Privacy
What stays on your computer, and what leaves it.
MaxiMouse turns what your webcam sees and what you say into mouse and keyboard input. Hand tracking and speech recognition run on your computer. MaxiMouse never sends video, audio or recordings anywhere.
Updated 2026-10-10 · MaxiMouse is made by Nomadic Dentists LLC (“we”)
The short version
- Camera: frames are read, turned into hand positions on your computer, and thrown away. None are saved or sent.
- Microphone: speech is turned into text on your computer. No audio is saved or sent.
- Private mode, the default, sends nothing about what you say or what is on screen.
- Smart mode, which you turn on, sends the text of commands MaxiMouse doesn't know to TypeSafe AI's Jev service. It switches back to Private whenever a chart program is in front.
- Your plan: the app tells maximouse.io which computer it is so it can check your plan. That is the only connection it makes in Private mode.
- The website has no analytics, no ad trackers and no cookies until you sign in.
What the app works with
Camera frames
MaxiMouse reads frames from the webcam you choose and runs a hand-tracking model (Google MediaPipe Hand Landmarker, which ships inside the app) to find 21 points on each hand. A frame lives in memory only as long as it takes to process. The points drive the cursor, clicks and scrolling, and are then thrown away. Choose Off (voice only) in the Camera menu, or say “camera off”, to close the camera.
The microphone
Voice control is on by default (Settings → Voice → Listening). While it is on, the microphone stays open so MaxiMouse can hear “wake up”. MaxiMouse cuts what it hears into stretches of speech and turns each into text on your computer, with whisper.cpp and a model that ships with the app, and on macOS 26 or later also with Apple's on-device speech recognizer. A safety check decides which sentences may act; everything else does nothing. A thumbs-up records dictation until the next thumbs-up (30 seconds at most) and types it into the field in front of you. The app you install never saves what the microphone hears. Set Listening to Off to close the microphone.
Sound your computer plays
So a video does not drown out a command, MaxiMouse turns the volume down when it hears the wake word while something plays, and back up afterwards. To tell your voice from the video it takes a copy of what other apps play and subtracts it from what the microphone hears. On macOS 14.2 or later this uses a system audio tap, which macOS shows as recording system audio. The copy is used as it arrives and is never kept or sent.
What is on screen
- Control names. For voice commands MaxiMouse asks macOS Accessibility or Windows UI Automation for the names and positions of the buttons, links, tabs, fields and menu items in the front window, so you can say “click export”. They are held in memory for a short time and never written to disk.
- Pictures of a window (macOS, optional). When an app does not name its controls, MaxiMouse takes a picture of the front window, reads its words on your computer with Apple's Vision framework, and deletes the picture at once. This needs Screen Recording permission; without it, only control names are used.
- Snapping. Snapping the cursor onto buttons asks which control sits near the cursor (its kind and its rectangle). No pictures are taken and nothing is stored.
What the app keeps on your computer
- Settings: calibration numbers, preferences, the camera you chose and your voice settings.
- Your sign-in: a random install number made on your computer and a device token, in
account.jsonin the app's data folder. - A Jev API key, if you save one, encrypted with a key held by your system keychain.
- Learned commands: when Jev works out a command, its words, what it did and the front app's name, in
learned-commands.json, so the same words run next time with nothing sent. At most 500 are kept. - Speech corrections: words Apple's recognizer misheard (for example “buckle” for “buccal”) with counts, and short values you said into form fields, in
speech-book.json. Values for fields named like a name, birth date, address, phone, email or ID are never kept. - Recipes: forms you teach MaxiMouse to fill, with the values you used, in
recipes.json. Passwords are never kept. Teach recipes on test patients. - Chart notes: when you say “pull up notes”, the findings you dictate are saved as files in
Documents/MaxiMouse Notesuntil you delete them. If iCloud Drive syncs your Documents folder, they sync too.
Delete any of these files to make MaxiMouse forget what it holds. No video, camera frame, hand position or audio is ever written to disk.
What the app sends
To maximouse.io, to check your plan
When you sign in, the app sends its random install number, your computer's name (so you can tell your computers apart in your account) and whether it is a Mac or a Windows PC. After that it sends its device token when it starts and every 12 hours, and gets back how long your plan runs. If it cannot reach us it keeps working for up to 30 days. Nothing about what you see, say or click is sent.
To TypeSafe AI, only in Smart mode
Smart mode is off until you choose it and save a TypeSafe API key. It sends only commands you say after the wake word that MaxiMouse does not already understand. For those, TypeSafe AI's Jev service receives:
- the words you said after the wake word;
- the name of the front app and the names of your installed apps;
- the kinds of your last five voice commands (for example “scroll” or “click”), not what they clicked or typed;
- only when Jev decides you asked for a click, the names of the buttons, links, tabs, menu items and checkboxes in the front window;
- when a recipe step can no longer find its button or field, the name that step was taught with and the names of the controls in the front window.
Never sent: audio, page text, table cells, images, anything scrolled out of view, chart notes, speech without the wake word, and commands MaxiMouse already knows. Control names can include what is on screen, such as a patient's name on a button. That is why Smart mode switches to Private while a practice-management, imaging or scanning program is in front (Dentrix, Open Dental, Eaglesoft, DEXIS and others, and browser tabs for Curve, Denticon and Dentrix Ascend). If MaxiMouse cannot tell which app is in front, it stays private. For a program it does not recognize, choose Private mode while patient records are open. TypeSafe's own terms govern what it receives.
Shared phrases
A later version may share phrases that worked in Smart mode, so every copy of MaxiMouse needs Jev less. Current versions send none. If we switch it on, the reports will carry no name, email or license, will leave out anything said while a chart program was in front and any phrase with three or more digits or an email address, and you will be able to turn it off under Settings → Diagnostics (Help make MaxiMouse better).
Links you open
Saying “go to” a site or “search for” something opens your web browser, and the browser makes the connection, not MaxiMouse.
The website and your account
- The demo on maximouse.io runs in your browser tab. It downloads the hand model and speech model from maximouse.io once; your camera and microphone stay in the tab and nothing is uploaded.
- No tracking. The site has no analytics, no ad trackers and no third-party cookies. Fonts come from Google Fonts.
- Signing in sets one cookie,
mm_account, that keeps you signed in. We email you a sign-in link through Resend; there is no password. - Paying happens on Stripe's page. Stripe handles your card; we never see the card number. Stripe tells us your email, what you bought and when it renews.
- What we keep: your email address, your plans, the names of the computers you sign in and when each last checked in, and a log of emails we sent you (kept 365 days) and of account changes (kept 2 years). Sign-in links expire within a day.
- Abuse limits use a scrambled, salted form of your IP address that cannot be turned back into the address.
- Hosting is on Cloudflare, which carries every request to the site.
We do not sell or share your information for advertising. To close your account and delete what we hold, email support@maximouse.io.
Health information
MaxiMouse is an input device, not a patient record system, and it does not copy patient records out of the programs you control with it. Some of its voice features can hold health information on your computer: chart notes, recipes and control names held in memory. Whether files kept on your computer need further safeguards in your practice is a question for your compliance adviser; until then, delete chart notes you no longer need and teach recipes on test patients.
Permissions the app asks for
- Camera: to see your hands.
- Microphone: for voice control and dictation.
- Accessibility (macOS): to move the cursor, press keys and read the names of controls.
- Screen Recording (macOS, optional): to read words on screen when an app does not name its controls.
- Automation (macOS): to read menus and the focused field through System Events.
Changes and contact
If a new feature changes any of this, we will update this page and the privacy notice in the app before the feature ships. Questions: support@maximouse.io.