Skip to main content

Sensitive apps and privacy

Sensitive-app detection protects high-risk windows (especially password managers). When the focused app matches your list, Kalam forces local speech-to-text, skips surroundings context and AI polish, blocks voice editing, and types text without leaving a transcript on the clipboard. Configure under Settings → Privacy.

What happens on a match​

BehaviorEffect
Force local STTAudio stays on-device for that dictation
Skip context + polishNo surroundings capture; no Improve call
Block voice editVoice editing hotkey errors with a clear message
Fail closedIf no local engine is installed → dictation fails (no cloud fallback)
Clipboard hygienePrefers keystroke injection so the OS clipboard stays clean

The floating pill may show a Local only / context-blocked style hint while you dictate in a sensitive app. Concepts: Context awareness, Speech-to-text.

Default patterns​

Detection is on by default. The built-in process-name pattern covers common password managers:

  • 1Password
  • Bitwarden
  • KeePass
  • LastPass
  • Dashlane
  • NordPass

Add or remove apps​

  1. Open Settings → Privacy.
  2. Ensure Sensitive app detection is enabled.
  3. Click Add app and pick from running or installed apps (matched by process name).
  4. Remove any card with the × control when you no longer need protection for that app.
Install a local engine first

Fail-closed means: sensitive match + no local model → error asking you to install an engine under Settings → AI & Models → Local engines. See Downloading local models.

Why this exists​

Cloud STT and polish send audio or text to providers. Password vaults and similar apps often contain secrets in titles or fields. Sensitive-app mode keeps that dictation path local-only and refuses cloud shortcuts when Local is unavailable — privacy over convenience.

More privacy controls: Privacy settings.