Updated September 3, 2026 · By Sumbat.T

Is Wispr Flow Safe? What Its Own Privacy Pages Say

A microphone, a cloud and a padlock, representing where dictated audio travels

The short answer

  • Yes for ordinary work, with three caveats most articles get wrong. Wispr Flow has disclosed no breach, encrypts audio and transcripts in transit and at rest, and runs a bug bounty paying up to $5,000 for critical findings.
  • SOC 2 Type II and ISO 27001 are Enterprise-only. Wispr Flow's own privacy page marks both "Available to Enterprise plans only". If you pay $15 a month as an individual, those two badges are not yours. HIPAA is the exception, offered on all plans with a signed BAA.
  • Transcription is always cloud, with no opt-out. Stated twice in Wispr Flow's own documents. There is no offline mode at any tier, so your audio always leaves the machine.
  • "Privacy Mode" no longer exists by that name. The Data Controls page updated 18 August 2026 says the setting "was previously called Privacy Mode". Guides telling you to switch it on are describing an older build.
  • If you want the recording to stay on your machine, that is a different product decision. BlabbyAI writes its History audio to your own disk on Windows and never uploads it, at $8.49/month.

Dictation that keeps the recording on your disk

ChatGPTGoogle DocsGmailWhatsAppMicrosoft Word

Microphone

Your audio does not have to become someone's training set

BlabbyAI is zero data retention on transcription, and on Windows its History saves every recording to your own machine instead of a server. 60 credits a week free, no card.

Add BlabbyAI to Chrome

What "safe" actually means for a dictation app

The question "is Wispr Flow safe" is really four separate questions wearing one coat, and the answer is different for each. Most coverage answers whichever one is easiest and moves on, which is why you can read three articles and come away with three impressions. Before looking at what the company actually publishes, it is worth separating them.

1. Has it been breached?

A factual question with a factual answer. No disclosed compromise of user data.

2. Is it audited?

Certifications exist, but they do not all apply to every customer. This is where most summaries go wrong.

3. Where does my audio go?

An architecture question. No setting changes it, and it is the one that decides whether a policy rule is met.

4. What is it doing while I work?

Context reading, dictionary learning, model training. All configurable, and worth configuring.

Everything below is read from Wispr Flow's published privacy page and its Data Controls page, both of which anyone can check. Where the wording matters, it is quoted rather than paraphrased, because the paraphrases circulating are where the confusion comes from.

Wispr Flow logo

The certifications, and who actually gets them

This is the detail that is most consistently misreported, and it is not a small one. Search for whether Wispr Flow is safe and you will be told it holds SOC 2 Type II, ISO 27001 and HIPAA. All three are indeed listed on the company's privacy page. What the summaries drop is the line printed underneath two of them.

"SOC 2 Type II Compliance. Audited against rigorous trust principles for security, availability, and confidentiality. Available to Enterprise plans only."

Wispr Flow privacy page, read September 2026

The identical restriction appears under ISO 27001. HIPAA is described differently, as available on all plans once a Business Associate Agreement is accepted, which an individual can do inside the app or an administrator can do for an entire organisation. So the three badges split into two groups, and which group you are in depends on what you pay.

CertificationWho it coversWhat it is
SOC 2 Type IIEnterprise plans onlyIndependent audit of security, availability and confidentiality practices.
ISO 27001Enterprise plans onlyInternational framework for managing information security.
HIPAAAll plans, with a signed BAAAccepted in Settings > Data and Privacy, or by an admin for a whole team.

Why this matters more than it sounds

A SOC 2 Type II report describes the controls the audited organisation runs. Wispr Flow scoping it to Enterprise plans is a normal commercial decision and plenty of vendors do the same. The problem is downstream: an individual reads "SOC 2 Type II certified" in a review, assumes it describes the product they are buying, and never sees the qualifier. If you are on Pro at $15 a month and someone asks whether your dictation tool is SOC 2 covered, the accurate answer is no.

Where your audio goes, and why no setting changes it

This is the architectural fact underneath every other privacy question about Wispr Flow, and the company is admirably direct about it. It appears in both documents, in almost the same words.

"Your data is encrypted in transit (while it's moving) and at rest (while it's stored). We use secure cloud servers and limit access to authorized personnel only. Transcription always happens in the cloud to provide the best speed and accuracy."

