Ten dictation products were read on 2026-08-29 against their own privacy policies, data processing agreements, support docs, and trust centres. One of the ten, Otter.ai, publishes a complete, dated, public subprocessor list. Two products carry a “never leaves your device” claim on one page that the same vendor’s own documentation on another page does not support.
Nothing below is inferred. Every cell is a quote from a document the vendor publishes, or a statement that a document does not address the question. Where a page returned 404 or named nothing, that is recorded as an absence and nothing further is read into it. Voice Type is the last row and is held to the same standard, including where the answer is unflattering.
The page is refreshed quarterly. Policies change, and a claim about a vendor is only as good as the date beside it.
The table
| Vendor | Publishes a subprocessor list | Where audio is processed | Retention | Training on user content | Human review | Certifications claimed |
|---|---|---|---|---|---|---|
| Wispr FlowTrust centre, Security FAQ, Data controls, Privacy policy, DPA | Partial. The trust centre publicly names AWS, Baseten, Vercel, OpenAI, and Supabase. The authoritative list is Annex 2 of the DPA, available under NDA. | Cloud, United States. "Transcription always occurs on the cloud." All customer data processed and stored in the US regardless of user location. | Content sent to third-party AI providers "is generally deleted within 30 days". No fixed window published for Wispr’s own store, checked 2026-08-29. | Toggle. In standard mode, "audio and transcription data may be used to evaluate, train, and improve Wispr’s models". Data sharing defaults to off. | Not addressed in the privacy policy, data controls page, security FAQ, or DPA, checked 2026-08-29. | Security FAQ: SOC 2 Type I (A-LIGN, April 2026), ISO 27001 Stage 1 complete and Stage 2 scheduled, HIPAA BAA available. The marketing page advertises SOC 2 Type II and ISO 27001. |
| SuperwhisperPrivacy policy, Sensitive data docs, Models docs | No published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The docs name the providers instead. | On device by default. Cloud voice models are optional and configured per mode. Docs name Deepgram, OpenAI, Anthropic, Groq, Superwhisper Cloud, Azure OpenAI, and AWS Bedrock. | "All transcription history is stored locally on your device." Third-party providers are accessed under zero data retention terms. | "Your data is not being used for training AI models or any other machine learning purposes." | Not addressed in the privacy policy or the security docs, checked 2026-08-29. | None claimed, checked 2026-08-29. The policy asserts GDPR and CCPA compliance and no SOC 2 or ISO claim was found. |
| MacWhisperPrivacy policy, Keeping transcriptions private | No published subprocessor list, checked 2026-08-29. | Local by default. Docs name Groq, ElevenLabs, and Deepgram for cloud transcription, DeepL for translation, OpenAI and Anthropic for AI prompts, and Ollama or LM Studio for a local path. | No retention statement in the privacy policy or the docs, checked 2026-08-29. | Not addressed, checked 2026-08-29. | Not addressed, checked 2026-08-29. | None claimed, checked 2026-08-29. |
| VoiceInkPrivacy policy, GitHub README | No published subprocessor list, checked 2026-08-29. The privacy policy names the optional providers directly. | Local by default. Cloud only with a user-supplied key: Groq, OpenAI, Anthropic, Gemini, Mistral, Cerebras, Deepgram, ElevenLabs, Speechmatics, Soniox, OpenRouter, Ollama for local, plus custom endpoints. | Transcriptions and audio files "Kept indefinitely by default until you delete them", on the device. Optional auto-delete runs 24 hours to 7 days for text and 7 days for audio. | No training clause in the privacy policy, checked 2026-08-29. The policy does state VoiceInk "does not collect or transmit any personal data by default". | Not addressed, checked 2026-08-29. | None claimed, checked 2026-08-29. Licensed under GPL v3. |
| Otter.aiSubprocessors, Privacy policy, Privacy and security, Terms of service | Yes. A complete public list of 17 entries, last updated 2026-03-31. The only vendor of the ten with one. | Cloud. AWS, Google Cloud, and Crusoe, all United States. Data may be transferred outside the user’s country. | Conversations are deleted from trash after 30 days. General retention runs "as long as necessary". No fixed audio or transcript window published, checked 2026-08-29. | The privacy policy permits "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)". No user opt-out found, checked 2026-08-29. | "Before audio recordings are ever reviewed manually by a human (Otter personnel or its third parties), we require explicit consent from customers." The subprocessor list includes Research Transcriptions for annotating training and evaluation data. | A SOC 2 report is maintained with an independent auditor. GDPR standards are "incorporated" and HIPAA requirements "followed". ISO 27001/2 is named as a policy framework, not a certification. |
