One page, because this is the whole story.
When you press a correction hotkey, the selected text is sent only to the AI endpoint you configured: your Azure OpenAI resource, your OpenAI account, your local Ollama, or any custom server you chose. With your own key there is no RefineLoop server in the path: we never see, store, or relay your text. If you use Ollama, your text never leaves your machine at all.
The Assistant (Tools → Assistant) takes the same path. What you type there goes to the same endpoint you configured, through the same credential guard, and to nothing else. The one connection it will not use is the free trial. That relay exists to demonstrate the correction loop, so the Assistant refuses it and points you at Ollama on this PC or your own key instead. Nothing you type there is ever sent to RefineLoop.
The one exception is the trial connection, and you choose it explicitly (the "Start - free for 14 days" button on first run, which says so right beside it, or "RefineLoop Trial" in Settings). During the trial your text passes through RefineLoop's relay on its way to the AI provider, because a trial that works on day one needs a connection you did not have to create. The relay forwards and does not store your text; it counts requests (per install, per day) so the trial stays free, under an anonymous token: rl_ plus random hex, minted on this machine, containing no email, no machine name, nothing about you. Switching to any free key at the end of the trial (or on day one) takes RefineLoop's server out of the path entirely.
Every outbound request (corrections, drafts, lookups, meeting digests) is scanned locally, on your machine first. The scan itself makes no network call. If it finds something that looks like a credential (an API key, a private key block, a JWT, a connection string, a Luhn-valid card number, or a high-entropy string), nothing is sent until you choose: send redacted, send anyway, or don't send.
Names, email addresses, and phone numbers are deliberately not flagged. They are the ordinary content of the messages this tool exists to fix, and an alert that fires on every colleague's name is one you learn to click through.
Administrators can change secret_guard from ask to redact (silent), block (no override), or off.
config.ini: your API settings, including your API key, stored locally in your data folder (%APPDATA%\RefineLoop). Treat it like a password file.logs\<lang>_YYYY-MM.<machine>.jsonl: your correction history (original + corrected text), one file per language per month per machine, so a cloud-synced data folder never has two computers appending to the same file. Written locally so the app can show your progress and recurring mistakes. Delete these files at any time; the app recreates empty ones.logs\errors.log: timestamps and error messages from failed API calls (no message text).logs\latency.jsonl: how long each phase of a spoken turn took, never what was said.logs\audit.log: off by default. When enabled, one line per outbound request: time, mode, endpoint host, character count, findings, and outcome. It never contains your text. An audit trail that stored the sensitive content would defeat its own purpose.knowledge\captures\captures_YYYY-MM.<machine>.jsonl: off by default. When you switch the capture archive on (capture_archive = on), every text a hotkey grabs is appended here, so "what did the app see?" has an answer in your own files. Text only (audio is deliberately out of scope, because the recording and replay promises are memory-only and this archive must not quietly break them), and anything the credential guard flags is not archived at all.knowledge\scenes\threads\<person>.jsonl: your practice conversations, one file per person or room. This is what makes the Conversation screen pick up where you left off instead of starting empty every time. Nothing new leaves your machine because of it (the last dozen turns already went to your AI provider as context), but it does mean your side of those conversations is now kept on disk rather than only in the open page. Each file keeps the most recent turns and drops the oldest. Conversation → Forget deletes them all, along with what the characters remember about you.knowledge\assistant\chats.json and knowledge\assistant\<id>.jsonl: your Assistant conversations, one file each, kept so they are still there tomorrow. Unlike the practice transcripts above, nothing here is ever pruned: a conversation you had is a thing you keep, so the app caps how much of it is sent as context rather than deleting the old part, and refuses to add to a conversation that has grown enormous instead of trimming it. Delete on a conversation removes that file and only that one. The Conversation screen's Forget button cannot reach these.knowledge\scenes\cast.json / memory.json / rooms.json: the people you practise with, generated from your own profile, plus what each one remembers about you.license.key / trial.dat: your license and trial start date.relay_token in config.ini: the anonymous trial token, if you used the trial connection. Deleting it (or the whole config) simply mints a new one on the next trial save.Recording only ever starts from your explicit action and is visibly indicated by the red tray icon. It captures the system's audio output and your microphone. The audio is sent only to your configured transcription endpoint, and the local audio file is deleted after the transcript is saved (unless you set keep_audio = on). Transcripts are stored locally in knowledge\transcripts\. Stopping a recording sends nothing to the chat model: the transcript window offers a summary and a speech-mistake pass, and each is a button you press. You are responsible for obtaining participants' consent where required by law or policy.
The replay buffer holds the last 60 seconds of what your PC played and what your microphone heard, in memory only. It is overwritten continuously, is never written to disk (not even temporarily to be uploaded) and is discarded the moment you stop listening or close the app.
