Skip to main content

Sensitive apps and privacy

Sensitive-app detection protects high-risk windows (especially password managers). When the focused app matches your list, Kalam forces local speech-to-text, skips surroundings context and AI polish, blocks voice editing, and types text without leaving a transcript on the clipboard. Configure under Settings → Privacy.

What happens on a match

BehaviorEffect
Force local STTAudio stays on-device for that dictation
Skip context + polishNo surroundings capture; no Improve call
Block voice editVoice editing hotkey errors with a clear message
Fail closedIf no local engine is installed → dictation fails (no cloud fallback)
Clipboard hygienePrefers keystroke injection so the OS clipboard stays clean

The floating pill may show a Local only / context-blocked style hint while you dictate in a sensitive app. Concepts: Context awareness, Speech-to-text.

Default patterns

Detection is on by default. The built-in process-name pattern covers common password managers:

  • 1Password
  • Bitwarden
  • KeePass
  • LastPass
  • Dashlane
  • NordPass

Add or remove apps

  1. Open Settings → Privacy.
  2. Ensure Sensitive app detection is enabled.
  3. Click Add app and pick from running or installed apps (matched by process name).
  4. Remove any card with the × control when you no longer need protection for that app.
Install a local engine first

Fail-closed means: sensitive match + no local model → error asking you to install an engine under Settings → AI & Models → Local engines. See Downloading local models.

Why this exists

Cloud STT and polish send audio or text to providers. Password vaults and similar apps often contain secrets in titles or fields. Sensitive-app mode keeps that dictation path local-only and refuses cloud shortcuts when Local is unavailable — privacy over convenience.

More privacy controls: Privacy settings.