Security & Privacy

Hermetiq is designed for therapists and mental health professionals who work with sensitive client information and need full control over their data.

This page explains, plainly, how Hermetiq handles security, privacy, and compliance.

HIPAA & Compliance Posture

Hermetiq's architecture avoids many common HIPAA concerns by design:

  • No cloud processing of PHI
  • No data transmission to external servers
  • No third-party AI services
  • No subprocessors handling client data
  • No data residency questions
  • No BAA required (no covered entity relationship)

Why no BAA?

A Business Associate Agreement is required when a vendor processes, stores, or transmits Protected Health Information (PHI). Because Hermetiq runs entirely on your device and never transmits client data, there is no covered entity relationship. Your data stays under your control at all times.

Local-only by design

Hermetiq runs entirely on your Mac. All processing happens locally.

  • Speech-to-text transcription runs locally (Whisper AI)
  • Note generation runs locally (on-device LLM)
  • Client records stored locally in encrypted database
  • No audio or text sent to external servers
  • No cloud inference, ever

Hermetiq works without an internet connection after initial setup.

Data handling

Hermetiq does not:

  • upload session recordings
  • transmit transcripts
  • send generated notes to any server
  • store data in the cloud
  • share client information with third parties

All session data exists only on your device and is under your control.

What Hermetiq stores locally

Hermetiq maintains a local database on your Mac containing:

  • Client profiles (name, notes)
  • Session records (date, duration, notes)
  • Generated documentation
  • Your customization settings

Audio files are not stored by default.

Hermetiq processes audio in memory and discards it after transcription. You can optionally choose to keep audio files, but this is off by default.

No accounts. No identity tracking.

Hermetiq does not require:

  • an account
  • email registration
  • authentication
  • API keys

Hermetiq does not identify users or devices. Your license is validated locally.

Telemetry & analytics

Hermetiq collects zero usage data. Period.

No analytics. No telemetry. No crash reports. No usage tracking.

  • No automatic error reporting
  • No feature usage tracking
  • No session statistics
  • No behavioral analytics
  • No third-party analytics SDKs

Bug reports and feedback: If you choose to report an issue, the in-app form opens your email client. You control exactly what information you send. Nothing is collected automatically.

The only network call Hermetiq makes is to validate your subscription.

Permissions

Hermetiq requests a minimal set of macOS permissions, only when required.

Microphone (optional)

Required only if you record sessions directly in Hermetiq.

Audio is processed locally and is not stored by default.

File Access

Required to import audio files (Voice Memos, Zoom recordings, etc.).

Hermetiq only accesses files you explicitly select.

Application sandboxing

  • Hermetiq is a signed and notarized macOS application
  • The AI models run as sandboxed local processes
  • Hermetiq cannot access files outside its own directories unless you explicitly select them
  • Database is stored in the app's sandboxed container

Encryption & storage

  • Client data is stored in an encrypted SQLite database
  • Hermetiq relies on standard macOS file system protections
  • FileVault encryption recommended for additional security
  • Backup files can be password-protected

Offline operation

Hermetiq works fully offline after initial setup.

Network access is not required for:

  • transcribing sessions
  • generating SOAP notes
  • generating DAP notes
  • generating progress notes
  • managing clients
  • exporting documentation

You can use Hermetiq in airplane mode.

License validation

Hermetiq validates your license periodically when connected to the internet.

This check only verifies your license status. It does not transmit:

  • client names or data
  • session content
  • transcripts or notes
  • usage patterns

If offline for extended periods, Hermetiq continues to work with a grace period.

Practice & enterprise review

Hermetiq is a local productivity tool, not a SaaS platform.

Because Hermetiq does not process or store data on remote systems, many traditional vendor risk categories do not apply.

If your practice, clinic, or compliance team has questions, we are happy to provide a technical overview.

Contact us

Short summary (copyable)

Hermetiq Security & Privacy Summary

Hermetiq processes all data locally on your Mac.

No client data is transmitted, stored remotely, or shared.

No accounts, analytics, telemetry, or external AI services.

Zero usage data collected. Only subscription validation.

Suitable for HIPAA-conscious practices. No BAA required.

Hermetiq is built to be easy to trust, easy to approve, and easy to remove.

No lock-in.No hidden processing.No surprises.