How Lyra uses the cloud
The short version
Lyra is private by default. Everyday corrections run entirely on your Mac. Cloud features send only what is listed on this page — cloud-grade polish for the hard cases, voice profiles if you switch them on — and Local-Only mode turns them all off.
On-device does the work. For the harder cases Lyra also asks a cloud model, but the cloud's answer arrives behind the instant local one — you see the on-device fix immediately and it quietly sharpens a beat later. You never wait on the cloud.
This page is the full account: which features run where, what free and Pro each get, how to switch the cloud off entirely, and what our server sees. It is the canonical description — where another page on this site summarises any of it, this page is the detail.
What runs where
| Feature | On your Mac | Cloud | Who |
|---|---|---|---|
| Fix-as-you-type (instant fill) | Always | Never | Everyone |
| Sentence polish — clean English | Yes | No | Everyone |
| Sentence polish — typos, other languages, hard cases | Shows the local result first | Upgrades it a moment later | Pro only |
| Reply & compose drafting | Yes | Yes | Everyone — free is capped at 5 drafts a month |
| Two-tone (⌘⌘) rewrites | Yes — this is the free version | Yes — this is the trial and Pro version | Everyone; the cloud version on the trial and Pro |
| Voice profile classification | Corpus and finished profile stay here | Classifies a sample of your sent messages | Off by default — on only if you enable it. A profile is only ever used on a cloud rewrite, so it mainly affects the trial and Pro |
| First run, while the local model downloads | Not yet available | Temporary bridge, capped | Everyone |
Two things stay on-device forever, by design. Fix-as-you-type fires every fraction of a second — the cloud is simply too slow for it. And the free tier's everyday writing is handled locally, so it stays on your Mac.
Voice profiles (how Lyra learns how you write to each person)
Voice profiles are new, and off by default — none of what follows happens unless you turn them on in Settings. A profile is only ever attached to a cloud rewrite, so it mainly affects the trial and Pro.
Lyra keeps a record of messages you actually sent — your words, as you wrote them — in a local database on your Mac. Messages Lyra rewrote are excluded from this learning, so the profile reflects your voice, not Lyra's suggestions.
To turn that history into a usable profile ("casual with Dave on WhatsApp, professional with Jamie on Outlook"), Lyra periodically sends a small sample of your sent messages for one recipient to our server, which asks the AI model to classify the writing style. The result — a register label and a short list of words you use — is stored back on your Mac. The sampled messages are processed for that classification and are not stored on our servers or used to train anything.
This happens at most once per week per contact, only for contacts you've written to at least 30 times, and only while voice profiles are enabled.
Your controls: turn voice profiles off entirely in Settings; turn them off for one person in "How Lyra sees your writing"; or use Local-Only mode, which disables this along with every other cloud feature. You can view, correct, and delete every profile Lyra has derived.
When the cloud actually fires
On-device handles the common case. Lyra asks the cloud only when the local result is in doubt — a typo the small local model can't fix, another language, a complex rewrite. Clean English is handled on your Mac and is not sent for a cloud rewrite.
In practice that means a normal typist barely touches the cloud at all. Someone writing in French or Hinglish uses it more, because that is exactly where they need it.
Free and Pro
Free
Everyday corrections on the free tier run on your Mac and work fully offline. The only cloud touches are opt-in and metered: a few full cloud rewrites a day (you tap the cloud chip to use one), 5 reply drafts a month, and the one-time first-run bridge described below.
Pro
Pro adds the cloud upgrade on hard cases — other languages, tricky typos, complex rewrites. It is never used for your routine writing, and every request is authenticated as you.
The first-run bridge
Lyra downloads its private on-device model the first time you launch it. Until that finishes there is no local model to rewrite with, so rewrites are served by a secure cloud assist instead. It is temporary and capped — at most 60 rewrites, and at most 10 minutes — and it stops automatically the moment the model is ready. The menu bar shows the model downloading while this is happening. It never happens in Local-Only mode.
Local-Only mode
Settings has a single switch — Local-only mode — that turns off every cloud writing feature. With it on, Lyra uses nothing but the private on-device model: no cloud upgrade, no cloud reply drafting, no first-run bridge, and no voice-profile classification.
You give up quality on the hard cases (other languages, tricky typos, complex rewrites) and keep everything else. It is the one switch that turns "private by default" into "nothing you write is sent anywhere".
Working offline
Your everyday writing needs no connection at all — once the model has downloaded, the on-device path works with the Wi-Fi off. The cloud extras simply pause while you are offline, and are disabled entirely in Local-Only mode.
What our server sees — and does not store
Cloud requests go to a small server we run, which holds the model API key so the app never has to. Concretely:
What leaves your Mac
| Feature | What is sent | When | What comes back | Stored on our servers |
|---|---|---|---|---|
| Everyday corrections | Nothing — runs entirely on your Mac | Never | — | Nothing |
| Cloud rewrite (trial and Pro) | The text being rewritten, plus a short stated style rule. No historical messages. | Only on the hard cases described above | The rewritten text | Not stored, never used for training |
| Voice profile classification | Sample of your sent messages to one contact | Weekly at most, per contact with 30+ messages, only if enabled | Register label + keep-words, cached on your Mac | Not stored |
| Reply & compose drafting | The message you are replying to, the instruction you typed, and up to three of your own past messages to that person as voice examples | Only when you ask for a draft | The draft, for you to review before anything is inserted | Not stored, never used for training |
| First-run bridge | The text being rewritten | First launch only, until the on-device model has finished downloading — capped at 60 rewrites or 10 minutes | The rewritten text | Not stored, never used for training |
| Usage telemetry | Feature-event names and daily counts, app version, macOS version, your Mac's RAM size, local model tier. Never your text. | As you use the app | — | Yes, linked to your account — unless you switch it off in Settings → Privacy |
Reply drafting, compose drafting and the first-run bridge all run under the same server terms set out here. Usage telemetry is the one thing in that table we do keep; it is described in full in the Privacy Policy, and it has its own off switch in Settings → Privacy.
- It sees the text of the specific sentence being upgraded, for the duration of that one request, and your account identity. When you ask for a reply or compose draft it also sees the message you are replying to and the instruction you typed. If you have voice profiles switched on, it also sees the sample of sent messages for the contact being classified. In every case, for the duration of that one request.
- It does not store your text. Nothing you write is retained, logged as content, or used for training — ours or anyone else's.
- There is no shared password in the app. Every request is signed with your own login, so there is no shared secret to leak and every call is tied to a real account.
- Your plan is checked server-side. The server independently confirms whether you are Pro; the app cannot claim it.
- Usage is capped per account. A generous daily limit, well above any real person's use, means a bug or an abuser cannot run up an open-ended bill.
The model provider for the cloud path is Google (Gemini), reached through our server. See Privacy for the full list of subprocessors and what account data we hold.
Questions
If anything here is unclear, or you want a detail we have not covered, email founder@heylyra.co.uk.