Blog1 October 20268 min readby Madhur

Why I open-sourced my Mac app, relay and all

Deiko watches your screen and listens to you talk. That is a lot to ask of a stranger's app. So the app, the pipeline, the memory server and the server in the middle are all on GitHub now, under MIT. Here is why, what it took, and what is still rough.

A white card on a whiteboard headed “Read it, then trust it”, listing the app, the pipeline, the memory server and the relay, with a hand-drawn marker arrow pointing at the relay line and the note “this one too”.

Here is the pitch for Deiko, from the point of view of someone who has never heard of me.

"Hi. Please give my app four macOS permissions, Screen Recording, Accessibility and Microphone among them. It will take screenshots of whatever you point at, read the text under your cursor and record your voice. Some of that goes to a server I run. Trust me, it's fine."

I wouldn't install that. You probably shouldn't either.

Quick refresher if you're new: you double-tap Right Option, point at things on screen and talk, and Deiko turns that into a brief (your words, crops of what you pointed at, the text under the cursor) for Claude Code, Cursor, Codex or a chat window. On 30 September I put all of it on GitHub under the MIT licence. Not just the app. The relay too.

A screen-and-voice app asks for a lot of trust

Every app like this has a privacy page. Mine too. But a privacy page is a promise, words a company wrote about itself, and you can't check it.

Code is something you can check. Here is what Deiko says about your data, and where you can verify each line:

That last line is the one to doubt most. docs/architecture.md walks through the pipeline, and the code that builds a brief, redacts secrets and decides what goes where is in packages/core/src.

Why the relay is in the repo too

A lot of "open source" apps open the client and keep the server closed. That is backwards for a tool like this. The client is what runs on your Mac, where you could at least watch its network traffic. The server is where your audio actually goes.

So the relay, services/relay, is in the repo, about 2,400 lines of plain Node whose only dependency is the AWS SDK for DynamoDB. Here is what it does, straight from the code:

My favourite detail is a paranoid one. The upload is never forwarded as-is. The relay parses it, checks it is the app's own WAV (16 kHz mono, at most 40 seconds), and rebuilds the request from scratch. A verbatim body would let someone add Groq's url field and have Groq fetch an hour of audio off my meter. A privacy page would never mention that. A diff does.

And here's the honest limit of all this: reading the code tells you what the code does, not what is running on my Lambda right now. If that gap matters to you, and for some people it should, don't use my relay. You have two ways out:

  1. Bring your own Groq key. Paste it in Settings and transcription goes straight from your Mac to Groq on your account. The relay never sees your audio.
  2. Self-host the relay. make relay-dev runs it locally with in-memory metering; make relay-deploy puts it on AWS Lambda with a DynamoDB usage table. docs/self-hosting.md is about a page long, and the relay's README lists every setting.

A build made without a relay URL transcribes with your own key or on-device and files briefs locally, with no server of mine anywhere.

A closed Mac app from one person is invisible

The second reason is less noble, and I'd rather say it than pretend.

A closed Mac app from a solo developer has a landing page nobody visits. Developers don't find tools that way. They find them on GitHub, in MCP server directories, in awesome-lists, in someone's dotfiles. All of those point at a repo.

Deiko ships an MCP server (deiko-memory, five tools, runs only on your Mac) that coding agents use to search past briefs and report back what they did. An MCP server you can't read is a hard sell to exactly the people who install MCP servers. Open source puts it where they already look, and lets them read it before they do.

So what does anyone pay for?

Convenience. That's the whole answer.

Deiko is free, and free includes 2 hours a month of hosted transcription per Mac. After that it falls back to Apple's on-device recogniser. Your own Groq key has no cap on my side at all.

What does your own key cost? Groq lists whisper-large-v3, the model Deiko uses, at $0.111 per hour of audio, with a 10-second minimum per request. Deiko sends chunks of about 25 seconds, so the minimum rarely bites. Ten hours of talking costs about $1.11.

The same page lists whisper-large-v3-turbo at $0.04 an hour. Deiko can't use it: turbo doesn't translate, and Deiko asks Whisper to translate, because I narrate half my briefs in Hinglish and transcribing that gives Devanagari that can't be lined up with the on-device word timings. Translating gives Latin text that can.

Pro is $6.99 a month (or $69 a year, or $169 once) for 10 hours of hosted transcription. Yes, that's more than the raw Groq cost. What you're paying for is not making a Groq account, not keeping a key safe, and not thinking about any of this. Some people would rather pay a few dollars than do that. If you wouldn't, the free path isn't a crippled one.

What going open source actually took

Less than I feared, more than flipping a switch.

