Explicit Lesson Notes opt-in only. Normal startup does not run this engine. Use it only for the teacher-armed Lesson Notes workflow after the named school, privacy, child-safety, participant-notice, data-minimisation, correction, access and no-storage gates have passed. A local checkbox alone is not approval.
This documents the local speech-to-text boundary using whisper.cpp on a teacher computer or trusted private-network computer. It is not a cloud service and must never become a recording archive.
Current Status
- Lesson Notes automatically prepare name-minimised Draft structures from the timetable and always retain a typed fallback.
- The temporary scratchpad is browser-only and not submitted as raw transcript text.
- The visible workflow requests permission only after the teacher deliberately arms the selected teaching date for its combined lesson-and-rehearsal list and keeps Armed/Capturing state plus Stop/Discard visible.
- Guarded app routes accept only authorised, size-limited temporary content and do not write audio or raw transcripts.
- Normal HTTP, private-network and HTTPS startup does not start or connect to a transcription engine.
- The current app stores no audio or raw transcripts.
Chosen Engine
whisper.cpp is the selected local speech-to-text engine for Band Licence because it can run offline on the teacher's own computer or a trusted private-network computer.
The repository provides these explicit setup and opt-in commands:
pnpm lesson-notes:engine:install
pnpm lesson-notes:engine:start
pnpm lesson-notes:engine:check
pnpm start:pilot:lesson-notespnpm start:pilot:lesson-notes is the deliberate opt-in start mode. It may start the local engine and pass the Lesson Note feature switches to the app. Ordinary pilot/private-network/HTTPS startup remains audio-free. An HTTPS opt-in equivalent must be separately named and tested rather than changing the ordinary HTTPS command.
The installer downloads and builds whisper.cpp into the ignored local/whisper.cpp folder and downloads the default base.en model. This keeps the speech-to-text engine out of the app source and out of the database.
The Band Licence wrapper runs Whisper in CPU-only mode by default because that is the most predictable local path across teacher machines. GPU use can be tested later by setting:
BAND_LICENCE_WHISPER_USE_GPU=YESPrerequisites:
- Git.
- CMake.
- ffmpeg, if browser audio needs converting before transcription. WAV input can be processed without ffmpeg.
For the local macOS pilot, FFmpeg 8.1.2 is installed in:
local/tools/ffmpeg/ffmpeg
local/tools/ffmpeg/ffprobeThe local wrapper checks that folder automatically before looking for a system-wide ffmpeg.
The local wrapper exposes:
GET /healthPOST /transcribe
The wrapper may create a temporary per-request working folder so whisper.cpp can process the audio. That working folder is deleted before the response completes. Audio and transcript text are not logged by the wrapper.
Engine Location
The current built-in engine must run on the same host as the Band Licence server and bind only to loopback.
Allowed examples:
http://localhost:3133http://127.0.0.1:3133
Rejected examples:
- private-network IP and
.localaddresses; - public websites.
- cloud speech-to-text APIs.
- URLs with usernames, passwords, query strings, or tokens.
Required Health Check
The engine should expose:
GET /health
Expected response:
{
"ok": true,
"engine": "Local Whisper"
}The app only uses this to confirm the local engine is reachable. It does not send audio or transcript text during the health check.
Environment Settings
Set these only after all external approval/evidence and technical safeguards are recorded:
BAND_LICENCE_LOCAL_TRANSCRIPTION_URL=http://localhost:3133
BAND_LICENCE_LOCAL_TRANSCRIPTION_APPROVED=YES
BAND_LICENCE_LOCAL_TRANSCRIPTION_ENABLED=YES
BAND_LICENCE_LESSON_NOTE_DICTATION_ENABLED=YESThese switches are necessary but not sufficient. School-specific approval evidence, privacy/child-safety/data-minimisation/correction gates, current Teacher/Administrator access, authenticated loopback URL validation and deliberate teacher arming must also pass.
Transcription Contract
When temporary local transcription is enabled, the engine may receive temporary audio only for an active scheduled lesson or rehearsal within the deliberately armed teaching date. The app must then:
- create a temporary transcript.
- generate a name-minimised Candidate Draft without claiming guaranteed anonymisation.
- discard the audio.
- discard the raw transcript.
- save only a privacy-filtered Candidate Draft for teacher review; sharing still requires deliberate sign-off.
Audio and raw transcripts must not be written to SQLite, persistent app files, browser storage, logs, exports, notifications, or backups. The local engine wrapper may use a temporary process folder only while transcribing, and it must delete that folder before the response completes.
Windows Host Notes
An approved Windows Lesson Notes host requires Git and CMake:
pnpm lesson-notes:engine:install
pnpm lesson-notes:engine:startKeep the engine URL at http://localhost:3133 when the app and engine run on the same Windows computer. Starting the standalone engine does not arm capture; the explicit app mode, gates and deliberate teacher action are still required.