Limited time: Save up to 33% on every planView pricing
Voibe Logovoibe Resources
privacydictationvoice-dataon-devicespeech-to-texthipaamac

Dictation Privacy Hub: The Complete Guide to Protecting Your Voice Data

Your voice is biometric data that can never be changed. Explore our complete library of dictation privacy guides covering HIPAA, voice data, Apple Dictation, and more.

ยท Updated

Dictation Privacy: Why Your Voice Needs Protection

TL;DR: Your voice is biometric data โ€” a permanent identifier as unique as your fingerprint that cannot be changed after a breach. Cloud dictation apps send this data to remote servers where it can be stored, shared, breached, or used for AI training. On-device dictation keeps all audio on your Mac, eliminating server-side exposure. This hub organizes our complete library of dictation privacy guides to help you protect your voice data.

In 2025, Google agreed to a $1.375 billion settlement with Texas for unlawfully collecting biometric data including voiceprints. Apple paid $95 million to settle a Siri recording lawsuit. Amazon eliminated the option to store Echo recordings locally. The message is clear: voice data is a high-value target, and the companies you trust with your voice do not always protect it.

Whether you are a healthcare professional bound by HIPAA, a lawyer protecting attorney-client privilege, or simply someone who values privacy, understanding how dictation tools handle your voice is essential. Explore the guides below to find exactly what you need.

Key Takeaway

Your voice is biometric data that cannot be changed after a breach. This hub connects you to our complete library of dictation privacy guides.

Key Takeaways: Dictation Privacy Essentials

Privacy TopicKey InsightDeep Dive
Cloud vs. On-DeviceCloud sends audio to servers (breach risk). On-device processes locally (no exposure).Cloud vs. Local Dictation Guide
HIPAA ComplianceRequires BAA, encryption, audit trails. On-device is the strongest posture.HIPAA Dictation Guide
Dragon Medical AlternativesDragon Medical One costs $79–$99/month with cloud-only processing. On-device alternatives keep patient audio off servers entirely.Dragon Medical Alternatives
Voice Data HandlingApps collect audio, transcripts, voiceprints, metadata. Some share with 41+ ad partners.Voice Data Privacy Guide
Apple DictationMostly on-device on Apple Silicon, but has caveats. Not HIPAA compliant.Apple Dictation Privacy Guide
Whisper TechnologyOpen-source, runs on-device on Apple Silicon. Powers private dictation apps.How Whisper Works
Offline Dictation on MacComplete comparison of cloud vs on-device Mac dictation tools and privacy.Offline Dictation Privacy on Mac
Typeless Case StudyIndependent researchers reported Typeless sends voice data to AWS cloud despite "on-device" marketing.Typeless Privacy Issues
Wispr Flow SafetyCloud routing through Baseten + OpenAI/Anthropic + AWS, Privacy Mode off by default, prior compliance vendor (Delve) named in March 2026 fake-audit investigation. Wispr is remediating with A-LIGN + Drata.Is Wispr Flow Safe?
Superwhisper SafetyOn-device modes are genuinely local; cloud modes (Ultra, Super Mode) proxy through Superwhisper but are not separately documented in the privacy policy. Local audio recordings ON by default. No SOC 2 / HIPAA.Is Superwhisper Safe?
Aqua Voice SafetyCloud-only architecture. Privacy Mode OFF by default for individuals. Privacy policy does not address AI training. SOC 2 Type II via Advantage Partners.Is Aqua Voice Safe?
Otter.ai SafetyCloud-only meeting transcription. SOC 2 Type 2. Default-opt-out training. Visible-bot consent model being challenged in In re Otter.AI Privacy Litigation (5:25-cv-06911, N.D. Cal., consolidated Oct 2025). Case ongoing.Is Otter Safe?
Dragon SafetyThree products with three architectures, all now Microsoft-owned (Nuance acquired March 2022 for $19.7B). Professional v16 mostly on-device on Windows; Anywhere cloud-only mobile; Medical One cloud + signed BAA on Azure. No Mac product since 2018 discontinuation.Is Dragon Safe?
Willow Voice SafetyCloud-first architecture (Mac + Windows + iPhone + Android). Private Mode is the default opt-out for training โ€” the most privacy-protective default among major cloud dictation peers. Privacy policy effective April 30, 2025 predates Windows / Cursor / Teams launches and does not document Offline Mode, subprocessors, or HIPAA framework specifics.Is Willow Voice Safe?
Claude Code SafetyTwo-tier framework: Consumer Pro/Max trains on code by default (5-year retention) after August 28 2025 consumer terms update โ€” opt out at claude.ai/settings/data-privacy-controls. Commercial Terms (API, Bedrock, Vertex, Foundry, AWS, Teams, Enterprise) maintain no-training default with 30-day retention and ZDR on Enterprise.Is Claude Code Safe?
Spokenly SafetyThree architectures โ€” Local Only (on-device), BYOK cloud (your provider's posture), and Pro managed cloud through 5 named subprocessors (Cerebras, Fireworks, Groq, Mistral AI, ElevenLabs). No SOC 2 / HIPAA. Audio not stored per policy effective March 2, 2026.Is Spokenly Safe?
Blip AI SafetyCloud-only (GPT-powered). Policy claims audio deleted within seconds, transcripts not stored, and HIPAA with a BAA on request โ€” but no published SOC 2 / ISO audit backs it, subprocessors are unnamed, and AI training is not addressed. Launched Oct 2025, 1–10-person team.Is Blip AI Safe?
VoiceDash SafetyCloud-only thin client to the OpenAI API. Policy and founder commit to no audio/transcript storage and no training (“we do not use your data for any training purposes”). Two trust perimeters (VoiceDash + OpenAI); no SOC 2 / HIPAA; no HIPAA claim made. Founded Feb 2025, Dubai.Is VoiceDash Safe?
Voicy SafetyCloud-only via Voicy servers (Heroku, USA) โ†’ Groq. Deletion promises are specific โ€” audio and transcripts deleted immediately per security policy v1.3 โ€” and Groq Zero Data Retention is claimed but self-attested. The no-training promise appears on marketing pages only; both policies are silent. No SOC 2 / HIPAA / BAA, and the security policy scope does not cover the 2026 iPhone and Android apps.Is Voicy Safe?
Wisprtype SafetyLocal WhisperKit by default; BYOK cloud strictly opt-in; no audio retention. Telemetry shipped on in v1.1.0 despite the policy's 'disabled by default' wording (still the current build as of July 2026; opt-out at Settings โ†’ Privacy). Closed-source, no legal entity, no terms of service, zero third-party reviews.Is Wisprtype Safe?
VoiceInk SafetyOpen-source GPL v3, on-device by default (Parakeet / whisper.cpp); zero telemetry verified in a full source audit; transcripts stored locally with iCloud sync disabled in code. Nuances: license activation sends hostname + hardware serial to Polar.sh, BYOK cloud is opt-in, history is kept until deleted. Scores 97/100 on our tracker โ€” the highest non-Voibe result.Is VoiceInk Safe?
Handy SafetyFree, MIT-licensed, cross-platform, and fully on-device โ€” no cloud transcription path exists in the codebase; zero telemetry today (opt-in analytics on the roadmap, unshipped). No privacy policy document and no legal entity โ€” a donation-funded solo project; the GitHub update check is on by default but toggleable.Is Handy Safe?
AI Tool Privacy TrackerCross-product reference matrix: 12 AI tools (assistants, coding, dictation) with training, retention, and on-device columns separated by Consumer / Business tier. Every cell linked to a primary source. Reviewed monthly.AI Tool Privacy Tracker
AI and Privilege (Heppner)SDNY ruled in Feb 2026 that public AI chats are not privileged โ€” same logic applies to cloud voice tools touching privileged audio.US v. Heppner Analysis
Accessibility & DictationUsers dictating because of carpal tunnel, RSI, arthritis, or post-surgery recovery often reference medical context in the dictated stream. On-device processing keeps that context off vendor servers entirely; Hands-Free Mode removes the held-key barrier other dictation apps create.Accessibility Dictation Hub
Zero Data RetentionA promise about storage, not about selling or training. In several dictation apps the zero-retention toggle ships switched off.Zero Data Retention Explained

