Built to protect every
word you say.
Data controls, admin enforcement, and independent audits to prove it.
Trusted by security leaders

“Most vendors hand you one privacy switch and a promise. Wispr gave me separate controls for training storage, and retention. That's the strongest endorsement I can give a vendor.”

“Most AI companies selling into the enterprise ask you to trust them. Very few show you the architecture and let you verify it for yourself. Wispr does.”
What we collect
Only what's needed to turn your voice into text, and only when you ask.

Dictation only records when you press your shortcut, and stops when you release it. Notetaker detects when you join a meeting but doesn't transcribe until you click Start Notetaker.
Flow reads limited, relevant text from the app you're dictating into, enough to spell names right and match formatting, and only while you're dictating. Turn it off in Settings. Admins can disable it org-wide on Enterprise.
Notetaker can connect to Google Calendar Outlook, both optional. Calendar access is read-only and includes contact and directory lookups used to match attendee names to speakers. We never write to your calendar.
How we use it
To deliver the product. Training on your data is a choice you make.

The "Improve the model for everyone" setting covers all of your Wispr Flow data, across Dictation and Notetaker. Anyone can turn it off. On Enterprise it's off across the organization and enforced in your MSA and DPA.
Customer content is processed by third-party AI and language model providers to deliver the service. They process it solely to provide the service, and it's generally deleted within 30 days. Our current subprocessor list is published in the Trust Center.
Retention
You choose what's kept, for how long, and on which machine.

Dictation cloud storage controls whether transcripts and audio are stored on our servers at all. Turn it off and audio is discarded once it's transcribed.
Local data storage controls whether dictation history is kept on your computer: store it, auto-delete every 24 hours, or never store it. Desktop today, with mobile coming soon.
Governance
Set policy once and apply it across the organization. Members can always choose something stricter than the org policy, never looser.

On Enterprise, model training is off across the organization and enforced in your MSA and DPA.
Set dictation cloud storage for the whole organization, or leave it to individual users.
Set how dictation history is handled across the org: leave it to individuals, auto-delete every 24 hours, or never store locally.
Make context awareness available to your team, or disable it for everyone.
Turn Notetaker on or off for the organization, and require a consent confirmation before every meeting.
Single sign-on with SAML, SCIM provisioning, and MDM deployment, all managed from the same admin portal.
Assign roles so each user's access to org settings, user management, and data controls matches their responsibility.
Team membership and activity are tracked automatically, with manual export available today.
Built to keep your words safe.
Every plan gives users control over model training, storage, and retention. Enterprise adds org-wide enforcement, provisioning, and audit logs.
Compare plansNo model training
Model training is off for every user on Enterprise plans, with no ability to turn it on.
Retention controls
Control whether dictation data is stored in our cloud. And control local retention on devices: store normally or auto-delete after 24 hours.
Data minimization
Flow reads only the on-screen text and app you're dictating into — enough to format correctly, nothing more. Turn it off anytime in Settings.
Manual activation
Dictation only activates when you trigger it with a keyboard shortcut. Notetaker detects when you join a meeting, but only begins transcribing when you click 'Start Notetaker'
Admin-enforced policy
Admins can enforce whether dictation data is stored in our cloud at all, and set retention settings org-wide.
Role-based access control
Each user's access is restricted based on their assigned role, so permissions always match responsibility.
SSO, SCIM & MDM
SSO/SAML with enforcement, SCIM provisioning, and MDM deployment are all managed from the same admin portal.
Audit logs
Team membership and activity are tracked automatically, with manual exports available today.
Yes, and you control most of it. Dictation transcripts and audio are stored on Wispr servers only if Dictation cloud storage is on. Separately, you choose whether dictation history is kept on your computer: keep it, auto-delete every 24 hours, or never store it. That one is desktop today, with mobile coming soon.
Notetaker is different: meeting transcripts are kept so you can come back to them, and meeting audio is retained encrypted for a short period so you can resume a meeting and so we can verify transcription quality.
Customer content is also processed by third-party AI and language model providers to deliver the service. They process it solely to provide the service, and it's generally deleted within 30 days. Our current subprocessor list is published in the Trust Center.
Only if you allow it. The "Improve the model for everyone" setting covers all of your Wispr Flow data, across both dictation and Notetaker, and any user can turn it off.
On Enterprise, model training is off across the organization and enforced in your MSA and DPA, so individual users can't turn it back on.
Third-party AI and language model providers we work with process your data solely to deliver the service and don't train their models on it.
Limited, relevant text from the app you're dictating into, and only while you're dictating. It's how Wispr Flow knows to spell a colleague's name correctly or match the tone of the app you're writing in.
You can turn it off in Settings at any time, and admins can disable it for the whole org.
No. Dictation only records when you press your shortcut, and stops when you release it.
Notetaker works differently, because it's a meeting recorder. It detects when you join a meeting, but only begins transcribing when you click “Start Notetaker.”
Wispr Flow runs a lightweight background process to detect your dictation shortcut, the same permission a password manager or clipboard tool uses to respond to a hotkey. It doesn't record, log, or transmit anything you type outside an active dictation session. Wispr Flow launches at login like most desktop utilities, and admins can control this via MDM.
Yes. Admins set policy once in the admin portal and it applies to every member. Individuals can choose something stricter, never looser.
Model training is off across the organization and enforced in your MSA and DPA. Dictation cloud storage can be turned off for everyone, so transcripts and audio are never stored on Wispr servers. Dictation history on devices is set the same way: leave it to individuals, auto-delete every 24 hours, or never store it locally. Context awareness can be made available to the team or disabled for everyone. Notetaker can be turned on or off org-wide, with an optional consent confirmation before every meeting.
Yes, all managed from the same admin portal: SSO/SAML with enforcement, SCIM provisioning, and MDM deployment across major device management providers.
Yes. Admins can assign roles with different levels of access to org settings, user management, and data controls, so permissions match responsibility.
Yes. Audit logs are available for export from the admin portal today. API and SIEM connectors are in progress.
Wispr Flow runs in the cloud, so everyone gets the newest model instantly and dictation doesn't drain your battery the way local processing would. We don't offer on-prem, private tenant, or offline deployment today.
Yes. We work with EU and UK customers under a Data Processing Agreement with Standard Contractual Clauses, the standard legal mechanism for cross-border data transfer. Data is processed and stored in the United States, and we don't currently offer data residency outside the US.
In the United States, on AWS. The primary region is Northern Virginia, with failover in Northern California.
Everything is encrypted in transit with TLS 1.2+ and at rest with AES-256. Internal access is limited to authorized personnel and every access is logged. Transcription happens in the cloud rather than on your device, which is what enables real-time speed and accuracy.
SOC 2 Type I is complete, audited by A-LIGN in April 2026 with a clean unqualified opinion. Our SOC 2 Type II audit is complete and the report is expected in September. We've been recommended for ISO 27001 certification and the certificate is pending issue. HIPAA support is available on any plan with a signed BAA, and our HECVAT Full is complete.
Notetaker reached general availability after the current audit period began, so it will be covered in the next one.
Reports are available through the Trust Center.
Any user can accept the Business Associate Agreement in Settings → Data and Privacy, on any plan. Admins can accept it for the whole organization from the admin portal, which enables HIPAA support for every user automatically.
Accepting a BAA turns off Notetaker and Scratchpad. Notetaker's subprocessors aren't covered by BAAs yet, so it isn't HIPAA compliant today. We intend to get there.
Yes. Wispr conducts an annual third-party penetration test following an OWASP-based methodology. Our next test is scheduled for the end of September and includes Notetaker. Reports are available through the Trust Center.




