Dictate

Privacy policy

Effective 25 July 2026.

This policy describes what Dictate collects, why, who else sees it, and how long we keep it. It is written to be checkable against the product rather than to be broad enough to cover anything we might do later. If something here is unclear or looks wrong, email privacy@dictates.app.

1. Who we are

Dictate is operated by the entity identified on our terms page, which is the data controller for the information described here. Contact: privacy@dictates.app.

2. Audio

This is the part most people care about, so it goes first.

If you enable local recording history in the app, copies of your audio are written to your own Mac, under your control, and never uploaded. You can delete them from the app or from Finder.

3. What we hold about you

DataWhyRetention
Email address Identifies your account, receives your receipts, activation links and service notices Life of the account
Transcript text and metadata (timestamp, duration, target app) Your searchable history Until you delete it or close your account
Glossary entries and settings Sync between your Macs Until you delete them or close your account
Device records: a device identifier, a hardware fingerprint hash, app and OS version, and the public key from App Attest Binds your subscription to your Macs — see section 4 Life of the account
Device activity log (dictation events, seconds used, no content) Usage metering and abuse detection 180 days
Device session tokens Keeps you signed in without a password 30 days after expiry or revocation
Email delivery records (recipient, template, delivered / opened / bounced) Deliverability and suppression of bounced addresses 90 days
Subscription records (Stripe customer and subscription identifiers, status, plan) Billing and entitlement Life of the account, then as tax law requires
IP address Rate limiting and abuse detection Transient in our cache; the last seen address is kept on the device record

We never receive your card number. Payment details go directly to Stripe.

4. App Attest, in plain English

On first launch, your Mac generates a private key inside Apple's Secure Enclave and obtains an attestation from Apple confirming the key belongs to a genuine copy of Dictate on genuine hardware. Every request your Mac makes is signed with that key, and we verify the signature.

This is how your subscription is bound to the Macs you actually use without making you manage a Dictate password. It also lets us reject the obvious abuse cases — replayed requests, tampered builds, one subscription distributed to an unbounded number of machines.

The private key never leaves the Secure Enclave, and we never see it. What we store is the corresponding public key, a device identifier we generate, and a hash of a hardware fingerprint. The fingerprint is a one-way hash: it lets us recognise the same Mac after a reinstall, and cannot be reversed to identify your hardware.

5. Legal bases (UK/EU)

6. Who else processes your data

We use a small number of subprocessors. Each is bound by contract to process data only on our instructions.

SubprocessorPurposeRegion
OpenAISpeech-to-text and text cleanupUnited States
StripePayments and subscription managementUnited States / global
ResendTransactional and lifecycle emailUnited States
DigitalOceanApplication hosting and databaseUnited States
CloudflareDNS, website hosting, bot protectionGlobal
PostHogProduct analyticsUnited States
SentryCrash and error reportingUnited States
AppleApp Attest device attestationGlobal

Audio passes through OpenAI only. It is not sent to any other subprocessor listed here.

7. International transfers

Our subprocessors are largely in the United States, so data leaves the UK and EEA. Those transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with the safeguards each provider offers. Details on request from privacy@dictates.app.

8. Analytics and crash reporting

We record product events — app launched, dictation completed, subscription started — to understand what people actually use. Where an event involves an email address it carries a one-way hash, never the address itself. We do not record transcript content in analytics, and we do not sell or share this data with advertisers.

The website sets analytics cookies only. We do not run advertising trackers.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your data, to receive a portable copy, and to withdraw consent. Exercise any of them by emailing privacy@dictates.app. We will respond within one month.

You can delete your account from the app, which removes your transcripts, glossary, settings and device records. Billing records are retained where tax law requires it.

If you are in the UK you may complain to the Information Commissioner's Office; in the EU, to your local supervisory authority. We would prefer you raised it with us first.

10. Security

All traffic is TLS-encrypted. Device tokens are held in the macOS Keychain, marked as non-syncing so they never leave the Mac they were issued to. Your own OpenAI API key, if you use one, is stored in the Keychain and never transmitted to us. Access to production systems is limited to people who need it.

Report a vulnerability to security@dictates.app. See the security page for details.

11. Children

Dictate is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us information, email us and we will delete it.

12. Changes

If we make material changes we will email anyone with an account at least 14 days before they take effect. The effective date at the top of this page always reflects the current version.

Contact

privacy@dictates.app