Limited time: Save up to 33% on every planView pricing
Voibe Logovoibe Resources
wispr flowwispr flow safewispr flow privacywispr flow securitywispr flow incidentsprivacy modecloud synczero data retentiondelve compliancesoc 2hipaacloud dictationon-devicemacprivacy

Is Wispr Flow Safe? Seven Incidents and Two Toggles You Need to Know

Screenshots, a keystroke tap, a fake-audit scandal, and LinkedIn posts built from user dictations. Every Wispr Flow incident, and the two settings that help.

· Updated

Is Wispr Flow Safe? The Short Answer

Nobody has hacked Wispr Flow. There is no breach, no leaked database, no ransom note. That is exactly why the safety question is harder than it looks — everything that has gone wrong with Wispr Flow went wrong on purpose, as a documented default, and every time a user found one of them, they found it themselves.

The short answer: Wispr Flow is fine for the stuff you would happily say out loud in a coffee shop. It is a poor fit for anything you would not. It is a cloud-only product — there is no offline mode on any platform — your audio is transcribed on someone else's servers, and the two settings that stop your dictation being stored and trained on are both off by default on a standard account. Most people never find them.

Since 2025 the company has accumulated seven public incidents: screen capture discovered by a user who was then banned for reporting it, a fake-audit scandal at its compliance vendor, an independent forensic report documenting a system-wide keyboard tap and a 694 MB local database of your dictations, days of outages, a founder demoing per-user analytics on a podcast, and — most recently — a team member publishing word-frequency data mined from what users dictate, on LinkedIn, as marketing.

To Wispr's credit, one item on that list is good news: after the audit scandal it hired A-LIGN, a serious auditor, and the fresh SOC 2 Type I came back clean in April 2026. The company is also unusually candid in its own docs about what it cannot do — no EU data residency, no end-to-end encryption, no customer-managed keys.

Below: every incident with its source, the two toggles you should change in the next five minutes if you keep using it, and the architectural alternative if you would rather not have this conversation at all. Voibe — the Mac and Windows dictation app we build — runs fully on-device on Apple Silicon, so none of the questions on this page have an answer to look up.

Key Takeaway

Wispr Flow has never been breached. Its safety problems are defaults, not attacks: cloud-only processing, Privacy Mode and Cloud Sync both off on standard accounts, and seven public incidents between 2025 and August 2026. On-device dictation removes the question rather than answering it.

Key Takeaways: The Wispr Flow Safety Picture (August 2026)

AreaWhere it standsSource
ArchitectureCloud-only on every platform. No offline mode exists. Audio is decrypted server-side to be transcribed.Wispr security & compliance FAQ
Privacy ModeOff by default on trial and standard accounts. Controls training only.Wispr security & compliance FAQ
Cloud SyncThe second toggle. Controls whether transcripts, audio and history are stored on Wispr's servers. ZDR = Privacy Mode on and Cloud Sync off.Wispr security & compliance FAQ
Screen readingAccessibility-text context is default on. Screen OCR (a full-display screenshot) is opt-in.Wispr security & compliance FAQ
KeyboardAn April 2026 forensic report documents a system-wide event tap that sees every keystroke, active or not. Not mentioned in the privacy policy.Wensen Wu forensic report
Subprocessor listFormerly public and self-serve. Now Annex 2 of the DPA, available under NDA via the trust center.Wispr security & compliance FAQ
Data residencyUS only. “Wispr does not operate a European or other regional processing location for customer data.”Wispr security & compliance FAQ
EncryptionTLS 1.2+ in transit, AES-256 at rest. No end-to-end encryption, no customer-managed keys (BYOK), no FedRAMP.Wispr security & compliance FAQ
SOC 2Prior report issued in the Delve ecosystem. A-LIGN Type I clean, April 2026. Type II observation period still open as of August 2026.Wispr security & compliance FAQ
HIPAASelf-serve BAA on Desktop and iOS. Locks Privacy Mode on and Cloud Sync off — until it is revoked, which silently unlocks both.Wispr security & compliance FAQ
Content analysisAug 2026: a team member published India-vs-US word-frequency data from user dictations on LinkedIn (“kindly” 5.6×, “incredible” 0.3×).Public LinkedIn post
Trustpilot2.7/5. Complaints cluster on post-trial reliability, referral rewards, and terms-of-service language.trustpilot.com/review/wisprflow.ai
AlternativeOn-device dictation (Voibe, VoiceInk, Superwhisper offline) has no cloud surface to assess.Architectural comparison

Each row is unpacked below, in the order the incidents happened.

Every Wispr Flow Incident, in Order

Read together, the list matters more than any single item. One privacy misstep is a bad quarter. Seven since 2025 — every one surfaced by an outsider, every one defensible under the company's own policies — is a pattern — and the pattern is the safety finding.

  1. 2025 — the screenshots, and the ban. A user watching their own network traffic found Wispr Flow shipping screenshots of the active window off-device. The company's first move was to ban them. The CTO later apologized publicly and Context Awareness was reworked.
  2. March 2026 — Delve. Wispr Flow's compliance vendor was accused, in a detailed public investigation, of generating templated audit reports. Wispr Flow was a named customer. Its SOC 2 Type II and ISO 27001 were both issued inside that ecosystem.
  3. April 2026 — the forensic report. A software engineer, debugging a broken spacebar, took the Mac app apart and documented a system-wide keyboard event tap, a 694 MB local database of audio and transcripts, and hourly uploads that continued with data sharing switched off.
  4. April 2026 — A-LIGN Type I lands clean. The good news item. An independent, well-established auditor verified that the controls exist.
  5. Late May to June 2026 — the outages. Days of dictation failures across every platform, because there is no local mode to fall back to. Covered in our outage timeline and our running reliability log.
  6. June 2026 — the podcast. The CEO walked through an analytics stack that ties dictation volume and app usage to named individuals at named employers. Full breakdown here.
  7. August 2026 — the LinkedIn post. A team member published word-frequency comparisons drawn from user dictations, split by country, as social content. Our report on it.

Notice what is not on the list: a breach, a leak, a rogue employee. Every entry is either a default somebody had to go looking for, or something the company chose to publish about itself. That is the honest shape of the Wispr Flow safety story — and it is why “is it secure?” is the wrong question. It is secure. The question is what it is permitted to do.

Key Takeaway

Seven public Wispr Flow incidents between 2025 and August 2026: the 2025 screenshot discovery and user ban, the March 2026 Delve fake-audit scandal, the April 2026 forensic keyboard report, a clean A-LIGN SOC 2 Type I, the May–June outages, the June founder podcast, and the August LinkedIn dictation-data post. None involved an attacker.

Where Your Voice Actually Goes

Wispr Flow is a cloud product, and it does not pretend otherwise. You speak, the audio is encrypted, sent across the internet, decrypted on Wispr's infrastructure, transcribed, passed through one or more third-party language models for formatting, and returned to your cursor as text. There is no on-device mode on Mac, Windows, iOS, or Android.

