Every process, permission and network call it makes, drawn. The AI runs on this Mac, and nothing from your class leaves unless you turn it on. Beyond the Zoom meeting itself, only update checks and anonymous usage counts leave by default, and the usage counts have a switch.
01 · The whole system
ws:4455 socket only at 127.0.0.1, the address that means this Mac. Pages you open exists only when Greenroom Browser is your main app: that window is Apple's WebKit (the engine inside Safari) running in Greenroom's process, so the sites you visit load from Greenroom rather than from Chrome. Its history is one local file, its cookies live in WebKit's standard store, and nothing about your browsing is reported anywhere.02 · Press Start
03 · Window access
activate, new window, set bounds and the address you configured. No history, no tabs. Chrome-type browsers accept these. Other browsers, such as Safari, open the page normally and are placed with Accessibility. Greenroom Browser needs neither route: it is Greenroom's own window, so there is nothing to read from and nothing to automate.04 · Permissions
You approve each of these yourself and can revoke any of them in System Settings → Privacy & Security. Greenroom can't grant itself anything.
Zoom's Meeting SDK runs inside Greenroom, so the camera is opened in its process — that's exactly why it holds this. In a class it is used for the meeting: your composited picture, read from the OBS Virtual Camera, on its way to Zoom. Screenroom opens a camera too, only while the Screenroom window is open, and a recording goes to presentation.mov in that presentation's folder. During a class, camera switching does not open a camera itself: it reads frames of your cameras from OBS over the localhost socket and hands them to Apple's Vision framework on this Mac (see camera switching). When you aim a camera in Settings, Greenroom opens that camera itself for the preview. Either way the picture stays on this Mac.
Three readers of the same device inside a class: Zoom's SDK sends your voice to the meeting; the participants panel's level meter shows whether it hears you; and, only with Cues turned on, Apple's speech model or whisper turns it into text on this Mac. Cues reads the default input device — never Zoom's incoming audio — and pauses while you are muted in Zoom. The text is saved as transcript.txt in that class's folder, beside its recording, with the suggested cards in cues.txt, so you have the record of what was said; a switch in Settings → Cues turns that off and keeps both in memory only. Either way the audio and the transcript stay on this Mac. macOS asks no additional permission for Cues: it is the same microphone grant, and no speech-recognition service is involved. The one reader outside a class is Screenroom, only while its window is open; a recording's audio goes into presentation.mov on this Mac.
Broad by design — macOS has no narrower option. The honest safeguard is the code: it only ever touches the window values in the diagram above, on named windows. Verifiable in AppWindowManager.swift. Not used at all for the main pane when Greenroom Browser is the main app.
Tried for any browser you pick as the main app, and macOS asks per-app the first time. Chrome-type browsers (Chrome, Edge, Brave, Ulaa…) accept it. Others, such as Safari, are placed with Accessibility instead. Greenroom Browser needs no Automation permission.
Asked for when Screenroom transcribes with Apple's recogniser instead of whisper. That recogniser can quietly send audio to Apple when its local model is missing, so Screenroom pins it to on‑device and refuses to transcribe rather than let that happen. With whisper this permission is not used at all.
For the class itself, OBS holds this permission and does the capture; Greenroom only hands it the identifier of the display to show. Greenroom has screen-capture code of its own for one thing: Screenroom can record a presenter from a screen or a window, for example a remote student in a meeting window, with the Mac's sound. macOS asks Greenroom for Screen Recording the first time you pick that source, and never if you only record with a camera.
⌥⌘ + G / X / R / S / Z / 1 / 2 / 5. macOS reports only that one of those eight was pressed — it cannot see anything else you type. Control is deliberately not in the combination: Control-Option is VoiceOver's own modifier, so those presses are swallowed whenever VoiceOver is running.
05 · Every network call
Four are Greenroom's own. Two exist only when you choose Greenroom Browser as the main app, and one of those has its own switch. The seventh carries class content — your recording — and the eighth carries the search phrases Cues builds from what you say. The ninth is not Greenroom's at all: it is whatever the agent you give Screenroom does with a presentation. All three are off until you turn them on. The tenth happens only when you set up a speech model, and carries nothing of yours.
