| On-device mode (Apple Silicon β M1 or later) | None β audio is transcribed entirely on your Mac and never transmitted. Account holders: email (account auth) plus non-identifying usage analytics; crash reports exclude dictated content. | No In on-device mode nothing leaves your Mac: your voice is transcribed entirely on the device. Because audio never crosses the network, there is no training to opt out of. Training25/25 | Audio: not transmitted, not retained. Account email: kept while account is active. Retention25/25 | Yes β Whisper models running on the Apple Silicon Neural Engine. Requires an Apple Silicon Mac (M1 or later). On-device25/25 | New entrant; on-device processing removes the surface for retention or training incidents. Track record22/25 | 97/100Excellent | Jul 10, 2026 | |
| Private cloud mode (open-weight models on Voibe infrastructure β all Macs) | Audio is sent over an encrypted connection to Voibe's own infrastructure for transcription, then deleted the moment transcription completes. Account email plus non-identifying usage analytics as above. | No Cloud mode runs only open-weight models β Whisper Large Turbo (open-source) on Groq or Cloudflare for transcription, and GPT-OSS 120B (open-weight) on Cerebras for text refinement β not proprietary models from the major research labs or hyperscalers. Voice is never stored and never used to train any AI model; the same applies to text. Users choose on-device or cloud in Settings. Training23/25 | Audio is deleted the moment transcription completes. Neither voice nor text is stored. Retention23/25 | No β private cloud mode runs on Voibe's own infrastructure (works on all Macs, Intel and Apple Silicon). On-device3/25 | Hybrid model documented publicly on Voibe's AI & privacy page; open-weight models only, zero retention, no training. Track record22/25 | 71/100Strong | Jul 10, 2026 | |
| Free (Privacy Mode OFF, default) | Audio, transcripts, edits, optional Context Awareness (screen content from active app) | Yes (opt-in) After 2024 community backlash, training is now off by default and requires opt-in. Audio retained indefinitely; 30 days for data passed to third-party LLMs (OpenAI, Meta). Local data-storage controls let users store transcripts locally, auto-delete local data after 24 hours, or never store data locally. Training20/25 | Indefinite for retained dictation data; 30 days for third-party LLM passthrough. Retention3/25 | No β transcription always happens in the cloud, even in Privacy Mode (zero-retention cloud, not local). On-device3/25 | 2024 community backlash forced opt-in training and Privacy Mode; Free tier still indefinite by default. March 2026: Wispr's prior SOC 2 Type II (Accorp Partners) and ISO 27001 (Gradient) certifications were proactively invalidated over platform-integrity concerns at the original auditor; A-LIGN re-audited, completing a clean SOC 2 Type I in April 2026 (Type II in progress) and ISO 27001:2022 Stage 1 in April 2026 (Stage 2 scheduled June 2026). Track record10/25 | 36/100Poor | Jul 1, 2026 | |
| On-device modes (Fast / Nano / Standard / Parakeet β Free + Pro) | None β audio processed locally and never transmitted | No "Your data is not retained on Superwhisper servers" and "not used for training AI models or any other machine learning purposes." Audio recordings are saved to local disk by default β opt out in settings. Training25/25 | N/A on servers. Local recordings persist until the user deletes them. Retention23/25 | Yes On-device25/25 | Stable privacy-first stance; cloud modes added without separate disclosure in the public privacy policy. Track record18/25 | 91/100Excellent | Apr 27, 2026 | |
| Cloud modes (Ultra transcription / Super Mode LLMs β Pro) | Audio sent to Superwhisper's proxy infrastructure | No (per vendor) Superwhisper says cloud audio is proxied through their infrastructure, third-party providers don't see user account or content, and there is no training or retention. Cloud-mode handling is not currently distinguished in the public privacy policy from on-device modes β verify the latest with the vendor before sensitive use. Training18/25 | Stated as not retained on servers; not separately documented for cloud modes. Retention13/25 | No On-device3/25 | Stable privacy-first stance; cloud modes added without separate disclosure in the public privacy policy. Track record18/25 | 52/100Weak | Apr 27, 2026 | |
