Security and privacy overview

Last updated: October 2, 2026

Available on: Mac, Windows, iOS, Android

Wispr Flow processes dictated audio in the cloud to turn speech into text. This overview covers the privacy controls you can change, how your data is protected, and the documents available for a security review.

For current audit reports and supporting policies, visit the Wispr Trust Center. For a specific requirement or contract question, contact security@wispr.ai or your account representative.


Control how your data is used and stored

Find these in Settings → Data and Privacy. Model improvement and Dictation Cloud Storage are separate settings; changing one does not change the other.

Control

What it governs

Improve the model for everyone

Whether Notetaker and dictation content may be used to improve Wispr's models.

Dictation Cloud Storage

Whether dictation data is stored on Wispr's servers; dictation only, not Notetaker or Scratchpad.

Download your data

Requests a copy of your dictations, meetings, notes, and settings.

Improve the model for everyone is on by default for Free and Pro, with the choice shown during onboarding, and you can turn it off; it is off for Enterprise and administrators cannot re-enable it. Organization policies or a signed Business Associate Agreement may lock settings, and a member cannot relax an admin-managed setting. If your organization has specific storage or deletion requirements, confirm the enforced settings and covered products with your administrator or account representative.

Turning it off stops your content from being used to improve Wispr's models; it does not turn off Dictation Cloud Storage or delete local history. Wispr's third-party AI providers cannot use your data to train their models, whatever your model-improvement setting. For current definitions, see Data Controls.

Warning: Read deletion confirmations before accepting them. Deleted records cannot be restored.


Download a copy of your data

On Mac and Windows, go to Settings → Data and Privacy and use Download your data.

  1. Select Request a copy. Wispr emails you a confirmation and starts preparing the export.

  2. Wait for the second email telling you the export is ready. While it is being prepared you can select Cancel request.

  3. Select Download and choose where to save the file. The export arrives as a single ZIP file, up to 2 GB.

The status line under the row shows the request state — preparing, ready until a given date, expired, failed, or cancelled. An export stays available for 30 days; after that Download disappears and you can select Request a new copy.

Note: If a request is refused, the status line explains why — for example your organization has turned export off, a request is already in progress, you requested one too recently, or your account is being deleted. If you are told your account is too large to export, contact support rather than retrying.

What the export contains

  • Dictation history: One entry per dictation, showing its latest version. Dictations you deleted are not included.

  • Meetings: Meeting records, including summaries, language, recording length and speaker details.

  • Notes: Scratchpad notes.

  • Settings: Your account preferences.

An export covers only what is stored, so it cannot include dictation history that was never retained on Wispr's servers, and local history on one device is not a complete record of activity across all your devices. For contractual retention periods, deletion confirmation, or an export at the end of your agreement, contact your account representative.


What privacy settings do not remove

  • Account data: Account information, preferences, and subscription details are kept to provide the service.

  • Dictionaries and snippets: Content you create is stored and synced separately from dictated content.

  • Diagnostics and usage statistics: Operational data such as word counts is distinct from dictation history.

  • Reported transcripts: Submitting a transcript through Report or another feedback action intentionally sends that content for investigation.

  • Notetaker recordings: Transcripts and summaries are stored in Wispr's cloud, Dictation Cloud Storage does not govern them, and there is no customer setting to opt out of that storage. Meeting audio uploaded to Wispr is kept for 7 days from upload to support troubleshooting and speaker attribution, then deleted; transcripts and summaries remain. Improve the model for everyone does apply to Notetaker as well as dictation.

  • Scratchpad notes: On Mac and Windows, notes sync to the cloud whatever your Dictation Cloud Storage setting; only an organization turning Scratchpad off stops note sync. On iOS, note sync does not apply to accounts under a Business Associate Agreement or in privacy mode.


Encryption and access protection

Wispr encrypts service data in transit and at rest. It is not end-to-end encrypted in the strict sense, because the service must process audio to produce a transcript. Wispr manages service encryption keys; customer-managed keys are not supported.

Access to production systems is restricted and logged, and support access to account details is separate from access to stored customer content. Passwords are stored as hashes rather than plaintext, and employee access to sensitive systems requires multifactor authentication.

Organizations can use SAML single sign-on on Growth and Enterprise; with SSO, your identity provider controls its MFA policy. Enterprise adds controls such as SCIM user management, audit logs, and managed deployment. See the plan comparison for the controls included in your subscription, and request detailed control documentation through the Trust Center.


Compliance reports and healthcare use

The Trust Center provides Wispr's SOC 2 Type II report, the ISO/IEC 27001:2022 certificate, the earlier SOC 2 Type I report, penetration-test information, policies, and other security-review materials. Restricted documents may require approval and an NDA. It also handles vendor security questionnaires and data processing addendum requests.

Note: Wispr Flow dictation is the in-scope system for the SOC 2 examinations and the service assessed in the ISO 27001 certification audit. Meeting Notetaker launched after those audit periods and was not assessed in the SOC 2 Type I, the SOC 2 Type II, or the ISO 27001 certification audit.

HIPAA-ready dictation requires a signed Business Associate Agreement (BAA). Authorized Growth and Enterprise admins manage organization agreements in the admin portal; individual and organization agreements have different management controls.

Important: A signed personal or organization BAA blocks Notetaker recording. Revoking a BAA can change enforced data settings, and an organization policy or another active BAA may still apply. Review the agreement and your settings before changing it.


Data location, subprocessors, and your rights

Wispr Flow is a cloud service, not an on-premise deployment, and it processes and stores customer data in the United States. Review your DPA and its transfer terms if your organization has regional requirements.

Wispr does not sell your data. Subprocessors provide parts of the service under contractual privacy and security obligations; the Trust Center holds the current subprocessor list and supporting documents.

You can request a copy of your data (see Download a copy of your data) or request account deletion from Settings → Data and Privacy. The Privacy Policy explains how personal information is handled and how to make a rights request.


Still need help?