Wispr Flow privacy page FAQ

"Transcription always occurs on the cloud. This is the best way for us to provide accurate, low latency transcription."

Wispr Flow Data Controls, last updated 18 August 2026

Two consequences follow, and both are practical rather than theoretical. The first is that Wispr Flow does not work without an internet connection, so a flight, a train tunnel or a bad hotel connection means no dictation at all. The second is the one that matters for policy: your audio leaves your computer every single time you speak, and there is no tier, setting or enterprise agreement that changes that. It is not a bug or an oversight. It is how the product is built, and the company says so plainly.

Worth saying clearly, because comparison posts often blur it: this is normal for the category rather than unique to Wispr Flow. BlabbyAI transcribes in the cloud too, and so does Otter. The genuine exception is Superwhisper, which can download and run speech models on the machine. Even there the exception is narrower than it looks, since Superwhisper's own FAQ notes that offline models "only run really well on Apple Silicon macs", which makes local transcription a Mac answer rather than a general one.

What "zero data retention" covers, and what it does not

Zero data retention is the phrase doing the heaviest lifting in this whole category, and it is used loosely enough to be nearly meaningless unless you check the scope. Wispr Flow's version is real, and it is narrower than a casual reading suggests.

"Wispr always maintains zero data retention agreements with all third-party AI providers. All third party AI models used in Flow Dictation are subject to these agreements."

Wispr Flow Data Controls

Read the qualifier. That sentence is a commitment about the outside model vendors Wispr routes your audio through, not a statement that Wispr Flow itself keeps nothing. What Wispr keeps on its own servers is governed by a separate control called Dictation Cloud Storage, which the company describes as storing transcripts, audio and dictation history to enable cross-device features. Those are two different promises, and only one of them is about the vendor you are paying.

The company also names its own exception, which is a point in its favour for candour: certain Notetaker features "rely on features from third party AI providers that are not supported under zero data retention", though it states those providers still cannot use the data for model training. None of this is alarming. It is simply more specific than the phrase implies, and the specificity is the part worth carrying into any comparison.

The renamed setting

If a guide tells you to turn on "Privacy Mode" for zero data retention, it is describing an older build. Wispr Flow's Data Controls page states: "This setting was previously called 'Privacy Mode.' If you had Privacy Mode enabled, your data is not shared for model training. This behavior remains unchanged." The control is now the model-training toggle in Settings > Data and Privacy. Your old setting was carried over, so nothing silently changed, but the name in the instructions no longer matches the name in the app.

The four settings to check in the first two minutes

Every meaningful privacy decision in Wispr Flow lives in Settings > Data and Privacy, and the defaults are reasonable rather than aggressive. Model training is off unless you turn it on. Still, four toggles decide how much the app knows about your work, and they are worth a deliberate pass rather than an assumption.

SettingWhat it doesWhat to do about it
Improve the model for everyoneLets Wispr use your audio, transcripts and edits to evaluate, train or improve AI models.Off by default. Leave it off if you dictate anything confidential.
Context AwarenessReads relevant text from the active app window to improve transcription accuracy.Turn it off if you dictate into documents you would not want read.
Dictation Cloud StorageStores your transcripts, audio and dictation history on Wispr servers for cross-device access.Off means no dictation history syncing. That is the trade.
Auto-add to DictionaryWatches the text box where Flow pasted text to spot spelling edits and learn them.Harmless for most people, worth knowing it monitors the field.

Context Awareness is the one that surprises people. Wispr Flow uses the name of the app you are dictating into regardless of your settings, so it can pitch an email more formally than a chat message, and it reads the surrounding text box to get capitalisation and punctuation right. That is genuinely how the output stays clean. But when Context Awareness is enabled it goes further, and the company's own wording is that "relevant text data from the active app window may be used to improve transcription accuracy". If your active window is a contract, a medical record or someone else's salary, that is the sentence to weigh.

The trade on Dictation Cloud Storage is a real one rather than a free win. Turn it off and your transcripts stop syncing across devices, because the syncing is what the storage is for. Whether that is worth it depends entirely on whether you dictate on more than one machine.

