settings. The first time you enable it, Visage shows its own explanation before your operating system's own camera-permission prompt appears (macOS wording shown; other platforms differ slightly): “Visage: Presence uses your camera so the face can meet your eyes. Frames are analyzed on this Mac and never stored or sent anywhere. macOS will ask for camera permission next.” This is accurate to how it works: each camera frame is analyzed the instant it arrives and then discarded; frames are never written to disk, never buffered, and never transmitted anywhere — there is not even a local network request involved, unlike the microphone pipeline's local transcription hop. Turning Presence off stops the camera immediately.

Memory (Stage A26). Visage keeps a small encrypted file on this computer (SQLCipher, AES-256), created the first time Visage runs. It holds the words you teach it, your conversations, your codes, and — only if you switch on “Visage remembers things about you” — facts about you that you or the AI model chose to keep. Conversations are kept by default, one copy each, encrypted and local; the switch “Keep conversations” in Settings turns this off, and the Memories window deletes any one of them or all of them at once. The key stays in this computer’s keychain; a recovery key is shown to you once. Nothing in the file is sent anywhere by Visage. No AI model is told anything from it unless you switch that on; a cloud model or a custom endpoint needs its own switch, and only then may it see your memories and short excerpts of kept conversations that match your question. Finding memories “by meaning” uses a small model that runs only on this machine. Codes (door codes, PINs, passwords) are refused as memories and are never spoken, never sent to any model and never leave the Settings screen that shows them after your operating system has checked it is you. Back-ups are encrypted files you save where you choose. “Forget all” deletes the file and its keys.

Dictation and your words (Stage A27). The names and terms you teach Visage — by saying “add … to my words”, by typing them in the Words list, or by importing a text list — are stored in that same encrypted file as words. Visage shows them to the on-device speech model before it listens and uses them to correct what it heard, on this computer. Nothing you dictate is stored: when Visage corrects one of your words it keeps only the word pair (how it was heard, how you spell it), which you can see, switch off or delete in Words. “Polish” sends a dictated sentence to the local AI model on this computer only; no cloud model ever receives dictation. Whether a cloud model may see your words as spelling hints follows the same “may see memory” switches as the rest of the memory.

What this means together: with Presence off and a local AI model selected (the default state), Visage functions with no network access at all — it works with Wi-Fi off.

4. Cloud AI providers (opt-in only)

Visage lets you optionally connect it to a third-party cloud AI provider — currently Anthropic, OpenAI, or any OpenAI-compatible endpoint you specify yourself — using your own account and API key with that provider. Settings states this plainly next to the controls: “Local is the default. Nothing leaves this machine unless you select a cloud provider.”

If, and only if, you choose to do this: the text of your conversation (and the conversation context needed to keep replies coherent) is sent to that provider's own servers for processing, and is handled under that provider's own privacy policy and terms, not this one. We do not receive a copy of that traffic, do not log it, and are not a party to that processing. Your API key for that provider is stored only in your computer's own secure credential store (the login Keychain on macOS; Credential Manager on Windows) — never in Visage's own application data, never logged, and never transmitted to us. It is read back only at the moment a message is sent to that provider and held only in memory for that one request.

5. Update check

Visage may check, at most once every 24 hours on launch, whether a newer version is available, by fetching a small static file (latest.json — version number, release notes, download link, and a cryptographic signature used only to verify the update artifact itself) from our website's hosting. This request carries no account identifier, no device identifier, and no usage data — it is the same kind of anonymous request your browser makes when loading any public web page, and our hosting does not receive anything that identifies you individually beyond what any web request inherently carries (e.g. IP address, handled per our hosting provider's own standard server logs, not by us). The check fails silently if you're offline, never runs during first launch, and can be turned off entirely in Settings; a manual “Check for updates” button is also available for when you want to check without the automatic schedule. Separately, and on the same anonymous basis, Visage also re-checks the published catalogue of downloadable brain/voice/hearing components (PACKS.json) from the public GitHub release that hosts them, purely to notice when a component has been re-published so your next install of it fetches the current, verified file instead of a stale one — the same static-file-fetch class as the update check above: no account identifier, no device identifier, no usage data, and it fails silently offline.