The company is explicit about the consequence in its own security and compliance FAQ: “Wispr Flow does not provide end-to-end encryption in the strict cryptographic sense (where the service provider cannot decrypt content)… Wispr's backend must decrypt audio to perform transcription.” And, plainly: “For customers requiring true E2E encryption where the provider cannot read content, Wispr Flow's transcription model does not support that architecture.” That is a genuinely useful admission. It is also the whole argument on this page in one sentence.

Who handles your data. Through April 2026, Wispr Flow published a self-serve subprocessor list naming every vendor in the path. That page is gone. The FAQ now says: “The authoritative subprocessor list is Annex 2 of the DPA, available under NDA via the Trust Center.” You now have to sign a document to find out who processes your voice.

From the list as it stood while it was public — corroborated for several vendors by the April 2026 forensic analysis of the Mac binary described below — the path was:

  • Baseten — transcription. Your audio goes here.
  • OpenAI, Anthropic, Cerebras — text formatting and Polish. Your transcript goes here.
  • Fireworks AI, OpenRouter — Command Mode fallback.
  • AWS — storage, us-east-1.
  • Supabase — authentication.
  • PostHog, Sentry, Segment, Datadog — analytics, error tracking and telemetry. PostHog can capture session replays; Sentry can capture screenshots of error states.
  • Stripe, RevenueCat — payments. Twilio — SMS. Attio, Pylon — CRM and support.

Eleven-plus companies for the sentence you just dictated. None of that is unusual for cloud SaaS — and that is the point. It is the normal cost of the architecture. The FAQ also notes there is no customer veto: subprocessor risk is reviewed annually by Wispr, not approved by you, and customers do not get to pick which model provider sees their text.

Warning

The subprocessor list used to be a Wispr Flow strength — a public page anyone could read. As of August 2026 it is Annex 2 of the DPA, behind an NDA. If you want to know which companies handle your voice, you now have to ask for a legal document first.

2025: The Screenshots — and the User Who Got Banned for Finding Them

The original Wispr Flow privacy story starts with someone watching their own firewall. In 2025 a user monitoring outbound traffic found the app uploading screenshots of the active window, on a timer, to cloud infrastructure. They posted about it. Reddit did what Reddit does.

Wispr Flow's first response was to ban them.

That is the detail worth sitting with. Not the screenshots — a context feature that reads the screen is a defensible product decision, badly disclosed. The ban is the tell. The company's instinct, when shown evidence of its own data practices, was to remove the person holding the evidence. The CTO later apologized publicly, acknowledged the ban was wrong, and Context Awareness was reworked into something with real toggles.

Where it landed, per Wispr's own current FAQ. Context Awareness is now two separate controls, and the split matters more than most write-ups admit:

  • Accessibility-text context — default on. “Reads text from the active application's accessibility tree to improve AI formatting.” This is not opt-in. If you installed Wispr Flow and never opened settings, it is reading the text of whatever app you are dictating into.
  • Screen OCR — default off, opt-in. “Captures a full-display screenshot to extract proper nouns.” Note full-display, not active-window: per the FAQ, “Screen OCR captures the display containing the mouse cursor.” Everything on that monitor, not just your text field.

Screenshots only flow when both toggles are on, and turning off accessibility-text context automatically disables Screen OCR. Fair. But the widely repeated claim that Wispr Flow's screen reading is off by default is wrong — half of it ships on.

And there is a second clause most people miss. Screen context is stripped server-side only when Privacy Mode is on and Cloud Sync is off. In the FAQ's words: “Under Cloud Sync on with Privacy Mode off, screen-context fields may be persisted alongside the transcript.” That combination — Cloud Sync on, Privacy Mode off — is the standard-account default. So on a default install, what your screen said can be stored next to what you said.

Here is how that goes wrong in real life, with nobody doing anything malicious:

  • A clinician dictates a note with the patient's chart open on the same display.
  • A lawyer dictates an email with a privileged document in the next pane.
  • An engineer dictates a commit message with an .env file open in the editor.
  • Anyone dictates while a password manager, a bank statement, or a private thread sits behind the text field.

Nothing in the dictation flow signals any of this. There is no indicator, no prompt, no “screen read” badge. You press a hotkey and talk.

Key Takeaway

Wispr Flow's screen reading is not fully opt-in: accessibility-text context is on by default, and Screen OCR captures the whole display containing the cursor. Screen context is only stripped server-side when Privacy Mode is on and Cloud Sync is off — neither of which is the standard-account default.

Warning

Check this one now: Settings → Data & Privacy. Accessibility-text context ships ON, so Wispr Flow is reading the active app's text unless you turned it off. Screen OCR, if you ever enabled it, screenshots the entire display your cursor is on — not just the window you are typing into.

April 2026: An Engineer Debugged His Spacebar and Found a Keyboard Tap

On April 4, 2026, software engineer Wensen Wu noticed his spacebar dropping presses. He ruled out Sticky Keys, remappings, hardware, input sources. Then he killed Wispr Flow and the keyboard started working again.

What followed is the most detailed public look inside the Wispr Flow Mac client that exists: a forensic write-up built entirely from the app's own log files, its SQLite database, and its code-signing entitlements. No packet interception, no decompilation, no reverse engineering — the app documented itself. Version tested: 1.4.752.

What he found:

  • A system-wide keyboard tap. Wispr Flow installs an active CGEventTap — an interceptor that receives every keystroke before the app you are typing into does, and can drop them. It runs whether or not you are dictating. A passive monitor would be enough to detect a hotkey; an active tap is what lets the app eat your spacebar. The bug that started all this: a stale modifier key left the tap convinced the dictation shortcut was held down, and it suppressed 145 spacebar presses in under ten minutes — logged, by name, in the app's own log file.
  • A 694 MB local database. flow.sqlite in Application Support held a History table with 3,404 dictation entries and roughly 198 MB of raw audio — plus transcripts, accessibility-tree HTML, text-box contents, app names and URLs. The schema includes a screenshot BLOB column.
  • An hourly upload loop that keeps going with sharing off. The logs show POST /history/upload firing on a schedule against rows flagged needsUploading. One line reads, verbatim: “Usage data sharing is off, only uploading metadata.” Off meant less, not none.
  • Browsing history, effectively. 1,688 app-and-URL events in a 30-hour window, logged as “Sending application info request for bundle ID: com.google.Chrome and URL: github.com.”
  • Four telemetry services and 1,183 distinct analytics events — PostHog, Sentry, Segment and Datadog — for a dictation app.
  • Hardened Runtime protections switched off. The bundle is not sandboxed and ships disable-library-validation and allow-unsigned-executable-memory, plus NSAllowsArbitraryLoads = true. Translated: another process on your Mac can inject code into an app that already holds Accessibility permission and a live keystroke tap. That is a meaningful privilege-escalation surface, regardless of Wispr's own intentions.

