iPhone and iPad Preview
The mobile Preview uses Apple’s on-device SpeechAnalyzer path after you explicitly prepare its speech assets. Unsupported devices and languages are reported; there is no cloud-recognition fallback. Audio stays in the app’s local container. A cancelled or interrupted capture keeps one recovery slot until you save or explicitly discard it. Recording stops when Workbench leaves the foreground.
Reading uses installed Apple voices. Workbench uses a generic Lock Screen title rather than exposing your passage there. Photos and Files imports are selected by you. Saving a new image to Photos requests add-only permission. Workbench does not inspect your photo library, monitor your clipboard or set your system wallpaper.
Saved text, original audio and pictures, editable ink and separate image-project settings have local copies in the app container. Optional personal photo and scene sync are described below. This Preview retains imported original assets when records are deleted. Deleting the iOS app can remove its local work, unlike replacing an app update; export important results first. Device backups follow your Apple settings. There is no analytics, tracking or Workbench account. Cloud transfers require an enabled handoff or scene-sync setting in a configured build. Share destinations and Photos syncing apply their own policies.
The Mac-only server, Speko, Accessibility and desktop-overlay features below do not apply to the mobile target. Mobile Preview and testing limits.
Mac dictation and local models
Built-in Parakeet recognition processes recordings on your Mac. Its initial model download requires internet access; the model host receives normal download-request information, such as your IP address. Subsequent built-in transcription works offline.
If you select a local transcription server, Workbench sends your selected audio and model name to the loopback endpoint you configured. Workbench refuses remote endpoints and redirects. The server is separate software: it may forward audio to other services if configured to do so. Check that server’s settings before using private audio.
Drafts, transcripts, dictionary entries and preferences are stored locally. In the current source Preview, one unfinished Mac capture also retains its recording and recovery text locally until the capture is saved or explicitly discarded. Quit stops recording but keeps unfinished recovery for the next launch. Successful capture saving releases that recovery; imported audio originals are never deleted by this cleanup. Recovery is outside photo and scene sync. Microphone access is used when you start recording. Optional Accessibility access supports automatic paste into your chosen text field. Workbench does not press Return.
Optional text refinement
Original keeps the transcription; Light applies local cleanup rules. Neither mode calls a text-refinement model. Natural can use Apple’s on-device model or an Ollama server you explicitly configure on this Mac. Speech recognition and text refinement are separate choices.
With Ollama selected, Workbench checks model metadata before sending the transcript and editing instructions to your loopback endpoint. It refuses remote endpoints, redirects and models identified as cloud-backed. These checks rely on the server’s responses; they do not audit separate software or prove that a user-configured server never forwards text. Check that server’s settings before using private text.
Model downloads use the internet and the model host receives normal download-request information. Downloading or loading a model is separate from saving it as your refinement choice. Workbench preserves the original transcription and reports when refinement falls back to Light cleanup. It does not silently switch to a cloud text model.
Reading aloud
Mac voices are the default. Optional Speko reading sends the text you choose to read—including clipboard text if you request it—to Speko’s hosted Router and its selected voice provider. Speko may bill accepted text even if you cancel. Your personal API key is kept in this app edition’s macOS Keychain. Removing it returns reading to Mac voices.
When you open or refresh Speko's voice picker, Workbench sends the API key and English/length filters to Speko's catalogue; it does not send your draft for that lookup. Choosing a voice saves its public name and compatible provider/model/voice identifiers in app preferences. Actual reading text is sent only when you choose Listen or Save audio. Speko speech-to-text is not enabled by this picker.
Exported audio is saved where you choose. Workbench does not automatically send it to anyone.
Annotation and presentation
Annotations, saved boards, imported images, persona cards, presentation scenes and preferences are stored locally on your Mac. Enabling personal scene sync also uploads saved scenes and the artwork they contain, as described below. Persona imports create local image copies; the floating card and a saved scene can use the same artwork. Removing a persona from the library retains its image for scenes that still reference it. Drawing uses overlay windows and does not itself record the screen. Selected device capture displays a live device feed; it requires the relevant macOS permission.
QuickTime and iPhone Mirroring open as separate Apple apps. Your meeting or screen-sharing app determines what the audience sees and how it is transmitted. Whole-screen sharing can include floating personas and controls; a separate native overlay is not part of a shared browser tab. Workbench does not upload annotation boards or the standalone persona library. A persona explicitly placed in a synced scene is part of that scene’s uploaded package.
Chrome destinations · Preview
Workbench Preview for Chrome requires the matching Workbench Preview companion for macOS. It saves named web destinations and returns to their explicitly paired Chrome profiles.
The extension handles destination names and profile labels you type, a generated profile identifier, chosen saved URLs, and temporary tab/window identifiers. Opening the popup reads the current tab address locally so you can review it. Query parameters and fragments are removed before an address is saved or sent to the companion; usernames and passwords embedded in addresses are rejected. When opening a saved destination, the extension checks the current or pending addresses of permitted tabs. It does not read page content, forms, stored passwords, cookies or browsing history. It does not sign in or rotate credentials.
Chrome stores the profile label, generated identifier and pairing state locally in that profile. Session storage keeps destination-to-tab bindings and an unfinished save draft. A permission-step draft can be restored for 15 minutes; an expired draft is not used and may remain until overwritten or the browser session ends. Runtime tab IDs do not enter durable extension storage. Chrome Sync is not used.
