Closed source, inspectable behavior
Check the claims yourself.
Pouchette is closed source, so the useful question is what you can independently inspect. Here is how to observe its network behavior and its public Cloud proxy.
Start with a local-only session
Use Quick notes or a local Ollama engine. Record, stop, review the Wrap, and use Ask. Apart from an optional update check, a local-only session should produce no content egress. You can disable update checks for a cleaner observation.
Use Little Snitch or the free LuLu firewall to alert on new connections. With an external engine selected, the new destination should be the provider you explicitly configured.
Inspect the request boundary
For a deeper inspection, mitmproxy’s macOS local-capture mode can show which transcript lines and notes context an external engine receives. Compare that with the per-session Data Flow Ledger in the app.
Network checks verify egress, not every privacy property. They are evidence you can gather without asking you to trust marketing copy; they are not a substitute for a complete source audit.
Read the code that handles Cloud requests
The optional Cloud proxy is public reference source. It enforces anonymous device-token and budget controls and is designed not to store meeting content.
Read the Cloud worker sourceWhat the app is designed to contact
Local transcription uses loopback communication with the local speech process. Optional destinations include the AI provider you configure, Pouchette Cloud, a one-time model download host, the update feed, and an explicit CLI export destination. The app’s source has an egress-allowlist test so a new outbound host must be deliberately added and reviewed.