Being fair about what this is and isn't. It is one engineer, one machine, one app version, published on a personal site — not a coordinated disclosure and not an audit. Wispr Flow has not publicly responded to it, and the post got very little traction when it was submitted to Hacker News. Its evidence is unusually checkable, though: the log paths and the database path are on your own disk, and Wu tells readers exactly where to look (~/Library/Logs/Wispr Flow/accessibility.log and ~/Library/Application Support/Wispr Flow/flow.sqlite). Some of it has also been overtaken by events — enterprise admins can now set local storage to “Delete after 24 hours” or “Never store,” which addresses the on-disk pile-up for managed fleets, though not for individual Pro users.

The part that still stands. Wispr Flow's privacy policy, last updated July 25, 2026 — three months after the report — still contains no instance of the words keystroke, keyboard, typing, URL, or browsing. It discloses “audio Inputs,” “Usage Data,” and “the application used for dictation.” An app that intercepts every key you press system-wide and logs the websites you visit should say so in the document users are pointed to.

You can check the keystroke-suppression part yourself in about ten seconds — open ~/Library/Logs/Wispr Flow/accessibility.log and search for Suppressing event.

Key Takeaway

An April 2026 forensic report on Wispr Flow 1.4.752 documented a system-wide CGEventTap that suppressed 145 spacebar presses in ten minutes, a 694 MB local database with 3,404 dictations and 198 MB of audio, hourly uploads that continued with sharing off, 1,688 app/URL events in 30 hours, and disabled Hardened Runtime protections. Wispr Flow's privacy policy still does not mention keystrokes or URLs.

Warning

The gap here is disclosure, not malice. A dictation app needs Accessibility permission to paste text and catch a hotkey — that part is legitimate. What is hard to defend is an always-on active event tap that can drop keystrokes, plus app-and-URL logging, neither of which appears anywhere in a privacy policy updated three months after the finding was published.

Privacy Mode Alone Is Not Zero Retention — Cloud Sync Is the Second Toggle

This is the single most useful thing on this page, and almost nobody gets it right, including plenty of reviews that praise Wispr Flow's Privacy Mode.

Privacy Mode is not zero data retention. Per Wispr Flow's own FAQ, the product uses “two independent controls”:

  • Privacy Mode — “controls whether your dictation data is used to evaluate, train, or improve AI models.”
  • Cloud Sync — “controls whether your transcription data (transcripts, audio, dictation history) is stored on Wispr's servers.”

And then, verbatim: “Zero Data Retention (ZDR) is the combination of Privacy Mode on and Cloud Sync off.”

So flipping Privacy Mode stops the training. It does not stop the storing. If you turned on Privacy Mode and stopped there — which is what nearly every guide tells you to do — your audio, transcripts and dictation history are still sitting on Wispr's servers. You need both.

The defaults, spelled out:

  • Trial and standard accounts: Privacy Mode off. In Wispr's words, “audio and transcription data may be used to evaluate, train, and improve Wispr's models. This is the default for trial and standard accounts.”
  • Enterprise: data sharing defaults off (Privacy Mode effectively on) — but “Cloud Sync defaults to on unless the enterprise has explicitly enabled ZDR or a HIPAA BAA is active.” An enterprise that thinks it bought zero retention by default did not.
  • HIPAA BAA: the only configuration that locks both — Privacy Mode on, Cloud Sync off, enforced.

Three sharp edges worth knowing.

1. Revoking the BAA silently unlocks everything. Wispr's own warning: “Revoking the BAA removes that enforcement, so review your Privacy Mode and Cloud Sync settings immediately after revoking.” A doctor who cancels a BAA after leaving a practice, and forgets, is back on the training default. (Also: iOS cannot revoke a signed BAA at all.)

2. Your custom vocabulary is stored regardless. Snippets and dictionary entries “are stored in Wispr's backend and synced across the user's devices regardless of Privacy Mode or Cloud Sync status.” Wispr classifies them as “productivity assets, not dictation content,” which is reasonable — right up until you remember what people put in a custom dictionary: client names, drug names, matter numbers, codenames, colleagues. The most identifying vocabulary you own is the part that syncs no matter what you switch off.

3. Android users may not have the toggles at all. Per the FAQ: “Android's Data & Privacy Settings section, Privacy Mode toggle, and Cloud Sync are being rolled out and may not yet be visible to all Android users.” If you dictate on Android and cannot find Privacy Mode, it is because you may not have it yet — while the default remains off.

Key Takeaway

Privacy Mode controls training; Cloud Sync controls storage. Zero data retention requires Privacy Mode on AND Cloud Sync off. Standard accounts default to Privacy Mode off, enterprise accounts default to Cloud Sync on, snippets and custom dictionaries sync regardless of both, and revoking a HIPAA BAA silently removes the enforcement.

Tip

The two-minute fix if you keep using Wispr Flow: Settings → Data & Privacy → turn Privacy Mode ON and Cloud Sync OFF. Both. Privacy Mode alone stops training but leaves your audio and transcripts stored on Wispr's servers. If your work touches regulated or privileged material, sign the in-app BAA instead — it enforces both and cannot be flipped by accident.

March 2026: The Delve Fake-Audit Scandal

If you have ever accepted “SOC 2 Type II” on a vendor page as the end of the conversation, this is the story that should change how you read that badge.

In March 2026 an anonymous investigator publishing as Deepdelver analyzed 494 SOC 2 reports produced through Delve, a Y Combinator-backed compliance automation startup, and reported that 99.8% of them shared identical boilerplate. The same garbled sentence — “An Endpoint Security Solution is installed with the feature of scanning the device automatically and log reports are reviewed” — turned up in 493 of 494. Auditor conclusions, the investigation alleged, were pre-populated before client evidence arrived. Wispr Flow was one of the named customers, alongside Lovable, Cluely, Greptile and others.

What happened next, quickly:

  1. March 22 — TechCrunch covers it. Delve says it is “an automation platform, not an auditing firm.”
  2. March 23 — lead investor Insight Partners scrubs its investment announcement.
  3. April 1 — a second allegation: Delve's no-code product was forked from a fellow YC company's open-source project with attribution stripped.
  4. April 4 — Y Combinator removes Delve from its community: “YC is a community, not just an accelerator.”

Wispr Flow's two pre-scandal certifications were both issued in that environment: a SOC 2 Type II by ACCORP Partners covering February 15 – May 15, 2025, and ISO 27001:2022 (certificate GCI/IS/202509008) by Gradient Certification Inc., issued September 8, 2025. Both auditors appear in the Deepdelver investigation as part of the allegedly Delve-affiliated network.