Your meeting audio, video and chat, and requests to create or join your own meetings — through Zoom's official software. Identical to using Zoom directly. Before creating a meeting it checks for meetings already live and ends any meeting still live on your account, for example one a crash left open. Zoom allows a host one live meeting, so a leftover would make the new class fail to start. It says so in the status log whenever it does this. It lists your scheduled meetings only when you open Join Existing.
A periodic update check and the download if you accept one. EdDSA-signed, verified against a key inside the app, so only genuine releases install.
Anonymous usage analytics: which features get used, which settings are switched on or off, roughly how long a session ran, whether something failed, and a crash report if Greenroom crashes. Counts, coarse durations and enum codes only — never student names, meeting IDs, file paths, web addresses or chat, because the status log those events are derived from is deliberately never forwarded. The chosen main app is reported as one of four kinds, never by name. Settings → Layout → Privacy turns it off, crash reports included, which stops every call including registering this Mac.
Only when Greenroom Browser is your main app. It is Apple's WebKit — the engine inside Safari — running in Greenroom's process, so the sites you visit load from Greenroom instead of from Chrome, and see the same request any browser would send. Cookies and sign-ins stay in WebKit's standard store under ~/Library; the visited-pages list is one local file, ~/Library/Application Support/Greenroom/browser-history.json, with a Clear History button. Nothing about your browsing is sent anywhere else.
While Settings → Layout → Suggest searches as you type is on, each keystroke in the address bar is sent to Google for completions — exactly what Chrome and Safari do. Switch it off and only your own history is suggested; nothing leaves until you press Return.
The one channel that carries class content: when Settings → YouTube is set to ask or to upload automatically, a finished recording — the shared screen with you in it, and your voice — is uploaded over HTTPS to the connected Google account's channel, unlisted or private as you chose. Sign-in happens in your browser on Google's own page; Greenroom keeps a token with YouTube's manage-your-videos permission, the narrowest one that can rename a video. It uses it to upload, to rename uploads, to delete an upload when you press Delete and confirm, and for Cues video search if you allow that. Nothing else. Disconnect revokes it at Google. With “Do nothing” selected (the default) this channel does not exist.
Only with Settings → Cues on. When you name a book, a video, a topic, a person, a place, a product or a quotation, the short search phrase Cues built — a title or a name, a few words — goes over HTTPS to Google Books and Open Library at the same time (books), to Wikipedia's title search (topics, people, places, products), to Wikiquote (quotations), and, if you allow it and a Google account is connected, to the YouTube Data API (videos). Where no service fits, the card is a search link that sends nothing until you open it. A word you ask the meaning of is looked up in the Mac's own dictionary and sends nothing. Never the audio, never the transcript. A phrase matching a name in the meeting is dropped before any request, unless it is inside a quotation, which is sent as it was said. Each phrase sent is written to the status log and to ~/Library/Logs/Greenroom-session.log, with the host it went to. Card pictures come from those services' image servers, in a separate request that carries no phrase and is not logged. Capped at 80 lookups a class and 12 a minute; a fixed User-Agent names Greenroom.
Only with Settings → Screenroom → Hand each presentation to my agent on. Greenroom runs the agent you chose — Claude Code, Codex, or a command of your own — through zsh as a login shell, with your own profile, and it reads the presentation's transcript, your notes, a still every 20 seconds, the counts, the rubric and the student's name. Greenroom makes no network call for this; the agent does, to wherever it runs its model. For Claude Code and Codex that is their own service. For your own command, only you know. See Screenroom for exactly what it can reach.
Setting up a speech model. Choosing Apple's model for Cues downloads it once from Apple, through macOS's own asset service. For whisper, in Cues or Screenroom, Download fetches a model file over HTTPS from huggingface.co/ggerganov/whisper.cpp into ~/Library/Application Support/Greenroom/whisper, with progress and Cancel. Install runs your own Homebrew (brew install whisper-cpp), which fetches the program the way Homebrew always does; its output is shown as it runs. Both are one-off downloads: nothing about you, your class or your recordings is sent, and nothing downloads without a press. The recommended model is 465 MB; the largest offered is 1.5 GB.