| NottaPrivacy policy, Security | No published subprocessor list, checked 2026-08-29. /en/subprocessors returns 404. | Cloud. "Notta hosts all its software on Amazon Web Services (AWS)." Region not stated. No speech-to-text or language model vendor is named in any primary document, checked 2026-08-29. | No audio or transcript retention period in the privacy policy or the security page, checked 2026-08-29. | Addressed only for Google Workspace API data, which is "not used to develop, improve, or train generalized/non-personalized AI and/or ML models". Notta’s own transcription pipeline is not covered, checked 2026-08-29. | Not addressed in the privacy policy or the security page, checked 2026-08-29. | The security page asserts SOC 2 Type II, ISO 27001, GDPR, CCPA, and that Notta will "Follow HIPAA guidelines". No auditor named and no report availability stated, checked 2026-08-29. |
| SpeechifyPrivacy policy, SOC 2 blog post | No published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The policy names analytics and advertising vendors only. | "Information submitted to Speechify will be transferred to, processed, and stored in the United States." No speech or language model vendor is named, checked 2026-08-29. | No audio or text retention period. Data may be kept "as long as reasonably necessary for our legitimate business interests", checked 2026-08-29. | No AI training clause in the policy, checked 2026-08-29. The policy refers to using data "to improve our algorithms", which is not the same permission. | "Speechify employees do not monitor or view your User Content ... but it may be viewed if ... we need to do so to respond to your requests for support ... proofreaders may also read the User Content you submit for this specific service." | A 2023 blog post states Speechify "is SOC2 compliant" and that enterprise clients can request the report. Type and auditor not stated, checked 2026-08-29. |
| Apple DictationAsk Siri and Dictation notice, Improve Siri and Dictation notice | Apple publishes no subprocessor list for Dictation, checked 2026-08-29. Apple is the processor and no third-party vendor is named. | Both. On capable devices the audio stays on device; otherwise "your audio is sent to and processed on Apple servers". Siri Settings indicates which applies. | Server request history carries "a random, device-generated identifier that rotates multiple times per hour". "Apple may retain and use this data for up to two years", and a reviewed subset "may be kept beyond two years". | Server data is used "to develop and improve Siri, Dictation, Search, and limited other language processing functionality". Audio is collected only if you opt in to Improve Siri and Dictation. | "Apple may review a subset of the transcripts of your interactions with Siri." On audio: "Only Apple employees, subject to strict confidentiality obligations, are able to access audio interactions with Siri and Dictation." | No SOC 2 or ISO 27001 claim appears in the Dictation privacy notices, checked 2026-08-29. |
| Aqua VoicePrivacy policy | No published subprocessor list, checked 2026-08-29. The policy names attribution, advertising, and compliance vendors only. | Not stated in the privacy policy, checked 2026-08-29. No speech or language model vendor and no hosting region are named. | "For users with Privacy Mode disabled, we may securely store transcript data on our servers to the extent necessary to improve the product. Otherwise, transcript data is not collected". No time window stated, checked 2026-08-29. | No training clause, checked 2026-08-29. "to improve the product" is not a training permission in either direction. | Not addressed, checked 2026-08-29. | "SOC 2 Type II compliant" via Advantage Partners, with Vanta for monitoring. Report availability not stated, checked 2026-08-29. |
| Willow VoicePrivacy policy | No published subprocessor list, checked 2026-08-29. Providers are named by category: "cloud infrastructure, transcription, security, diagnostics, customer support, and payment services". | Not stated in the privacy policy, checked 2026-08-29. | Private Mode: "Willow and its service providers do not retain that audio or use it for model training." Help Improve Willow: "Willow may retain anonymized recognized text, but not audio." History is stored locally on the device. | Only under Help Improve Willow, on anonymized recognized text and never audio. No retention window for that text, checked 2026-08-29. | Covered for Google User Data only. An equivalent statement covering dictation audio or text generally was not found, checked 2026-08-29. | None claimed in the privacy policy, checked 2026-08-29. |
| Voice TypeVoice Type trust page, Voice Type privacy policy | Yes. Three subprocessors, published on the trust page: Apple, Cloudflare, PostHog. None of the three is in the path of a spoken word. | On the Mac, by whisper.cpp. There is no upload endpoint in the app source and no Voice Type application server to upload to. | No audio or transcript store, because there is no backend to hold one. Transcripts live wherever the text was typed. | None. We receive no audio and no transcripts, so there is nothing to train on. | None. No dictation reaches us, so there is nothing for a person here to read. | None claimed. No SOC 2, no ISO 27001, no HIPAA BAA. A one-person macOS app has not been through those audits and this page will not imply otherwise. |
Every cell read on 2026-08-29 from the linked sources. Vendor names link to the detail below. Retention, training, and human review are reported as the vendor writes them, including where the vendor writes nothing.
