Trusted by security leaders

“Most vendors hand you one privacy switch and a promise. Wispr gave me separate controls for training storage, and retention. That's the strongest endorsement I can give a vendor.”

Rinki Sethi
Lockstep advisor · ex-CISO, Bill.com, Twitter, Rubrik

“Most AI companies selling into the enterprise ask you to trust them. Very few show you the architecture and let you verify it for yourself. Wispr does.”

Lucas Moody
Lockstep advisor · CISO, Altera · ex-CISO, 
Palo Alto Networks, Rubrik, Alteryx

What we collect

Only what's needed to turn your voice into text, and only when you ask.

Manual activation

Dictation only records when you press your shortcut, and stops when you release it. Notetaker detects when you join a meeting but doesn't transcribe until you click Start Notetaker.

Context awareness

Flow reads limited, relevant text from the app you're dictating into, enough to spell names right and match formatting, and only while you're dictating. Turn it off in Settings. Admins can disable it org-wide on Enterprise.

Connected apps

Notetaker can connect to Google Calendar Outlook, both optional. Calendar access is read-only and includes contact and directory lookups used to match attendee names to speakers. We never write to your calendar.

How we use it

To deliver the product. Training on your data is a choice you make.

Model training

The "Improve the model for everyone" setting covers all of your Wispr Flow data, across Dictation and Notetaker. Anyone can turn it off. On Enterprise it's off across the organization and enforced in your MSA and DPA.

Third-party processors

Customer content is processed by third-party AI and language model providers to deliver the service. They process it solely to provide the service, and it's generally deleted within 30 days. Our current subprocessor list is published in the Trust Center.

Retention

You choose what's kept, for how long, and on which machine.

Dictation in the cloud

Dictation cloud storage controls whether transcripts and audio are stored on our servers at all. Turn it off and audio is discarded once it's transcribed.

Dictation history on your device

Local data storage controls whether dictation history is kept on your computer: store it, auto-delete every 24 hours, or never store it. Desktop today, with mobile coming soon.

Governance

Set policy once and apply it across the organization. Members can always choose something stricter than the org policy, never looser.

Model training policy

On Enterprise, model training is off across the organization and enforced in your MSA and DPA.

Cloud storage policy

Set dictation cloud storage for the whole organization, or leave it to individual users.

Local retention policy

Set how dictation history is handled across the org: leave it to individuals, auto-delete every 24 hours, or never store locally.

Context awareness policy

Make context awareness available to your team, or disable it for everyone.

Notetaker controls

Turn Notetaker on or off for the organization, and require a consent confirmation before every meeting.

Identity and provisioning

Single sign-on with SAML, SCIM provisioning, and MDM deployment, all managed from the same admin portal.

Role-based access control

Assign roles so each user's access to org settings, user management, and data controls matches their responsibility.

Audit logs

Team membership and activity are tracked automatically, with manual export available today.

Built to keep your words 
safe.

Every plan gives users control over model training, storage, and retention. Enterprise adds org-wide enforcement, provisioning, and audit logs.

Compare plans

No model training

Model training is off for every user on Enterprise plans, with no ability to turn it on.

Retention controls

Control whether dictation data is stored in our cloud. And control local retention on devices: store normally or auto-delete after 24 hours.

Data minimization

Flow reads only the on-screen text and app you're dictating into — enough to format correctly, nothing more. Turn it off anytime in Settings.

Manual activation

Dictation only activates when you trigger it with a keyboard shortcut. Notetaker detects when you join a meeting, but only begins transcribing when you click 'Start Notetaker'

Admin-enforced policy

Admins can enforce whether dictation data is stored in our cloud at all, and set retention settings org-wide.

Role-based access control

Each user's access is restricted based on their assigned role, so permissions always match responsibility.

SSO, SCIM & MDM

SSO/SAML with enforcement, SCIM provisioning, and MDM deployment are all managed from the same admin portal.

Audit logs

Team membership and activity are tracked automatically, with manual exports available today.

Data & training
Do you store our data?

Yes, and you control most of it. Dictation transcripts and audio are stored on Wispr servers only if Dictation cloud storage is on. Separately, you choose whether dictation history is kept on your computer: keep it, auto-delete every 24 hours, or never store it. That one is desktop today, with mobile coming soon.

Notetaker is different: meeting transcripts are kept so you can come back to them, and meeting audio is retained encrypted for a short period so you can resume a meeting and so we can verify transcription quality.

