Privacy Notice

Last updated: 7 September 2026

Sorrel is operated by an independent developer as a sole proprietor in Canada, who is responsible for the limited personal data described below under applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies. The person accountable for privacy can be reached at me@julyskyfly.com.

Sorrel is built privacy-first. The short version:

Editions and version scope

Sorrel for iPhone offers Sorrel Voice local neural voices and Apple on-device voices, with no cloud voice providers or API-key settings. The Kokoro model and voice assets used by Sorrel Voice are bundled with the app; Sorrel does not download them on demand. On Mac, the direct-download edition offers optional bring-your-own-key cloud voices (Google Cloud TTS, Gemini, OpenAI, and ElevenLabs) in addition to local Apple/System Voice playback. The Mac App Store edition, version 1.0.5 or later, includes only local Apple/System Voice paths and has no API Keys settings or cloud provider endpoints.

The Mac App Store 1.0.4 build still exposes optional BYOK cloud voices. If you use that older build and opt into a cloud voice, its text handling is the same as the direct-download cloud path below. The cloud-free claim applies only to the 1.0.5-or-later Mac App Store update.

Where your text goes

  1. On iPhone, you provide text by typing or pasting into the editor, using Paste & Play, or choosing Read in Sorrel from another app's share sheet. On Mac, you can also use the optional hotkey, Speak Clipboard or Speak Text from Shortcuts, or Read Selection with Sorrel from macOS Services.
  2. The filter engine strips the patterns you have enabled (URLs, markdown, tables, and so on).
  3. With Sorrel Voice or an Apple voice on iPhone, or an Apple voice or Mac System Voice on Mac, the filtered text is synthesized on your device. Reading text is not sent to Sorrel or a cloud voice provider for these local voice paths. These are the only voice paths in the iPhone edition and Mac App Store 1.0.5 or later.
  4. In the direct-download Mac edition (or the legacy Mac App Store 1.0.4 build), if you opt into a cloud provider (Google Cloud, Gemini, OpenAI, ElevenLabs), the filtered text is sent to that provider's server over HTTPS using the API key you supplied. Sorrel does not proxy or log these requests.
  5. Sorrel Voice, Mac System Voice, and cloud-provider audio can be cached in the app's local caches directory for replay. On iPhone, this also includes word-timing data for Sorrel Voice highlighting. The cache has a 200 MB limit and automatically trims older entries.

Local storage and system backups

History and settings: With Keep history enabled, Sorrel saves the original and filtered reading text, date, selected voice/provider, and playback duration locally. Settings such as voice choice and filter rules are also stored locally. Turning history off stops new history entries; existing entries remain until you erase them.

iPhone share handoff: Read in Sorrel writes the text you share, an identifier, and a timestamp to a local container used by Sorrel and its share extension. The pending share is removed when the app reads it, or replaced by a newer share. It can remain there while Sorrel is closed; it is not uploaded to a Sorrel server.

System backups: Sorrel does not sync reading history between devices. Local app data, including saved readings and pending shared text, may be included in ordinary system backups, such as iCloud Backup, an iPhone backup on your computer, or a Mac backup, depending on your settings. These backups are managed separately through your system or backup provider; Sorrel does not receive them. Erasing history in Sorrel does not remove copies already held in backups.

Third-party cloud providers

Cloud voices are available only in the direct-download Mac edition (and remain present in the legacy Mac App Store 1.0.4 build until it is updated). When you enable one, that provider receives your filtered text and handles it under their own privacy policy. Sorrel has no agreement with those providers on your behalf, and is not responsible for how they handle your data or what their service produces. The local voice paths described above do not send reading text to a cloud voice provider.

Purchases and license activation

Sorrel is local-first, not network-free. You need an internet connection to download Sorrel, buy a license, receive or recover a direct-download license key, start or restore an App Store trial/purchase, check for software updates, and use any optional direct-download cloud voice provider. After a valid direct-download license key is stored, Sorrel verifies that signed key locally on your Mac; it does not need an ongoing license-server check to keep working.

