HR.

Case III: FlyOnTheWall · AI Meeting Notes for Mac

FlyOnTheWall

How do you design trust into every pixel when the entire product is built on one promise: your audio never leaves your Mac?

Industry
Native macOS · Privacy-first AI
Role
Lead Product Designer · End-to-end · Creo IT
Duration
12 weeks → ongoing
Year
2025

Project overview

Shipped to the Mac App Store, August 2025. Competing with $1.5B unicorns by refusing to send your audio to the cloud, and letting you bring your own AI key.

FlyOnTheWall is a privacy-first AI meeting assistant for macOS: every recording stays on the user's Mac, every AI key is the user's own. A 34.6 MB menu-bar utility competing with apps a hundred times its size, live, paid, on macOS 15.0+.

My role

Lead Product Designer, brand, product, marketing, App Store

Team

Creo IT, founder, engineers; sole designer of record

Timeline

12 weeks to 1.0 · Aug 2025 · ongoing

Tools

Figma · SwiftUI · Core ML · Whisper · Anthropic · GPT · Gemini · Grok · Linear · TestFlight

Problem statement

A category racing to the cloud.

The AI meeting notes market is a $3.5 billion race to the cloud. Every major player, Otter, Fireflies, Granola, Read AI, sends your audio off-device. Most also send a visible bot to your meeting. The category is consolidating fast, and incumbents are racing to lock users into their AI models and their data infrastructure.

For a large slice of professionals, legal, clinical, financial, anyone under NDA, that architecture is disqualifying. They either take notes by hand or accept a compliance risk nobody signed off on. The problem wasn't a missing feature; it was a missing trust model.

Creo IT bet the opposite direction: every recording stays on the user's Mac, every AI key is the user's own. Solving it mattered because trust, once the category's afterthought, was becoming its differentiator.

Business goals

What the product had to earn.

I.

Ship 1.0 to the Mac App Store in a quarter

A real, paid launch on macOS 15.0+, not a beta, not a waitlist. Twelve weeks from blank Figma file to storefront.

II.

Differentiate on trust, not features

Privacy and BYOK as the moat against incumbents with 100× the funding. The design's job: make the trust model visible on every surface, so the differentiator survives first contact.

III.

Undercut the category on price

$4.99/month, or free with your own AI key, against $14–35/month incumbents. Remove the subscription objection entirely for the developer segment.

IV.

Stay light as a product value

A 34.6 MB native app against 500 MB Electron competitors. Ship weight as a felt proxy for craft, discipline users can sense even when they can't name it.

User research

Fourteen competitors, two hundred reviews, five users who read privacy policies.

The category was crowded, so research started from the losers' complaints: what do people actually say when they abandon Otter or Fireflies? From there, interviews with privacy-bound professionals and developer power-users defined the segments the product would bet on.

Methodology, Lean UX

HypothesizeBuildMeasureLearn

Shipping to the App Store in twelve weeks forced Lean UX discipline: principles were written as testable hypotheses ('privacy is believed when it's visible in the UI, not the policy'), every flow was prototyped and pressure-tested before a line of SwiftUI, and post-launch telemetry now closes the build-measure-learn loop each release.

How I ran it

14

Competitor audit

Otter, Granola, Fireflies, Jamie, Read AI and nine more, mapped on a privacy × pricing grid.

200+

Reviews mined

App Store and G2 reviews of incumbents, bot complaints and privacy anxiety, coded by theme.

5

User interviews

Privacy-bound professionals and BYOK developers, the two segments the product bets on.

5

Prototype tests

Clickable Figma runs of onboarding, recording, and BYOK setup, two flows rewritten after round one.

What the research surfaced

#1

coded complaint against incumbents: the visible bot joining calls, participants described it as 'bringing a stranger to the meeting.'

5 / 5

interviewees said they read privacy policies before adopting a notes tool, and none believed marketing claims without a visible mechanism.

3 / 5

already paid for an AI API key and resented paying a second AI subscription on top, BYOK wasn't a niche feature, it was the deal.

2 flows

rewritten after testing: the recording pulse gained the 'audio is local' popover, and BYOK moved to after the first recording.

User personas

The three Mac users the product bets on.

One persona per beachhead segment, developer power-users, privacy-bound professionals, and Mac-native minimalists. Every design principle maps to at least one of them.

DK

Daniel Kim

33 · Startup founder-engineer · BYOK power user

I already pay for Claude. Why am I paying your markup to use my own model?

Goals

  • Meeting notes without another AI subscription
  • Pick the model doing his summarization
  • Tools that respect his API keys and his intelligence

Frustrations

  • $15–35/mo for a wrapper around a model he owns
  • Vendor lock-in dressed as convenience
  • Jargon-free onboarding that hides the actual mechanics

Behaviours

  • Reads the docs before the landing page
  • Free tier with own key converts him to advocate
  • Evaluates apps by their menu-bar footprint
MI

Dr. Meera Iyer

41 · Clinical psychologist · Privacy-bound

One recording leaving my machine is a licence problem, not a product preference.