How the main dictation tools handle your audio

Certifications tell you how a company runs its own house. For most people the more useful comparison is simpler: where does the audio go, where does the recording end up, and can the vendor train on it. Those three answers separate these tools more sharply than any badge does.

ToolTranscriptionWhere the recording livesTraining on your dataPrice
Wispr Flow logoWispr Flow
Cloud only, no opt-outVendor servers, if cloud storage onOpt-in, off by default$15/mo
BlabbyAI logoBlabbyAI
Cloud transcriptionLocal disk on Windows, never uploadedZero data retention$8.49/mo
Superwhisper logoSuperwhisper
Local models availableOn device with local modelsNot used with local models$8.49/mo
Otter.ai logoOtter.ai
Cloud onlyVendor serversAccount settings$16.99/mo

The column that tends to decide things is the third one, and it is the one least often compared. Every tool here sends audio to a server to turn it into text. What differs is what happens to the recording afterwards, and that is a design decision each vendor made independently of its certifications.

BlabbyAI logoWindows logo

Where BlabbyAI keeps your recordings

BlabbyAI transcribes in the cloud like the rest of the category, and its transcription runs under a zero data retention policy, as do the Gemma and Llama models behind its custom modes. The part that differs is what happens to the audio itself on the Windows desktop app.

BlabbyAI's History writes the recording to your own disk the instant you stop speaking, before transcription has even begun. The transcript, tokens and timing are stored locally alongside it. All of that data stays on your machine and none of it goes to a server. It was built as a recovery path, so that a dropped connection or a failed transcription never costs you the recording, and you can replay any past audio and re-run it through a different mode or language later. The practical privacy consequence is a side effect of that design: the recording never becomes an asset held by anyone but you.

The BlabbyAI recording shortcut overlay on a Windows desktop

BlabbyAI on Windows. Press the shortcut, speak, and the text lands in whatever field has the cursor. The audio is written to your own disk before transcription starts.

History holds 500 entries by default with the oldest audio evicted first, and the cap is configurable in settings, including to unlimited. Because everything is local, clearing it is a matter of deleting from your own machine rather than trusting a deletion request to propagate through someone's infrastructure.

For readers who work in a browser rather than on a Windows desktop, the BlabbyAI Chrome extension does the same dictation into any text field on any site, on Windows, Mac or a Chromebook, with the same zero data retention transcription. It needs no download and no admin rights, which is often the deciding factor on a managed work laptop where installing a desktop app is not an option in the first place.

Two ways to run it

ChatGPTGoogle DocsGmailWhatsAppMicrosoft Word

Microphone

Windows app or Chrome extension, same dictation

The Windows app adds History, which keeps every recording on your own disk. The extension types into any text field in the browser with nothing to install. Both start free at 60 credits a week.

Add BlabbyAI to Chrome

Match the tool to your actual obligation

Most arguments about dictation privacy go wrong by skipping this step. "Is it safe" has no answer in the abstract, because safety is measured against a specific requirement, and the requirements people are actually operating under differ enormously.

Ordinary work

Emails, documents, notes, code. Encryption in transit and at rest plus training switched off is a proportionate answer. Any of these tools qualifies.

Confidential work

Client material, unreleased work, personal data. Now context reading and where the recording is stored both matter, and they are separate questions.

Audio must not leave

A hard rule that recordings are never transmitted. Cloud transcription cannot satisfy it, whichever vendor you pick. Local models are the only architecture that can.

The middle column is where most professional readers actually sit, and it is the one the marketing pages serve worst, because it is not answered by a certification badge. It is answered by two specific questions: is the app reading the document around my cursor, and does the recording of my voice end up on my disk or on a server. Both have concrete answers for every tool, and neither appears in a compliance logo strip.

It is also worth being honest about the third column, because it is smaller than the internet suggests. A rule that audio must never be transmitted is a real constraint in some regulated settings, but many people who believe they are in that column are actually in the second one, working under an obligation about confidentiality rather than about transmission. Reading your own requirement before shopping saves picking a tool on a constraint you do not have.

A checklist that works on any dictation tool

These questions are worth more than a vendor's security page, because they are answerable for every product in the category and they surface the differences that badges hide. Run them on whatever you are considering, including on us.