Disclosure: Voibe is our product. We compare fairly and acknowledge competitor strengths throughout our guides.

The Privacy Landscape: What Has Changed

Voice data privacy has reached an inflection point. Three trends are reshaping how dictation tools handle your audio:

Regulatory enforcement is accelerating. Over 107 BIPA class-action lawsuits were filed in Illinois in 2025 alone, targeting companies that collected voiceprints without consent. The Clearview AI settlement reached $51.75 million. GDPR classifies voice recordings as special-category biometric data requiring explicit consent. HIPAA violations involving voice data carry fines up to $2.07 million per violation category per year. On-device processing sidesteps all of this regulatory complexity by ensuring no voice data is collected in the first place.

Big tech is collecting more, not less. Amazon eliminated its local-only voice processing option in March 2025, requiring all Echo recordings to travel to the cloud. A University of Washington study found Alexa data is shared with up to 41 advertising partners. The FTC fined Amazon $25 million for keeping children's voice recordings indefinitely after parents requested deletion. Wispr Flow, positioned as a productivity tool, faced a viral privacy backlash when users discovered it captures screenshots of the active window every few seconds and sends them to external servers (OpenAI and Meta) for context awareness โ€” with no offline alternative. The company reportedly banned the user who first raised these concerns publicly, and only updated its policies after significant public pressure.

"On-device" is not always private. Superwhisper processes speech locally but saves audio recordings by default โ€” users have repeatedly requested the ability to disable this on the public feedback board, with no resolution. API keys are stored in plaintext JSON on disk. A persistent microphone indicator stays on between dictations. These behaviors create privacy risk even when the core transcription is on-device. The architectural difference between "runs locally" and "keeps all data under your control" matters.

On-device AI has closed the accuracy gap. OpenAI's Whisper large-v3 achieves a 2.7% word error rate on clean English audio โ€” competitive with cloud services. Apple Silicon's Neural Engine enables real-time local inference. Tools like Voibe now deliver cloud-quality accuracy with zero data leaving your device.

These trends mean the choice between cloud and on-device dictation is no longer a trade-off between accuracy and privacy โ€” it is purely a privacy decision. And within on-device tools, architecture and data-handling defaults matter as much as where transcription happens.

Privacy Guides by Topic

Each guide below covers a specific aspect of dictation privacy in depth. Start with whichever topic is most relevant to your situation.

HIPAA-Compliant Dictation

HIPAA Dictation: Requirements, Tools, and Compliance Guide

Healthcare professionals who dictate patient notes handle Protected Health Information (PHI). Voiceprints are explicitly listed as HIPAA identifier #16, meaning dictation audio is inherently PHI. This guide covers the five HIPAA requirements for dictation software, compares tool compliance (Dragon Medical One at $79-99/mo vs. Voibe at $149 lifetime vs. Superwhisper at $249.99 lifetime), penalty structures up to $2.07M per category, and implementation checklists.