Goals

  • Session notes without typing through the night
  • Absolute certainty audio never leaves the Mac
  • Documentation she can defend to a review board

Frustrations

  • Every mainstream tool processes audio server-side
  • Consent theatre, policies nobody can verify
  • Bots appearing in sensitive conversations

Behaviours

  • Reads the privacy policy first, fully
  • Asks 'where does the audio live?' before price
  • Pays readily for tools that carry her liability
TW

Tom Walsh

37 · Product manager · Mac-native minimalist

If it's a 500 MB Electron app with a dock icon, it's already lost me.

Goals

  • Notes that appear without ceremony
  • An app that feels like part of macOS
  • One honest price, no seat math

Frustrations

  • Electron bloat and battery drain
  • Web apps cosplaying as Mac apps
  • Feature checklists where craft should be

Behaviours

  • Lives out of the menu bar
  • Judges apps by ship weight and first launch
  • Churns fast, but keeps keepers for years

User problems

Four reasons users were stuck.

I.

Bot fatigue

An opaque robot joining your call reads as surveillance to everyone else in the meeting. Users stopped tolerating it, Granola rode exactly that wave from $250M to $1.5B in ten months.

II.

Audio leaving the device

For legal, clinical, and financial professionals, off-device processing is a compliance non-starter. These users read privacy policies, and found every mainstream tool failing the same clause.

III.

Model and data lock-in

Incumbents lock users into their own cloud model at $14–35/month. Power users who already pay for Claude or GPT keys pay twice, and can't choose the model doing their thinking.

IV.

Bloat where craft should be

500 MB Electron apps for what is, at heart, a recorder and a notes pane. Mac-native minimalists had no option that respected the platform.

Market research

What the giants got wrong.

Two macro trends reshaped the category in 2025–2026. First, bot fatigue: users stopped tolerating an opaque robot joining their calls. Granola rode that wave from a $250M valuation to $1.5B in ten months. Second, commoditization: Zoom, Teams, and Meet all shipped native AI notes, collapsing the floor under standalone transcription apps.

I mapped 14 competitors on a privacy × pricing grid. Differentiation now lives in three places, privacy, AI flexibility, and native craft, and almost no competitor commits to all three. Granola comes closest on privacy but locks users into its own cloud model and charges $14–35/month. Jamie is bot-free but processes audio on its servers. Otter and Fireflies ship visible bots.

The gap that shaped every design decision: a Mac-native app that processes audio locally, lets the user pick the model, and prices itself under five dollars a month.

Competitive analysis

PlayerNo meeting botOn-device audioBYOKNative MacApp sizePrice / mo
Otter~500 MB$17
FirefliesWeb$18
GranolaPartial~300 MB$14–35
Jamie~250 MB$24
Zoom / Teams native, Bundled
FlyOnTheWallthis project34.6 MB$4.99 / free

Privacy, AI flexibility, and native craft, almost no competitor commits to all three. The full rightmost row is the unowned middle the product shipped into.

Constraints

The box the design had to fit.

I.

On-device only, by contract

No server-side features, ever. Cross-meeting search and cloud embeddings were off the table before sketching began; every feature idea got gated against the privacy contract.

II.

Sole designer, twelve weeks

Brand, product, marketing surfaces, and the App Store storefront, one designer, one quarter, a founder to convince, and engineers waiting on specs.

III.

Native platform discipline

SwiftUI and macOS conventions, App Store review rules, and a 34.6 MB ship-weight budget. Every kilobyte and every non-native pattern had to be argued for.

IV.

BYOK depends on strangers' UX

The bring-your-own-key flow hands users to four different AI providers' key dashboards mid-setup. The design had to absorb that friction without owning those surfaces.

Design strategy

Three rules I shipped every screen against.

  1. I.

    Show the contract, not the policy.

    Privacy isn't a footnote, it's a pulse in the menu bar that says 'audio is local, right now.' I designed every recording surface to make the promise visible without saying it twice.

  2. II.

    Make BYOK feel like a premium choice, not a configuration chore.

    Bring-your-own-key is a developer-flavored feature. I designed the setup flow to feel as honest about its trade-offs as Apple's onboarding is about Face ID, one screen, four model choices, no jargon.

  3. III.

    The smallest surface wins.

    A 34.6 MB menu bar utility competing against 500 MB Electron apps. Every kilobyte saved is a UX choice. Discipline is what users feel, even when they can't name it.

Information architecture

Three surfaces, one contract.

The product lives across a tiny menu-bar pulse, a 902-px notes window, and settings, structured so any privacy decision is reachable in one click. Two artifacts below: the sitemap of the full app, and the first-run flow from welcome to notes.

Sitemap

Menu bar, main window, settings. Three surfaces, one contract.

The product lives across a tiny menu-bar pulse and a 902-px notes window. The IA is built so any privacy decision is reachable in one click. Click a node to inspect.

User flow

Welcome → first recording → notes that cite themselves.

Six states, one privacy contract held the whole way through. No bots, no cloud, no surprises. Hit play to watch the flow auto-advance.

Step I / VI

Currently inspecting

Welcome

Brand-first splash. The promise is the headline: bot-free, on-device, bring your own AI key.

