Skip to main content

Privacy research

Dictation app privacy: what ten vendors actually publish

Ten dictation products read against their own privacy policies, DPAs, docs, and trust centres on 2026-08-29. One publishes a complete subprocessor list.

Ten dictation products were read on 2026-08-29 against their own privacy policies, data processing agreements, support docs, and trust centres. One of the ten, Otter.ai, publishes a complete, dated, public subprocessor list. Two products carry a “never leaves your device” claim on one page that the same vendor’s own documentation on another page does not support.

Nothing below is inferred. Every cell is a quote from a document the vendor publishes, or a statement that a document does not address the question. Where a page returned 404 or named nothing, that is recorded as an absence and nothing further is read into it. Voice Type is the last row and is held to the same standard, including where the answer is unflattering.

The page is refreshed quarterly. Policies change, and a claim about a vendor is only as good as the date beside it.

The table

What ten dictation vendors publish about subprocessors, processing location, retention, training, human review, and certifications. Every cell was read from the vendor’s own documents on 2026-08-29.
VendorPublishes a subprocessor listWhere audio is processedRetentionTraining on user contentHuman reviewCertifications claimed
Wispr FlowTrust centre, Security FAQ, Data controls, Privacy policy, DPAPartial. The trust centre publicly names AWS, Baseten, Vercel, OpenAI, and Supabase. The authoritative list is Annex 2 of the DPA, available under NDA.Cloud, United States. "Transcription always occurs on the cloud." All customer data processed and stored in the US regardless of user location.Content sent to third-party AI providers "is generally deleted within 30 days". No fixed window published for Wispr’s own store, checked 2026-08-29.Toggle. In standard mode, "audio and transcription data may be used to evaluate, train, and improve Wispr’s models". Data sharing defaults to off.Not addressed in the privacy policy, data controls page, security FAQ, or DPA, checked 2026-08-29.Security FAQ: SOC 2 Type I (A-LIGN, April 2026), ISO 27001 Stage 1 complete and Stage 2 scheduled, HIPAA BAA available. The marketing page advertises SOC 2 Type II and ISO 27001.
SuperwhisperPrivacy policy, Sensitive data docs, Models docsNo published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The docs name the providers instead.On device by default. Cloud voice models are optional and configured per mode. Docs name Deepgram, OpenAI, Anthropic, Groq, Superwhisper Cloud, Azure OpenAI, and AWS Bedrock."All transcription history is stored locally on your device." Third-party providers are accessed under zero data retention terms."Your data is not being used for training AI models or any other machine learning purposes."Not addressed in the privacy policy or the security docs, checked 2026-08-29.None claimed, checked 2026-08-29. The policy asserts GDPR and CCPA compliance and no SOC 2 or ISO claim was found.
MacWhisperPrivacy policy, Keeping transcriptions privateNo published subprocessor list, checked 2026-08-29.Local by default. Docs name Groq, ElevenLabs, and Deepgram for cloud transcription, DeepL for translation, OpenAI and Anthropic for AI prompts, and Ollama or LM Studio for a local path.No retention statement in the privacy policy or the docs, checked 2026-08-29.Not addressed, checked 2026-08-29.Not addressed, checked 2026-08-29.None claimed, checked 2026-08-29.
VoiceInkPrivacy policy, GitHub READMENo published subprocessor list, checked 2026-08-29. The privacy policy names the optional providers directly.Local by default. Cloud only with a user-supplied key: Groq, OpenAI, Anthropic, Gemini, Mistral, Cerebras, Deepgram, ElevenLabs, Speechmatics, Soniox, OpenRouter, Ollama for local, plus custom endpoints.Transcriptions and audio files "Kept indefinitely by default until you delete them", on the device. Optional auto-delete runs 24 hours to 7 days for text and 7 days for audio.No training clause in the privacy policy, checked 2026-08-29. The policy does state VoiceInk "does not collect or transmit any personal data by default".Not addressed, checked 2026-08-29.None claimed, checked 2026-08-29. Licensed under GPL v3.
Otter.aiSubprocessors, Privacy policy, Privacy and security, Terms of serviceYes. A complete public list of 17 entries, last updated 2026-03-31. The only vendor of the ten with one.Cloud. AWS, Google Cloud, and Crusoe, all United States. Data may be transferred outside the user’s country.Conversations are deleted from trash after 30 days. General retention runs "as long as necessary". No fixed audio or transcript window published, checked 2026-08-29.The privacy policy permits "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)". No user opt-out found, checked 2026-08-29."Before audio recordings are ever reviewed manually by a human (Otter personnel or its third parties), we require explicit consent from customers." The subprocessor list includes Research Transcriptions for annotating training and evaluation data.A SOC 2 report is maintained with an independent auditor. GDPR standards are "incorporated" and HIPAA requirements "followed". ISO 27001/2 is named as a policy framework, not a certification.