| Pro (Gumroad) / Whisper Transcription (App Store) | On-device modes: none transmitted. App Store version discloses "Usage Data" and "Product Interaction" as Data Not Linked to You. Cloud Assistant or BYOK (OpenAI / ElevenLabs) features send audio to those providers under their terms. | No (by MacWhisper) MacWhisper does not train its own models on user audio. Cloud Assistant and BYOK integrations inherit the chosen provider's terms (e.g., OpenAI Whisper API, Anthropic / ElevenLabs). Training23/25 | On-device transcription: not retained. Cloud Assistant / BYOK: per third-party provider's terms. Retention20/25 | Yes (primary mode) β local Whisper models plus Apple Foundation Models for AI features. Cloud Assistant is opt-in for higher-quality transcription. On-device23/25 | Long-running indie tool; on-device by default; no documented incidents. Track record22/25 | 88/100Excellent | Jul 1, 2026 | |
| Free / Pro / iOS Pro | Audio inputs, technical data (IP, browser, OS, performance metrics), session metadata. With Privacy Mode disabled, "we may securely store transcript data on our servers." | Yes (opt-out) Privacy Mode toggle stops transcript storage on Aqua Voice servers; with it enabled, "transcript data is not collected" though session metadata may still be. The privacy policy does not explicitly state whether stored transcript data is used for AI training. SOC 2 Type II certified by Advantage Partners. No HIPAA BAA publicly advertised. Training8/25 | With Privacy Mode disabled: not specified in policy. With Privacy Mode enabled: transcripts not stored; session metadata (timestamps, device type, performance metrics) may be retained. Retention0/25 | No β cloud transcription On-device3/25 | SOC 2 Type II via Advantage Partners; privacy policy ambiguous on whether stored transcripts are used for AI training. Track record15/25 | 26/100Poor | Jul 1, 2026 | |
| Free / Pro | Audio plus limited contextual information, processed on Typeless's cloud servers. Subprocessors include third-party LLM providers, analytics, and cloud infrastructure. | No (per vendor) Privacy policy: "Your data is never used to train these services and is configured for zero retention by the providers." Note: the November 2025 reverse-engineering analysis documented in our Typeless privacy issues investigation reported collection beyond what the public policy describes β verify against the current policy and subprocessor list before sensitive use. Training15/25 | Per privacy policy, audio + contextual information are "processed in real time on our cloud servers and immediately discarded once the result is returned to your device." Retention23/25 | No β cloud-processed in real time On-device3/25 | Nov 2025 reverse-engineering analysis documented collection (URLs, window-title metadata, broad permissions) beyond what the public policy describes. Track record5/25 | 46/100Weak | Jul 1, 2026 | |
| macOS / iOS (Apple Silicon, supported languages) | Audio inputs, plus contextual data (contacts, app names, etc.) when sent to servers | Opt-in only "Improve Siri & Dictation" must be enabled. Default at setup is to be asked. Training20/25 | If opted in: audio + transcripts kept under a rotating random ID for up to 6 months, dissociated and kept up to 2 years for improvement; reviewed subset retained beyond 2 years. If opted out: not retained for improvement. Retention13/25 | Yes (partially) β most languages on Apple Silicon process locally for general text fields (Notes, Mail, Messages). Server fallback applies to unsupported languages, search-box dictation, and some third-party Speech Recognition API uses. On-device18/25 | 2019 Siri grading scandal led to opt-in for human review; otherwise privacy-forward. Track record18/25 | 69/100Adequate | Jul 1, 2026 | |
| Free Trial / Individual ($12/mo annual = $144/yr, Private Mode default) | Private Mode (default): basic technical and account-related data only β verbatim: "In private mode, Willow only collects basic technical and account-related data needed to run the app and nothing else. No voice, no dictated text." Opt-In Mode: anonymized text and usage data to improve text-correction models. | No (Private Mode default) Private Mode is the default. Training only occurs if the user explicitly opts into Opt-In Mode β "You can allow Willow to collect minimal usage data to help improve our text correction models." This is the inverse of Wispr Flow Free, which had Privacy Mode off by default until the 2024 community backlash. Privacy policy last updated April 30 2025. Training20/25 | Private Mode: no audio or transcript collected on Willow servers. Opt-In Mode: "We keep anonymized text