The two contradicted local-only claims
Both products below run recognition locally by default, and both are good software. The problem is not the default. It is that the marketing sentence describes the default as though it were the whole capability, while the same vendor documents a cloud path elsewhere.
MacWhisper
What the vendor says
"MacWhisper does all it’s functionality on your device. No data (audio, text or other) leaves your device."
Privacy policy, last updated February 14, 2024
What the same vendor’s documentation says
"By default, transcriptions (including Speaker Identification) is all performed locally on your Mac or iOS device". The same page then documents a "Cloud Transcription provider (such as Groq, ElevenLabs or Deepgram)", DeepL Translation, and AI prompt providers "such as OpenAI or Anthropic", with the note that "The exception to this is if you use a local AI Service Provider such as Ollama or LM Studio, which runs locally on your Mac."
Docs: keeping transcriptions private
The policy predates the cloud features the docs describe. It states the default as though it were the whole capability set. Both documents are current and public, and they do not agree.
VoiceInk
What the vendor says
"100% offline processing ensures your data never leaves your device."
What the same vendor’s documentation says
The privacy policy, last updated April 20, 2026, names twelve optional cloud providers that receive audio or text once enabled: Groq, OpenAI, Anthropic, Gemini, Mistral, Cerebras, Deepgram, ElevenLabs, Speechmatics, Soniox, OpenRouter, and custom OpenAI-compatible endpoints, plus Ollama for a local path.
The README describes the default configuration. The policy describes the capability. A reader who stops at the README gets a different product than the one the policy documents.
Superwhisper is a near miss worth naming separately. Its privacy policy is dated June 19, 2024 and states the product is "designed to process audio data locally on your device", while the current docs describe optional cloud voice models and a Superwhisper-hosted cloud tier. The docs are the more current description, and unlike the two above they are explicit about the cloud path, per mode, on the same site.
Vendor by vendor
Wispr Flow
- Publishes a subprocessor list
- Partial. The trust centre publicly names AWS, Baseten, Vercel, OpenAI, and Supabase. The authoritative list is Annex 2 of the DPA, available under NDA.
- Where audio is processed
- Cloud, United States. "Transcription always occurs on the cloud." All customer data processed and stored in the US regardless of user location.
- Retention
- Content sent to third-party AI providers "is generally deleted within 30 days". No fixed window published for Wispr’s own store, checked 2026-08-29.
- Training on user content
- Toggle. In standard mode, "audio and transcription data may be used to evaluate, train, and improve Wispr’s models". Data sharing defaults to off.
- Human review
- Not addressed in the privacy policy, data controls page, security FAQ, or DPA, checked 2026-08-29.
- Certifications claimed
- Security FAQ: SOC 2 Type I (A-LIGN, April 2026), ISO 27001 Stage 1 complete and Stage 2 scheduled, HIPAA BAA available. The marketing page advertises SOC 2 Type II and ISO 27001.
Read 2026-08-29 from Trust centre, Security FAQ, Data controls, Privacy policy, DPA.