It does not start on its own. You turn it on from the tray or with the hotkey, and while it runs the tray icon carries an amber ring. When you press Ctrl+Alt+Q, that minute of audio is sent to your configured transcription endpoint; if that endpoint is not local, the app tells you the audio would leave your PC and asks first. Nothing is stored unless you click "Save to notes" (which writes a file into knowledge\transcripts\), or unless you switched the capture archive on, in which case the transcript is appended to knowledge\captures\ like every other hotkey capture. The audio itself is never written either way.
The same consent rules as recording apply: capturing other people may require their consent depending on your country's law and your employer's policy.
The snip and the text recognition run entirely on your PC using the OCR engine built into Windows: no image or text goes anywhere at capture time, and the screenshot is discarded as soon as recognition finishes. The recognized text is sent to your configured AI endpoint only when you explicitly click Explain or Translate, passing through the credential guard like every other request.
The word or sentence you select is sent only to the AI endpoint you configured, exactly like a correction. What you look up is stored locally in knowledge\vocabulary\ as vocabulary.jsonl and a readable vocabulary.md, yours to export, sync, or delete.
Read aloud never records audio. Whether it sends anything depends on one setting. With speech = auto (the default), the word or sentence being spoken is sent as text to your provider's speech endpoint, which returns the audio (the same provider and the same key your corrections already use), and it is checked by the secret guard first, like every other outbound request. Set speech = local in Settings and the synthesis happens on this PC instead: the request goes to the bundled Kokoro voice server over loopback, with no key and no auth header, and falls back to the voices already installed in Windows while that server is not yet up. Either way nothing leaves your machine. Providers with no speech endpoint of their own (Ollama among them) always fall back to the Windows voices. Synthesised audio is cached under audio\ so the same word is only ever fetched once.
Pictures are OFF by default. If you turn them on ("Show a picture for concrete words"), the app asks Openverse, the Creative-Commons image search, for an illustration. Only the two-or-three-word search term is sent, never the sentence, the document, or anything else; images are cached locally so a word is only ever requested once. This is the single feature that contacts a third party other than your own AI endpoint and your own update host, which is exactly why it ships switched off.
If you switch on selection_widget (off by default, and removable org-wide by an administrator's policy file), the app watches the mouse so that a small button can appear beside text you have just selected. It installs a low-level mouse hook and nothing else: there is no keyboard hook anywhere in this product, structurally rather than by promise. It reads no text at all until you pick a command from that button's menu, at which point the text takes exactly the same path as the matching hotkey, credential guard included.
Nothing, unless you switch it on. There is no RefineLoop account and no analytics service. Usage telemetry exists but is off by default and described in full below.
Here is every network connection the app can make, grouped by what causes it. Only the first one ever carries your text.
Automatic, while the app runs:
1. The AI endpoint you configured: every correction, draft, translation and lookup. That is whichever you chose: OpenAI, Azure OpenAI, Google Gemini, Anthropic Claude, Groq, an OpenAI-compatible server of your own, Ollama on this PC (which leaves the machine not at all), or the 14-day trial relay described below. 2. refineloop.app: two small public files, no identifying information sent, silent on failure. version.json says whether a newer release exists, and carries the list of revoked licence identifiers (short hashes of keys leaked publicly, never emails, never the keys themselves), which your app compares against its own key locally. presets.json is the command-pack gallery. Turning off the daily update check in Connection stops both. 3. The trial relay (*.workers.dev): only while you are on the 14-day trial connection, because that is the AI endpoint in that case. It forwards your text to the AI provider under RefineLoop's key and stores none of it. Your install is identified by a random token that identifies a trial, never a person. Switching to any key of your own takes it out of the path entirely.
Only after you explicitly say yes to a dialog (nothing downloads before that):
4. ollama.com: the one-click local-AI setup, to fetch the Ollama installer and pull the model you pick. 5. www.python.org: the one-click Python install that local speech needs. 6. Python package and speech-model downloads: when local speech or the local voice runs for the first time, the bundled servers fetch their Python packages and their model files (about 340 MB for the voice). These are ordinary downloads made by those tools, not by RefineLoop, and they carry nothing about you.
Off unless you turn it on:
7. Openverse (api.openverse.org): only if you switch memory-hook pictures on, and only the search term (see above). 8. Anonymous usage ping: off unless you turn it on in Connection → "Allow RefineLoop to send anonymous app usage data". When enabled it sends one request per day containing exactly five things: a random identifier generated on this PC, the app version, whether you are on trial or licensed, which day of the trial you are on, and your Windows version. That identifier is a random value with no connection to your name, your machine name, or your licence. It never carries your text, your vocabulary, your prompts, your settings, or your API key. Switching the toggle off stops it immediately.
Separately, several buttons open a page in your normal browser rather than connecting themselves: the free-key doors (console.groq.com, aistudio.google.com, platform.openai.com, console.anthropic.com, portal.azure.com) and the help links. Those are your browser's connections, made only when you click, and the app sends nothing with them.
Contact: support@refineloop.app