To be clear about what we are and are not saying: the investigation did not examine Wispr Flow's controls, and Wispr says its controls were built independently of Delve. We are not claiming Wispr Flow's reports were fabricated. We are saying those two badges carried less assurance than a SOC 2 normally implies, until somebody outside that ecosystem checked. As IANS Research put it, “hundreds of companies may be relying on security attestations that do not reflect real control implementation or testing.”

What Wispr Actually Fixed — Credit Where It Is Due

Wispr Flow's response to Delve was fast, public and substantive, and it deserves saying plainly. Two posts carry it: “A note on our compliance program” by CTO Sahaj Garg (March 19, 2026) and “Our path to a new, independent audit” (March 27, 2026).

  • New auditor: A-LIGN. One of the largest SOC 2 firms in the world — 31,000+ audits, 5,700+ clients, including US Bank and Snowflake. The fresh SOC 2 Type I completed in April 2026 with a clean, unqualified opinion, and the ISO 27001:2022 Stage 1 audit completed the same month. The Type II observation period was still running as of August 2026 — which is not foot-dragging. A Type II attests that controls operated over months; rushing it would defeat the point.
  • New compliance platform: Drata, replacing Delve. Established, widely deployed, no fraud allegations.
  • New trust center on SafeBase at trust.wispr.ai, off Delve's hosted platform.
  • A far more detailed security FAQ. The current version answers questions most vendors dodge — that there is no end-to-end encryption, no BYOK, no FedRAMP, no EU processing region. Candid documentation is worth something.

What Wispr has not done is retract the old certifications or concede they were unsound. Its position — controls were “built and implemented independently of Delve,” and the open question is whether Delve verified them properly — is defensible. The clean Type I says the controls exist today. The finished Type II, when it lands, is the report that closes the file. That is the one to wait for if you are making a regulated decision.

Key Takeaway

Wispr Flow's remediation is real: A-LIGN as auditor, Drata as platform, SafeBase trust center, and a clean SOC 2 Type I in April 2026. The SOC 2 Type II observation period was still open as of August 2026 — that report is the one to wait for before regulated use.

June and August 2026: The Company Published Its Own Users' Data

Two incidents, six weeks apart, neither of them a leak. Both were the company voluntarily showing the public what its data lets it see.

June: the founder's podcast. On a Think School episode framed as a sales masterclass, Wispr Flow's CEO walked through an analytics stack that tracks which applications individual users dictate into, surfaces named users inside their employers, de-anonymises website visitors, and triggers outreach off usage patterns — with the whole thing flowing into a third-party analytics platform. It was a growth story. It doubled as a data-flow diagram. Our full breakdown is here.

August: the LinkedIn post. On August 10, 2026, a Wispr Flow team member posted, publicly: “We looked at which filler words and phrases show up most across Wispr Flow users in India vs the U.S.” The numbers were India-to-US usage ratios drawn from user dictations — “incredible” 0.3×, “awesome” 0.4×, “fantastic” and “love” 0.5×, “wonderful” 0.6×, “amazing” 0.7×. A companion chart titled “Linguistic Fingerprint: India vs US,” credited in the corner to “Wispr Flow voice dictation data,” added “excellent” at 0.7×, plus “kindly” at 5.6×, “sir” at 2.5× and “please” at 1.3× from an earlier post in the same series. It signs off: “— Written with Wispr Flow.”

The post is careful — “Not what people are saying, just the filler words” — no individual is named, and it is aggregate analysis. It is also, on Wispr's own documented defaults, entirely permitted: standard accounts run with Privacy Mode off, and “dictation data may be used to improve Wispr Flow.” Privacy Mode and BAA users should be excluded from that corpus. This is not a breach and we are not calling it one.

What it is, is proof of capability. A ratio like “kindly, 5.6×” cannot be computed unless dictation content is retained, queryable, joined to user geography, and reachable by staff for analysis and publication. Whether the slice that becomes a LinkedIn post is filler words or something else is an editorial choice, not a technical limit. That is the difference between a promise and an architecture.

Numbers, quotes, chart and sources in full: Wispr Flow Analyzed What Users Dictate — and Posted It on LinkedIn.

The same defaults have a second consequence, and it arrived in August 2026: Wispr previewed Canto, its own speech model, tuned for noise, heavy accents and Hinglish — the conditions clean training corpora do not contain. The company has not published what trained it. For the three most likely sources, and what its own policy pages do and do not say, read Whose Voice Trained Canto?

Key Takeaway

In June 2026 Wispr Flow's CEO demoed per-user analytics on a podcast; in August 2026 a team member published word-frequency data drawn from user dictations on LinkedIn. Neither is a breach — both are permitted by the default settings, and both prove the dictation corpus is retained, queryable and publishable.

The Limits Wispr Documents About Itself

Not every safety issue is an incident. Some are just constraints — and to Wispr Flow's credit, most of these come straight from its own security and compliance FAQ. If any of these is a hard requirement for you, the decision is already made.

  • No EU or UK data residency. “All customer data is processed and stored in the US, regardless of where the user is located. Wispr does not operate a European or other regional processing location for customer data.” Transfers rely on the EU SCCs and a UK Addendum in the DPA. Wispr also does not produce a vendor-side Transfer Impact Assessment — that work lands on you as the controller. If your organization runs an EU-only data policy, Wispr Flow does not fit, full stop.
  • No end-to-end encryption. The backend must decrypt your audio to transcribe it. Wispr says so outright.
  • No customer-managed keys. “Customer-managed keys (BYOK) are not currently supported.”
  • No FedRAMP authorization. Rules out most US federal work.
  • No public subprocessor list. Now Annex 2 of the DPA, under NDA via the trust center. This is a regression — it used to be a page you could read.
  • No API export. “API export is no longer available; the API has been sunsetted.”
  • Staff can reach production. “A limited number of engineering and infrastructure personnel hold read-only, MFA-gated, logged production access for troubleshooting.” That is a normal, well-controlled arrangement — and it is still a human path to a system your dictation passes through, unless you are running ZDR, where there is nothing retained to reach.
  • One user-triggered exception to ZDR. If you hit “Report” on a bad transcript, “that record is uploaded in full.” Intentional and clearly documented — just worth knowing before you report the transcript of something sensitive.

Read that list again and notice its shape. None of it is negligence. It is what a cloud transcription product is. Every constraint traces back to the same root: the audio has to leave your machine and be readable by somebody else's computer for the product to work at all.

Key Takeaway

Wispr Flow documents its own hard limits: no EU/UK data residency, no end-to-end encryption, no customer-managed keys, no FedRAMP, no public subprocessor list, and no API export. Each traces back to the same root cause — the audio must leave your device and be decrypted to be transcribed.

Why Architecture Beats Audit

Here is the thread running through all seven incidents. A SOC 2 report, a privacy policy and a subprocessor list are all promises about what a company will do with data it holds. They are only as durable as the company, the auditor, and the policy version.