Greenroom talks to OBS only at 127.0.0.1, the address that means this Mac. The password is fixed and published in the source, so it stops accidents rather than a program already running on your Mac. Recordings are written to a folder per session under ~/Documents/Greenroom, with any clips you mark beside them.
This socket is also how a clip is saved after the fact — see the clip buffer below for the full machinery.
06 · The clip buffer
Press ⌥⌘1, 2 or 5 after a good moment and the last one, two or five minutes appear as a file — even with recording off. Here is the machinery, exactly.
RecRB=true and RecRBTime=300 into OBS’s own config before launch and arms it at session start. It holds the composited picture — the same screen the class sees — encoded in memory, oldest seconds continuously discarded. A hotkey triggers one SaveReplayBuffer over the loopback socket; Greenroom then trims the saved file to the requested minutes with a passthrough export (a byte-for-byte copy that cuts at a keyframe, so nothing is re-encoded or degraded) and files it in the session’s folder. Nothing persists unless you press the key, and the buffer never leaves the machine. The buffer is a setting, Keep the last 5 minutes clippable in Settings → Webcam, on by default. While a recording is running, the key marks the recording instead, and the clip is cut from the finished file after the class.07 · Cues
Off by default, and it needs macOS 26: on macOS 14 and 15 the Cues tab says so and nothing listens. You turn it on in Settings → Cues (or during onboarding) and, while a class is live, Greenroom listens to your microphone and offers link cards for what you mention. Nothing opens by itself: you click Open, or send the card to the chat. Here is the pipeline, with the one point where anything crosses.
SpeechAnalyzer or, if you pick it in Settings → Cues, whisper.cpp — a binary and a model file on this Mac, the same model Screenroom uses. The transcript is written to transcript.txt in the class's folder as each sentence is finalised, so a class that crashes keeps what was said; Settings → Cues turns that off. It is written to your disk, never sent anywhere. Only finalised sentences are used; the in-progress guesses go nowhere. Detection runs on the new sentences plus twenty words of lead-in, as each sentence finishes (every eight seconds or so with the opt-in model). A card exists only after a lookup answered with a title and a page, with two exceptions that send nothing: a “search link” card, which points at a search page, and a word's meaning from the Mac's own dictionary. Five cards show at once, twelve are kept, a class gets eighty lookups, and a dismissed card stays dismissed for the class. Every card shown is listed in cues.txt in the class folder, unless saving is off. The Links tab in Sessions keeps the ones you opened or sent. The whole engine is App/Cues/, and every line the status log writes for it begins with Cues:.08 · Screenroom
Screenroom records a student presenting, lets you type notes timed into the recording, counts how the talk went, and writes feedback against your rubric. Open it from the main window's Screenroom button or Open Screenroom… in the menu bar. It runs on macOS 14 or later; only one of its three ways of writing feedback needs macOS 26. Almost all of it happens on your Mac. Here is the pipeline, with the one part that can leave.
brew install whisper-cpp and a downloaded model; the commands are in Settings → Screenroom), because Apple's recogniser tidies “um” and “you know” away before Screenroom sees them; with it, fillers show “Not counted” rather than a confident zero. Each rubric line gets a score and a reason. The report is a window on your Mac; exporting it asks where the file goes.A camera and microphone, or a screen or window with the Mac's sound, written straight to presentation.mov in a folder of its own under ~/Documents/Greenroom. A presentation needs no name, and one can never overwrite another. The screen or window source is the one thing in Greenroom that asks for Screen Recording of its own; with a camera it is never asked.
Two engines, both local. whisper.cpp is a binary on your Mac reading a file on your Mac, and it returns what was actually said. Apple's recogniser is the other, and Screenroom pins it to on‑device: it refuses to transcribe rather than fall back to Apple's servers, which that recogniser would otherwise do silently when a local model is missing.