Superwhisper
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The docs name the providers instead.
- Where audio is processed
- On device by default. Cloud voice models are optional and configured per mode. Docs name Deepgram, OpenAI, Anthropic, Groq, Superwhisper Cloud, Azure OpenAI, and AWS Bedrock.
- Retention
- "All transcription history is stored locally on your device." Third-party providers are accessed under zero data retention terms.
- Training on user content
- "Your data is not being used for training AI models or any other machine learning purposes."
- Human review
- Not addressed in the privacy policy or the security docs, checked 2026-08-29.
- Certifications claimed
- None claimed, checked 2026-08-29. The policy asserts GDPR and CCPA compliance and no SOC 2 or ISO claim was found.
Read 2026-08-29 from Privacy policy, Sensitive data docs, Models docs.
MacWhisper
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29.
- Where audio is processed
- Local by default. Docs name Groq, ElevenLabs, and Deepgram for cloud transcription, DeepL for translation, OpenAI and Anthropic for AI prompts, and Ollama or LM Studio for a local path.
- Retention
- No retention statement in the privacy policy or the docs, checked 2026-08-29.
- Training on user content
- Not addressed, checked 2026-08-29.
- Human review
- Not addressed, checked 2026-08-29.
- Certifications claimed
- None claimed, checked 2026-08-29.
Read 2026-08-29 from Privacy policy, Keeping transcriptions private.
VoiceInk
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29. The privacy policy names the optional providers directly.
- Where audio is processed
- Local by default. Cloud only with a user-supplied key: Groq, OpenAI, Anthropic, Gemini, Mistral, Cerebras, Deepgram, ElevenLabs, Speechmatics, Soniox, OpenRouter, Ollama for local, plus custom endpoints.
- Retention
- Transcriptions and audio files "Kept indefinitely by default until you delete them", on the device. Optional auto-delete runs 24 hours to 7 days for text and 7 days for audio.
- Training on user content
- No training clause in the privacy policy, checked 2026-08-29. The policy does state VoiceInk "does not collect or transmit any personal data by default".
- Human review
- Not addressed, checked 2026-08-29.
- Certifications claimed
- None claimed, checked 2026-08-29. Licensed under GPL v3.
Read 2026-08-29 from Privacy policy, GitHub README.
Otter.ai
- Publishes a subprocessor list
- Yes. A complete public list of 17 entries, last updated 2026-03-31. The only vendor of the ten with one.
- Where audio is processed
- Cloud. AWS, Google Cloud, and Crusoe, all United States. Data may be transferred outside the user’s country.
- Retention
- Conversations are deleted from trash after 30 days. General retention runs "as long as necessary". No fixed audio or transcript window published, checked 2026-08-29.
- Training on user content
- The privacy policy permits "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)". No user opt-out found, checked 2026-08-29.
- Human review
- "Before audio recordings are ever reviewed manually by a human (Otter personnel or its third parties), we require explicit consent from customers." The subprocessor list includes Research Transcriptions for annotating training and evaluation data.
- Certifications claimed
- A SOC 2 report is maintained with an independent auditor. GDPR standards are "incorporated" and HIPAA requirements "followed". ISO 27001/2 is named as a policy framework, not a certification.
Read 2026-08-29 from Subprocessors, Privacy policy, Privacy and security, Terms of service.
Notta
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29. /en/subprocessors returns 404.
- Where audio is processed
- Cloud. "Notta hosts all its software on Amazon Web Services (AWS)." Region not stated. No speech-to-text or language model vendor is named in any primary document, checked 2026-08-29.
- Retention
- No audio or transcript retention period in the privacy policy or the security page, checked 2026-08-29.
- Training on user content
- Addressed only for Google Workspace API data, which is "not used to develop, improve, or train generalized/non-personalized AI and/or ML models". Notta’s own transcription pipeline is not covered, checked 2026-08-29.
- Human review
- Not addressed in the privacy policy or the security page, checked 2026-08-29.
- Certifications claimed
- The security page asserts SOC 2 Type II, ISO 27001, GDPR, CCPA, and that Notta will "Follow HIPAA guidelines". No auditor named and no report availability stated, checked 2026-08-29.
