Beta

Trust levels

You set the ceiling before you speak.

Six levels on one slider, glance by default. What you grant is what mumblemuch keeps until you move the slider again.

You grant capability. It does not take it.

Capability here is one setting, made once and in advance. Six levels sit on the Trust slider in mumblemuch's settings, and they are strictly nested: each level permits everything the level below it permits, and nothing above it. Move the slider and the ceiling moves with it.

The six levels, weakest first

shield

Reads and touches nothing outside its own window. Not the application you are in, not what you have copied. This is the floor.

scrivener

Everything shield permits, plus typing into the application that has focus and reading that application's process name. The clipboard, the selection and the window title belong to the next level up.

glance

Everything scrivener permits, plus reading the clipboard, the selection and the window title, once per request. This is the default.

runner

Everything glance permits, and launching a program.

watch

Everything runner permits, plus a standing subscription to the clipboard and to the foreground application, instead of one read per request.

operator

Everything watch permits, plus driving another program's user interface. This is the ceiling.

Why the default is glance

glance is the level at which the everyday requests already work. Translating what you copied takes one read. Asking what a copied error message means takes another. Neither needs anything watched, and at glance nothing is.

Raising the slider buys one thing at a time. runner admits launching a program. watch turns those one-off reads into continuous ones. operator admits driving another program's interface. Each one is a deliberate move of one slider, made before you speak.

Requests, and the level each one needs

Examples, not a feature list.

You press the dictate shortcut and speak a paragraph. The words land as clean text in the application that has focus. That is scrivener.

You say "translate what I copied", and name the language in the same breath. The clipboard is read once and the translation is pasted back. That is glance, the default.

You copy an error message and ask what it means. The clipboard is read once and the answer comes back. That is glance again.

Launching a program sits above glance, so glance does not admit it. runner does, and the slider stays where you put it until you move it back.

There is more on the actions a trust level admits.

It is not an autonomous agent

One press starts a recording. One press stops it. A spoken request is classified into one continuation, and that continuation runs inside the ceiling you set. When no intent is clear, mumblemuch abstains: nothing runs, and nothing is guessed.

There is no wake word. A run begins when you press and ends when you press again. You can read the steps between a press and a result.

New behaviour arrives the same way. mumblemuch mines its own run history for the patterns you repeat, and each one comes back to you for a decision. It proposes. You approve.

What the levels do not decide

A trust level decides what mumblemuch may read and reach on your machine. It does not decide where your words are processed, or what is kept afterwards.

mumblemuch runs locally by default. Audio, transcripts and history stay on this device, under retention settings you control. Retention is a separate setting from this one, and it is worth reading what is kept and for how long.

Windows carries its own microphone privacy settings as well. They belong to Windows and you set them there: Microsoft's page on the camera, the microphone and privacy says Windows gives you control over which applications can access your camera and microphone.

Beta

mumblemuch is in closed beta. Leave your email below and set your own trust level when it opens up.

There are short answers to common questions if you have one.