Help & FAQ

Everything you need to install, trust, and (if you must) remove WinTinyBar.

Português (Brasil)

Is it free? · Ads? · Installing · The SmartScreen notice · Your data · Voice models · Interests · Fresh Picks · Research · Updates · Uninstalling · Contact

Is WinTinyBar really free?

The core app and its local AI tools labeled free are free, with no account, subscription, or expiring trial. Contributions and optional add-ons help sustain the project; future partner tools or connected services may be paid only when clearly labeled before you choose them. Local interests are never used to select paid offers for you.

Will there be ads?

No third-party ads or advertising trackers inside your toolbar. The website uses limited first-party aggregate measurement for visits and download actions. WinTinyBar does not send install or tool-use analytics unless you switch product metrics on yourself, in the app's My interests & privacy settings; it is off until you do. The website's download metric is a redirect click, not proof of a completed download or installation. Any later product measurement and community research are separate, default-off choices. Your private content and local interests are never used to choose paid offers. The privacy page explains the boundaries.

Installing WinTinyBar

Download the installer (~72 MB), run it, and the bar appears at the top of your screen. WinTinyBar runs on Windows 10 and 11. No account, no sign-in, no configuration is required for the core bar. Optional voice/translation models need a confirmed download, while rates, updates and other clearly connected tools need internet access. Private speech, selected text and local AI output stay on your machine after the chosen models are installed.

Windows says “Windows protected your PC” — what does that mean?

On first run of a freshly downloaded installer, Windows may show a blue SmartScreen banner:

Microsoft Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk.

What the notice actually says. SmartScreen looked this exact file up in Microsoft's reputation service and found nothing on record. That is not a finding that the file is safe, and it is not a finding that the file is dangerous — it is Windows telling you it cannot vouch for the file either way, and that stopping is the correct default when nothing is known. Please read it as a real warning about a real gap in what Windows knows, because that is what it is.

Why it appears for WinTinyBar. Reputation is earned by one specific file, or by the publisher identity carried inside it. Every release is a brand-new file with no download history, and WinTinyBar is not code-signed yet — so there is no publisher identity for one release to hand its reputation on to the next. A small independent studio therefore meets this dialog on nearly every build, and will keep meeting it until the work below is done.

What we are doing about it. Downloads are paused right now while we finish exactly this work. In order: an organization-validated code-signing certificate for Uppercut Studio, so that every executable we ship — app, helpers, updater and installer — is signed and timestamped under a name you can read in the Windows dialog; a public multi-engine scan of each release, with the result recorded in that release's notes; and publication through the Microsoft Store, where the package is re-signed by Microsoft and carries full reputation, which is the only route that makes this dialog stop appearing at all.

What we will never ask you to do. We will never ask you to switch off your antivirus, add an exclusion for us, or click past a security alert. If your security software — as opposed to this reputation notice — flags WinTinyBar, let it do its job, leave the file where it put it, and tell us at wintinybar@uppercut.studio with the name and version of the product that flagged it. That report is worth more to us than the installation. Anyone taught to wave one alarm away will wave away the next one too, and the next one might be real.

What you can check for yourself. Download WinTinyBar only from wintinybar.com or the official releases page it links to, and compare the SHA-256 published beside the release with the file you received. Windows keeps the decision with you: More info reveals the app name and the publisher recorded inside the file — today that still reads Unknown publisher, which is precisely the gap the certificate closes — and a Run anyway button appears beneath it. We are not going to tell you to press it. Verify the source and the checksum first, and if either one does not match, do not run the file. Once installed, in-app updates are cryptographically verified (signed manifest plus SHA-256 checksum) before they run.

Where does my data live?

Everything the current app stores lives under %LOCALAPPDATA%\WinTinyBar — that is C:\Users\<you>\AppData\Local\WinTinyBar:

Notes and ordinary settings can be readable local files. Legacy wellness and manual interest data use separate Windows current-user DPAPI vaults and never fall back to plaintext. The Persona/dictionary vault is staged local infrastructure and is not yet connected to ordinary app use. Private work is not synced. Public rates, downloads and future common content still require ordinary network requests; the full story is on the privacy page.

