Privacy

Dictation means streaming everything you say at your computer to someone's model. The only real question is whose computer that model runs on

What dictation apps actually do with your audio and transcripts: cloud retention policies, training opt-outs, what 'on-device' does and doesn't guarantee, and how to choose for clinical, legal or confidential work.

Published 2026-08-31 · Updated 2026-08-31

The three privacy tiers

Every app in our ranking falls into one of three tiers, and the tier matters more than any policy document. Cloud-only apps (Wispr Flow, Aqua Voice, Willow Voice, Monologue) stream your audio to vendor servers for recognition and cleanup: nothing works offline, and the vendor's infrastructure sees everything you dictate. Hybrid apps can run locally but offer cloud features — the privacy question becomes which features silently escalate to the network. Fully on-device apps (Handy, OpenWhispr, VoiceInk, Superwhisper, MacWhisper's local mode, SpeechPulse, Dragon Professional) never need to send audio anywhere, which is the only guarantee that doesn't depend on trusting a policy.

Our ranking's privacy gate maps directly onto these tiers: choosing 'fully on-device' removes the first tier entirely.

Reading a cloud vendor's policy like a skeptic

Three questions cut through any privacy page. Is audio retained after transcription, and for how long? 'Processed in real time and discarded' is the answer you want; 'retained to improve our services' means stored. Are transcripts or audio used for model training, and is the opt-out default-on or default-off? And who else touches the data — many apps don't run their own models but pass your audio to a third-party API (OpenAI, Groq, Deepgram), each with its own retention terms that the app's marketing page won't mention.

Enterprise tiers change everything, and it cuts both ways. Business plans usually come with zero-retention agreements and no-training clauses that consumer tiers lack — the same app can be a reasonable choice for a company with a signed agreement and a poor one for a private individual on the free plan.

What 'on-device' doesn't cover

Local recognition closes the audio channel, but check the rest of the surface. Licensing and activation: does the app phone home to validate, and does it stop working when it can't? Analytics: many otherwise-local apps ship telemetry SDKs that report usage patterns, crash logs — occasionally including snippets of dictated text in a crash report. Update checks are benign but are still a network signal. And the cleanup layer: some 'local' apps send the recognised text (not audio) to a cloud LLM for polishing, which is a meaningfully different exposure than sending audio but is still exposure — our reviews flag which apps do this.

Open source is the strongest answer to all of the above: with Handy or OpenWhispr you can verify the network behaviour yourself or rely on the fact that hundreds of others already have. It's not a coincidence that the apps with the cleanest privacy stories are the ones whose code you can read.

Choosing for regulated work

Clinical and legal users should start from the requirement, not the app. HIPAA-covered work in the US effectively requires either a fully on-device app or a cloud vendor willing to sign a Business Associate Agreement — Dragon's decades of hospital dominance rest on exactly this, and several newer cloud apps now offer BAAs on enterprise plans. Privileged legal work has no statute as clean as HIPAA, but the bar associations' guidance lands in the same place: know where the audio goes, get it in writing, or keep it on the machine.

For everyone else, the honest framework is simpler. If you would not say it in front of the vendor's engineering team, don't dictate it into a cloud app. Everything else — email, drafts, messaging, notes — is a personal risk decision, and for most people most of the time the convenience of the cloud leaders is a defensible trade. Just make it a decision, not a default.

Frequently asked questions

Is any cloud dictation app HIPAA compliant?

Some offer Business Associate Agreements on enterprise plans, which is the mechanism that makes cloud processing permissible. The consumer tiers of the same apps are a different story — check for a signed BAA, not a marketing badge.

Do on-device apps collect any data at all?

Recognition itself is local, but check analytics and licensing behaviour. The open-source local apps (Handy, OpenWhispr, VoiceInk) are the cleanest; commercial local apps vary, and our reviews note what we found in each.

← All guides