Read 2026-08-29 from Privacy policy, Security.
Speechify
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The policy names analytics and advertising vendors only.
- Where audio is processed
- "Information submitted to Speechify will be transferred to, processed, and stored in the United States." No speech or language model vendor is named, checked 2026-08-29.
- Retention
- No audio or text retention period. Data may be kept "as long as reasonably necessary for our legitimate business interests", checked 2026-08-29.
- Training on user content
- No AI training clause in the policy, checked 2026-08-29. The policy refers to using data "to improve our algorithms", which is not the same permission.
- Human review
- "Speechify employees do not monitor or view your User Content ... but it may be viewed if ... we need to do so to respond to your requests for support ... proofreaders may also read the User Content you submit for this specific service."
- Certifications claimed
- A 2023 blog post states Speechify "is SOC2 compliant" and that enterprise clients can request the report. Type and auditor not stated, checked 2026-08-29.
Read 2026-08-29 from Privacy policy, SOC 2 blog post.
Apple Dictation
- Publishes a subprocessor list
- Apple publishes no subprocessor list for Dictation, checked 2026-08-29. Apple is the processor and no third-party vendor is named.
- Where audio is processed
- Both. On capable devices the audio stays on device; otherwise "your audio is sent to and processed on Apple servers". Siri Settings indicates which applies.
- Retention
- Server request history carries "a random, device-generated identifier that rotates multiple times per hour". "Apple may retain and use this data for up to two years", and a reviewed subset "may be kept beyond two years".
- Training on user content
- Server data is used "to develop and improve Siri, Dictation, Search, and limited other language processing functionality". Audio is collected only if you opt in to Improve Siri and Dictation.
- Human review
- "Apple may review a subset of the transcripts of your interactions with Siri." On audio: "Only Apple employees, subject to strict confidentiality obligations, are able to access audio interactions with Siri and Dictation."
- Certifications claimed
- No SOC 2 or ISO 27001 claim appears in the Dictation privacy notices, checked 2026-08-29.
Read 2026-08-29 from Ask Siri and Dictation notice, Improve Siri and Dictation notice.
Aqua Voice
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29. The policy names attribution, advertising, and compliance vendors only.
- Where audio is processed
- Not stated in the privacy policy, checked 2026-08-29. No speech or language model vendor and no hosting region are named.
- Retention
- "For users with Privacy Mode disabled, we may securely store transcript data on our servers to the extent necessary to improve the product. Otherwise, transcript data is not collected". No time window stated, checked 2026-08-29.
- Training on user content
- No training clause, checked 2026-08-29. "to improve the product" is not a training permission in either direction.
- Human review
- Not addressed, checked 2026-08-29.
- Certifications claimed
- "SOC 2 Type II compliant" via Advantage Partners, with Vanta for monitoring. Report availability not stated, checked 2026-08-29.
Read 2026-08-29 from Privacy policy.
Willow Voice
- Publishes a subprocessor list
- No published subprocessor list, checked 2026-08-29. Providers are named by category: "cloud infrastructure, transcription, security, diagnostics, customer support, and payment services".
- Where audio is processed
- Not stated in the privacy policy, checked 2026-08-29.
- Retention
- Private Mode: "Willow and its service providers do not retain that audio or use it for model training." Help Improve Willow: "Willow may retain anonymized recognized text, but not audio." History is stored locally on the device.
- Training on user content
- Only under Help Improve Willow, on anonymized recognized text and never audio. No retention window for that text, checked 2026-08-29.
- Human review
- Covered for Google User Data only. An equivalent statement covering dictation audio or text generally was not found, checked 2026-08-29.
- Certifications claimed
- None claimed in the privacy policy, checked 2026-08-29.
Read 2026-08-29 from Privacy policy.
Voice Type, same columns
Voice Type has three subprocessors. Apple handles App Store distribution, payment, receipts, and the iCloud mailbox behind [email protected]. Cloudflare handles website hosting, DNS, the files.carelesswhisper.app host, and email forwarding. PostHog handles website analytics on us.i.posthog.com, which is PostHog’s United States cloud. None of the three receives dictation, because none of them sits in the dictation path.
