Audio is transcribed on this device. Here's exactly how.
No hand-waving. This page is the whole mechanism — including the parts we can't promise — so you can decide whether it's right for your meeting.
- On your device
Record & transcribe
MediaRecorder captures your microphone (or you upload a file) straight into browser memory — this path does not upload the recording. A Whisper speech model (transformers.js, self-hosted, no HF hub) turns it into text in the same tab. This step sends nothing: its only network traffic is the one-time download of the speech model from this site.
- Still on your device
Detection & cloaking
A WebAssembly tokeniser and a multilingual name model run entirely in your tab over the transcript. They find names, emails, phones, postal addresses, cards, national IDs and IPs, and write a realistic surrogate over each. This step sends nothing: its only network traffic is the one-time download of the name models from this site.
- Leaves your device
Cloaked-text relay
Only the surrogate transcript is sent to a summary model, through the CloakAPI gateway, carrying a cryptographic pre-tokenisation proof (a MAC over the exact bytes). The gateway relays those bytes verbatim. Your audio is not part of the request; every real value the engine detects, and the map back, stay out of the request — anything it misses goes as written, which is why you should check the preview first.
- Back on your device
Re-ink & receipt
The finished summary returns still carrying the surrogates. cloak-meet maps them back to your real values locally, then signs a content-free receipt: category counts, the engine's identity, and the SHA-256 of the exact bytes that egressed. Transcription runs on this device and the relay carries text only, so no audio is sent. The receipt records that the cloaking pipeline ran for that send. It does not measure how much the detector missed: text the engine did not flag — person names outside its dictionary, single-word company names, reference numbers in unfamiliar formats — went as written.
What is guaranteed
- Recording, decoding and transcription all happen in this tab. This path has no upload endpoint for audio.
- A strict Content-Security-Policy limits the connections this page can open to this origin, the CloakAPI gateway (
api.cloakapi.io) and your CloakAPI account (app.cloakapi.io). The browser blocks any other origin. - The cloaking step runs before any relay; it sends no text, and its only requests are same-site model and engine downloads. The relay is fail-closed: if it can't obtain the privacy proof, nothing is sent.
- The summary request carries the cloaked transcript, not the re-identification map, which stays in your browser's memory. Sign-in and billing requests go to your CloakAPI account.
- Your recordings and transcripts are not stored on our server: it serves this site, handles sign-in and billing, and relays the cloaked transcript to the gateway without saving it. It also counts requests for free-tier limits and logs the gateway's error reply when a relay fails.
- A summary produces a receipt whose signature you (or anyone you show it to) can check offline on this page.
What we don't claim
- Transcription accuracy depends on audio quality, accents and background noise, like any speech model. Always glance at the transcript before summarising, and edit it if something's wrong.
- Detection is very good, not omniscient. An unusual identifier the models don't recognise stays in the text — always glance at the "preview what leaves" view before you run.
- What's said around the names still travels. If the words themselves identify someone ("our only left-handed violinist"), cloaking can't hide that — speak with that in mind.
- Surrogates are realistic, gender- and locale-matched where the engine can; for scripts it can't morph, it falls back to a safe neutral stand-in. They preserve fluency, not always exact nationality.
- If the summary model re-spells a surrogate, that altered token simply stays as a safe placeholder in the output rather than being mapped back to a real value.
- The summarising itself is performed by a third-party model via the gateway. It sees the surrogate transcript, and it is billed. That's the one thing that leaves — on purpose.
Verify a receipt
Paste any cloak-meet receipt JSON to check its signature offline. This runs the same on-device verification a recipient would — no server involved.
Where a receipt comes from: after you send something to the AI, a receipt appears with the answer, and its Copy button puts the receipt JSON on your clipboard. Paste it into the box below. "Verify signature" stays off until the box has text in it, so if you haven't sent anything yet you won't have a receipt to check.