tl;dr
Five questions settle it: does audio leave the device, how long is audio kept, where do transcripts live and for how long, what happens by default before you change any setting, and who else receives the data. Verify what you can: turn off the network and see what still works, and look for a real delete path. Auri Voice transcribes on your Mac by default. The cleanup pass sends the transcribed text (never audio) to the provider you pick — Auri Cloud unless you change it; choose Auri Local in AI settings to keep both steps on the Mac (Apple Silicon). Auri Keyboard on iPhone defaults to cloud dictation, with an On-Device option for English.
Five questions that settle it
These five questions produce specific answers, which are the kind you can hold a vendor to.
- Does my audio leave the device, and when?
- If audio is uploaded, how long is it kept, and is it used for training?
- Where do transcripts live, for how long, and does deleting mean deleted?
- What happens by default, before I change any setting?
- Who else receives the data: model providers, analytics, human reviewers?
Ask them in email or a support ticket so you have the answer in writing. Vagueness is data too: industry-standard and may retain with no timeframe mean the answer is complicated in a direction you would not like.
Audio: uploaded, buffered, or discarded
Audio is the most sensitive part, because your voice carries who is in the room and what the background sounds like. Vendors blur three distinct cases.
- Never leaves: recognition runs on device. Verifiable by turning off the network.
- Uploaded and discarded: sent for transcription, deleted after processing. Ask for the timeframe.
- Uploaded and retained: kept for quality, training, or support. Ask how long and whether you can opt out.
Transcription does not require keeping the recording, so when a vendor keeps audio anyway, ask what you get in exchange.
Ask about failure paths too. Some apps fall back to a server when a local model is missing, mid-download, or unavailable for your language, and a local default that quietly becomes a cloud request is worth knowing about before a sensitive call.
Transcripts outlast the audio
The transcript is what contains names, salaries, medical details, and half-finished thoughts, and it usually outlives the recording by a long way. Ask:
- Is history stored on the device, in the vendor’s cloud, or both?
- Is it encrypted at rest, and can the vendor read it?
- Does deleting an entry remove it everywhere, including backups?
- Is history synced across devices, and can sync be turned off?
- Can support staff view your text when you file a ticket?
Check your own backups as well: a local history file can land in a cloud backup you set up years ago, which quietly moves data you meant to keep on the device.
Whatever app you use, find the delete path once so you are not hunting for it later. In Auri Voice it is Settings > Dictation > History, where the trash button offers Delete all history.
Good answers and red flags
Judge each answer by the default, not the option; the chooser guide makes the full case for why defaults decide what happens to most people's data.
| Question | Good answer | Red flag |
|---|---|---|
| Where does recognition run by default? | On device, no account needed | Cloud, with local available somewhere |
| How long is audio kept? | Not stored after transcription | Retained for an unstated period |
| Is my text used for training? | No, or off unless you opt in | On by default, opt-out only |
| Can I delete history? | Yes, locally and on the server | Contact support and wait |
| What works with no network? | Dictation and insertion | Nothing |
Subprocessors, training, and human review
Data rarely stops at the vendor. AI features often call a model provider, and each hop has its own retention and access rules that a privacy page may compress into one sentence.
- Which third parties receive audio or text, and for which features?
- What are their retention periods, and are they contractually limited?
- Is any content reviewed by humans for quality or abuse handling?
- Is content used to train the vendor’s or the provider’s models?
- Where is data processed geographically, if that matters for your work?
Knowing that a small share of requests may be read by a person changes what you are willing to dictate, so ask about human review directly rather than hoping the policy volunteers it.
Ask for a subprocessor list too. Companies that serve business customers usually maintain one; if there is none, ask support to name the model providers behind the AI features.
How to verify instead of trusting the page
Most claims can be spot-checked in ten minutes, which is faster than reading a policy and shows what the software does rather than what the marketing says.
- Download any language or engine packs, then turn off Wi-Fi.
- Dictate two paragraphs into the app you actually write in.
- Note what fails: recognition, insertion, or the rewrite features.
- Look through settings for history, sync, and cloud toggles.
- Delete one history entry and confirm it is gone after a restart.
- Optionally run a network monitor and watch what the app contacts.
Record the results in a note with the date and app version, since behavior changes across updates.
One caution on the offline test: recognition working offline proves the recognition path is local. It does not prove nothing is uploaded when the network returns, so check sync settings too.
Where Auri stands
The same questions applied to our own products, since a guide asking you to demand specifics should offer them.
- Dictation audio: transcribed on the Mac by a local engine by default. Audio leaves only if you choose the Auri Cloud engine yourself.
- Cleanup text: sent to the provider you pick, Auri Cloud by default, and never the audio. Auri Local in AI settings keeps cleanup on the Mac (Apple Silicon).
- Dictation history: stored on the Mac. Save transcriptions is on by default and can be turned off in Settings > Dictation > History; the trash button's Delete all history clears everything. Audio history (Save audio) is off by default.
- Meeting audio: Keep for 30 days by default. The gear in Meetings > Capture and storage > Saved audio also offers Keep until I delete it and Delete after notes are ready.
- Apple Watch dictation to Mac: audio is encrypted in transit, transcribed on the Mac by a local engine, and deleted after 15 minutes.
- Auri Keyboard on iPhone: cloud dictation by default, with an On-Device option (English-only). In password and PIN fields, iOS swaps in the Apple keyboard, so no third-party keyboard sees them; many apps also block custom keyboards in payment fields, though that is each app's decision. The app's Full Access prompt says "I can't access password or credit card fields."
On training, the app's own wording is "I don't collect any data you type"; the privacy policy carries the specifics, and it is the document to hold us to. For anything beyond this list, email us the question; a written answer you can keep is worth more than a claim on a landing page, including ours.
FAQ
Is "we do not sell your data" a good answer?
It is a narrow one. Selling is a small subset of what can happen to your text: storage, training, subprocessors, human review, and support access all matter more day to day. Ask about retention and defaults instead.
How long should audio be kept?
For dictation, the useful answer is not at all. Transcription does not require keeping the recording afterwards. If a vendor keeps audio, the follow-up is why, for how long, and whether you can opt out without losing features.
Does on-device processing mean nothing is stored?
No. On-device recognition means the audio is transcribed locally, and the transcript can still be saved in history, synced, or included in backups. Local processing and local storage are two separate questions.
How do I test the claims myself?
Turn off Wi-Fi and dictate. If recognition still works, that path is local. Then check for a delete option, look for sync settings, and use a network monitor if you want to see what the app contacts during normal use.
What is the biggest red flag?
A privacy page that describes intentions without numbers or timeframes. The second biggest is a local mode buried in settings while the default sends everything, since defaults describe what happens to most users.