Aloud holds no user accounts and persists no user data; all API keys are server-side environment variables.
If you find a vulnerability (a way to reach a key, to make the app speak a medical claim, or to exfiltrate a capture), please email stephensookra@gmail.com rather than opening a public issue. You will get a reply within 72 hours.