How do voice models work, and how much disk do they take?

Talk Type (dictation) uses open-source speech models that run entirely on your machine. The app ships without them; the first time you use Talk Type it asks before downloading, and shows the size first:

The size is shown before anything downloads, and nothing downloads without your click. Models are stored in %LOCALAPPDATA%\WinTinyBar\ai\models — delete a model's folder there to free the disk space; the app will simply offer the download again if you ever need it back. After the download, dictation works fully offline: your voice audio never leaves your computer.

Say Selected works immediately with Windows voices. Its recommended Natural option is a separate ~356 MB one-time download with default voices for English and Brazilian Portuguese; after downloading them, selected text and generated speech stay entirely on this PC. The app never sends text to a speech service, and you can remove the model from the voice manager whenever you want.

Does WinTinyBar read what I say to discover interests?

Not in WinTinyBar 1.16.0-beta, and not in any release so far. In the staged design, manual My interests choices are fixed tags stored in a separate protected vault on your PC. A future Learn from translations option may use a signed local classifier only after you turn that separate switch on. It may suggest one broad non-sensitive tag after several independent sessions, but you approve it before it becomes a preference. A suggested tag may keep only bounded metadata (state, strength, capped session count, and first/last day); the phrase, audio, translation, keyword, dictionary and underlying evidence content are not retained or sent. Sensitive or uncertain material is ignored.

How can Fresh Picks be relevant without sending my interests?

Every installation downloads the same signed multilingual catalog from one fixed URL. Your PC compares that common catalog with the tags you approved and explains why an item appears. The request contains no tag, locale, account, installation ID or content ID. Saves, hides and “more like this” stay local; there is no article click beacon. Opening the original story in your browser does contact that publisher like any normal web visit.

Are community research and product metrics the same?

No. Community research does not exist yet. Product metrics are off until you switch them on, and switching them off deletes the counters already held on your PC. Product metrics share small fixed operational counters such as a tool starting or failing. Once they are on, the report is posted straight to uppercut.studio, so — as on any web request — the receiving server sees your IP address and the time of the send; that rides in the transport rather than in the report, which is why the “no identifier” promise above does not reach it. Community research may later attempt at most one locally randomized broad category in a 30-day period while local state remains intact. Its exact body also contains a random one-use anti-replay receipt, not a persistent user/device/install ID. Deleting local state or reinstalling can reset the local guard, so server-side one-use enforcement and a published fixed receipt-retention limit are launch requirements. The two planes have different consent switches, endpoints, collections, retention and dashboards, and neither receives your content or detailed local tags. Declining either does not reduce tools or local recommendations.

How do updates work?

Installing an update is always manual: open the coffee menu (the ☕ button) and click Check for updates… (or Get Latest in the tray icon's menu). The app fetches the newest release, verifies it cryptographically (Ed25519 signature plus SHA-256 checksum — if verification fails, nothing installs), and runs the installer. Nothing ever installs on its own.

There is also an optional Check for updates weekly toggle — off by default. If you switch it on, once a week the app quietly fetches just the small signed version manifest. When a verified newer version exists, it may pre-download the installer into the Windows temporary folder, verifies the signed manifest and SHA-256, and asks before running it. It never installs or restarts without that separate confirmation (details in the privacy policy). Your settings and notes survive updates.

How do I uninstall — and does it remove my data?

Uninstall the app from Windows Settings → Apps → Installed apps → WinTinyBar → Uninstall.

Two honest notes:

Something else?

E-mail wintinybar@uppercut.studio — the team will review it as capacity allows. You can also use the support and bug-report form; it lands directly in the Uppercut tool inbox.

← back · Support · Report a bug · Terms · Privacy · EULA · © 2026 Uppercut Studio