How Lyra uses the cloud

The short version

Lyra is private by default. Your everyday writing never leaves your Mac. Cloud-grade polish only for the hard cases — Pro only, and only when it counts.

On-device does the work. For the harder cases Lyra also asks a cloud model, but the cloud's answer arrives behind the instant local one — you see the on-device fix immediately and it quietly sharpens a beat later. You never wait on the cloud.

This page is the full account: which features run where, what free and Pro each get, how to switch the cloud off entirely, and what our server sees.

What runs where

Feature On your Mac Cloud Who
Fix-as-you-type (instant fill) Always Never Everyone
Sentence polish — clean English Yes No Everyone
Sentence polish — typos, other languages, hard cases Shows the local result first Upgrades it a moment later Pro only
Reply & compose drafting Yes Yes Everyone — free is capped at 5 drafts a month
Two-tone (⌘⌘) rewrites Yes No Pro
First run, while the local model downloads Not yet available Temporary bridge, capped Everyone

Two things stay on-device forever, by design. Fix-as-you-type fires every fraction of a second — the cloud is simply too slow for it. And the free tier's everyday writing is handled locally, so free stays private.

When the cloud actually fires

On-device handles the common case. Lyra asks the cloud only when the local result is in doubt — a typo the small local model can't fix, another language, a complex rewrite. Clean English never leaves your Mac.

In practice that means a normal typist barely touches the cloud at all. Someone writing in French or Hinglish uses it more, because that is exactly where they need it.

Free and Pro

Free

Everyday writing on the free tier is 100% on-device. The only cloud touches are the 5 reply drafts a month and the one-time first-run bridge described below.

Pro

Pro adds the cloud upgrade on hard cases — other languages, tricky typos, complex rewrites. It is never used for your routine writing, and every request is authenticated as you.

The first-run bridge

Lyra downloads its private on-device model the first time you launch it. Until that finishes there is no local model to rewrite with, so rewrites are served by a secure cloud assist instead. This is temporary, capped, disclosed in the app while it happens, and stops automatically the moment the model is ready. It never happens in Strict Local-Only mode.

Strict Local-Only mode

Settings has a single switch — Local-only mode — that disables all network use for writing features. With it on, Lyra uses nothing but the private on-device model: no cloud upgrade, no cloud reply drafting, no first-run bridge.

You give up quality on the hard cases (other languages, tricky typos, complex rewrites) and keep everything else. It is the one switch that turns "private by default" into "private, absolutely".

Working offline

Your everyday writing needs no connection at all — once the model has downloaded, the on-device path works with the Wi-Fi off. The cloud extras simply pause while you are offline, and are disabled entirely in Strict Local-Only mode.

What our server sees — and does not store

Cloud requests go to a small server we run, which holds the model API key so the app never has to. Concretely:

The model provider for the cloud path is Google (Gemini), reached through our server. See Privacy for the full list of subprocessors and what account data we hold.

Questions

If anything here is unclear, or you want a detail we have not covered, email founder@heylyra.co.uk.