NottaPrivacy policy, SecurityNo published subprocessor list, checked 2026-08-29. /en/subprocessors returns 404.Cloud. "Notta hosts all its software on Amazon Web Services (AWS)." Region not stated. No speech-to-text or language model vendor is named in any primary document, checked 2026-08-29.No audio or transcript retention period in the privacy policy or the security page, checked 2026-08-29.Addressed only for Google Workspace API data, which is "not used to develop, improve, or train generalized/non-personalized AI and/or ML models". Notta’s own transcription pipeline is not covered, checked 2026-08-29.Not addressed in the privacy policy or the security page, checked 2026-08-29.The security page asserts SOC 2 Type II, ISO 27001, GDPR, CCPA, and that Notta will "Follow HIPAA guidelines". No auditor named and no report availability stated, checked 2026-08-29.
SpeechifyPrivacy policy, SOC 2 blog postNo published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The policy names analytics and advertising vendors only."Information submitted to Speechify will be transferred to, processed, and stored in the United States." No speech or language model vendor is named, checked 2026-08-29.No audio or text retention period. Data may be kept "as long as reasonably necessary for our legitimate business interests", checked 2026-08-29.No AI training clause in the policy, checked 2026-08-29. The policy refers to using data "to improve our algorithms", which is not the same permission."Speechify employees do not monitor or view your User Content ... but it may be viewed if ... we need to do so to respond to your requests for support ... proofreaders may also read the User Content you submit for this specific service."A 2023 blog post states Speechify "is SOC2 compliant" and that enterprise clients can request the report. Type and auditor not stated, checked 2026-08-29.
Apple DictationAsk Siri and Dictation notice, Improve Siri and Dictation noticeApple publishes no subprocessor list for Dictation, checked 2026-08-29. Apple is the processor and no third-party vendor is named.Both. On capable devices the audio stays on device; otherwise "your audio is sent to and processed on Apple servers". Siri Settings indicates which applies.Server request history carries "a random, device-generated identifier that rotates multiple times per hour". "Apple may retain and use this data for up to two years", and a reviewed subset "may be kept beyond two years".Server data is used "to develop and improve Siri, Dictation, Search, and limited other language processing functionality". Audio is collected only if you opt in to Improve Siri and Dictation."Apple may review a subset of the transcripts of your interactions with Siri." On audio: "Only Apple employees, subject to strict confidentiality obligations, are able to access audio interactions with Siri and Dictation."No SOC 2 or ISO 27001 claim appears in the Dictation privacy notices, checked 2026-08-29.
Aqua VoicePrivacy policyNo published subprocessor list, checked 2026-08-29. The policy names attribution, advertising, and compliance vendors only.Not stated in the privacy policy, checked 2026-08-29. No speech or language model vendor and no hosting region are named."For users with Privacy Mode disabled, we may securely store transcript data on our servers to the extent necessary to improve the product. Otherwise, transcript data is not collected". No time window stated, checked 2026-08-29.No training clause, checked 2026-08-29. "to improve the product" is not a training permission in either direction.Not addressed, checked 2026-08-29."SOC 2 Type II compliant" via Advantage Partners, with Vanta for monitoring. Report availability not stated, checked 2026-08-29.
Willow VoicePrivacy policyNo published subprocessor list, checked 2026-08-29. Providers are named by category: "cloud infrastructure, transcription, security, diagnostics, customer support, and payment services".Not stated in the privacy policy, checked 2026-08-29.Private Mode: "Willow and its service providers do not retain that audio or use it for model training." Help Improve Willow: "Willow may retain anonymized recognized text, but not audio." History is stored locally on the device.Only under Help Improve Willow, on anonymized recognized text and never audio. No retention window for that text, checked 2026-08-29.Covered for Google User Data only. An equivalent statement covering dictation audio or text generally was not found, checked 2026-08-29.None claimed in the privacy policy, checked 2026-08-29.
Voice TypeVoice Type trust page, Voice Type privacy policyYes. Three subprocessors, published on the trust page: Apple, Cloudflare, PostHog. None of the three is in the path of a spoken word.On the Mac, by whisper.cpp. There is no upload endpoint in the app source and no Voice Type application server to upload to.No audio or transcript store, because there is no backend to hold one. Transcripts live wherever the text was typed.None. We receive no audio and no transcripts, so there is nothing to train on.None. No dictation reaches us, so there is nothing for a person here to read.None claimed. No SOC 2, no ISO 27001, no HIPAA BAA. A one-person macOS app has not been through those audits and this page will not imply otherwise.