Five things a promise cannot survive, and an architecture can:

  • An audit-quality crisis. Delve is the proof. Every certification issued in that ecosystem became provisional overnight. On-device processing produces no data flow to audit.
  • A policy update. Privacy policies change with 30 days' notice. The same servers running “zero retention” today can store tomorrow. Audio that never crossed your network cannot be retained by a future clause.
  • A subprocessor incident. Eleven-plus vendors, each with its own incident history. On-device dictation has zero subprocessors, so there is no third party to breach.
  • An acquisition. When Microsoft bought Nuance in 2022, the whole Dragon customer corpus moved under new governance. A startup's commitments do not automatically survive a change of owner. On-device data has nothing to transfer.
  • Legal compulsion. A subpoena can force a vendor to preserve and hand over data it would otherwise discard. A vendor cannot produce what it never received.

This does not make cloud dictation unusable. It makes it a trust product: you are trusting the vendor's commitments, the auditor's rigor, the subprocessors' diligence and the policy's continuity, all at once. On-device dictation is a physics product: the audio is transcribed by your own chip and discarded. For the average email, trust is a fine trade. For privileged, clinical or regulated material, physics is the stronger answer. More on the distinction in our cloud vs. local dictation guide, our voice data privacy guide, and zero data retention explained.

Can You Install Wispr Flow on a Work Mac?

Everything above assumes the call is yours. On a managed machine it usually is not — and 2026 is the year that stopped being hypothetical. Per Netskope's Cloud and Threat Report 2026, nine in ten organizations now block at least one generative AI application, the average organization blocks ten, and companies log an average of 223 gen-AI-linked policy violations a month. Meanwhile 47% of gen-AI users are working through personal, unmanaged accounts — which is precisely how a dictation app lands on a fleet before security ever hears the name.

Run the review before your security team does, because “Wispr Flow — cloud dictation” on an inventory expands into a full vendor assessment. From Wispr's own documentation alone, a reviewer finds: Accessibility permission on a managed device (with the keyboard-tap question from the forensic report attached to it), audio egress to a transcription vendor, transcript text through third-party LLMs, US-only storage with no EU option, screen-text reading on by default, Privacy Mode off by default, Cloud Sync on by default at enterprise tier unless explicitly disabled, a subprocessor list that requires an NDA to read, and SOC 2 mid-transition. None of it is hidden. None of it waves through in a fifteen-minute meeting either.

An August 2026 post in r/growthhackers described exactly that sequence — a quarterly audit, then Wispr Flow removed from six machines over compliance concerns. It is a single anonymous account and we cannot verify it, so treat it as illustration rather than evidence. The detail that rings true is what came after: the team had built daily email and documentation workflows on voice, and everything slowed down once the tool was gone. Dictation is sticky. That is an argument for choosing a tool that survives the audit, not for hoping the audit never arrives.

In fairness, Wispr Flow has a real enterprise answer: IP allowlists, application and browser-URL deny lists, quarterly access recertification, SSO across the major identity providers, enforced org-wide ZDR that overrides user settings, and admin-set local-data policies down to “Never store.” An organization that adopts Wispr Flow top-down through procurement, with ZDR enforced, has a defensible posture. The pattern that fails audits is the other one: a personal Pro subscription on a managed Mac that IT never saw.

On-device dictation changes the shape of the review entirely. There is still an app to inventory, but the questions that eat a vendor assessment — where does audio go, who are the subprocessors, what does the DPA cover, what can DLP inspect — collapse into one sentence: audio is processed on the Mac's own silicon and never crosses the network.

Key Takeaway

Nine in ten organizations block at least one gen-AI app and the average blocks ten (Netskope, 2026). A Wispr Flow review covers Accessibility permission, audio egress, third-party LLMs, US-only storage, default-on screen reading, default-off Privacy Mode, and an NDA-gated subprocessor list. Wispr's enterprise tier is built for that review; on-device tools reduce it to one answer.

The Wispr Flow Safety Decision Tree

Five questions, easiest case to hardest. Stop at the first one where you cannot live with Wispr Flow's answer.

  1. Is this general content — emails, drafts, notes, AI prompts? If yes, Wispr Flow with Privacy Mode on and Cloud Sync off is a reasonable choice. If the content is confidential, privileged or regulated, keep going.
  2. Is it covered by HIPAA, privilege, an NDA, or a compliance regime? If no, you are still fine on the settings above. If yes, question 3.
  3. Will you sign the in-app BAA? It is the only configuration that enforces both Privacy Mode on and Cloud Sync off rather than leaving them to a toggle you might flip back. If yes, continue. If no, go on-device — an unenforced setting is not a control.
  4. Does a clean SOC 2 Type I, with the Type II still in observation, meet your bar? If your policy (or your client's) demands a finished Type II, wait for it or use an on-device tool meanwhile.
  5. Is it acceptable for your audio to leave the machine at all — and for the vendor to be technically able to read it? Wispr Flow states plainly that it cannot offer end-to-end encryption. If that is a no, only on-device dictation will do. On Mac that means Voibe, VoiceInk, or Superwhisper's offline mode.

The pattern is consistent: the further down the tree you get, the more the architectural answer beats the policy answer.

The Five-Minute Wispr Flow Safety Audit

If you are keeping Wispr Flow, do these six things tonight. They take about five minutes and they fix most of what this page describes.

  1. Turn Privacy Mode ON. Settings → Data & Privacy. Stops your dictation being used for training.
  2. Turn Cloud Sync OFF. Same screen. This is the one everyone misses — it is what stops your audio, transcripts and history being stored on Wispr's servers. Privacy Mode without it is half a fix.
  3. Turn off accessibility-text context unless you actively want better formatting from on-screen content. It ships on. Doing this also auto-disables Screen OCR.
  4. Sign the in-app BAA if your work is regulated. Desktop and iOS. It is the only setting that is enforced rather than toggled — and remember that revoking it silently removes the enforcement.
  5. Audit your local database. Check the size of ~/Library/Application Support/Wispr Flow/flow.sqlite. If it is hundreds of megabytes, that is your dictation history and audio sitting on disk. While you are there, search ~/Library/Logs/Wispr Flow/accessibility.log for Suppressing event to see the keyboard tap at work.
  6. Check trust.wispr.ai for the finished SOC 2 Type II before you rely on Wispr Flow for anything regulated. As of August 2026 the observation period was still open.

Do the first two even if you skip the rest. They are the difference between “my words are on their servers being trained on” and “my words are transcribed and dropped.”

Tip

If steps 1–6 feel like more diligence than you want to run on a $144/year subscription, that instinct is the real finding. On-device dictation has no equivalent checklist, because there is no server-side state to configure.

