Moro
Home/Privacy and security

Privacy and security

Know what stays local and what leaves.

Moro works close to your cursor, microphone, and selected text. This page explains the boundaries in plain language so you can choose the right mode for each task.

Apple Silicon · macOS 15 Sequoia+ · Windows version in development

What it does

The boundaries that matter

Local-only means local processing

When enabled, supported transcription and AI processing use local backends. Cloud-model tasks are blocked instead of being sent silently.

Cloud use follows your model choice

When you choose a cloud model, the task content is sent to that configured provider under its API terms. Moro does not use your content to train its own models.

Local history stays on the Mac

Sensitive local history is stored on the device, with encrypted fields and keys held in the macOS Keychain, and can be deleted.

Workflow

macOS permissions by purpose

  1. 01

    Microphone

    Required only for voice input and transcription.

  2. 02

    Accessibility

    Used for global shortcuts, cursor context, and writing results back to the active field.

  3. 03

    Optional permissions

    Full Disk Access is for local file search; Screen Recording is off by default and limited to explicitly enabled features.

Common questions

A few details worth knowing

Does Moro read password fields?

No. Secure input fields are detected and skipped.

Can I delete local data?

Yes. Local history and learned preferences can be removed from the app. Exact controls are documented in the product help.

Moro

Take the shorter path from thought to text

Moro private beta is now underway. Apply to receive download access in batches.

Apply for the private beta →