Read this if: You work in healthcare, handle patient data, or need to understand HIPAA dictation compliance.

See also: Dragon Medical Alternatives for Mac โ€” a comparison of 7 Dragon Medical One alternatives including on-device options that keep patient audio off cloud servers.

Voice Data Privacy

Voice Data Privacy: How Dictation Apps Collect, Store, and Use Your Audio

Cloud dictation apps collect five categories of data from your voice: raw audio, transcripts, biometric voiceprints, metadata, and background audio. This guide explains exactly what each dictation service collects, how data is shared with third parties (Alexa shares with up to 41 ad partners), the regulatory frameworks that protect you (GDPR, BIPA, CCPA), and how to minimize exposure.

Read this if: You want to understand what happens to your voice data after you speak into a dictation app.

Zero Data Retention

Zero Data Retention: The Privacy Promise Almost Nobody Checks

Zero data retention means a service keeps no copy of your audio or transcript once a request has been processed. This guide separates it from the three claims it gets confused with (not selling, not training, encryption), sets out the Retention Ladder from level 0 (nothing collected) to level 4 (retained and trained on), names the six terms-of-service clauses that quietly undo a zero-retention promise, and gives a five-question test you can run on any voice app in about ten minutes.

Read this if: You have seen an app advertise zero retention and want to know whether your own account is actually covered by it.

Cloud vs. Local Dictation

Cloud vs. Local Dictation: Privacy, Speed, and Accuracy Compared

The fundamental choice in dictation privacy is where your audio gets processed โ€” on remote servers or on your device. This guide provides a technical comparison across privacy, latency (100-500ms cloud overhead vs. near-zero local), accuracy (Whisper large-v3 at 2.7% WER matches cloud services), and cost (Voibe lifetime at $149 vs. Otter Pro 3-year at $611.64, vs. Superwhisper lifetime at $249.99).

Read this if: You want a data-driven comparison to decide between cloud and on-device dictation.

How Whisper Works

How Whisper Works: OpenAI's Speech Model Explained for Mac Users

Whisper is the open-source AI model that enables private on-device dictation. Trained on 1 million+ hours of audio, it runs locally on Apple Silicon's Neural Engine with Core ML delivering 3x faster inference than CPU-only. This guide explains the encoder-decoder architecture, model sizes from tiny (39M params) to large (1.55B), and why Apple Silicon makes real-time local speech recognition possible.

Read this if: You want to understand the technology behind on-device dictation and how Apple Silicon enables it.

Apple Dictation Privacy

Apple Dictation Privacy: What Data Apple Collects and How to Stop It

Apple Dictation is free and mostly on-device on Apple Silicon, but has privacy caveats. The "Improve Siri & Dictation" setting sends audio samples to Apple. Apple paid $95M in January 2025 to settle a Siri recording lawsuit. This guide covers exactly what Apple collects, step-by-step instructions to disable data sharing, HIPAA limitations, and how Apple Dictation compares to fully on-device alternatives.

Read this if: You use Apple's built-in dictation and want to maximize its privacy settings.

Companion piece: Apple Dictation Pricing Breakdown โ€” the dollar-cost analysis on what "free" actually costs in time, accuracy losses, and HIPAA exposure (Apple does not sign BAAs, which makes Apple Dictation a regulatory blocker for any PHI workflow).

Offline Dictation Privacy on Mac

Offline Dictation Privacy on Mac: How On-Device Speech to Text Keeps Your Data Safe

Our comprehensive deep-dive into the cloud dictation data pipeline, the specific risks at each stage (transmission, server processing, retention, training use), which Mac professionals face the highest risk, and a detailed privacy comparison of every major Mac dictation tool. Includes a verification checklist and decision framework.

Read this if: You want the most thorough analysis of Mac dictation privacy with tool-by-tool comparisons.

Typeless Privacy Case Study

Typeless Privacy Issues: What Researchers Found and Why Cloud Dictation Is Risky

A real-world case study of the gap between "privacy-first" marketing and cloud-based architecture. Typeless markets "on-device history" and "zero data retention," but its own privacy policy confirms audio is processed on cloud servers, and a November 2025 reverse-engineering analysis reported routing to AWS us-east-2 alongside URL capture, window-title collection via the accessibility API, and broad permission requests. Introduces the 8-point Dictation Privacy Audit framework you can apply to any dictation app before granting microphone access.

Read this if: You want to see what happens when cloud dictation marketing does not match architecture โ€” or you need a framework to evaluate any dictation app's privacy claims.

Is Wispr Flow Safe? Privacy + Delve Audit Investigation

Is Wispr Flow Safe? Privacy, Delve Audit Scandal & Verdict (2026)

A current-state safety investigation of Wispr Flow. Walks through Wispr's actual cloud architecture (audio processed by Baseten, text by OpenAI/Anthropic/Cerebras, storage in AWS us-east-1), the Privacy Mode mechanics (off by default for non-HIPAA users; locks irreversibly when a BAA is signed), and the March 2026 Delve compliance scandal โ€” Wispr Flow's prior compliance vendor was named in a credible fake-audit investigation that 99.8% of 494 SOC 2 reports shared identical boilerplate text. Wispr Flow has remediated transparently with A-LIGN as the new auditor, Drata as the new compliance platform, and SafeBase for the trust center. Includes a five-question Wispr Flow Safety Decision Tree.