On-Device Alternatives

If the cloud architecture is the problem, only architecture is the fix. Three Mac-native options transcribe on Apple Silicon itself using Whisper models — nothing leaves the machine, no subprocessors touch dictation data, and audit-vendor quality stops being your problem because there is no data flow to audit.

ToolArchitecturePricingThe honest read
Voibe (ours)On-device on Apple Silicon, or private zero-retention cloud$7.50/mo, $59/yr, $149 lifetimeMic + accessibility permissions only, no account required, Developer Mode for Cursor and VS Code. Windows uses the private cloud, not on-device.
VoiceInk100% on-device on Apple Silicon$29–69 one-time, plus a free GPL v3 buildOpen source — you can read the code rather than trust an attestation. Rougher edges than the paid incumbents.
SuperwhisperOn-device, with an optional cloud LLM mode$249.99 lifetimeThe most configurable of the three. Historically stored audio recordings by default — check that setting.

Against Wispr Flow Pro Annual at $144/year:

  • 3 years: Wispr Flow $432 vs Voibe lifetime $149 — $283 saved, 65% cheaper.
  • 5 years: Wispr Flow $720 vs Voibe lifetime $149 — $571 saved, 79% cheaper.
  • Voibe lifetime pays for itself in roughly 12 months against Wispr Flow Pro Annual.

Superwhisper's $249.99 lifetime is also subscription-free, but $101 more than Voibe — details in our Wispr Flow vs. Superwhisper comparison and our VoiceInk pricing guide. For the wider field, see best offline dictation apps and the dictation privacy hub.

Key Takeaway

On-device dictation is the only architectural answer to a cloud-only product. Voibe ($149 lifetime) is 65% cheaper than Wispr Flow Pro Annual over three years; VoiceInk is open source from $29; Superwhisper is $249.99 lifetime.

How Voibe Answers Each of These Questions

Voibe is the Mac and Windows dictation app we build. The promise is narrow and durable: your audio and text are never stored, never sold, and never used to train any model — and you pick how they are processed. In on-device mode Voibe runs Whisper on Apple Silicon: audio is captured to memory, transcribed locally, written into the active field, and discarded. In private cloud mode (Windows and Intel Macs) it goes over an encrypted connection to Voibe's own infrastructure, runs open-weight models only, and is deleted the moment transcription finishes.

Mapped to the questions this page raised:

  • Where does the audio go? On-device mode: nowhere. No transcription vendor, no third-party LLM, no storage region.
  • Who are the subprocessors? On-device mode: none for dictation data, because none is transmitted. Nothing to gate behind an NDA.
  • Is it retained? No, in either mode.
  • Which toggles do I need to find? None. There is no training default to opt out of.
  • Does it read my screen? No. Voibe requests microphone and macOS accessibility permission and nothing else — no screen recording, no screenshots, no session replay.
  • Does an audit scandal affect me? On-device mode has no SaaS data flow for an audit to be wrong about.
  • Can I verify it? Run Little Snitch during an on-device dictation session. Outbound traffic from Voibe during transcription is zero.
  • Do I need an account? No. There is no identity-to-voice link on any Voibe server.

Pricing: $7.50/month, $59/year, or $149 lifetime for unlimited dictation on Mac and Windows (on-device mode needs an Apple Silicon Mac, M1 or later). Developer Mode resolves file and folder names inside VS Code and Cursor — a feature Wispr Flow and Superwhisper users keep asking for and neither ships.

Try Voibe free — install, grant microphone and accessibility permission, dictate. No account, no card, and in on-device mode, no audio leaving your Mac.

The Bottom Line

Wispr Flow is a good dictation product with a governance problem it keeps rediscovering in public.

Use it if you dictate ordinary work, you are willing to spend five minutes in Settings turning Privacy Mode on and Cloud Sync off, and you accept that a company you do not control can technically read what you say. On those terms it is a reasonable cloud product, and Wispr's response to the Delve mess — a real auditor, a clean Type I, a genuinely candid security FAQ — is better than most of the category would have managed.

Don't use it if your dictation contains client matters, patient details, unreleased work, or anything you would not put in a third party's database. Not because Wispr Flow is careless — because seven public incidents since 2025, none of them a breach, tell you the risk was never an attacker. The risk is what the defaults permit, what a policy can change, and what an employee can query on a slow Tuesday and post to LinkedIn. You cannot settings-toggle your way out of an architecture.

For lawyers specifically, where ABA Rule 1.6(c) diligence has to be documented per matter, see our Wispr Flow alternatives for lawyers. If you would rather audit source code than attestations, our open-source alternatives guide covers eight credible options with maintenance signals and an honest read on abandonment risk. And if you want the whole field, our tested roundup of nine Wispr Flow alternatives compares privacy, price and performance.

If the five-minute checklist above felt like more work than a $144/year subscription should require, that is the finding. Voibe at $149 lifetime skips every step of it, because on-device dictation has nothing to configure.

Keep reading: our Wispr Flow review, the pricing breakdown, the reliability log, and the LinkedIn dictation-data report. Sibling investigations: Is Superwhisper Safe?, Is Willow Voice Safe? (the only major cloud dictation app with private mode on by default), Is Aqua Voice Safe?, Is Otter Safe?, and Is Dragon Safe? Head-to-heads: vs. Superwhisper, vs. Apple Dictation, vs. VoiceInk, and vs. Willow Voice. Not sure whether you meant this product at all? Wisprtype is a different app.

Key Takeaway

Wispr Flow is safe enough for ordinary dictation with Privacy Mode on and Cloud Sync off. It is the wrong tool for privileged, clinical or confidential material — not because it is careless, but because seven public incidents since 2025 show the risk is what the defaults permit, not what an attacker might do.

Frequently Asked Questions

Is Wispr Flow safe to use in 2026?

Wispr Flow is reasonably safe for ordinary dictation and a poor fit for confidential work. It has never been breached: data is TLS 1.2+ encrypted in transit, AES-256 at rest in AWS us-east-1, it holds a clean A-LIGN SOC 2 Type I from April 2026, and a self-serve HIPAA BAA is available. It is structurally unsafe for anyone who cannot accept audio leaving their machine, because there is no on-device mode on any platform and Wispr states plainly that its backend must decrypt audio to transcribe it. The practical risk is defaults, not attackers: Privacy Mode is off by default on standard accounts, Cloud Sync (which controls server-side storage) is separate and also has to be switched off, and accessibility-text screen reading ships on. Seven public incidents accumulated between 2025 and August 2026, including the Delve fake-audit scandal, an independent forensic report on the Mac client, and a team member publishing word-frequency data drawn from user dictations. On-device tools like Voibe remove the question rather than answering it.

What incidents has Wispr Flow had?