Chosen names, saved URLs and profile labels pass through Chrome native messaging to the local Workbench app, which owns their canonical Saved resources records on the Mac. The companion supplies this destination list to your connected profiles. Browser destinations are not included in optional Workbench photo or scene sync. This feature sends no destination records to a developer server or other third parties and includes no analytics, advertising or sale of data.
When you choose to open a destination, Chrome contacts that website normally under its own privacy policy. Opening the Workbench website or support links similarly makes a normal web request. The extension does not request account credentials for those sites.
Site access is optional and requested when you choose Allow this site. The extension uses the grant to inspect tab addresses and focus a saved tab. A new tenant subdomain needs a new grant. Chrome may describe the grant broadly as access to that site; this extension has no content scripts and does not inspect or change the page. Incognito is disabled.
You can manage site permissions or remove the extension in Chrome. Removing the extension removes its Chrome-managed local data; closing Chrome clears session storage. Saved resources in the Mac app is separate, so uninstalling the extension does not delete those records. Manage those items in Workbench. Device backups follow your system settings.
Workbench’s use of data received through Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
For privacy questions, use Workbench support. Public issues must not include private destinations or customer details. Security-sensitive information can use private vulnerability reporting.
Selected-photo handoff · optional Preview feature
Optional photo handoff sends only pictures you choose to a private CloudKit container in your Apple Account. It requires a configured, signed build and the same Apple Account on both devices; the notarized Mac Preview includes this configuration. The separate iOS build is in App Store Connect testing preparation. There is no Workbench login, public photo link or full photo-library upload.
The sending device retains the selected original locally. The transferred copy is a freshly rendered JPEG, capped at 3,840 pixels on its long edge, without copied GPS or camera metadata. The picture itself, your optional title, capture time, source-platform label and technical validation data are stored in iCloud. Image contents and titles can still identify people or workplaces. Apple’s iCloud policies and available storage apply; Workbench does not claim end-to-end encryption for this feature.
Turning handoff off stops cloud work and preserves local photos. Cloud removal deletes the selected cloud record, while local copies and pictures already placed in scenes remain independent. Local removal is a separate action. Photo handoff does not transfer recordings, text, scene documents or wallpaper settings. Personal scene sync is a separate choice. Read the delivery and deletion contract.
Optional personal scene sync
In a configured build, enabling scene sync uploads your saved scenes to a private CloudKit database in your Apple Account. It includes existing saved scenes, later edits, scene names, layout and crop settings, and all images referenced by each scene, including placed logos and persona artwork. It is for your own devices using the same Apple Account; there is no shared team workspace or public scene link.
Scene packages retain the image bytes used by the scene and any original artwork kept for recovery. Unlike the rendered JPEG used by photo handoff, imported scene images may retain embedded camera or location metadata. Review the pictures and remove sensitive metadata before importing them if necessary. A portable .workbenchscene export contains these same assets; it is not just a flattened preview.
Sync runs while Workbench is active. Committed edits schedule a transfer after a short pause; delivery depends on connectivity, Apple’s service and the receiving app being active. Turning sync off stops new cloud work and keeps local copies. It does not remove earlier uploads. Changing Apple Accounts pauses transfers and preserves local work.
Deleting a synced scene sends a deletion marker so it disappears from synced libraries. This Preview retains its scene package and assets for recovery; deletion is not a permanent erasure of those bytes from the device or iCloud. A conflicting unsent edit may survive as a separate kept copy. Local photo handoff records, exported files, Photos images and other independent copies are unaffected. Workbench does not yet provide an in-app permanent purge of scene assets.
Apple’s iCloud policies and storage limits apply. Workbench has no developer-operated photo or scene server and does not claim end-to-end encryption for this feature. Recordings, transcripts, standalone persona groups and system wallpaper settings are outside scene sync. Scene preparation and current validation limits.
Shortcuts and other handoffs
In the Apple Shortcuts workflow, Apple’s Record Audio action owns recording and its Stop control. Transcribe with Workbench uses your selected speech engine and returns text. Subsequent shortcut actions determine where that result goes, including services that may sync online.
Copying, dragging, exporting or sharing content puts you in control of its next destination. Those destination apps apply their own policies.
Website and feedback
This website includes no analytics, advertising or feedback database. Vercel receives normal page requests to serve it. Trial progress and draft reports stay in page memory until you close or reload the page.
“Review on GitHub” sends the draft to GitHub for review. Posting an issue or discussion makes it public. Remove private recordings, text, images and identifying details before submitting.
Inside Workbench, the optional founder introduction opens an editable email draft to Ethan and Matt in your usual email app. It includes no transcripts, recordings, device details or usage history. You choose what to write and whether to send it. Workbench does not send email itself; a download does not identify your email address or notify the founders about you.
Your data and questions
Preview keeps its own working data under ~/Library/Application Support/Workbench Preview. Importing earlier Voice or StageMark data copies it; the original stays in place. Replacing the application preserves saved data. Removing the application does not erase those files.
You control permissions in macOS System Settings. We cannot access or remotely erase your local files. For general questions, use Workbench issues. Use GitHub’s private vulnerability reporting for security-sensitive information.