For direct-download Mac purchases and license delivery, Gumroad handles payment and sends Sorrel the purchase details needed to fulfill your license. Sorrel's license delivery service may process your buyer email address, Gumroad sale/order identifier, product identifier, assigned license key, delivery status, and timestamps. If Sorrel adds an in-app activation or recovery flow, the app may contact the license service to claim or retrieve the same license key using purchase or license details you provide. That activation flow is only for licensing; it is not used to send your reading text to Sorrel.

For the iPhone and Mac App Store editions, Apple handles payment, purchase history, refunds, and Apple Account records. Sorrel's 14-Day Trial is an explicit free StoreKit non-consumable on iPhone and in Mac App Store 1.0.5 or later. Its verified purchase date starts a one-time 14-day playback window shared by those editions under the same Apple Account. Restoring the trial uses the original dates; it does not restart the trial. The trial does not renew or automatically charge you. The full unlock uses the localized price shown by the App Store. After the trial, continued playback requires the separate one-time StoreKit full unlock. That universal purchase unlocks both the iPhone and Mac App Store editions on your compatible devices using the same Apple Account; Restore Purchases can recover an existing purchase. Sorrel uses verified StoreKit purchase status to determine access. Direct-download/Gumroad licenses are separate and do not unlock either App Store edition, and App Store purchases do not provide a direct-download license key.

License emails are sent through a transactional email provider. Those providers process the email address and message content needed to deliver the license key under their own terms and privacy policies.

Software updates

The direct-download version of Sorrel uses Sparkle to check for software updates. Automatic update checks fetch an appcast from https://sorrelreader.com/appcast.xml; if you choose to install an update, Sparkle downloads the notarized DMG from Sorrel's public GitHub Releases. These requests include normal web request metadata such as IP address, user agent, date/time, and requested URL as processed by Cloudflare, GitHub, and related hosting infrastructure. The iPhone and Mac App Store editions use Apple's App Store update mechanism instead of Sparkle.

Update checks are only for app version delivery. They do not send Sorrel your pasted text, reading history, API keys, license key, transcript content, playback events, or Shortcuts run logs.

Mac Shortcuts, App Intents, and Services

Sorrel exposes two App Intents you can wire into Shortcuts: Speak Clipboard and Speak Text. Both run on your Mac. Neither watches the clipboard in the background, and neither sends anything over the network when you use an Apple voice. When a Shortcut or App Intent fires, Sorrel reads the supplied text immediately without foregrounding the app. Clipboard access happens only during a Speak Clipboard run. We do not log when Shortcuts run or succeed.

Sorrel also advertises a macOS Services item, Read Selection with Sorrel. When you choose it from another app's Services or Quick Actions menu, macOS passes the current selected text through a temporary pasteboard for that explicit action. Sorrel reads the selection immediately and does not replace or monitor your general clipboard.

Transcript view

While playback is active, Sorrel renders the transcript, scroll position, and active-word or active-sentence highlight locally. Sorrel does not send transcript UI state or highlight activity to its servers. Reading text follows the selected voice path described above. On iPhone, Sorrel Voice word-timing data may be saved with cached audio to support highlighting on replay; history is stored separately when enabled.

Data you can delete at any time

Your data, retention & your rights

The personal data I hold off your device is limited to purchase and support records: your buyer email address, Gumroad sale/order details, assigned license key, delivery or activation status, StoreKit entitlement/support details if you contact me about an iPhone or Mac App Store purchase, and support/refund correspondence if you contact me. I use it to issue, recover, support, and refund direct-download licenses (my basis is performing your purchase), support App Store entitlement questions where possible, and keep the tax and accounting records required by law. I keep license records for as long as your license is active and as needed for support, refunds, abuse prevention, and required business records, then delete them when no longer needed. Gumroad, Apple, Cloudflare, the site's hosting, and the transactional email provider may store or process this limited data outside Canada, including in the United States, under their own policies. You can ask me to access, correct, or delete your Sorrel-held record anytime at me@julyskyfly.com. If you're in the EU or UK you may also complain to your local data-protection authority; in Canada, to the Office of the Privacy Commissioner.

Contact

For any privacy question, email me@julyskyfly.com.