Read this if: You currently use or are evaluating Wispr Flow, especially for sensitive or regulated work โ€” or you want to understand how the Delve compliance scandal changes the trust calculation for cloud SaaS dictation.

Is Superwhisper Safe? On-Device Modes, Cloud-Mode Gap & Local Recordings

Is Superwhisper Safe? Privacy Modes, Local Recordings & Verdict (2026)

A current-state safety investigation of Superwhisper. Walks through the architectural split between on-device modes (Tiny / Base / Small / Standard Whisper / Parakeet โ€” genuinely local) and cloud modes (Ultra transcription + Super Mode LLM post-processing โ€” proxied through Superwhisper to OpenAI / Anthropic / Google / Groq / Meta / Mistral / Grok). Documents three structural caveats: local audio recordings are ON by default (23 votes on the public feedback board to make it opt-in), API keys for cloud-mode providers are stored in plaintext JSON on disk (15+ votes), and the privacy policy was last updated June 19, 2024 and does not separately describe cloud-mode handling. Includes a five-question Superwhisper Safety Decision Tree and a Superwhisper Safety Audit checklist.

Read this if: You currently use or are evaluating Superwhisper for sensitive content โ€” or you want to understand the difference between “runs locally” and “keeps all data under your control.”

Is Aqua Voice Safe? Cloud-Only Architecture & Training Silence

Is Aqua Voice Safe? Privacy Mode, Training Silence & Verdict (2026)

A current-state safety investigation of Aqua Voice. Walks through Aqua Voice's cloud-only architecture (every dictation request transmits audio to Aqua Voice's servers โ€” no on-device mode), the Privacy Mode mechanics (OFF by default for individuals, with admin-enforceable org-wide enforcement on Teams + Enterprise), and the load-bearing documentation gap: the privacy policy at aquavoice.com/info/privacy effective May 22, 2025 does not address whether stored transcript data is used for AI model training. Covers the SOC 2 Type II attestation through Advantage Partners (Vanta-managed trust center) and what the certification does and does not tell you. Includes a five-question Aqua Voice Safety Decision Tree.

Read this if: You are evaluating Aqua Voice for daily dictation or sensitive content โ€” or you want to understand why a SOC 2 attestation does not by itself answer the AI-training question.

Is Otter.ai Safe? Class Action, Two-Party Consent & Verdict (2026)

A current-state safety investigation of Otter.ai, the leading cloud meeting transcription tool. Walks through Otter's cloud-only architecture (no on-device mode; audio + transcripts stored on Otter servers), the SOC 2 Type 2 attestation and AES-256 encryption baseline, the default-opt-out training pattern (Otter trains on de-identified user data unless you find and flip the setting), and the load-bearing legal story: In re Otter.AI Privacy Litigation, 5:25-cv-06911 (N.D. Cal.) โ€” a consolidated federal class action filed Aug-Sep 2025, consolidated by Judge Eumi K. Lee on October 22, 2025, with a consolidated complaint filed December 5, 2025 and Otter's motion-to-dismiss reply brief filed April 2026. The plaintiffs allege Otter recorded private conversations and trained AI on meeting data without all-participant consent in two-party-consent jurisdictions, citing ECPA, CFAA, CIPA, and two California statutes. Includes a five-question Otter Safety Decision Tree and an Otter Safety Audit checklist.

Read this if: You use OtterPilot for meeting transcription โ€” or you want to understand why the visible-bot-as-implicit-consent model is being litigated and what that means for organizations using meeting bots in mixed-jurisdiction calls.

Is Dragon Safe? Microsoft-Owned, Three Products, Three Architectures

Is Dragon Safe? Professional, Anywhere, Medical One & Microsoft (2026)

A current-state safety investigation of the Dragon dictation product line, now Microsoft-owned (Nuance acquired March 2022 for $19.7 billion). Walks through the three currently-sold Dragon variants โ€” Dragon Professional v16 ($699.99 Windows-only, mostly on-device), Dragon Anywhere ($14.99/mo or $149.99/yr mobile cloud), and Dragon Medical One ($79โ€“99/user/month on 1โ€“3 year terms, cloud-only on Azure with a signed BAA). Documents the Microsoft acquisition data-perimeter shift to Azure, the full healthcare compliance stack (SOC 2 Type 2, ISO 27001, HITRUST CSF, FedRAMP, HIPAA BAA), the orphaned-Mac-user gap from the 2018 Dragon Mac discontinuation, and Microsoft's March 2025 Dragon Copilot strategy (merged with DAX Copilot). Includes a five-question Dragon Safety Decision Tree and an architectural-alternatives breakdown by user segment (Mac users / healthcare users / legal users / mobile users).

Read this if: You are a Dragon user evaluating which Dragon variant fits your platform and use case โ€” or a Mac user orphaned by the 2018 discontinuation looking for the architectural alternative that Dragon's current line does not cover.

Is Willow Voice Safe? Private Mode Default-On & Documentation Gaps

Is Willow Voice Safe? Private Mode, HIPAA & Enterprise Verdict (2026)

A current-state safety investigation of Willow Voice, the YC X25-backed cloud dictation product (Mac + Windows + iPhone + Android). Walks through the privacy-protective Private Mode default โ€” Willow's policy explicitly designates Private Mode as the โ€œ(DEFAULT Opt-Out)โ€ for training, the strongest default among major cloud dictation peers we have investigated (Aqua Voice is Privacy Mode off by default, Superwhisper is local-recording on by default, Otter is training opt-out, Wispr Flow is Privacy Mode off by default for individuals). Documents three structural caveats: (1) cloud-first by default โ€” audio still routes through Willow's servers for transcription in both modes; (2) the optional Offline Mode on Mac and iOS is not addressed in the privacy policy effective April 30, 2025; (3) HIPAA is advertised on the homepage and pricing page but the privacy policy text mentions only SOC 2 and GDPR, leaving BAA scope undocumented publicly. Includes a five-question Willow Voice Safety Decision Tree and a Willow Voice Safety Audit checklist.