Customer content is also processed by third-party AI and language model providers to deliver the service. They process it solely to provide the service, and it's generally deleted within 30 days. Our current subprocessor list is published in the Trust Center.

Do you train on our data?

Only if you allow it. The "Improve the model for everyone" setting covers all of your Wispr Flow data, across both dictation and Notetaker, and any user can turn it off.

On Enterprise, model training is off across the organization and enforced in your MSA and DPA, so individual users can't turn it back on.

Third-party AI and language model providers we work with process your data solely to deliver the service and don't train their models on it.

Screen & context
What can Wispr Flow access, and what does context awareness capture specifically?

Limited, relevant text from the app you're dictating into, and only while you're dictating. It's how Wispr Flow knows to spell a colleague's name correctly or match the tone of the app you're writing in.

You can turn it off in Settings at any time, and admins can disable it for the whole org.

Is Wispr Flow always listening or recording in the background?

No. Dictation only records when you press your shortcut, and stops when you release it.

Notetaker works differently, because it's a meeting recorder. It detects when you join a meeting, but only begins transcribing when you click “Start Notetaker.”

Does Wispr Flow monitor or log my keystrokes?

Wispr Flow runs a lightweight background process to detect your dictation shortcut, the same permission a password manager or clipboard tool uses to respond to a hotkey. It doesn't record, log, or transmit anything you type outside an active dictation session. Wispr Flow launches at login like most desktop utilities, and admins can control this via MDM.

Access & admin
Can admins enforce settings org-wide?

Yes. Admins set policy once in the admin portal and it applies to every member. Individuals can choose something stricter, never looser.

Model training is off across the organization and enforced in your MSA and DPA. Dictation cloud storage can be turned off for everyone, so transcripts and audio are never stored on Wispr servers. Dictation history on devices is set the same way: leave it to individuals, auto-delete every 24 hours, or never store it locally. Context awareness can be made available to the team or disabled for everyone. Notetaker can be turned on or off org-wide, with an optional consent confirmation before every meeting.

Compare plans →

Do you support SSO, SCIM, and MDM deployment?

Yes, all managed from the same admin portal: SSO/SAML with enforcement, SCIM provisioning, and MDM deployment across major device management providers.

Compare plans →

Do you support role-based access control (RBAC)?

Yes. Admins can assign roles with different levels of access to org settings, user management, and data controls, so permissions match responsibility.

Compare plans →

Do you support audit logs?

Yes. Audit logs are available for export from the admin portal today. API and SIEM connectors are in progress.

Deployment & infrastructure
Can this run on-prem, in our own cloud tenant, or offline?

Wispr Flow runs in the cloud, so everyone gets the newest model instantly and dictation doesn't drain your battery the way local processing would. We don't offer on-prem, private tenant, or offline deployment today.

Can you work with EU customers?

Yes. We work with EU and UK customers under a Data Processing Agreement with Standard Contractual Clauses, the standard legal mechanism for cross-border data transfer. Data is processed and stored in the United States, and we don't currently offer data residency outside the US.

Where is data stored, and how is it protected?

In the United States, on AWS. The primary region is Northern Virginia, with failover in Northern California.

Everything is encrypted in transit with TLS 1.2+ and at rest with AES-256. Internal access is limited to authorized personnel and every access is logged. Transcription happens in the cloud rather than on your device, which is what enables real-time speed and accuracy.

Compliance
What certifications and independent audits do you hold?

SOC 2 Type I is complete, audited by A-LIGN in April 2026 with a clean unqualified opinion. Our SOC 2 Type II audit is complete and the report is expected in September. We've been recommended for ISO 27001 certification and the certificate is pending issue. HIPAA support is available on any plan with a signed BAA, and our HECVAT Full is complete.

Notetaker reached general availability after the current audit period began, so it will be covered in the next one.

Reports are available through the Trust Center.

How do I enable HIPAA compliance?

Any user can accept the Business Associate Agreement in Settings → Data and Privacy, on any plan. Admins can accept it for the whole organization from the admin portal, which enables HIPAA support for every user automatically.

Accepting a BAA turns off Notetaker and Scratchpad. Notetaker's subprocessors aren't covered by BAAs yet, so it isn't HIPAA compliant today. We intend to get there.

Compare plans →

Do you conduct penetration testing?

Yes. Wispr conducts an annual third-party penetration test following an OWASP-based methodology. Our next test is scheduled for the end of September and includes Notetaker. Reports are available through the Trust Center.

Person headshot

Built to protect every word you say.