Your agent, if you have set one up. Otherwise Apple's on‑device model, which needs macOS 26 with Apple Intelligence turned on; nothing crosses. Otherwise the counted report and your notes, with no written feedback. The report says which one wrote it.
Screenroom can hand a presentation to a command‑line agent you already have — Claude Code, Codex, or any command you write yourself. This is the one part of Greenroom that can send your material to a third party, and the only feature whose destination Greenroom does not control. It is off by default: Settings → Screenroom → Hand each presentation to my agent.
What that means concretely, when and only when you have turned it on:
Greenroom writes BRIEF.md into the presentation's folder, so you can read exactly what is being asked in your student's name.
It runs through zsh as a login shell, with your own profile and credentials. Greenroom holds no API key and has no account of its own.
The transcript, your notes, a still every 20 seconds, the counts, the rubric and the student's name. Audio and video are not sent by design: the brief points the agent at those files and nothing else.
Before the agent starts, Greenroom copies the brief, the transcript, your notes, the counts, the rubric and the stills into a temporary folder, and the agent works there. presentation.mov is not copied, and the temporary folder is deleted when the agent finishes. The default commands for Claude Code and Codex start it read-only in that copy (--allowedTools "Read,Glob,Grep" and -s read-only), and Greenroom saves what it prints rather than letting it write files. Those limits are the agent's own: Codex's read-only mode can still read other files on your Mac if asked, and a command you write yourself gets whatever limits you give it. If the copy cannot be made, for example on a full disk, the agent runs in the presentation's own folder instead, where presentation.mov is.
Whatever that agent then does with a transcript and photographs of a named student is between you and it. If its model is a cloud service, that material leaves your Mac. Greenroom cannot say where it goes and does not pretend to. This is the only feature on this page whose destination is not ours to describe.
The switch is off, the default is that no agent runs, and every other part of Screenroom works without it.
09 · Camera switching & summaries
Both are new in 0.9.0. Camera switching is a switch, off by default; the class summary is a button you press.
Settings → Webcam: pick two or more cameras and turn it on. An iPhone through Continuity Camera can be one of them. During a class every chosen camera is open in OBS, and only one is shown. Greenroom reads frames of each of them over the localhost socket, and Apple's Vision framework works out which way your head is turned, on this Mac. It compares the cameras: the class gets whichever one sees your face most head-on, once it is clearly better than the live one for the delay you set, 1 second by default, as a cut or a short crossfade. It reads head direction, not your eyes. Looking at the floor, or away from every camera, switches nothing. The first camera opens at Start and the others once the meeting is live. Nothing is sent anywhere; the only thing that changes is which camera the class sees.
In Sessions, a class's Transcript tab has Summarise on this Mac. Apple's on-device model reads that class's transcript and writes summary.md into the class folder. It never makes a cloud call. It needs macOS 26 with Apple Intelligence turned on, and a transcript, which means Cues was on for that class.
10 · For your IT team
Every way the app touches the system, with its exact scope — all verifiable in the open-source code. Greenroom runs on macOS 14 or later; the rows that need macOS 26 say so.