Every cell read on 2026-08-29 from the linked sources. Vendor names link to the detail below. Retention, training, and human review are reported as the vendor writes them, including where the vendor writes nothing.

The two contradicted local-only claims

Both products below run recognition locally by default, and both are good software. The problem is not the default. It is that the marketing sentence describes the default as though it were the whole capability, while the same vendor documents a cloud path elsewhere.

MacWhisper

What the vendor says

"MacWhisper does all it’s functionality on your device. No data (audio, text or other) leaves your device."

Privacy policy, last updated February 14, 2024

What the same vendor’s documentation says

"By default, transcriptions (including Speaker Identification) is all performed locally on your Mac or iOS device". The same page then documents a "Cloud Transcription provider (such as Groq, ElevenLabs or Deepgram)", DeepL Translation, and AI prompt providers "such as OpenAI or Anthropic", with the note that "The exception to this is if you use a local AI Service Provider such as Ollama or LM Studio, which runs locally on your Mac."

Docs: keeping transcriptions private

The policy predates the cloud features the docs describe. It states the default as though it were the whole capability set. Both documents are current and public, and they do not agree.

VoiceInk

What the vendor says

"100% offline processing ensures your data never leaves your device."

GitHub README

What the same vendor’s documentation says

The privacy policy, last updated April 20, 2026, names twelve optional cloud providers that receive audio or text once enabled: Groq, OpenAI, Anthropic, Gemini, Mistral, Cerebras, Deepgram, ElevenLabs, Speechmatics, Soniox, OpenRouter, and custom OpenAI-compatible endpoints, plus Ollama for a local path.

Privacy policy

The README describes the default configuration. The policy describes the capability. A reader who stops at the README gets a different product than the one the policy documents.

Superwhisper is a near miss worth naming separately. Its privacy policy is dated June 19, 2024 and states the product is "designed to process audio data locally on your device", while the current docs describe optional cloud voice models and a Superwhisper-hosted cloud tier. The docs are the more current description, and unlike the two above they are explicit about the cloud path, per mode, on the same site.

Vendor by vendor

Wispr Flow

Publishes a subprocessor list
Partial. The trust centre publicly names AWS, Baseten, Vercel, OpenAI, and Supabase. The authoritative list is Annex 2 of the DPA, available under NDA.
Where audio is processed
Cloud, United States. "Transcription always occurs on the cloud." All customer data processed and stored in the US regardless of user location.
Retention
Content sent to third-party AI providers "is generally deleted within 30 days". No fixed window published for Wispr’s own store, checked 2026-08-29.
Training on user content
Toggle. In standard mode, "audio and transcription data may be used to evaluate, train, and improve Wispr’s models". Data sharing defaults to off.
Human review
Not addressed in the privacy policy, data controls page, security FAQ, or DPA, checked 2026-08-29.
Certifications claimed
Security FAQ: SOC 2 Type I (A-LIGN, April 2026), ISO 27001 Stage 1 complete and Stage 2 scheduled, HIPAA BAA available. The marketing page advertises SOC 2 Type II and ISO 27001.

Read 2026-08-29 from Trust centre, Security FAQ, Data controls, Privacy policy, DPA.