Seven public events between 2025 and August 2026, none of them a breach. (1) 2025: a user monitoring network traffic found the app uploading screenshots of the active window and was banned for reporting it; the CTO later apologized. (2) March 2026: Wispr Flow was named as a customer of Delve, the compliance vendor accused in a public investigation of producing templated SOC 2 reports. (3) April 2026: engineer Wensen Wu published a forensic analysis of Mac app version 1.4.752 documenting a system-wide keystroke tap, a 694 MB local dictation database, and hourly uploads that continued with data sharing off. (4) April 2026: A-LIGN's fresh SOC 2 Type I came back clean — the good-news item. (5) Late May to June 2026: multi-day dictation outages across every platform. (6) June 2026: the CEO demonstrated per-user analytics tying dictation to named individuals at named employers on a public podcast. (7) August 2026: a team member published India-vs-US word-frequency data drawn from user dictations on LinkedIn.

Is Wispr Flow's Privacy Mode the same as zero data retention?

No, and this is the most commonly repeated mistake about Wispr Flow. Per its own security and compliance FAQ, the product uses “two independent controls”: Privacy Mode “controls whether your dictation data is used to evaluate, train, or improve AI models,” while Cloud Sync “controls whether your transcription data (transcripts, audio, dictation history) is stored on Wispr's servers.” The FAQ then states: “Zero Data Retention (ZDR) is the combination of Privacy Mode on and Cloud Sync off.” Turning on Privacy Mode alone stops training but leaves your audio, transcripts and dictation history stored server-side. You need both switches. The only configuration that enforces both rather than leaving them to a toggle is a signed HIPAA BAA — and revoking that BAA silently removes the enforcement.

Is Wispr Flow's Privacy Mode on by default?

No. Per Wispr Flow's security and compliance FAQ, without Privacy Mode “audio and transcription data may be used to evaluate, train, and improve Wispr's models. This is the default for trial and standard accounts.” Enterprise and HIPAA BAA customers run with Privacy Mode on by default — but the same document notes that for Enterprise, “Cloud Sync defaults to on unless the enterprise has explicitly enabled ZDR or a HIPAA BAA is active,” so enterprise dictation can still be stored server-side. Android users may not be able to change either setting yet: the FAQ states that Android's Data & Privacy Settings section, Privacy Mode toggle and Cloud Sync “are being rolled out and may not yet be visible to all Android users.”

Does Wispr Flow record my screen?

Partly, and not in the way most write-ups describe. Per Wispr Flow's security and compliance FAQ, Context Awareness has two separately-toggled components. Accessibility-text context is default ON and “reads text from the active application's accessibility tree to improve AI formatting.” Screen OCR is default off and opt-in, and “captures a full-display screenshot to extract proper nouns” — the FAQ specifies that “Screen OCR captures the display containing the mouse cursor,” meaning the whole monitor rather than just your active window. Screenshots only flow when both toggles are on, and disabling accessibility-text context automatically disables Screen OCR. Screen context is stripped server-side only when Privacy Mode is on and Cloud Sync is off; the FAQ warns that “under Cloud Sync on with Privacy Mode off, screen-context fields may be persisted alongside the transcript.” That combination is the standard-account default.

Does Wispr Flow read my keystrokes?

An April 2026 forensic report by software engineer Wensen Wu, analyzing Mac app version 1.4.752 using the app's own log files, SQLite database and code-signing entitlements, documented a system-wide CGEventTap — an active keyboard interceptor that receives every keystroke before the target application does and can suppress them. A stale-key bug caused it to suppress 145 spacebar presses in under ten minutes, logged by the app itself. The same report documented 1,688 app-and-URL events logged in a 30-hour window. Wispr Flow's privacy policy, last updated July 25, 2026, contains no instance of the words keystroke, keyboard, typing, URL or browsing — it discloses “audio Inputs,” “Usage Data,” and “the application used for dictation.” Wispr Flow has not publicly responded to the report. You can check the keystroke suppression on your own machine by searching ~/Library/Logs/Wispr Flow/accessibility.log for “Suppressing event.”

Where does Wispr Flow send my voice and text data?

Wispr Flow no longer publishes a public subprocessor list. Its security and compliance FAQ now states that “the authoritative subprocessor list is Annex 2 of the DPA, available under NDA via the Trust Center” — a transparency regression, since the list was a self-serve page through April 2026. From that list while it was public, and corroborated for several vendors by the April 2026 forensic analysis of the Mac binary, audio goes to Baseten for transcription, transcript text to OpenAI, Anthropic or Cerebras for formatting, with Fireworks AI and OpenRouter as Command Mode fallback, storage in AWS us-east-1, authentication via Supabase, telemetry to PostHog, Sentry, Segment and Datadog, payments via Stripe and RevenueCat, SMS via Twilio, and CRM via Attio and Pylon. Customers do not get approval rights over which model provider processes their text.

Does Wispr Flow store data in the EU?

No. Per Wispr Flow's security and compliance FAQ: “All customer data is processed and stored in the US, regardless of where the user is located. Wispr does not operate a European or other regional processing location for customer data.” EU and UK transfers rely on the EU Standard Contractual Clauses (June 2021) and a UK Addendum documented in the DPA. Wispr also does not produce a vendor-side Transfer Impact Assessment as a standalone document — it provides supporting material and leaves the TIA to you as the data controller. If your organization runs an EU-only data residency policy, Wispr Flow does not meet it.

Is Wispr Flow end-to-end encrypted?

No, and Wispr Flow says so plainly. Its security and compliance FAQ states that Wispr Flow “does not provide end-to-end encryption in the strict cryptographic sense (where the service provider cannot decrypt content)” because “Wispr's backend must decrypt audio to perform transcription,” and concludes: “For customers requiring true E2E encryption where the provider cannot read content, Wispr Flow's transcription model does not support that architecture.” Data is encrypted with TLS 1.2+ in transit and AES-256 at rest. Customer-managed encryption keys (BYOK) are not supported, and Wispr Flow does not hold FedRAMP authorization. Under zero data retention the mitigation is that decrypted audio and transcripts are not persisted — the provider can still read content in flight.

Was Wispr Flow's SOC 2 report actually fake?

Unproven, and that is the honest answer. Wispr Flow's prior SOC 2 Type II — issued by ACCORP Partners covering February 15 to May 15, 2025 — was administered through Delve, the compliance vendor accused in March 2026 of generating fabricated audit reports. The Deepdelver investigation analyzed 494 SOC 2 reports and reported that 99.8% shared identical boilerplate, with the same garbled sentence appearing in 493 of 494. Wispr Flow was named among the affected customers, and its ISO 27001:2022 certificate (GCI/IS/202509008, issued September 8, 2025 by Gradient Certification Inc.) came from the same alleged network. The investigation did not examine Wispr Flow's specific controls, and Wispr's March 19, 2026 response states its controls were “built and implemented independently of Delve.” The correct reading is that those two badges carried less assurance than a SOC 2 normally implies until an outside auditor checked.

Has Wispr Flow fixed the Delve compliance issue?