| Capability | How | Scope / limit |
|---|---|---|
| Move windows | AXUIElement | Reads title/size/position; sets position/size/minimized. Named apps only. No contents, no pixels. |
| Open browser window | Apple Events via osascript | Tried first for any browser you pick; Chrome-type browsers (Chrome, Edge, Brave, Ulaa) accept it, others are placed with Accessibility. activate, new window, set bounds & configured address, and, only if you turn it on, close that one window at End Session. No history/tab access. |
| Built-in browser | WKWebView (Apple WebKit) | Renders the pages you open in Greenroom's own window when Greenroom Browser is the main app. Persistent cookies in WebKit's data store; history in one local JSON file under Application Support; downloads to ~/Downloads; no extensions. Optional Google completions behind one switch. |
| Screen & camera capture (class) | Performed by OBS | For a class, Greenroom does no capture of its own; it resolves display/camera identifiers only. |
| Recording (Screenroom) | AVFoundation; ScreenCaptureKit for the screen source | Only while you record a presentation. A camera and microphone, or a screen or window with the Mac's sound, to presentation.mov in its own folder under ~/Documents/Greenroom. Screen Recording permission is asked for only when you pick a screen or window. |
| Transcription (Screenroom) | whisper.cpp, or Apple SFSpeechRecognizer | whisper is a binary from Homebrew (brew install whisper-cpp, which Settings can run for you) plus a model downloaded from huggingface.co with a button; it reads a file on this Mac. Apple's recogniser is pinned to on-device and refuses to run rather than send audio to Apple; it needs the speech-recognition permission. |
| Counts (Screenroom) | Arithmetic over timestamps; Apple Vision | Pace, filler words (whisper only), pauses of 2 s or more, and facing the room (head direction within 20°). No model writes these numbers. |
| Written feedback (Screenroom) | Your agent, or Apple FoundationModels | The first that is set up: your agent (off by default), run through zsh as a login shell, reading the transcript, notes, stills every 20 s, counts, rubric and the student's name; it works in a temporary copy of the folder without presentation.mov (or in the folder itself if the copy fails), and the default Claude Code and Codex commands are read-only there. Otherwise Apple's on-device model, on macOS 26 with Apple Intelligence on. Otherwise the counted report only. |
| Camera switching | OBS GetSourceScreenshot + Apple Vision | Off by default; needs two or more cameras. Every chosen camera is open in OBS and one is shown. Reads frames of each over the localhost socket and checks head direction on this Mac; switches to whichever camera has your head most head-on, once it is clearly better for 1 s by default. Extra cameras open only once the meeting is live. Nothing sent. |
| Class summary | Apple FoundationModels (on-device) | Only when you press Summarise on this Mac in Sessions. Reads the class transcript, writes summary.md into the class folder. Never a cloud call. macOS 26 with Apple Intelligence on, and a transcript from Cues. |
| Global shortcuts | Carbon RegisterEventHotKey | Eight fixed combos (⌥⌘ G/X/R/S/Z and 1/2/5). Receives an opaque ID only — no event taps. |
| Launch/quit apps | NSWorkspace | OBS, Zoom, and your chosen main app. |
| Meetings | Zoom Meeting SDK + REST | Creates/joins meetings under your own Zoom account with your Marketplace credentials; before creating one, ends any meeting still live on the account (for example one a crash left open); lists scheduled meetings only for Join Existing. |
| Usage analytics | Zoho Apptics SDK | On by default; Settings → Layout → Privacy turns it off, which stops every call. Anonymous feature counts, coarse durations and error codes, and a crash report if Greenroom crashes. Never names, meeting IDs, file paths, web addresses or chat. |
| Updates | Sparkle, EdDSA-signed | Appcast on GitHub Pages; installs only releases signed with the developer's key. System profiling disabled. |
| YouTube upload | YouTube Data API v3, OAuth 2.0 (PKCE, loopback) | Off by default. Resumable upload of a finished recording to the connected account's channel, and title changes and deletes from the Sessions window; scope youtube.force-ssl (manage the account's videos), also used for Cues video search when that is on. Refresh token stored like the Zoom credentials (plain preferences); revoked at Google on Disconnect. |
| Speech to text (Cues) | Apple SpeechAnalyzer / SpeechTranscriber, or whisper.cpp | macOS 26, off by default. whisper is selectable in Settings → Cues and uses the same local model as Screenroom. Own AVAudioEngine tap on the default input device only; runs between the meeting going live and End Session, or for two minutes when you press Try it in Settings. Text held in memory (≤ 90 s) for matching, and written to transcript.txt in the class folder unless that is switched off. Never in analytics, never sent anywhere. Model asset from Apple via the system asset service, downloaded once from Settings. No speech-recognition permission involved. |