Superwhisper

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The docs name the providers instead.
Where audio is processed
On device by default. Cloud voice models are optional and configured per mode. Docs name Deepgram, OpenAI, Anthropic, Groq, Superwhisper Cloud, Azure OpenAI, and AWS Bedrock.
Retention
"All transcription history is stored locally on your device." Third-party providers are accessed under zero data retention terms.
Training on user content
"Your data is not being used for training AI models or any other machine learning purposes."
Human review
Not addressed in the privacy policy or the security docs, checked 2026-08-29.
Certifications claimed
None claimed, checked 2026-08-29. The policy asserts GDPR and CCPA compliance and no SOC 2 or ISO claim was found.

Read 2026-08-29 from Privacy policy, Sensitive data docs, Models docs.

MacWhisper

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29.
Where audio is processed
Local by default. Docs name Groq, ElevenLabs, and Deepgram for cloud transcription, DeepL for translation, OpenAI and Anthropic for AI prompts, and Ollama or LM Studio for a local path.
Retention
No retention statement in the privacy policy or the docs, checked 2026-08-29.
Training on user content
Not addressed, checked 2026-08-29.
Human review
Not addressed, checked 2026-08-29.
Certifications claimed
None claimed, checked 2026-08-29.

Read 2026-08-29 from Privacy policy, Keeping transcriptions private.

VoiceInk

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29. The privacy policy names the optional providers directly.
Where audio is processed
Local by default. Cloud only with a user-supplied key: Groq, OpenAI, Anthropic, Gemini, Mistral, Cerebras, Deepgram, ElevenLabs, Speechmatics, Soniox, OpenRouter, Ollama for local, plus custom endpoints.
Retention
Transcriptions and audio files "Kept indefinitely by default until you delete them", on the device. Optional auto-delete runs 24 hours to 7 days for text and 7 days for audio.
Training on user content
No training clause in the privacy policy, checked 2026-08-29. The policy does state VoiceInk "does not collect or transmit any personal data by default".
Human review
Not addressed, checked 2026-08-29.
Certifications claimed
None claimed, checked 2026-08-29. Licensed under GPL v3.

Read 2026-08-29 from Privacy policy, GitHub README.

Otter.ai

Publishes a subprocessor list
Yes. A complete public list of 17 entries, last updated 2026-03-31. The only vendor of the ten with one.
Where audio is processed
Cloud. AWS, Google Cloud, and Crusoe, all United States. Data may be transferred outside the user’s country.
Retention
Conversations are deleted from trash after 30 days. General retention runs "as long as necessary". No fixed audio or transcript window published, checked 2026-08-29.
Training on user content
The privacy policy permits "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)". No user opt-out found, checked 2026-08-29.
Human review
"Before audio recordings are ever reviewed manually by a human (Otter personnel or its third parties), we require explicit consent from customers." The subprocessor list includes Research Transcriptions for annotating training and evaluation data.
Certifications claimed
A SOC 2 report is maintained with an independent auditor. GDPR standards are "incorporated" and HIPAA requirements "followed". ISO 27001/2 is named as a policy framework, not a certification.

Read 2026-08-29 from Subprocessors, Privacy policy, Privacy and security, Terms of service.

Notta

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29. /en/subprocessors returns 404.
Where audio is processed
Cloud. "Notta hosts all its software on Amazon Web Services (AWS)." Region not stated. No speech-to-text or language model vendor is named in any primary document, checked 2026-08-29.
Retention
No audio or transcript retention period in the privacy policy or the security page, checked 2026-08-29.
Training on user content
Addressed only for Google Workspace API data, which is "not used to develop, improve, or train generalized/non-personalized AI and/or ML models". Notta’s own transcription pipeline is not covered, checked 2026-08-29.
Human review
Not addressed in the privacy policy or the security page, checked 2026-08-29.
Certifications claimed
The security page asserts SOC 2 Type II, ISO 27001, GDPR, CCPA, and that Notta will "Follow HIPAA guidelines". No auditor named and no report availability stated, checked 2026-08-29.

Read 2026-08-29 from Privacy policy, Security.