6. Licence activation (paid versions only)

If you purchase Visage, activating your licence key sends a request to our licensing service containing only your licence key and a salted cryptographic hash of a hardware identifier from your machine (used only to count the two systems your licence permits) — the underlying raw identifier itself never leaves your machine, only the salted hash. To keep refunded licences from remaining in use, Visage repeats this same request when the app launches — the same two values, nothing more. If the licensing service is unreachable, the app simply continues: validation never blocks or degrades a licensed copy that is offline. All of this is unrelated to and separate from the 15-day trial (below), which involves no network request at all.

7. Trial period

Visage's 15-day evaluation trial is tracked entirely on your own computer (a timestamp stored in the same secure credential store used for API keys, with a second local consistency check) and involves no network request and no hardware identifier of any kind — unlike paid-licence activation (§6), the trial mechanism does not “phone home” in any form, consistent with the rest of this policy.

8. Purchases and payment data

Purchases are processed by Stripe, through Stripe Managed Payments, acting as merchant of record. This means Stripe — not us — is the seller of record for your transaction and the data controller for your payment data (card details, billing address, invoicing, VAT/sales tax handling, and refund processing). We never receive or store your card details. Stripe's own privacy policy governs the data you provide during checkout; we receive only what is necessary to issue and validate your licence key (e.g. that a purchase occurred and an order/licence identifier — not your payment details).

Refunds. Refund requests are handled per our payment processor's (Stripe) standard consumer refund policy. Contact support@raphs.app with your order details to request one.

9. Third-party components

The Software includes third-party open-source components (an AI model, a speech-recognition engine, a text-to-speech engine, a computer-vision library, and others). These run locally as part of the Software and do not independently transmit data anywhere; see our third-party licence records and the Software's own Settings → About → “Third-party licences” for the full, current list and each component's licence.

10. Children's privacy

Visage is a general-audience product and is not directed at children under 13. We do not knowingly collect personal information from children — and, as §2 describes, the Software has no accounts and sends us no personal data in ordinary use, from any user. If you believe a child has sent us personal information, contact support@raphs.app and we will delete it.

11. Your rights

Because Visage does not collect, store, or have access to your conversations, voice audio, or camera frames, there is generally nothing of that kind for us to provide, correct, or delete on request — it was never sent to us. For data that Stripe holds as merchant of record (§8) or that our website/update-check hosting incidentally logs (§5), please see Stripe's privacy policy and contact us at support@raphs.app for anything within our control.

UK GDPR / EU GDPR. For the minimal personal data within our control — in practice the licence-activation record described in §6 (a salted one-way hash of a hardware identifier plus your licence key; it contains no name and no email) and the standard, short-lived hosting logs described in §5 — the controller is RAPHS LTD (contact: privacy@raphs.app). Our lawful bases are performance of a contract (issuing and validating your licence — Art. 6(1)(b)) and legitimate interests (serving anonymous update and component-catalogue files, and preventing licence abuse — Art. 6(1)(f)). You have the rights of access, rectification, erasure, restriction, portability, and objection, exercisable by email. Because activation records contain no name or email, please include your licence key in any request so we can locate the record — without it we generally cannot identify which record, if any, relates to you (Art. 11 GDPR). Note that erasing your licence record renders the licence key inoperative; we will confirm with you before doing so. Licence records are retained while your licence remains valid or until you ask us to delete them. We do not sell or share personal data, and we make no automated decisions producing legal or similarly significant effects. Our website and licensing service run on Google Cloud (the services in Belgium, europe-west1; the licence record itself is stored in London, europe-west2); Google acts as our processor for that record. You may also complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

California (CCPA/CPRA). We do not sell or share personal information, and the Software collects none in ordinary use; the rights and contact route above apply equally.

12. Changes to this policy

We may update this policy as the Software changes (for example, when a new optional feature is added). Material changes will be reflected here with an updated “Last updated” date, and, where required by law, disclosed more prominently.

13. Contact

support@raphs.app (support) · privacy@raphs.app (data-protection requests)

© 2026 RAPHS LTD. support@raphs.app

Home · Visage · Support · EULA