| Mention detection (Cues) | Apple FoundationModels (on-device) or regex + NLTagger | Reads the new sentences and returns up to five short phrases with a kind, plus a fuller search query built from the surrounding words. Off by default: measured against a recorded class it found everything but suggested about twenty-five wrong cards for every right one, so a teacher turns it on knowingly. Roster names (meeting participants, waiting room, you) are excluded, except inside a quotation; an exact match is also written to the log. FoundationModels.framework is weak-linked so the app launches on macOS 14/15, where the tab says the feature needs 26. |
| Link lookups (Cues) | URLSession, HTTPS, fixed User-Agent | Wikipedia REST title search (the richer phrase and the bare name at once); Google Books (keyless) and Open Library at once; Wikiquote for quotations; YouTube Data API search.list only with a connected account and the switch on, otherwise a search-page link. Before anything is sent: the phrase must have been spoken, a lone word that is in the Mac’s dictionary is dropped unless it was said as a name, and roster names are dropped (quotations excepted). Per class: 80 lookups, 12 a minute, 20 YouTube; two in flight; five-minute back-off after three failures per host. Every lookup logged with its phrase and host; card pictures are fetched separately and not logged. |
| Entitlements | Hardened Runtime | device.camera, device.audio-input. Nothing else. Screen Recording and speech recognition are macOS privacy permissions rather than entitlements, and macOS asks for them only when Screenroom uses them. |
| Frameworks | Apple's own + Zoom SDK + Sparkle + Zoho Apptics | AppKit, SwiftUI, WebKit, AVFoundation, ScreenCaptureKit, Vision, ApplicationServices, Carbon, CryptoKit, NaturalLanguage; Speech and FoundationModels weak-linked. No cloud AI SDK. Every model Greenroom runs is Apple's or whisper, on the Mac. The one route to a model elsewhere is Screenroom's agent, which is your program, not Greenroom's. |
| macOS versions | — | macOS 14 or later. Needs macOS 26: Cues; the class summary (with Apple Intelligence on); Screenroom's written feedback when no agent is set up (with Apple Intelligence on). Screenroom's recording, notes, transcription, counts and agent feedback run on macOS 14. |
11 · Full honesty
The Zoom app credentials you enter, and the YouTube sign-in token if you connect a Google account, are saved in Greenroom's local preferences as plain text — not encrypted. Greenroom doesn't use the macOS Keychain at all. They never leave your Mac except to Zoom and Google respectively. The risk is purely local: anyone with access to your Mac user account could read them. The YouTube token can manage the account's videos (Greenroom uses it for uploads, title changes, deleting a video you chose to delete and, with Cues, video search), and Disconnect revokes it at Google.
In perspective: these are app-level Zoom API keys scoped to running meetings under your account — not your Zoom password — and revocable anytime in the Zoom Marketplace. The optional "export settings" file used to set up a colleague's Mac also contains them in plaintext by design; hand it over directly and delete it after importing.
Cues sends only the phrase it built — never audio, never the transcript, and never a name from the meeting unless it is inside a quotation you recite — but a term's worth of phrases to Google Books, Open Library, Wikipedia, Wikiquote and YouTube is still a record of what you taught, seen by those services like any search you typed yourself. Greenroom adds nothing to identify you beyond the connection itself (and, for YouTube video search, your own connected account). It is off by default; it pauses while you are muted; the menu bar can stop it for a class; and the log names every phrase, so you can see exactly what left.
Two more limits, plainly: it hears your microphone, so a student's voice coming out of your speakers can reach it as room sound (a headset removes that); and the word patterns it uses by default miss some things the opt-in on-device model finds, while that model interrupts far more often with wrong cards.
The agent reads a named student's transcript, your notes, stills of them every 20 seconds, the counts and the rubric. If its model runs in the cloud, all of that leaves your Mac, and Greenroom cannot tell you where it goes or how long it is kept. That is between you and the agent's provider.
The agent works in a temporary copy of the presentation's folder that leaves presentation.mov out, so there is no recording beside it to open. If that copy cannot be made, for example on a full disk, it works in the real folder, recording included. The default Claude Code and Codex commands are read-only, but those limits are the agent's own: an agent whose sandbox lets it read your whole disk could still go looking. A command you write yourself is limited only by what you put in it. It is off by default, and without it Screenroom still records, transcribes, counts and reports on this Mac.
Every claim on this page is checkable in the source. Read it, or hand it to someone technical you trust.