Speechify

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29. /subprocessors returns 404. The policy names analytics and advertising vendors only.
Where audio is processed
"Information submitted to Speechify will be transferred to, processed, and stored in the United States." No speech or language model vendor is named, checked 2026-08-29.
Retention
No audio or text retention period. Data may be kept "as long as reasonably necessary for our legitimate business interests", checked 2026-08-29.
Training on user content
No AI training clause in the policy, checked 2026-08-29. The policy refers to using data "to improve our algorithms", which is not the same permission.
Human review
"Speechify employees do not monitor or view your User Content ... but it may be viewed if ... we need to do so to respond to your requests for support ... proofreaders may also read the User Content you submit for this specific service."
Certifications claimed
A 2023 blog post states Speechify "is SOC2 compliant" and that enterprise clients can request the report. Type and auditor not stated, checked 2026-08-29.

Read 2026-08-29 from Privacy policy, SOC 2 blog post.

Apple Dictation

Publishes a subprocessor list
Apple publishes no subprocessor list for Dictation, checked 2026-08-29. Apple is the processor and no third-party vendor is named.
Where audio is processed
Both. On capable devices the audio stays on device; otherwise "your audio is sent to and processed on Apple servers". Siri Settings indicates which applies.
Retention
Server request history carries "a random, device-generated identifier that rotates multiple times per hour". "Apple may retain and use this data for up to two years", and a reviewed subset "may be kept beyond two years".
Training on user content
Server data is used "to develop and improve Siri, Dictation, Search, and limited other language processing functionality". Audio is collected only if you opt in to Improve Siri and Dictation.
Human review
"Apple may review a subset of the transcripts of your interactions with Siri." On audio: "Only Apple employees, subject to strict confidentiality obligations, are able to access audio interactions with Siri and Dictation."
Certifications claimed
No SOC 2 or ISO 27001 claim appears in the Dictation privacy notices, checked 2026-08-29.

Read 2026-08-29 from Ask Siri and Dictation notice, Improve Siri and Dictation notice.

Aqua Voice

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29. The policy names attribution, advertising, and compliance vendors only.
Where audio is processed
Not stated in the privacy policy, checked 2026-08-29. No speech or language model vendor and no hosting region are named.
Retention
"For users with Privacy Mode disabled, we may securely store transcript data on our servers to the extent necessary to improve the product. Otherwise, transcript data is not collected". No time window stated, checked 2026-08-29.
Training on user content
No training clause, checked 2026-08-29. "to improve the product" is not a training permission in either direction.
Human review
Not addressed, checked 2026-08-29.
Certifications claimed
"SOC 2 Type II compliant" via Advantage Partners, with Vanta for monitoring. Report availability not stated, checked 2026-08-29.

Read 2026-08-29 from Privacy policy.

Willow Voice

Publishes a subprocessor list
No published subprocessor list, checked 2026-08-29. Providers are named by category: "cloud infrastructure, transcription, security, diagnostics, customer support, and payment services".
Where audio is processed
Not stated in the privacy policy, checked 2026-08-29.
Retention
Private Mode: "Willow and its service providers do not retain that audio or use it for model training." Help Improve Willow: "Willow may retain anonymized recognized text, but not audio." History is stored locally on the device.
Training on user content
Only under Help Improve Willow, on anonymized recognized text and never audio. No retention window for that text, checked 2026-08-29.
Human review
Covered for Google User Data only. An equivalent statement covering dictation audio or text generally was not found, checked 2026-08-29.
Certifications claimed
None claimed in the privacy policy, checked 2026-08-29.

Read 2026-08-29 from Privacy policy.

Voice Type, same columns

Voice Type has three subprocessors. Apple handles App Store distribution, payment, receipts, and the iCloud mailbox behind [email protected]. Cloudflare handles website hosting, DNS, the files.carelesswhisper.app host, and email forwarding. PostHog handles website analytics on us.i.posthog.com, which is PostHog’s United States cloud. None of the three receives dictation, because none of them sits in the dictation path.

The app makes one call to a host we own. Every six hours it issues a plain GET to files.carelesswhisper.app/review-gate.json, a static file with three fields: an approved build number, a timestamp, and a schema version. No body, no identifier, no custom header beyond Accept. Run curl -s https://files.carelesswhisper.app/review-gate.json and you see everything that call can return.

The app bundles no analytics or crash SDK. Its dependency manifest pins exactly two packages, sindresorhus/Defaults and swiftlang/swift-syntax. No PostHog, Sentry, Mixpanel, Amplitude, or Firebase ships inside Voice Type.