Read this if: You currently use or are evaluating Willow Voice, especially for sensitive or regulated work โ€” or you want to understand why the most privacy-protective default in the cloud dictation category still leaves documentation gaps that matter for healthcare procurement.

Is Claude Code Safe? Pro/Max vs. Commercial Terms Split

Is Claude Code Safe? Pro/Max vs API Privacy, Aug 2025 Terms Verdict (2026)

A current-state safety investigation of Anthropic's Claude Code that directly addresses the developer confusion around the August 28, 2025 consumer terms update. Walks through the two-tier framework: Consumer (Free, Pro, Max) accounts where Anthropic CAN train on Claude Code prompts and outputs by default โ€” opt out at claude.ai/settings/data-privacy-controls โ€” versus Commercial Terms (Anthropic API, Amazon Bedrock, Google Cloud Vertex AI, Microsoft Foundry, Claude Platform on AWS, Claude for Teams, Claude for Enterprise, Claude Gov) where no training is the documented default. Documents the provider-specific defaults matrix (Bedrock / Vertex / Foundry / AWS all have telemetry / error reporting / /feedback DEFAULT OFF; direct Anthropic API has them on), Zero Data Retention configuration on Claude for Enterprise, the HIPAA BAA path, the local cache at ~/.claude/projects/ (plaintext for 30 days by default), and the environment-variable controls (DISABLE_TELEMETRY, DISABLE_ERROR_REPORTING, DISABLE_FEEDBACK_COMMAND, CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC). Includes a five-question Claude Code Safety Decision Tree.

Read this if: You use Claude Code for any sensitive, regulated, or compliance-audited code โ€” or you want to verify whether your Pro/Max account is currently training Anthropic's models with your code by default after the August 2025 terms update.

That review now anchors a five-page Claude cluster, refreshed August 2026: Claude Code privacy settings (every opt-out env var and the training toggle, copy-paste ready), Claude API data retention (the 30-day default, ZDR eligibility, and the June 2026 Covered Models rule), Claude Pro and Max privacy (the 5-year window, incognito, and what deletion removes), and Is Claude safe? for the claude.ai product itself.

One prompt inside Claude Code deserves its own answer, because it is the only place in the tool where a single keypress moves data: the post-rating question "Can Anthropic look at your session transcript?". Selecting Yes uploads the conversation transcript, any subagent transcripts, and the raw session log file from disk โ€” known API key and token patterns redacted, source code and file contents as-is, retained up to 6 months. It cannot be used for training, which makes it a separate decision from the training toggle.

Is Spokenly Safe? Three Architectures, Three Privacy Postures

Is Spokenly Safe? Local, BYOK & Pro Cloud Privacy Verdict (2026)

A current-state safety investigation of Spokenly, whose safety depends entirely on which of three architectural modes you use. Local Only Mode runs Whisper Large-v3 or Parakeet on Apple Silicon with no network calls; BYOK cloud routes audio to whichever provider you bring keys for (OpenAI / Deepgram / Groq / Anthropic / Google); Pro managed cloud routes through five named subprocessors per the privacy policy effective March 2, 2026 (Cerebras, Fireworks, Groq, Mistral AI, ElevenLabs). Documents the three cross-mode caveats โ€” no SOC 2 / HIPAA / ISO attestations, no corporate entity named in the policy (developer Vadim Akhmerov disclosed only via the App Store), and the iOS keyboard fix that recommends online models and defeats the on-device benefit. Includes a five-question Spokenly Safety Decision Tree and a five-step Spokenly Safety Audit.

Read this if: You use or are evaluating Spokenly and need to know which mode is safe for which kind of content โ€” or you want to see why a single product can carry three different privacy postures.

Is Blip AI Safe? Cloud-Only, HIPAA Claim Without Published Audit

Is Blip AI Safe? Cloud Privacy & HIPAA Verdict (2026)

A current-state safety investigation of Blip AI, a cloud-only, GPT-powered dictation tool that launched October 2025. Blip AI's privacy policy makes favorable commitments โ€” voice audio deleted within seconds, transcripts not stored on its servers, and HIPAA compliance with a Business Associate Agreement available on request โ€” but the verification behind them is thin: no published SOC 2 Type II or ISO 27001 audit backs the HIPAA claim, the policy names none of its subprocessors (the product is GPT-powered, so at least one model provider sits in the audio path), it does not address whether dictation trains AI models, and the company is a bootstrapped 1–10-person team with only thin, skewed third-party reviews. Frames the central tension as strong claims versus weak independent verification, and includes a five-question Blip AI Safety Decision Tree and a five-step Blip AI Safety Audit.

Read this if: You are evaluating Blip AI's AppSumo lifetime deal for anything beyond casual notes โ€” or you want to know what to request in writing before trusting a young cloud vendor's HIPAA claim with sensitive data.

