Security and data handling
What happens to your file, your results, your keys and your money. Written plainly so you can decide whether to trust us.
Your recording
- Uploaded over HTTPS and stored on our server only while it is being processed.
- Converted and split into chunks, sent to the transcription provider, then deleted immediately, whether the job succeeds or fails.
- We do not keep audio, ever, and there is no backup of it.
Your transcript and writing
- Stored for 30 days so you can copy and download them, then purged automatically.
- Visible only to your account. Every request is checked against the signed-in user; job and download links are random and cannot be guessed.
- Deleting your account erases results and keys at once.
AI providers
On the Standard and Premium tiers we send audio chunks to Groq for transcription (Whisper) and the transcript to the writer for the tier you chose: the OpenAI family of models on Standard, the Anthropic family on Premium. If a writer is unavailable, the job falls back to another of these providers so your result still arrives. These providers process API traffic to return a result. In "your own keys" mode the same data goes to whichever providers you have added keys for, under your agreement with them.
What we control, we state plainly: we do not train any model on your recordings, transcripts or results, and we do not pass them to anyone for that purpose. What the providers do is governed by their own published terms, which we can quote and link but cannot audit. As checked on 6 October 2026:
- OpenAI — "By default, we do not use your business data for training our models"; API inputs and outputs may be retained up to 30 days for abuse monitoring (API data usage policies).
- Anthropic — the commercial terms state Anthropic "may not train models on Customer Content from Services" (commercial terms).
- Groq — the services agreement states Groq "is not permitted to use Inputs or Outputs for training or fine-tuning" without the customer's instruction; inference data is retained up to 30 days for reliability and abuse monitoring (services agreement, data retention).
Terms change, and these are the providers' statements rather than ours. If this matters to your work, read the links above before you upload, and treat recordings that identify patients or clients as unsuitable for any third-party service, including this one.
The transcript is treated as untrusted text: instructions that appear inside a recording ("ignore previous instructions…") are not followed by the writing step.
Your API keys
Keys you add are encrypted at rest with a key that exists only on the server, never in the database and never in the code. They are never returned by any page or API, never written to logs, and are used only to make the provider calls for your own jobs.
Accounts
- Passwords are hashed with scrypt; we cannot read them. Minimum 10 characters.
- Email confirmation is required before the account can be used.
- Sessions use secure, HTTP-only cookies and can be revoked by changing your password.
- Sign-in, sign-up and reset endpoints are rate limited; reset links expire in one hour and work once.
Payments
Card and bank details go to Stripe; they never touch our servers. Your balance is kept in an append-only ledger: every top-up, hold and charge is a separate, immutable entry, so it can always be audited and never overdrawn.
Infrastructure
One application server, run by Hetzner in Helsinki, Finland (European Union). It accepts web traffic only through Cloudflare, and administrator access is by SSH key only (no passwords). HTTPS only (HSTS), plus security headers including a Content Security Policy.
Reporting a problem
If you find a security issue, email [email protected] with "security" in the subject. We acknowledge within two business days and will not take action against good-faith research.
Last updated 2026-10-06.