  • Does transcription happen locally or in the cloud? If cloud, the audio leaves. No setting alters this, so it is the first question rather than the last.
  • Which certifications apply to my plan? Not which certifications exist. Look for the qualifier under the badge, which is exactly where the Enterprise-only restriction hides.
  • Is model training opt-in or opt-out? Opt-in with a default of off is the good answer. Find the setting yourself rather than trusting the summary.
  • Does the app read the window around my cursor? Many do, for accuracy. It should be a setting you can see and switch off.
  • Where does the recording live afterwards? On your disk or on a server. This is the question most comparisons skip and it is often the one that decides the matter.
  • Does zero data retention describe the vendor or its subprocessors? The phrase is used for both. Read which one is being promised.

Try it on the tool you already use

Run those six questions against whatever is installed on your machine right now. If you cannot answer question five without guessing, that is the answer to question five.

Add to Chrome

The verdict

Wispr Flow is a safe tool for ordinary professional work. No breach has been disclosed, encryption is in place in transit and at rest, model training is off unless you enable it, the controls that matter are visible in settings, and the company runs a bug bounty with legal safe harbour for researchers. Those are the marks of a vendor taking the problem seriously rather than one hoping nobody asks.

The three things worth carrying away are the ones the summaries drop. SOC 2 Type II and ISO 27001 are Enterprise-only, so an individual subscriber is not covered by the badges quoted in reviews of the product they bought. Transcription is cloud-only with no opt-out at any tier, which is a permanent architectural fact rather than a setting. And zero data retention describes the third-party model providers rather than Wispr Flow's own storage, which is governed separately. None of those makes the product unsafe. All three change the answer for someone with a specific obligation to meet.

If what you want is dictation that costs less and keeps the recording on your own machine, BlabbyAI is $8.49 a month against $15, runs zero data retention on transcription, and on Windows writes every recording to your own disk through History rather than uploading it. If you are curious how the two compare on everything other than privacy, there is a full Wispr Flow review and a breakdown of Wispr Flow pricing, plus the wider list of Wispr Flow alternatives.

Frequently asked questions

Is Wispr Flow safe to use?

For ordinary work, yes. Wispr Flow has not disclosed a data breach, it encrypts audio and transcripts in transit and at rest using TLS, and it holds a SOC 2 Type II attestation. Three details on its own privacy pages are worth knowing before you decide, because they are widely misreported. First, the SOC 2 Type II and ISO 27001 certifications are described on the Wispr Flow privacy page as "Available to Enterprise plans only", so an individual on the $15 Pro plan is not covered by them. Second, transcription always happens in the cloud, which the company states plainly and offers no way to switch off. Third, the setting most articles still call "Privacy Mode" was renamed: the Data Controls page updated 18 August 2026 says "This setting was previously called Privacy Mode." If your threat model is ordinary confidentiality, none of that is disqualifying. If it is a hard rule that audio never leaves your machine, no cloud dictation tool meets it.

Does Wispr Flow work offline?

No. The Wispr Flow privacy page states it directly: "Transcription always happens in the cloud to provide the best speed and accuracy." The Data Controls page repeats it as "Transcription always occurs on the cloud." There is no local model option at any price tier, including Enterprise, so the app needs an internet connection to produce text and your audio always leaves the device to be transcribed. This is not a gap in the product so much as a design decision, and it is shared by most of the category. BlabbyAI is cloud-based for transcription too. Superwhisper is the usual exception, though its own FAQ notes that offline models "only run really well on Apple Silicon macs", which makes it a Mac answer rather than a general one.

Does Wispr Flow train its AI on your voice?

Only if you let it, and the default is off. The setting is called "Improve the model for everyone" and lives in Settings > Data and Privacy. Wispr Flow describes it as letting the company use your audio, transcripts and edits to evaluate, train or improve AI models. Separately, and regardless of how that toggle is set, Wispr states it "maintains agreements that no third party AI providers can use your data for model training", so the subprocessors behind the app are contractually excluded from training on you either way. The company also says plainly that it never sells your data and that its business model is selling software rather than information.

What does zero data retention actually mean at Wispr Flow?