Is VoiceDash Safe? Cloud-Only Through OpenAI, Two Trust Perimeters

Is VoiceDash Safe? Cloud Privacy, OpenAI & Verdict (2026)

A current-state safety investigation of VoiceDash, a cloud-only dictation tool (founded February 2025 in Dubai) that functions as a thin client to the OpenAI API. VoiceDash is unusually transparent for an indie cloud tool: its privacy policy and the founder's AppSumo Q&A both commit to not storing audio or transcripts and not training on user data โ€” “we do not use your data for any training purposes” โ€” and name OpenAI as the processor. The load-bearing insight is the two-perimeter trust model: your audio is governed by VoiceDash's policy AND OpenAI's API data-usage policy, so your effective privacy is the weaker of the two, and neither is independently audited for a VoiceDash buyer. Documents the absence of SOC 2 / HIPAA / BAA (VoiceDash makes no HIPAA claim โ€” honest, but disqualifying for regulated work), the GDPR Right to Erasure by email, and the OpenAI-API-cost dependency behind the lifetime deal. Includes a five-question VoiceDash Safety Decision Tree and a five-step VoiceDash Safety Audit.

Read this if: You are evaluating VoiceDash's AppSumo lifetime deal โ€” or you want to understand why a transparent, no-training cloud tool still leaves two policies to trust and no audit to verify them.

Is Voicy Safe? Groq Cloud Path & the Marketing-vs-Policy Training Gap

Is Voicy Safe? Groq Cloud Path & Policy Gaps (2026)

A current-state safety investigation of Voicy, the cross-platform cloud dictation app from solo founder Kourosh Ghaffari (Pishi LLC FZ). Voicy's deletion promises are among the clearest in the indie cloud field โ€” audio “permanently deleted immediately after processing,” transcripts “immediately deleted after delivery,” and a claimed Groq Zero Data Retention setting โ€” but the promises live in scattered paperwork: the no-training commitment appears only on marketing pages while both policies stay silent, the security policy is frozen at v1.3 (July 2025) and does not cover the 2026 iPhone and Android apps, the two app stores' privacy labels contradict each other, and there is no SOC 2, ISO 27001, HIPAA BAA, or terms of service. Includes a five-question Voicy Safety Decision Tree and a five-step Voicy Safety Audit.

Read this if: You dictate through Voicy on desktop or mobile and want to know exactly which promises are in binding documents โ€” or you're evaluating the $260 lifetime plan for anything beyond casual notes.

Is Wisprtype Safe? Local by Default, Closed Source, Telemetry Mismatch

Is Wisprtype Safe? Local by Default, Closed Source (2026)

A current-state safety investigation of Wisprtype, the free Mac dictation app from solo developer Piyush Garg. The architecture is genuinely privacy-first โ€” six local Whisper models via WhisperKit by default, local Llama 3.2 3B cleanup, and BYOK cloud that is strictly opt-in โ€” but the verification surface fails where it counts: the v1.1.0 binary shipped with PostHog telemetry on despite the policy's “disabled by default” wording (and v1.1.0 is still the current build), the app is closed-source with no public repository, no legal entity or terms of service exist, the policy is silent on AI training, and the website runs its own undisclosed analytics. Introduces the Dictation Trust Ladder (verifiable local โ†’ attested local โ†’ attested cloud) plus a five-question decision tree and five-step audit.

Read this if: You want free on-device dictation and need to know which toggle to flip on first launch โ€” or you're deciding between closed-source local tools and their open-source or vendor-accountable alternatives.

Is VoiceInk Safe? Open-Source On-Device โ€” Verified in Source

Is VoiceInk Safe? Open-Source, On-Device Verdict (2026)

A positive-verdict safety investigation of VoiceInk, the GPL v3 open-source Mac dictation app from developer Prakash Joshi Pax. We audited the shipping source: transcription is on-device by default (Parakeet on the Neural Engine, whisper.cpp Whisper models as alternatives), the transcript store is created with iCloud sync disabled, and there is zero telemetry or analytics code. The honest nuances: license activation sends the Mac's hostname and hardware serial to Polar.sh (not disclosed in the policy), BYOK cloud transcription and AI enhancement are one click away (off by default), history is kept until deleted, and there is no legal entity or attestation behind the project โ€” the GPL and 769 public forks are the continuity insurance. Includes the VoiceInk Network Ledger (every outbound call, enumerated), a decision tree, and a five-step audit.

Read this if: You want on-device dictation you can independently verify โ€” or you're weighing the $29–69 DIY open-source path against a managed commercial on-device tool.

Is Handy Safe? Free, MIT-Licensed, No Cloud Path at All

Is Handy Safe? Free, Open-Source, On-Device (2026)

A positive-verdict safety investigation of Handy, the free MIT-licensed cross-platform dictation app from developer CJ Pais (25,800+ GitHub stars). A full source audit found no cloud transcription path anywhere in the codebase โ€” all 65 supported models across 13 families run locally โ€” and zero telemetry or analytics code. The honest caveats: no privacy policy document exists (the auditable source stands in for one), the GitHub update check is on by default (toggleable), “Opt-in Analytics” sits unshipped on the roadmap, and it is a donation-funded solo-maintained project with real platform bugs and no compliance paperwork. Includes the Handy Network Ledger, a decision tree, and a five-step audit.

Read this if: You want free, verifiable, on-device dictation on macOS, Windows, or Linux โ€” or you need to explain to a compliance owner why good architecture still isn't paperwork.