Next: Continue

Process, AI-assisted workflow

How this was built, end to end.

The same loop I run on every project, tuned to FlyOnTheWall: start from the problem statement the business brings, let ChatGPT compile the prompts, let Claude do the heavy lifting, and keep every judgment call human.

ChatGPTClaudeFigmaStorybookNotion
  1. I.
    Notion

    Read the business, understand the problem

    The business prospect and problem statement were already on the table: a privacy-first Mac app where notes never leave the machine, capturing the meeting without a bot in the room. My job was to understand it, not invent it.

  2. II.
    ChatGPT

    ChatGPT engineers the prompt

    That problem statement went to ChatGPT, which wrote the .md prompt for Claude Code. ChatGPT's job here is precision: persona, context, constraints, and the success bar Claude has to hit.

  3. III.
    Claude

    Wireframes in Claude Code

    Claude Code built the wireframes from ChatGPT's prompt, purely to validate the flow and the screens: record, transcribe, summarize, search.

  4. IV.
    Notion

    Playtest with real users and the business owners

    I playtested with real users and the business owner, and iterated on the wireframes until the flow was stable.

  5. V.
    ClaudeFigma

    Color system, tokens, typography

    Then the brand color seeded a full color system in Figma, Claude driving the Figma MCP: tokens for light and dark, then the typography.

  6. VI.
    ChatGPTClaudeFigma

    Component library in Figma

    The wireframes dictated the component set. Prompt from ChatGPT, and Claude built the complete atomic component library in Figma.

  7. VII.
    ChatGPTClaudeFigma

    Hi-fi screens, my judgment calls

    Claude assembled the hi-fi screens, light and dark, from those components on another ChatGPT prompt. I kept the judgment calls on visual design and the user journey, playtested, and iterated to sign-off.

  8. VIII.
    Storybook

    Storybook, then handoff

    Post sign-off, the whole component library became a Storybook, the single source of truth, and went to the devs.

Key design decisions

Why the product works the way it does.

I.

Put the recording state in the menu bar as a privacy pulse

Why

Privacy claims made in marketing copy aren't believed, least of all by an audience that reads privacy policies. The promise had to be visible while it was being kept.

Impact

A pulsing dot with a popover showing exactly where the audio lives (your Mac), elapsed time, and one stop button. The contract is the UI, no copy needed.

II.

Ask for the AI key after the first recording, not during onboarding

Why

BYOK is the product's biggest friction point. Front-loading it would cost activations before the user ever felt the value.

Impact

Users experience a full record → notes loop first, then meet the key setup, one screen, four logos, paste and connect. Free tier for own-key users turns the friction into the deal.

III.

Make every AI answer cite the timestamp it came from

Why

Unverifiable AI answers erode exactly the trust this product sells. And cross-meeting search would require server-side indexing, breaking the contract.

Impact

Notes prove themselves: summary, decisions, and action items all trace to moments in the recording. The constraint became the credibility feature.

IV.

Add review friction to every export

Why

Notion and Slack export could silently leak content the user never meant to share, one careless default away from breaking the promise.

Impact

Only structured notes export, never audio, and the user reviews before every send. Friction, but the right kind, the kind the audience chose this app for.

V.

Write microcopy for readers of privacy policies

Why

The target user checks claims. 'Industry-leading privacy infrastructure' reads as evasion to them.

Impact

Every surface says 'audio stays on your Mac', concrete, checkable, repeated exactly where the anxiety occurs. Copy as a trust surface.

Final designs

Every screen, light and dark.

The full FlyOnTheWall surface from Figma, onboarding through settings, plus dialogues, paywall and share/modal, in both light and dark.

45 screens · 12 sections · macOS · 1440×776

01 · Onboarding & auth

3 screens

02 · Permissions & setup

2 screens

03 · Recording

2 screens

04 · Notes & generation

6 screens

05 · Note detail

1 screens

06 · Loading states

4 screens

07 · Settings

7 screens

08 · Subscription plans

1 screens

Dialogues

2 screens

Paywall on login

1 screens

Share & modal selection

2 screens

Dark theme

14 screens

Outcomes

Aug 2025
Launched to the Mac App Store. Live, paid, real users on macOS 15.0+.
34.6 MB
Ship weight. A fraction of Otter, Granola, or Fireflies, every byte a deliberate choice.
3 segments
Beachhead locked: developer power-users, privacy-first professionals (legal, clinical, financial), and Mac-native minimalists.

Reflection

The discipline is the moat.

What went well:the contract held. The hardest part of designing a privacy-first product isn't the UI, it's holding the line every time a feature wants to phone home. Cross-meeting search would have been a great feature. Server-side embeddings would have made summaries faster. Both would have broken the contract. I chose the slower path. Two quarters in, the bet is paying.

What I'd improve: I'd invest earlier in visible privacy state, make the local-only architecture readable from the recording surface itself, not from settings. Trust is earned in glances, not in dialogs.

What's next: iterating against telemetry and direct user feedback, deepening the three beachhead segments before widening the surface area.

More work

Keep looking.

Currently viewing: FlyOnTheWall