Pithflow
Privacy 7 min read · · Updated

Voice dictation privacy — what actually happens to your audio

Your microphone picks up a lot more than you intend. Here's how voice dictation apps handle the audio, what gets stored, what gets sent where, and how to tell whether a tool is worth trusting.

JZ
By Jesus Zamudio

Voice dictation has a privacy surface every other tool you use doesn't. The microphone picks up background noise — your kid playing in the next room, your spouse on a call, the TV. Anything you say near the microphone for the duration of a dictation session ends up in audio that has to be processed somewhere.

The privacy question that matters: what happens to that audio after the transcript comes back? Here's the honest answer for the category — what most apps do, what the corners cut look like, and how to evaluate a tool before installing it.

Two architectures

Every voice dictation app falls into one of two buckets:

The cloud approach is faster and more accurate today. The local approach is structurally more private because the audio never traverses a network. Both are reasonable; pick based on threat model.

What cloud dictation tools actually do with your audio

For cloud tools (most of the category), here's the typical lifecycle:

  1. Your hotkey starts recording. Audio is buffered locally as PCM.
  2. When you release, the buffered audio is sent over HTTPS to the vendor's backend (their server, or a cloud transcription provider they use).
  3. The backend runs a transcription model. Some vendors then run a second model for AI cleanup.
  4. The cleaned text comes back. The desktop app types it into whatever has focus.
  5. The audio is supposed to be discarded at this point. Whether it actually is depends on the vendor's data policy.

Step 5 is where the meaningful differences live. The honest split:

What to actually check before installing

1. Read the privacy policy

Specifically search for "audio" in the policy. Look for:

2. Check whether transcripts are stored

Distinct question from audio. Some vendors discard audio but store transcripts (text) tied to your account. This is usually for "history" features. Decide whether that's OK for you — if you dictate sensitive content, even text-only history is a leak surface.

Pithflow stores dictation transcripts locally on your machine in a SQLite database. The server doesn't keep them: your audio is sent, the cleaned text is returned, and the server discards both. Your local history is yours. There is one exception, and you control it. A meeting recorded from the Meetings tab is saved to your account so you can read it back later, and you can delete it from the app.

3. Look for SOC 2, ISO 27001, or HIPAA mentions

These don't guarantee anything by themselves, but their absence in a 2026 SaaS product is a yellow flag. SOC 2 means the company has documented + audited security practices. HIPAA means they have a BAA-eligible plan if you need to handle PHI.

Pithflow is NOT HIPAA-eligible and does not sign BAAs on any plan. If you need HIPAA compliance, use a tool whose vendor signs a BAA with your organization, such as Dragon Medical.

4. Check whether the app phones home unprompted

Some apps send telemetry every few minutes regardless of whether you're using them. That's separate from dictation audio but worth knowing.

Pithflow's desktop app sends:

It also syncs your snippets and dictionary, and uploads a meeting when you record one. No microphone activation outside of a dictation or a meeting you start, no continuous audio stream.

The microphone hijacking question

The most common privacy fear: "Can the app secretly turn on the microphone when I'm not dictating?"

Technically yes — any installed app with microphone permission can listen at any time. Practically, that would be a one-way ticket to a PR disaster for any legitimate company. Plus modern OSes show a microphone-in-use indicator (red dot on macOS, badge on Windows 11) that catches this kind of thing.

For Pithflow specifically: the app only activates the microphone when you press the configured hotkey or start a recording in the Meetings tab. The mic indicator on your OS will appear during that window only. If you ever see the indicator while you're not actively dictating, that's a bug we'd want to know about.

The realistic threat model

Most dictation users aren't being targeted by attackers. The actual risks are:

  1. Background audio in your recordings. A coworker says something confidential while you're dictating; that audio is in the file the model receives. Mitigation: dictate in private spaces for sensitive work.
  2. The vendor changes their privacy policy. Future you finds out that audio is now retained for training. Mitigation: review the policy after major company changes (acquisition, founding-team departure, pivot announcement).
  3. The vendor's server is breached. Audio in flight or in temporary processing buffers could be exposed. Mitigation: pick vendors with documented security practices.
  4. You install a sketchy free dictation app. Many free apps in adjacent categories make money by selling data. Mitigation: pay for the tool. The economics make sense for legitimate vendors.

The practical playbook

  1. Pick a vendor with explicit, audit-passing privacy claims.
  2. Don't dictate next to other people speaking unless you're OK with that audio being processed.
  3. Turn off cleanup history if you don't need it (or use a tool like Pithflow, where your dictation history stays on your computer).
  4. Watch the mic indicator. If it appears outside of dictation, file a bug.
  5. If you handle HIPAA-controlled data, only dictate it into a tool whose vendor signs a BAA with your organization, such as Dragon Medical. Pithflow does not.

Try Pithflow free

Voice dictation that's faster than typing. Hold a key, speak, get clean text in any Windows app. Free tier: 2,000 words a week, no credit card.

Get it from Microsoft Store