Is Paraspeech Safe? Local by Default, With a Named Cloud Path

Is Paraspeech Safe? What "Local-First" Leaves Out

A safety investigation of Paraspeech, the Mac and iOS dictation app from German vendor Burlis Management GmbH. On an Apple Silicon Mac running a local model with Cloud Cleanup off, audio never leaves the device and the app works offline — a real on-device guarantee. Outside that configuration the picture changes: Intel Macs get cloud-backed models only, the 100+ language Multilingual Large model is cloud-tied, and Cloud Cleanup requires internet access. Paraspeech names its processors individually, which most competitors do not — Deepgram receives audio for cloud transcription, Groq and Cerebras handle rewrite. The EU domicile makes GDPR domestic law, but no SOC 2 or ISO 27001 certification is published, and there is no HIPAA coverage or BAA at any tier.

AI Tool Privacy Tracker (Cross-Product Reference Matrix)

AI Tool Privacy Tracker: Verified Reference Matrix for 12 Tools

The cross-product flagship of this cluster. A continuously-updated reference page covering 12 major AI tools across three categories: AI Assistants (ChatGPT, Claude, Gemini, Perplexity), AI Coding Tools (Cursor, GitHub Copilot, Windsurf, Cline), and Voice & Dictation (Voibe, Wispr Flow, Superwhisper, Apple Dictation). Each row is split by plan tier (Consumer / Business-API) โ€” because the same tool typically gives different answers on each side โ€” and every cell links to a primary source (the vendor's own privacy policy, terms, or technical documentation). Includes a Recent Changes timeline of dated policy shifts that move tools between “trains by default” and “does not train.” Reviewed monthly.

Read this if: You want a single answer to “does [AI tool] train on my data?” โ€” or you are choosing between AI assistants, coding tools, or dictation apps and want to weight privacy posture in your decision.

AI and Attorney-Client Privilege (US v. Heppner)

AI and Attorney-Client Privilege After US v. Heppner: What Lawyers Must Know (2026)

In February 2026, Judge Jed S. Rakoff of the Southern District of New York held that a defendant's chats with public Claude were not protected by attorney-client privilege or the work product doctrine. The ruling applied the traditional three-part privilege test and found public AI tools fail every prong: the AI is not an attorney, the privacy policy disclaimed confidentiality, and independent client use lacked counsel's direction. The same third-party-disclosure logic extends to any cloud AI tool that touches privileged content โ€” including dictation, transcription, and meeting-summary tools. This analysis covers the case, the Heppner-Gilbarco split, the public-vs-enterprise-vs-on-device risk spectrum, and a practical post-Heppner checklist.

Read this if: You are a lawyer evaluating AI tools, or anyone curious about how Heppner reshapes privilege analysis for voice and dictation tools.

Accessibility Dictation: Health-Context Dictation on Mac

Accessibility Dictation: A Hub for Hands-Free Voice Typing on Mac

Users with carpal tunnel, RSI, arthritis, post-surgery hands, or ADHD often turn to dictation because typing is the actual cause of the pain or friction. The catch: most dictation apps default to push-to-talk activation, which replaces sustained typing load with sustained held-key load โ€” the same finger-flexion pattern that triggered the original injury. This hub leads with Voibe's Hands-Free Mode (double-tap activation, no key held during speech) as the structural solution, and on-device privacy as the supporting moat โ€” because users dictating about their condition often reference the condition itself in the dictated stream (medications, symptoms, doctor names, insurance codes). Related guides include Best Dictation Software for Carpal Tunnel, How to Type With Carpal Tunnel, Best Dictation Software for Arthritis (joint-protection approach for RA, OA, PsA โ€” including biologic and DMARD vocabulary), Typing With Arthritis (keyboard adaptation and joint protection at work), and Best Dictation Software for Hand Pain (a guide for users with undiagnosed or overlapping conditions).

Read this if: You are evaluating dictation as an ADA accommodation, recovering from hand surgery, managing a chronic condition that limits typing, or work with someone who is.

Rev.com Alternatives by Profession (Lawyers, Doctors, Journalists)

The Rev.com persona sub-cluster โ€” three guides covering the structurally same problem with different compliance frameworks:

  • Rev.com Alternatives for Lawyers and Small Law Firms โ€” anchored on ABA Rule 1.6(c) and the US v. Heppner third-party-disclosure analysis. 8 alternatives including SpeakWrite (1.5ยข/word human) and Sonix Enterprise (HIPAA BAA cloud). Pre-calculated 3-year savings on a representative solo workload: 99.2% vs Rev human transcription.
  • Rev.com Alternatives for Doctors and Small Practices โ€” anchored on the HIPAA Security Rule and the AI-medical-scribe-vs-transcription category gap. 8 alternatives spanning on-device dictation, AI scribes (Suki, DAX, Heidi), and HIPAA-aligned cloud transcription. 99.4% savings on a 3-doctor 30-min/day workload.
  • Rev.com Alternatives for Journalists and Newsrooms โ€” anchored on the state shield-law gap (Branzburg v. Hayes 1972, no federal shield, PRESS Act pending) and third-party-records-holder subpoena exposure. 8 alternatives including Trint Story Builder, Descript transcript-as-AV-editor, and Pinpoint (free Google News Initiative tool). 95.5% savings on a 50-source investigation.

Read these if: You currently use Rev.com for transcription and want to evaluate the dictation, ambient AI, or newsroom-collaboration tools that replace specific portions of that workflow without sending privileged or confidential audio to a third-party processor.