A layout a stranger can follow. The repo is a monorepo, and each folder is one thing:

PathWhat it is
apps/macosThe menu-bar app in Swift: capture, gestures, voice, the board, hand-off
packages/coreThe Node pipeline: transcription, briefs, filing, task memory and the memory MCP server
packages/alignmentMatches spoken words to what you pointed at while saying them
services/relayThe hosted relay, on AWS Lambda
evalsQuality checks for filing, search and memory
docsArchitecture, privacy, install and self-hosting notes

A licence file that is just the licence. My first LICENSE had a note about third-party components tacked onto the MIT text. I moved that to a NOTICE file and left LICENSE as plain MIT. The app bundles a few things with their own terms (onnxruntime, the on-device search models, a tokenizer, the Bricolage Grotesque font), and their notices live under apps/macos/licenses/.

A history worth reading. Commits follow Conventional Commits, so the log reads like feat(grounding): add region crop and Vision OCR capture all the way back to the first week. So I could publish the real history, not one giant "initial commit".

Cleaning that history first. Two months of working in a private repo leaves private notes and business docs in it. They had to come out of every commit before anything went public, which is a slower job than deleting a folder, since a file removed today is still sitting in last month's commits.

The boring community files. CONTRIBUTING.md, SECURITY.md, a changelog, issue templates and a pull request template.

CI. A GitHub Actions workflow runs the Node tests (pipeline, relay, evals) and the Swift tests for the app's libraries on every push and pull request. The Swift job runs on GitHub's macOS 26 runner, because the app needs Xcode 26.

The gaps I'm not hiding

It isn't notarized by Apple. Notarization needs the Apple Developer Program, which is $99 a year, and I'll join when Deiko earns enough to cover it. Until then the app is signed with its own certificate, macOS quarantines the download, and the install line is:

curl -fsSL https://deiko.app/install.sh | sh

That script downloads the disk image, replaces /Applications/Deiko.app and clears the quarantine flag recursively. The "recursively" matters: the right-click-Open bypass can leave the Node runtime inside the bundle quarantined, and the app then sits at "Transcribing…" forever with nothing pointing at why. Piping a script from a stranger into your shell is exactly what you should be suspicious of, so read it first. It's short. Or skip it and build from source with make install.

It's Mac only. macOS 14 or newer on Apple silicon. Capture leans on macOS Accessibility, screen capture and Vision OCR, none of which travel. The pipeline and the memory server are plain Node working over a folder of files, so they could run somewhere else. I'm not promising a port. I'm saying the parts that would make one possible are readable.

If you want to poke at it

Bug reports, fixes and ideas are welcome. CONTRIBUTING.md has the setup (Xcode 26, Node 22, make setup then make install) and asks you to open an issue before anything bigger than a small fix.

If you find a security problem, please don't open a public issue. SECURITY.md says how to report it: email [email protected] or use GitHub's private reporting. A brief that carries a credential from your screen to an agent counts as a vulnerability, and I want to hear about it.

And if you just want to read the relay and tell me where I'm wrong about metering, I'm @Deiko_App on X.

tl;dr An app that sees your screen should be readable, including the server your audio passes through. So all of it is MIT, there's a self-hosting guide, and your own Groq key skips my server entirely. Pro pays for not managing a key. It isn't notarized yet, so read the install script or build from source.

Questions people ask

Is Deiko really open source?

Yes, under the MIT licence since 30 September 2026. The repo at github.com/maddy30445r/deiko holds the macOS app, the Node pipeline, the memory server and the relay that the hosted version runs on. Third-party notices are in the NOTICE file.

Can I self-host the transcription relay?

Yes. The relay in services/relay runs locally with make relay-dev, or on AWS Lambda with a DynamoDB usage table via make relay-deploy. docs/self-hosting.md walks through it. If you only want transcription, paste your own Groq key in Settings and skip the relay entirely.

Is it safe to install Deiko with curl piped to sh?

Read the script first: it is scripts/install.sh in the repo, and it downloads the current disk image, replaces /Applications/Deiko.app and clears the quarantine flag. Deiko is signed with its own certificate but not notarized by Apple yet, which is why that last step exists. If you would rather not run it, build from source with make install.

Why is Deiko not notarized by Apple?

Notarization needs the Apple Developer Program, which costs $99 a year. I will join when the app earns enough to pay for it. Until then the app is signed with a self-signed certificate.

What does Deiko Pro pay for if the code is free?

Convenience. Pro is 10 hours a month of hosted transcription without managing an API key, for $6.99 a month. Free gets 2 hours a month on the relay, then Apple's on-device recogniser, and your own Groq key has no cap on Deiko's side.