and usage data only as long as needed to train and improve the app." No specific retention window disclosed for the Opt-In path. Retention13/25 | No β cloud-first transcription. The privacy policy's "this is only stored locally on your device for you to view" refers to local UI storage of past transcripts, not local transcription. No offline transcription mode advertised on the current pricing page. On-device5/25 | Newer entrant (YC X25 cohort). Marketing pricing page advertises HIPAA + SOC 2 + zero data retention at the Enterprise tier, but the privacy policy text itself only references "GDPR and SOC 2" β HIPAA / BAA scope is not documented in the policy. Minor discrepancy between marketing claims and policy substantiation. Track record13/25 | 51/100Weak | May 12, 2026 | |
| Free (1,000 words) / Pro ($144/yr) / Every Bundle ($30/mo) | Per the monologue.to data-privacy page: "No audio files or transcripts are saved on our servers," "Deep context screenshots are deleted immediately," "Zero LLM data retention," and "Custom modes and dictionaries stay on your device." The page does not enumerate categories of data collected beyond these statements. | Unknown β policy silent The published monologue.to data-privacy page and the Notion-hosted privacy policy neither explicitly state that user data is used for training nor that it is excluded. This silence is load-bearing: peer cloud dictation products (Wispr Flow, Typeless, Superwhisper, Willow Voice) all explicitly address training one way or the other. Treat as ambiguous until clarified. Training13/25 | Verbatim: "No audio files or transcripts are saved on our servers." "Zero LLM data retention." Deep context screenshots deleted immediately. Custom modes and dictionaries stay on the device. Retention22/25 | Partial β "Offline transcription support" is listed as a feature on both Free and Pro tiers per the monologue.to marketing site, and "Custom modes and dictionaries stay on your device," but the marketing site does not document the architecture (cloud-default with offline fallback vs. on-device-default). On-device13/25 | Indie product (1-person team). Privacy policy hosted on Notion at modern-ton-234.notion.site and is sparse β no list of data categories collected, no subprocessor list, no retention windows beyond the broad "not saved" claims, no SOC 2 / HIPAA / BAA. Training-silence is the load-bearing gap. Track record8/25 | 56/100Adequate | May 12, 2026 | |
| Free build (GPL v3) / Pro $39.99 one-time | None on VoiceInk servers β there is no VoiceInk-operated cloud service in the inference path. Audio is transcribed on-device using whisper.cpp. | No VoiceInk README verbatim: "100% offline processing ensures your data never leaves your device." Marketing site: "privacy-focused dictation app for macOS with local transcription." No telemetry, BYOK cloud feature, or AI-command post-processing service documented at this verification pass. Source code is auditable on GitHub under GPL v3.0. Training25/25 | Nothing leaves the device. No vendor server, no retention surface. Retention25/25 | Yes (only mode) β local Whisper models via whisper.cpp. Apple Silicon native. On-device25/25 | Open-source GPL v3.0; auditable on GitHub at Beingpax/VoiceInk; 4,900+ stars and 675+ forks; 119 releases; latest v1.76 (May 7 2026). No documented incidents. Mild deduction for being a single-maintainer project (continuity risk distinct from privacy risk). Track record22/25 | 97/100Excellent | May 12, 2026 | |
| Local Only Mode (Free) | None during transcription β audio runs through OpenAI Whisper Large-v3 and NVIDIA Parakeet locally on Apple Silicon with no network calls. Analytics per the privacy policy are limited to button clicks and page views, with no personally identifiable information stated. | No In Local Only Mode there is no transmission to train on. The privacy policy effective March 2, 2026 states audio recordings are "not stored" on Spokenly's servers; in this mode nothing reaches a server in the first place. Training25/25 | Audio: not transmitted, not retained. Local recordings persist on the Mac until the user deletes them. Retention25/25 | Yes β Whisper Large-v3 and Parakeet on Apple Silicon, no network calls during transcription. On-device25/25 | Indie product by named solo developer Vadim Akhmerov (disclosed via App Store, not the privacy policy); no disclosed corporate entity or jurisdiction; no SOC 2 / HIPAA / ISO 27001 / GDPR / CCPA attestations. App Store 4.4/5 from 43 ratings, active April 2026 release. No documented incidents. Track record14/25 | 89/100Excellent | May 25, 2026 | |