The unflattering entries belong here too. Voice Type holds no SOC 2 report and no ISO 27001 certificate, and offers no HIPAA BAA. The website analytics sit on PostHog’s US cloud rather than its EU cloud. Neither fact is hidden behind a stronger sentence elsewhere on the site.

The one case where text leaves your Mac

Recognition never needs the network. One feature can use it: LLM rewrite, which takes text that has already been transcribed and asks a language model to clean it up. It ships off. The default is set in the app source at WhisperState.swift:1835, where llmRewriteEnabled is declared false. Auto-rewrite is a separate switch, also false, at WhisperState.swift:2370.

The default is the easy part to publish. The capability is the part that matters, so here is the full list. The provider enum at LLMProvider.swift:212-232 names every destination the feature can reach. Three of them keep the rewrite on the machine:

  • Apple On-Device, which uses Apple Intelligence on macOS 26 and needs no key.
  • Ollama, which runs the model on the same Mac.
  • A user script, which runs a local executable you install yourself.

The rest are remote, and every one of them is bring-your-own-key. You supply the credential, you pay the provider, and the request goes from your Mac to that provider’s endpoint. There is no Voice Type server in the middle, because there is no Voice Type server. The remote options are Alibaba Cloud, Amazon Bedrock, Anthropic Claude, Azure OpenAI, Cerebras, Cohere, DeepSeek, Google Gemini, Groq, Mistral, OpenAI, OpenAI via a Codex OAuth sign-in to your own ChatGPT account, OpenRouter, Perplexity, Together AI, and XAI, plus a custom OpenAI-compatible endpoint you supply.

None of those providers is a Voice Type subprocessor. A subprocessor is a party we engage to process data on our behalf, and we engage none of them. They appear here because a reader deciding whether this app is private needs the list of places text can go, not just the switch position we happen to ship.

The Voice Type window on macOS, showing Settings with the LLM tab selected. LLM Shortcuts lists LLM Transcribe and Rewrite Selected with no shortcut recorded, plus a checked Limit selection length option set to 5,000 max characters. Below it, LLM Rewrite Settings holds an Enable LLM Rewrite checkbox and a note saying rewrite can run on device via Apple Intelligence on macOS 26 with no API key, and otherwise uses a Bring Your Own Key provider whose usage and billing are the user's responsibility.
Enable LLM Rewrite ships off and is shown here switched on. Once it is on, text goes from the Mac to the chosen provider directly. Screenshot of Voice Type on macOS, unretouched.

How to check this yourself

None of this required special access. It is six habits, applied to documents any vendor publishes.

  1. Open the marketing page and the security or privacy documentation side by side. Marketing describes the default. Documentation describes the capability. Where a product has an optional cloud path, the two pages are written by different people for different readers, and the gap between them is the finding.
  2. Ask for the subprocessor list by name. Try /subprocessors, then the trust centre, then the DPA. A vendor that processes speech in the cloud and names no processor has not told you who holds the audio.
  3. Read the date on the privacy policy. A policy from 2024 attached to a product that shipped cloud features in 2026 describes an older product.
  4. Separate "we do not train on your data" from "our vendors do not train on your data". Both sentences can appear on the same site and mean different things about different parties.
  5. Check whether a certification claim names an auditor, a scope, a type, and a date. SOC 2 Type I and SOC 2 Type II are different reports, and "compliant" is not the same word as "audited".
  6. Turn off Wi-Fi and dictate. An app that keeps working offline is doing the recognition locally, whatever any page says.

Run those six against Voice Type as well. The trust page lists the three subprocessors, the app keeps working with Wi-Fi off, the certification row says none, and the rewrite provider list above is longer than the one sentence about the default.

Method and limits

  • Sources are the vendors’ own live pages, read on 2026-08-29. No third-party review sites, no summaries of policies, no archived snapshots.
  • A missing document is recorded as a missing document. "No published subprocessor list" means the pages named above did not contain one on that date, and nothing more.
  • Silence is not evidence. Where a policy does not address training or human review, the cell says so rather than guessing the answer in either direction.
  • Claims that exist only in secondary sources were left out. That includes a widely repeated 90-day free-plan audio retention figure for Notta, which no Notta document confirms.
  • Voice Type facts come from the shipping Swift source and the site source, with file and line references given above.
Voice Type subprocessor listSee pricing