Hush Privacy Notice

HUSH is a macOS assistant from Kaizōsha. This notice describes the data behavior visible in the current public source. Packaged releases can differ from newer source, and third-party services have their own terms.

Last updated: August 20, 2026

THE SHORT VERSION

HUSH stores session history on your Mac. Provider keys use macOS Keychain by default. HUSH is not a fully local AI app: content needed for OpenAI-backed requests is sent directly to OpenAI under the account you connect.

The current source does not implement a Kaizōsha account, advertising service, analytics SDK, or telemetry pipeline. Visits to this website are governed separately by the Kaizōsha website privacy policy.

LOCAL STORAGE

By default, HUSH stores current and previous sessions as JSON files inside ~/Library/Application Support/HUSH. A person can choose another storage directory.

Local session records can include prompts, responses, live transcripts, timestamps, errors, capture and attachment metadata, image previews, file references, OpenAI file or conversation identifiers, and other state needed to reopen a session.

Preferences and provider-account records are stored in macOS preferences. HUSH supports searching, pinning, archiving, deleting, reopening, and branching sessions. Removing a local session does not remove content that was already transmitted to OpenAI.

OPENAI PROCESSING

OpenAI is the active connected AI provider in the current source. HUSH calls OpenAI directly with the project API key a person adds; it does not route these requests through a Kaizōsha AI server.

Depending on the feature used, OpenAI can receive prompts, instructions, recent conversation context, generated responses, screenshots or images, supported file uploads, microphone audio, system audio, live transcripts, model choices, and identifiers used to continue an OpenAI conversation.

When an optional OpenAI admin key is supplied, HUSH can also request organization cost and completions-usage summaries. OpenAI handles received data under the connected account and its own privacy policy, service terms, settings, and retention rules.

APPLE SPEECH FALLBACK

When OpenAI Realtime is not configured or available, HUSH can use Apple speech technology for live transcription. On supported newer systems, HUSH uses Apple's local SpeechAnalyzer path. The legacy Speech framework can be used as a fallback on other supported systems.

The legacy fallback does not force on-device recognition. Apple speech services may therefore process audio according to the Mac's software version, language support, settings, and Apple's own terms. HUSH should not be described as providing universally on-device transcription.

ACCOUNTS AND CREDENTIALS

API and admin keys are saved in macOS Keychain by default. If Keychain storage is disabled or a Keychain save fails, the current app can fall back to storing secrets in local macOS preferences. Account labels, provider settings, model selections, and masked key previews are also stored locally.

HUSH can optionally require Touch ID or the Mac login password before account changes or saved-key access. This protection is separate from Keychain storage and depends on the person's settings.

MACOS PERMISSIONS

MicrophoneUsed when Live includes microphone audio.
Screen RecordingUsed for system-audio capture and screen-capture workflows.
Speech RecognitionUsed when HUSH falls back to Apple speech transcription.
Camera and PhotosDeclared for camera-based input and images a person chooses from Photos when those inputs are used.

Permission choices can be reviewed in macOS System Settings. Use audio and screen capture only when you have permission and comply with applicable law, workplace rules, and platform policies.

SECURITY BOUNDARIES

The current source enables Apple's hardened runtime, but the app target is not configured with App Sandbox. HUSH should not be described as sandboxed or as keeping all data on the device.

Stealth controls can reduce window visibility in the Dock, screen capture, Mission Control, Stage Manager, or other macOS surfaces. These controls are not a guarantee of invisibility, confidentiality, or protection against every capture method.

CHANGES AND CONTACT

This notice should be reviewed when HUSH changes its provider integrations, local storage, permissions, analytics, telemetry, or distribution model.

Questions about HUSH privacy can be sent through the Kaizōsha contact page: https://kaizosha.org/contact.