Privacy Notice
Last updated: 17 June 2026
Sorrel is operated by an independent developer based in Canada, who is the party responsible for (the controller of) the limited personal data described below. The person accountable for privacy can be reached at [email protected].
Sorrel is built privacy-first. The short version:
- No in-app tracking. Sorrel does not collect reading activity, playback events, or user IDs in the app.
- No account required. You don't sign in to use Sorrel.
- No clipboard monitoring. Sorrel reads the clipboard only when you press the hotkey, tap Paste, or invoke an App Intent.
- API keys stay on your device. If you enable a cloud voice provider, your key is stored in the macOS Keychain, scoped to this device only.
- History is local. Your recent pastes are stored on-device. Nothing syncs to iCloud or to our servers — we have no servers that receive your text.
- Purchases and license delivery use online services. Gumroad handles direct-download checkout. Sorrel's license service uses your direct-purchase details to issue or recover a license key, but it does not receive your pasted text, history, API keys, or playback content. On the Mac App Store, Apple handles that purchase path.
- Software updates use standard update checks. Direct-download Sorrel checks for app updates through Sparkle, using an appcast hosted at sorrelreader.com and update downloads from GitHub Releases. The Mac App Store version uses App Store-managed updates. Update checks do not include your pasted text, history, API keys, or playback content.
Where your text goes
- You paste text into the app, or send it via App Intents (Shortcuts).
- The filter engine strips the patterns you have enabled (URLs, markdown, tables, and so on).
- If you use an Apple voice or the macOS Spoken Content voice, the text is synthesized entirely on your Mac. Your reading text is not sent to Sorrel or to a cloud provider.
- If you opt into a cloud provider (Google Cloud, Gemini, OpenAI, ElevenLabs), the filtered text is sent to that provider's server over HTTPS using the API key you supplied. Sorrel does not proxy or log these requests.
- Synthesized audio is cached in your app's local caches directory so replay doesn't re-hit the provider. The cache is capped and purged automatically.
Third-party cloud providers
When you enable a cloud voice provider, that provider receives your filtered text and handles it under their own privacy policy. Sorrel has no agreement with those providers on your behalf, and is not responsible for how they handle your data or what their service produces. If privacy is your priority, use the built-in Apple and Spoken Content voices, which never send your text anywhere.
- Google Cloud Text-to-Speech — cloud.google.com/text-to-speech
- Google Gemini — ai.google.dev
- OpenAI — openai.com/policies/privacy-policy
- ElevenLabs — elevenlabs.io/privacy
Purchases and license activation
Sorrel is local-first, not network-free. You need an internet connection to download Sorrel, buy a license, receive or recover a direct-download license key, make or restore a Mac App Store purchase, check for software updates, and use any optional cloud voice provider. After a valid direct-download license key is stored, Sorrel verifies that signed key locally on your Mac; it does not need an ongoing license-server check to keep working.
For purchases and license delivery, Gumroad handles payment and sends Sorrel the purchase details needed to fulfill your license. Sorrel's license delivery service may process your buyer email address, Gumroad sale/order identifier, product identifier, assigned license key, delivery status, and timestamps. If Sorrel adds an in-app activation or recovery flow, the app may contact the license service to claim or retrieve the same license key using purchase or license details you provide. That activation flow is only for licensing; it is not used to send your reading text to Sorrel.
On the Mac App Store, Apple handles payment, purchase history, refunds, and Apple ID account records for that channel. Sorrel uses StoreKit purchase status to unlock the Mac App Store build. Direct-download/Gumroad purchases and Mac App Store purchases are separate and do not transfer between stores.
License emails are sent through a transactional email provider. Those providers process the email address and message content needed to deliver the license key under their own terms and privacy policies.
Software updates
The direct-download version of Sorrel uses Sparkle to check for software updates. Automatic update checks fetch an appcast from https://sorrelreader.com/appcast.xml; if you choose to install an update, Sparkle downloads the notarized DMG from Sorrel's public GitHub Releases. These requests include normal web request metadata such as IP address, user agent, date/time, and requested URL as processed by Cloudflare, GitHub, and related hosting infrastructure. The Mac App Store version uses Apple's App Store update mechanism instead of Sparkle.
Update checks are only for app version delivery. They do not send Sorrel your pasted text, reading history, API keys, license key, transcript content, playback events, or Shortcuts run logs.
Shortcuts and App Intents
Sorrel exposes two App Intents you can wire into Shortcuts: Speak Clipboard and Speak Text. Both run on your Mac. Neither watches the clipboard in the background, and neither sends anything over the network when you use an Apple voice. When a Shortcut or App Intent fires, Sorrel reads the supplied text immediately without foregrounding the app. We do not log when Shortcuts run or succeed.
Transcript view
While playback is active, Sorrel shows the text broken into sentences and highlights the one being read. That view is rendered locally from the text you pasted — nothing about it is sent anywhere or written to disk beyond the normal history entry.
Data you can delete at any time
- History: Settings > Privacy > Purge history.
- API keys: Settings > API Keys > Remove (per provider).
- Audio cache: cycles automatically; to clear it manually, delete the Sorrel Caches directory.
Your data, retention & your rights
The personal data I hold off your device is limited to purchase and support records: your buyer email address, Gumroad sale/order details, assigned license key, delivery or activation status, StoreKit entitlement/support details if you contact me about a Mac App Store purchase, and support/refund correspondence if you contact me. I use it to issue, recover, support, and refund direct-download licenses (my basis is performing your purchase), support Mac App Store entitlement questions where possible, and keep the tax and accounting records required by law. I keep license records for as long as your license is active and as needed for support, refunds, abuse prevention, and required business records, then delete them when no longer needed. Gumroad, Apple, Cloudflare, the site's hosting, and the transactional email provider may store or process this limited data outside Canada, including in the United States, under their own policies. You can ask me to access, correct, or delete your Sorrel-held record anytime at [email protected]. If you're in the EU or UK you may also complain to your local data-protection authority; in Canada, to the Office of the Privacy Commissioner.
Contact
For any privacy question, email [email protected].