| BYOK cloud (Free β bring your own API key) | Audio routed to whichever provider you configure keys for β OpenAI, Deepgram, Groq, Anthropic, or Google. Spokenly passes audio through; data handling is governed by the chosen provider's terms. | Depends on provider Spokenly itself does not train on audio, but BYOK transfers the training and retention question to the provider whose key you supply. Each provider (OpenAI, Deepgram, Groq, Anthropic, Google) has its own training and retention terms β verify the specific provider before sensitive use. Training16/25 | Spokenly: "not stored" on its servers. Provider-side retention follows whichever API you bring keys for. Retention14/25 | No β audio leaves the device for the configured cloud provider. On-device3/25 | Indie solo-developer product; no disclosed corporate entity; no compliance attestations. App Store 4.4/5 from 43 ratings. Track record14/25 | 47/100Weak | May 25, 2026 | |
| Pro managed cloud ($9.99/mo) | Audio routed through five named subprocessors per the privacy policy: Cerebras, Fireworks, Groq, Mistral AI, and ElevenLabs. Each is a separate data-handling entity. | Policy silent on subprocessor training The privacy policy names the five subprocessors and states audio recordings are "not stored" on Spokenly's servers, but it does not explicitly state whether those subprocessors train on or retain the audio they receive. Treat the subprocessor chain's training posture as undocumented. Training15/25 | Spokenly: audio "not stored" on its servers. Each of the five subprocessors retains per its own terms β not enumerated in Spokenly's policy. Retention16/25 | No β audio is processed through the managed-cloud subprocessor chain. On-device3/25 | No SOC 2 / HIPAA BAA / ISO 27001; no disclosed corporate entity. Five subprocessors named but their handling terms are not enumerated. Track record14/25 | 48/100Weak | May 25, 2026 | |
| Dragon Professional v16 β Windows desktop, fully offline (no Mac version since 2018; Dragon Home discontinued 2023) | None transmitted in local desktop operation. Voice profile (acoustic data, custom vocabulary, dictionary) stored locally on the user's Windows machine. | No Dragon Professional v16 is a locally installed Windows desktop application that processes audio on-device once activated. Audio is not transmitted to Nuance/Microsoft servers in normal desktop operation. Product is Windows-only β Mac version was discontinued in 2018. Training22/25 | Profile and acoustic data stored locally on the user's machine; nothing sent off-device in desktop dictation mode. Retention22/25 | Yes β fully offline/local processing on Windows (x86). Apple Silicon Mac users have no native Dragon option since the 2018 Mac discontinuation. On-device23/25 | 2017 NotPetya attack disrupted Nuance's hosted services (including Dragon Medical) for weeks. Development largely stalled since Microsoft's 2022 Nuance acquisition (v17 β v16). Mac version discontinued 2018; Dragon Home (consumer) discontinued 2023. Non-medical product marketing pages now redirect to Microsoft's health-solutions hub. Track record16/25 | 83/100Strong | May 22, 2026 | |
| Dragon Anywhere (iOS/Android) β cloud | Audio and transcripts transmitted to Nuance/Microsoft cloud for recognition. Account/device metadata also collected. | Unknown β policy silent Microsoft's general Privacy Statement reserves the right to use customer data to develop and train AI models (with opt-out paths surfaced through Copilot privacy controls). Dragon-specific product pages do not separately disclose AI-training commitments or carve-outs for Dragon Anywhere at the consumer/mobile tier. Treat as unverified until Microsoft publishes a Dragon-specific commitment; do not assume the Commercial Terms no-training stance applies to a consumer Dragon Anywhere subscription. Reach out to Microsoft sales for written confirmation before sensitive use. Training13/25 | Microsoft Privacy Statement's general retention framework applies. Dragon-specific retention windows for Anywhere are not separately disclosed on the current product pages. Retention10/25 | No β cloud recognition. On-device3/25 | Same 2017 NotPetya history. Post-acquisition product reorganization removed many Nuance trust-center URLs (now redirect to Microsoft health-solutions), creating a discovery gap that itself is a track-record drag for buyers trying to verify privacy commitments. Track record14/25 | 40/100Weak | May 22, 2026 | |