Quick Privacy Comparison: Mac Dictation Tools

ToolProcessingAudio Leaves Device?BAA Available?Pricing
Voibe100% on-deviceNoNot needed$7.50/mo, $59/yr, or $149 lifetime
SuperwhisperOn-device + optional cloudNo (default)No$8.49/mo, $84.99/yr, or $249.99 lifetime
Apple DictationMostly on-devicePartialNoFree
Otter.aiCloudYesEnterprise onlyFrom $16.99/mo
Wispr FlowCloud (OpenAI, Meta)Yes โ€” including screenshotsYes (all plans)~$10/mo
Dragon Medical OneCloudYesYes$79-99/mo

For the complete analysis with pros, cons, and decision guidance, see our offline dictation privacy deep-dive and best offline dictation apps roundup. Healthcare professionals currently using Dragon Medical should also review our Dragon Medical alternatives guide — it covers 7 replacements including on-device tools that keep PHI off cloud servers entirely.

Newer investigations in this cluster: is DictaFlow safe? โ€” a hybrid app whose consumer plan names OpenAI and NVIDIA as cloud processors, whose separate Medical build names Deepgram, OpenAI and Groq, and whose own privacy policy states the $69 plan is not configured as a HIPAA-compliant medical service. It publishes no retention window, no processing region and no legal entity.

Getting Started with Private Dictation

The fastest path to private dictation on Mac: Voibe runs 100% on-device on Apple Silicon, requires no account, and costs $7.50/month, $59/year, or $149 lifetime. Download, install, and dictate โ€” your voice never leaves your Mac. Dictation history is stored locally on your device, and for zero-retention workflows (legal drafts, patient notes, privileged communications) you can disable transcript storage entirely in Voibe's settings, so no record of what you dictated exists anywhere.

For a complete walkthrough, see our how to use dictation on Mac guide.

Switching from cloud tools? See our guides to TurboScribe alternatives and SpeakOneAI alternatives for privacy-focused replacements. For a real-world look at how much a cloud dictation tool can track โ€” straight from a founder's own podcast walkthrough โ€” read what Wispr Flow's founder revealed about user tracking โ€” and its August 2026 sequel, in which Wispr Flow team members published word-frequency analyses of user dictations on LinkedIn.

Comparing Apple Dictation to the main cloud and open-source alternatives? See Apple Dictation vs Wispr Flow for the upgrade-decision framework around cloud AI dictation, and Apple Dictation vs OpenAI Whisper for the built-in vs open-source model trade-off. For the free-vs-$699 end of the spectrum, see Apple Dictation vs Dragon. Once you have a private dictation tool in place, see our voice input workflow guide for the Talk-Draft-Polish pattern that makes on-device dictation sustainable day-to-day โ€” including a dedicated section on why offline workflows matter for regulated work and private drafting.

Frequently Asked Questions

Why is dictation privacy important?

Dictation privacy is important because voice recordings contain biometric voiceprints โ€” unique vocal characteristics that identify you as reliably as fingerprints. Unlike a compromised password, a leaked voiceprint cannot be reset or changed. Cloud dictation services that send audio to remote servers expose this permanent biometric data to breach risk, third-party access, and potential misuse for AI model training.

What is the safest way to dictate on Mac?

The safest way to dictate on Mac is to use an on-device dictation app that processes all audio locally on your Apple Silicon chip. Voibe ($7.50/month, $59/year, or $149 lifetime) runs 100% on-device using Whisper models, requires no account, and never sends any data to servers. This eliminates breach risk entirely because your voice never leaves your hardware.

Which dictation apps are HIPAA compliant?

On-device dictation apps like Voibe offer the strongest HIPAA compliance posture because no Protected Health Information (PHI) leaves the device. Cloud-based options with HIPAA compliance include Dragon Medical One ($79-99/month with BAA) and Otter.ai Enterprise (custom pricing with BAA). Apple Dictation, Wispr Flow (consumer plan), and Otter.ai Free/Pro are not HIPAA compliant. Wispr Flow also captures screenshots of the active window every few seconds and sends them to external servers (OpenAI, Meta), which creates additional PHI exposure risk. See our full HIPAA dictation guide for details.

Does Apple Dictation protect my privacy?

Apple Dictation on Apple Silicon Macs processes most speech on-device, but has privacy caveats. The optional 'Improve Siri & Dictation' setting sends audio samples to Apple servers. Apple does not sign Business Associate Agreements (BAAs), making it unsuitable for HIPAA work. Contextual data including contact names and app names may be transmitted alongside dictation requests. See our Apple Dictation privacy guide for configuration steps.

What laws protect voice data in dictation apps?

Voice data is protected by multiple regulatory frameworks. HIPAA governs audio containing patient health information (fines up to $2.07M per category per year). GDPR classifies voice recordings as biometric data requiring explicit consent (fines up to 4% of global revenue). Illinois BIPA requires written consent before collecting voiceprints ($1,000-$5,000 per violation, with over 107 class actions filed in 2025). CCPA gives California residents the right to know and delete voice data.

How does OpenAI Whisper enable private dictation?

OpenAI Whisper is an open-source speech recognition model that can run entirely on your device. Unlike cloud speech APIs, local Whisper processes audio on your Mac's Apple Silicon chip without any internet connection. The model weights are stored locally, audio is converted to text in memory and discarded immediately, and no data is transmitted to servers. This architectural approach makes dictation private by design rather than by policy.

Ready to type 5x faster?

Voibe is the fastest, most private dictation app for Mac and Windows. Try it today.

  • On-device or private cloud
  • Free to try
  • No subscription
  • Mac + Windows
  • 90+ languages

Prefer to go Pro? Save 20% on any plan with code VOIBE20 View pricing โ†’