The app makes one call to a host we own. Every six hours it issues a plain GET to files.carelesswhisper.app/review-gate.json, a static file with three fields: an approved build number, a timestamp, and a schema version. No body, no identifier, no custom header beyond Accept. Run curl -s https://files.carelesswhisper.app/review-gate.json and you see everything that call can return.
The app bundles no analytics or crash SDK. Its dependency manifest pins exactly two packages, sindresorhus/Defaults and swiftlang/swift-syntax. No PostHog, Sentry, Mixpanel, Amplitude, or Firebase ships inside Voice Type.
The unflattering entries belong here too. Voice Type holds no SOC 2 report and no ISO 27001 certificate, and offers no HIPAA BAA. The website analytics sit on PostHog’s US cloud rather than its EU cloud. Neither fact is hidden behind a stronger sentence elsewhere on the site.
The one case where text leaves your Mac
Recognition never needs the network. One feature can use it: LLM rewrite, which takes text that has already been transcribed and asks a language model to clean it up. It ships off. The default is set in the app source at WhisperState.swift:1835, where llmRewriteEnabled is declared false. Auto-rewrite is a separate switch, also false, at WhisperState.swift:2370.
The default is the easy part to publish. The capability is the part that matters, so here is the full list. The provider enum at LLMProvider.swift:212-232 names every destination the feature can reach. Three of them keep the rewrite on the machine:
- Apple On-Device, which uses Apple Intelligence on macOS 26 and needs no key.
- Ollama, which runs the model on the same Mac.
- A user script, which runs a local executable you install yourself.
The rest are remote, and every one of them is bring-your-own-key. You supply the credential, you pay the provider, and the request goes from your Mac to that provider’s endpoint. There is no Voice Type server in the middle, because there is no Voice Type server. The remote options are Alibaba Cloud, Amazon Bedrock, Anthropic Claude, Azure OpenAI, Cerebras, Cohere, DeepSeek, Google Gemini, Groq, Mistral, OpenAI, OpenAI via a Codex OAuth sign-in to your own ChatGPT account, OpenRouter, Perplexity, Together AI, and XAI, plus a custom OpenAI-compatible endpoint you supply.
None of those providers is a Voice Type subprocessor. A subprocessor is a party we engage to process data on our behalf, and we engage none of them. They appear here because a reader deciding whether this app is private needs the list of places text can go, not just the switch position we happen to ship.

How to check this yourself
None of this required special access. It is six habits, applied to documents any vendor publishes.
- Open the marketing page and the security or privacy documentation side by side. Marketing describes the default. Documentation describes the capability. Where a product has an optional cloud path, the two pages are written by different people for different readers, and the gap between them is the finding.
- Ask for the subprocessor list by name. Try /subprocessors, then the trust centre, then the DPA. A vendor that processes speech in the cloud and names no processor has not told you who holds the audio.
- Read the date on the privacy policy. A policy from 2024 attached to a product that shipped cloud features in 2026 describes an older product.
- Separate "we do not train on your data" from "our vendors do not train on your data". Both sentences can appear on the same site and mean different things about different parties.
- Check whether a certification claim names an auditor, a scope, a type, and a date. SOC 2 Type I and SOC 2 Type II are different reports, and "compliant" is not the same word as "audited".
- Turn off Wi-Fi and dictate. An app that keeps working offline is doing the recognition locally, whatever any page says.
Run those six against Voice Type as well. The trust page lists the three subprocessors, the app keeps working with Wi-Fi off, the certification row says none, and the rewrite provider list above is longer than the one sentence about the default.
Method and limits
- Sources are the vendors’ own live pages, read on 2026-08-29. No third-party review sites, no summaries of policies, no archived snapshots.
- A missing document is recorded as a missing document. "No published subprocessor list" means the pages named above did not contain one on that date, and nothing more.
- Silence is not evidence. Where a policy does not address training or human review, the cell says so rather than guessing the answer in either direction.
- Claims that exist only in secondary sources were left out. That includes a widely repeated 90-day free-plan audio retention figure for Notta, which no Notta document confirms.
- Voice Type facts come from the shipping Swift source and the site source, with file and line references given above.