It is narrower than most summaries suggest, and the distinction matters. Wispr Flow says it "always maintains zero data retention agreements with all third-party AI providers", which is a statement about the outside model vendors it routes audio through, not about Wispr Flow itself. Whether Wispr stores your transcripts and audio on its own servers is governed by a separate control called Dictation Cloud Storage, which exists to enable persistent, cross-device features. The company also carves out an exception: certain Notetaker features "rely on features from third party AI providers that are not supported under zero data retention", though it states those providers still cannot train on your data. So zero data retention is a real commitment with a defined scope, rather than a blanket promise that nothing is kept anywhere.

Is Wispr Flow HIPAA compliant?

Wispr Flow lists HIPAA compliance on its privacy page and describes it as available on all plans with acceptance of a Business Associate Agreement, which an individual user accepts in Settings > Data and Privacy and an Enterprise administrator can accept for a whole organisation. Note this is the one certification the company does not restrict to Enterprise: the same page marks SOC 2 Type II and ISO 27001 as "Available to Enterprise plans only", while HIPAA is listed as available on all plans once the BAA is accepted. If you are evaluating dictation for clinical work, that distinction between what is available to you and what is available only to a company plan is the thing to check on any vendor, not just this one.

Can Wispr Flow see my screen?

It can read text near where you are typing, if you leave one setting on. Wispr Flow calls it Context Awareness, and its Data Controls page says that when it is enabled "relevant text data from the active app window may be used to improve transcription accuracy." You can turn it off at any time in Settings > Data and Privacy. A second setting, Auto-add to Dictionary, monitors the text box where Flow pastes text so it can detect edits you make to transcribed words and learn spellings. Both are legitimate accuracy features and both are optional, but if you dictate into documents containing information you would not want read, those two toggles are the ones to find first.

Where does Wispr Flow store my dictation?

On its servers, when Dictation Cloud Storage is on. Wispr Flow describes that control as governing whether it stores transcripts, audio and dictation history on its servers, and says the purpose is persistent, cross-device access. Notetaker transcripts are handled separately and are stored in what the company calls its private cloud for cross-device syncing and meeting resumption, with retention configurable in settings. Everything is encrypted in transit and at rest, and access is limited to authorised personnel. The practical point is that the history of what you dictated lives with the vendor by default rather than on your computer, which is a different arrangement from tools that keep recordings locally.

Is Wispr Flow safe for confidential or client work?

It depends on whether your obligation is about encryption or about location. Wispr Flow encrypts everything in transit and at rest, has no disclosed breach, and lets you switch off model training, context reading and dictionary learning. That satisfies most ordinary confidentiality expectations. What it cannot do is keep the audio on your machine, because transcription is cloud-only with no opt-out at any tier. If you work under a rule that says recordings of client or patient conversations must not be transmitted to a third party at all, that rule excludes Wispr Flow, and it excludes almost every cloud dictation tool alongside it. The honest test is to read your own obligation first, then check which of these controls it actually implicates.

What is the safest way to use a cloud dictation app?

Four settings, and they take about two minutes. Turn off model training so your audio is not used to improve anyone's models. Turn off context awareness or its equivalent, so the app is not reading the document around your cursor. Decide whether you want your dictation history stored on the vendor's servers, and switch cloud storage off if you do not. Then check where recordings live: some tools keep audio on your own disk rather than uploading it, which means the recording never becomes someone else's asset. BlabbyAI's History on Windows works that way, saving audio locally the moment recording stops and never uploading it. Those four checks apply to any dictation tool you are evaluating, and they matter more than the certification badges on the marketing page.

Has Wispr Flow ever had a security incident?

No breach of user data has been disclosed. What exists in the review coverage is a set of criticisms about behaviour rather than a compromise: reviewers questioned how much surrounding context the app read before the controls were made explicit, and some early reports described the app as heavy or intrusive on the system. The company has since made context awareness an optional setting you can see and switch off, and it runs a bug bounty program offering rewards up to $5,000 for critical findings with legal safe harbour for researchers who follow its disclosure policy. A published bounty program with stated safe harbour is a reasonable signal, since it means outside researchers have a sanctioned route to report problems.

Check where your own recordings are stored

BlabbyAI is $8.49 a month, zero data retention on transcription, and its Windows History keeps every recording on your disk. Start on 60 credits a week, no card.

Add BlabbyAI to Chrome