Paluku

Talk to your Mac.
It stays on your Mac.

Paluku types what you say, rewrites what you select, and gets things done in your apps. It uses free, open-source models that run locally. No account, no subscription, no audio leaves your computer.

Latest release · macOS 15+ · Apple Silicon · MIT licensed · All releases

The Paluku agent panel answering 'What's on my calendar tomorrow?' with a calendar card, and asking for confirmation before creating a reminder.

Three modes, two keys

Hold a key, speak, let go. Double-tap for hands-free; tap again to stop. Esc cancels at any point, including while the text is still being written.

Hold fn

Dictation

Clean text appears where your cursor is. Filler words and false starts are dropped, and “no wait, make that Tuesday” is applied for you.

Select text, hold fn

Edit

Say “make this shorter” or “translate to Spanish”. The selection is rewritten in place, in any app.

Hold Right ⌥

Agent

Ask a question or give an instruction. It answers out loud and acts in your apps. Point with the mouse to ask about what's on screen.

A pill, not a window

While you talk, a small pill shows the live level and a timer. When you let go it shows “Writing…” until the text lands. Nothing else gets in your way.

  • Hands-free recording for long thoughts (capped at 20 minutes).
  • Media ducking: music lowers while you speak.
  • Your words are never lost: if the model is slow or down, you get the raw transcript.
Recording pill: red dot, level meter, 'Hands-free · tap to stop', 0:12. Pill showing that Paluku is writing the text.

An agent that asks before it acts

Calendar, Reminders, Finder, Notes, Mail, Messages, Music and Spotify, Maps, web search and weather, scheduled tasks, Claude Code and Codex, and any MCP server (Gmail, Google Calendar, Drive, Notion…).

Agent answer with a Files card listing two matching spreadsheets.

Results you can click

  • Cards for files, events, mail and places. Click to open, drag to drop into another app.
  • Switch model from the chip at the top of the panel.
  • Spoken replies with the system voice you pick; start talking to interrupt.
Agent drafted a reply with Copy, Insert + Return and Insert buttons.

Drafts go where you are

  • “Reply saying Thursday at 3 works” writes a draft for the app in front of you.
  • Insert types it at your cursor, Insert + ↩ also presses Return, Copy puts it on the clipboard. Nothing is sent until you choose.
  • Anything that sends, creates, moves or deletes shows a confirmation card first. Say “yes” or click.

Pick any open model, switch any time

Choose separate models for the agent and for dictation. Switching applies to the next request, with no restart. Download models with a progress bar, or point Paluku at another local runtime.

Models tab: runtime Ollama with URL, agent and dictation model pickers, installed models with Use and delete, and a download in progress.
RuntimeBase URLNotes
Ollama (default)http://127.0.0.1:11434Download and delete models from the Models tab.
LM Studiohttp://127.0.0.1:1234/v1OpenAI-compatible; tools and images supported.
llama.cpp llama-serverhttp://127.0.0.1:8080/v1Start with --jinja for tool calling.
MLX-LMhttp://127.0.0.1:8080/v1Fast on Apple Silicon.
Jan · vLLMhttp://127.0.0.1:1337/v1 · your serverOptional API key, stored in the Keychain.

Recommended: gemma4 (vision + tools, 16 GB+), qwen3:30b-a3b for the agent, qwen3:4b for fast dictation on 8 GB Macs. See docs/MODELS.md.

Every screen

The settings window, tab by tab. Screenshots follow your light or dark appearance.

Install

About five minutes, most of it downloading a model.

  1. Install Ollama and a model.

    Download from ollama.com, then run ollama pull gemma4 (or qwen3:4b on an 8 GB Mac).

  2. Install Paluku.

    Download the latest DMG and drag Paluku to Applications, or use Homebrew:

    brew tap gvsrusa/paluku https://github.com/gvsrusa/paluku
    brew install --cask paluku

    If macOS says “Paluku” Not Opened, click Done, then open Privacy & Security and click Open Anyway (the DMG has a link that does this too). Or run xattr -dr com.apple.quarantine /Applications/Paluku.app.

  3. Grant permissions in the Setup tab.

    Microphone, Accessibility (to type), Screen Recording (only for “what's on my screen”), Calendars, Reminders and Contacts. The speech model (~630 MB) downloads on first launch.

  4. Free up the fn key.

    System Settings › Keyboard › “Press 🌐 key to” → Do Nothing, so holding fn doesn't open the emoji picker.

Verify a download: shasum -a 256 -c Paluku-x.y.z.dmg.sha256. Updates: Paluku checks daily (can be turned off) and installs a new version from the menu with one click, after verifying its checksum and signature. Homebrew users can also run brew upgrade --cask paluku.

Privacy and safety

Local by default, careful by design. The full threat model is in docs/SECURITY.md.

What stays on your Mac

  • Speech-to-text runs in WhisperKit on the Neural Engine. Audio is never stored.
  • The language model runs in Ollama or your own runtime.
  • History, dictionary and memory are JSON files in ~/Library/Application Support/Paluku; secrets live in the Keychain.
  • Logs contain event names and timings, never what you said.

What the agent can't do on its own

  • Send, create, move or delete without a confirmation card.
  • Send data out after reading a web page, email or your screen, unless you approve it.
  • Open links to other apps, local-network addresses or executables.
  • Read Library, hidden or system files. Memories picked up from outside content stay flagged until you trust them.
Memory and Schedule tab: remembered facts, one flagged with an orange shield and a Trust button, and scheduled tasks.

You stay in charge of memory

  • Lock facts so the agent can't remove them.
  • Trust a flagged fact once you've checked it wasn't planted by a web page or email.
  • Scheduled tasks run later with the same rules and need a click to approve.

Build it yourself

Swift 6 toolchain, SwiftUI + AppKit, two dependencies (WhisperKit, MCP Swift SDK). All logic lives in a unit-tested Swift package; the app is a thin shell.

brew install xcodegen
git clone https://github.com/gvsrusa/paluku && cd paluku
scripts/build.sh Debug
open build/dd/Build/Products/Debug/Paluku.app
CommandWhat it does
scripts/lint.shswift-format check
scripts/test.shUnit tests, including security abuse cases (no network)
PALUKU_LIVE=1 PALUKU_PERF=1 swift test --package-path Packages/PalukuCore --filter PerfLatency budgets against a real model
scripts/screenshots.shRegenerate every screenshot on this page (demo data, dark + light)
scripts/package.shSigned, notarized DMG when Apple credentials are set
scripts/release.sh 1.3.0 --pushBump, stamp the changelog, tag; CI builds and publishes

CI/CD

Every push runs lint, tests, an app build and UI snapshots on GitHub Actions. A v* tag builds a Release, signs and notarizes it when secrets are present, publishes the DMG with a SHA-256, and updates the Homebrew cask. See RELEASING.md.

Why not the Mac App Store?

The App Store requires the App Sandbox, which forbids typing into other apps, global key monitoring, AppleScript control of Mail and Messages, and launching MCP servers. That is everything Paluku does, so it ships as a signed DMG and a Homebrew cask instead (ADR-0001).