Trust center

Security at Cinder

A practical summary of the protections implemented in the Mac app and release pipeline. This page describes shipped controls; it is not a certification or an independent security audit.

Encrypted local database

Cinder stores local call data in a SQLCipher-encrypted database. Each installation creates its own database key.

Secrets in macOS Keychain

The local database key and Cinder authentication credentials are stored through macOS Keychain rather than in plain-text app storage.

Raw audio is not saved

Call audio is processed in real time. Free audio stays on the Mac for transcription; paid audio is streamed to a transcription provider. Cinder does not save raw call audio.

Plan-specific storage controls

Paid Starter and Pro subscriptions can disable cloud transcript storage and purge cloud transcript copies while retaining local data.

Signed Mac updates

Cinder's release workflow signs and notarizes Mac builds. The in-app updater checks signed release artifacts and waits until an active call ends before restarting.

Your responsibilities

No participant bot joins the call. You remain responsible for giving notice and obtaining any consent required for recording, transcription, or monitoring.

Questions about these practices?

Use Cinder's general support inbox. Include enough detail to route your question, but do not email passwords, full payment-card details, or sensitive call content.

hello@getcinder.ai