Sensitive apps and privacy
Sensitive-app detection protects high-risk windows (especially password managers). When the focused app matches your list, Kalam forces local speech-to-text, skips surroundings context and AI polish, blocks voice editing, and types text without leaving a transcript on the clipboard. Configure under Settings → Privacy.
What happens on a match
| Behavior | Effect |
|---|---|
| Force local STT | Audio stays on-device for that dictation |
| Skip context + polish | No surroundings capture; no Improve call |
| Block voice edit | Voice editing hotkey errors with a clear message |
| Fail closed | If no local engine is installed → dictation fails (no cloud fallback) |
| Clipboard hygiene | Prefers keystroke injection so the OS clipboard stays clean |
The floating pill may show a Local only / context-blocked style hint while you dictate in a sensitive app. Concepts: Context awareness, Speech-to-text.
Default patterns
Detection is on by default. The built-in process-name pattern covers common password managers:
- 1Password
- Bitwarden
- KeePass
- LastPass
- Dashlane
- NordPass
Add or remove apps
- Open Settings → Privacy.
- Ensure Sensitive app detection is enabled.
- Click Add app and pick from running or installed apps (matched by process name).
- Remove any card with the × control when you no longer need protection for that app.
Fail-closed means: sensitive match + no local model → error asking you to install an engine under Settings → AI & Models → Local engines. See Downloading local models.
Why this exists
Cloud STT and polish send audio or text to providers. Password vaults and similar apps often contain secrets in titles or fields. Sensitive-app mode keeps that dictation path local-only and refuses cloud shortcuts when Local is unavailable — privacy over convenience.
More privacy controls: Privacy settings.