Substantially, and the first results are in. Wispr Flow engaged A-LIGN — 31,000+ audits across 5,700+ clients, including US Bank and Snowflake — as its new SOC 2 auditor, replaced Delve with Drata as its compliance automation platform, and moved its trust center to a SafeBase portal at trust.wispr.ai. Per Wispr's security and compliance FAQ, A-LIGN completed a fresh SOC 2 Type I in April 2026 with a clean unqualified opinion and completed the ISO 27001:2022 Stage 1 audit the same month, with Stage 2 in progress. The SOC 2 Type II observation period was still underway as of August 2026 — which is expected, since a Type II attests that controls operated over a window of months. The finished Type II is the report to wait for before relying on Wispr Flow for regulated work.

Should I trust Wispr Flow's HIPAA claim?

The mechanism is real; the caveats matter. Wispr Flow offers a self-serve Business Associate Agreement signable in-app on Desktop and iOS, which is more than most cloud SaaS vendors provide, and while the BAA is active Privacy Mode is locked on and Cloud Sync locked off — the only configuration Wispr enforces rather than leaves to a toggle. Three caveats: revoking the BAA removes that enforcement, and Wispr's own documentation warns you to “review your Privacy Mode and Cloud Sync settings immediately after revoking”; iOS does not currently support revoking a signed BAA at all; and the HIPAA posture in Wispr's documentation was developed during the Delve era, though the technical controls are independent of audit-vendor quality. Healthcare professionals should confirm the BAA and request the finished A-LIGN SOC 2 Type II before processing PHI.

Does Wispr Flow analyze the words users dictate?

Yes, at the aggregate level, per its own team's public posts. On August 10, 2026 a Wispr Flow team member published a LinkedIn post stating “We looked at which filler words and phrases show up most across Wispr Flow users in India vs the U.S.,” reporting India-to-US usage ratios — “incredible” 0.3×, “awesome” 0.4×, “amazing” 0.7× — with a companion chart credited to “Wispr Flow voice dictation data” adding “kindly” at 5.6× and “sir” at 2.5×. No individual was identified and this is aggregate analysis, not employees reading transcripts. It is also consistent with Wispr Flow's documented default that dictation data may be used to improve the product when Privacy Mode is off; Privacy Mode and BAA users should be excluded from that corpus. See our full analysis of the LinkedIn post at Wispr Flow Analyzed What Users Dictate for the complete numbers, quotes and source links.

What should I change in Wispr Flow's settings right now?

Six steps, about five minutes. (1) Settings → Data & Privacy → turn Privacy Mode ON, which stops your dictation being used for training. (2) On the same screen, turn Cloud Sync OFF — this is the one most people miss, and it is what stops your audio, transcripts and history being stored on Wispr's servers. (3) Turn off accessibility-text context unless you want on-screen content improving your formatting; it ships on, and disabling it also auto-disables Screen OCR. (4) Sign the in-app BAA if your work is regulated, since it enforces steps 1 and 2 rather than leaving them to a toggle. (5) Check the size of ~/Library/Application Support/Wispr Flow/flow.sqlite to see how much dictation history and audio is on your disk. (6) Check trust.wispr.ai for the finished SOC 2 Type II before relying on Wispr Flow for regulated work. Steps 1 and 2 matter most — do those even if you skip the rest.

Can I use Wispr Flow on a work Mac if my company hasn't approved it?

You can install it, but skipping approval is how dictation tools get pulled mid-workflow. Nine in ten organizations now block at least one generative AI application and the average organization blocks ten, per Netskope's Cloud and Threat Report 2026. A security review of Wispr Flow is a full cloud-vendor assessment: Accessibility permission on a managed device, audio egress for transcription, transcript text through third-party LLMs, US-only storage with no EU option, accessibility-text screen reading on by default, Privacy Mode off by default, Cloud Sync on by default at enterprise tier unless explicitly disabled, a subprocessor list that requires an NDA to read, and SOC 2 mid-transition. Wispr Flow does have a serious enterprise answer — IP allowlists, application and browser-URL deny lists, SSO, enforced org-wide ZDR, and local-data policies down to “Never store.” The pattern that fails audits is an individual Pro subscription on a managed Mac that IT never saw. An on-device tool gives IT a one-box data-flow answer instead.

Why is Wispr Flow's Trustpilot rating only 2.7/5?

Wispr Flow holds a 2.7/5 Trustpilot rating per trustpilot.com/review/wisprflow.ai. Complaints cluster on three themes: reliability degradation after the 14-day trial ends, with multiple reviewers reporting the app working “about 60% of the time” post-purchase; referral program rewards not being honored; and legal disclaimers in the terms of service. A February 2026 Medium article documented the pattern as the “Wispr Flow Trust Gap.” The spread between Wispr Flow's G2 rating (4.5/5 on a small sample), its iOS App Store rating (4.8/5 on 8,500+ reviews) and Trustpilot (2.7/5) is itself a signal — curated platforms often diverge from organic consumer review sites. Trustpilot complaints do not speak directly to data safety, but they do speak to whether a $144/year subscription reliably delivers. See our Wispr Flow reliability log.

What's the safest dictation app for Mac if Wispr Flow concerns me?

On-device dictation, because it removes the question instead of answering it. Voibe is a Mac and Windows dictation app whose on-device mode runs OpenAI Whisper models on Apple Silicon: audio is captured into memory, transcribed locally, written into the active text field, and discarded — no cloud round-trip, no third-party LLM provider, no storage region, no toggles to find. Voibe also offers a private zero-retention cloud running only open-source models for Windows and Intel Macs; either way, audio and text are never stored, sold, or used to train any model. It costs $7.50/month, $59/year, or $149 lifetime, requires no account, and requests only microphone and accessibility permissions — no screen recording. Against Wispr Flow Pro Annual at $144/year, Voibe lifetime saves $283 over three years (65% cheaper) and $571 over five (79%). Other Mac on-device options are VoiceInk (open-source, $29–69 one-time) and Superwhisper ($249.99 lifetime).

Does Wispr Flow work on Windows, and is the architecture different there?

Wispr Flow runs on Windows, Mac, iOS, Android, and as Chrome and Edge extensions, and the architecture is the same cloud-only pipeline on every one of them — there is no on-device mode on any platform. Android additionally may not yet expose the Privacy Mode and Cloud Sync controls, per Wispr's own documentation. If cloud-only processing is your sticking point on a Windows PC, Voibe's native Windows app uses a zero-retention private cloud running open-source models (Voibe for Windows); see also our privacy-focused Wispr Flow alternatives.

Ready to type 5x faster?

Voibe is the fastest, most private dictation app for Mac and Windows. Try it today.

  • On-device or private cloud
  • Free to try
  • No subscription
  • Mac + Windows
  • 90+ languages

Prefer to go Pro? Save 20% on any plan with code VOIBE20 View pricing →