> ## Documentation Index
> Fetch the complete documentation index at: https://docs.openwhispr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# GDPR and your data rights

> What rights you have over your data, how to exercise each one, and what business customers need for their own compliance.

You can get a copy of your data, correct it, delete it, or tell us to stop
processing it. Some of that you can do yourself in the app; the rest is one email
away.

Email [support@openwhispr.com](mailto:support@openwhispr.com) for any request you
can't complete in the app. A person handles it — there's no form to find.

## Your rights and how to use each one

| Right                                             | How                                                                                                          |
| ------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| **Access** — a copy of what we hold               | Email [support@openwhispr.com](mailto:support@openwhispr.com) and we'll put a full export together           |
| **Portability** — your content in a usable format | Export your notes as Markdown yourself ([saving notes as files](/guides/notes)), or ask us for a full export |
| **Correction**                                    | [Change your email address](/help/account/change-your-email) yourself, or ask us for anything else           |
| **Erasure**                                       | [Delete your account](/help/account/delete-your-account) in the app, or ask us                               |
| **Restriction and objection**                     | Email [support@openwhispr.com](mailto:support@openwhispr.com)                                                |
| **Complaint**                                     | You can lodge one with your supervisory authority at any time                                                |

Deleting individual notes, clearing your local history, and turning off cloud
features are all things you can do yourself — see [what OpenWhispr stores, and
for how long](/help/privacy/what-we-store-and-for-how-long).

## Getting a full export

You can export your notes yourself as Markdown, mirroring your folder structure.
For **everything we hold** — notes, transcription history and account data
together — email [support@openwhispr.com](mailto:support@openwhispr.com) and ask
for a full export. We'll put it together and send it to the address on the
account.

<Note>
  A formal request doesn't need special wording. Say what you want in plain
  language and we'll treat it as the request it is. Tell us the email address on
  the account so we can find it.
</Note>

## Where your data is processed

OpenWhispr is operated from the **United States**, and we and our sub-processors
process personal data primarily there. For transfers out of the EEA, the UK and
Switzerland, our [DPA](https://openwhispr.com/dpa) applies the first mechanism
that fits: an adequacy decision where the destination has one, and otherwise the
**Standard Contractual Clauses** — Module Two, controller to processor — with the
UK Addendum for UK data and the Swiss adaptations for Swiss data.

If you'd rather your content never left your machine at all, local and
self-hosted modes are the answer: [where your voice and text
go](/help/privacy/where-your-data-goes) explains the difference.

## Training

Your content is never used to train AI models, and our providers are contractually
held to the same. That's [its own article](/help/privacy/is-my-data-used-to-train-ai)
because it's the question we're asked most.

## If you're a business customer

For your own GDPR compliance you'll usually need three things, and all three are
published:

* **The DPA** — [openwhispr.com/dpa](https://openwhispr.com/dpa). It's incorporated
  into our terms, so it already applies. If your legal team needs it signed as a
  counterpart, email [support@openwhispr.com](mailto:support@openwhispr.com).
* **The sub-processor list** — Annex 3 of the DPA, with the live version on our
  [trust centre](https://trust.openwhispr.com).
* **Our security controls** — summarised in [how OpenWhispr is
  secured](/help/privacy/how-openwhispr-is-secured), with the full set on the trust
  centre.

We hold a GDPR attestation (2026, through our compliance platform). [Answering a
security review](/help/privacy/for-your-it-team) collects everything a vendor
assessment tends to ask for.

## FAQ

<AccordionGroup>
  <Accordion title="How long does a request take?">
    We aim to deal with it well inside the one-month period the GDPR allows, and
    usually much sooner. If a request is complex we'll tell you.
  </Accordion>

  <Accordion title="Do I have to delete my account to have my data erased?">
    No. Deleting the account is the fastest complete route, but you can ask us to
    erase specific data instead. If you want to stop paying without losing
    anything, [cancelling](/help/account/cancel-your-subscription) is a different
    thing again.
  </Accordion>

  <Accordion title="Are you a controller or a processor?">
    Both, depending on the data. For content you put through the product we act as
    a processor on your behalf. For your account and billing data we're the
    controller. The [DPA](https://openwhispr.com/dpa) sets out the split.
  </Accordion>

  <Accordion title="What about CCPA?">
    Californian users have the right to know what's collected, to request
    deletion, and to opt out of sale. We don't sell personal information. The
    [Privacy Policy](https://openwhispr.com/privacy) covers it.
  </Accordion>
</AccordionGroup>

<Snippet file="still-need-help.mdx" />

## Related

* [Deleting your account](/help/account/delete-your-account)
* [What OpenWhispr stores, and for how long](/help/privacy/what-we-store-and-for-how-long)
* [Answering a security review](/help/privacy/for-your-it-team)
* [Privacy Policy](https://openwhispr.com/privacy) · [DPA](https://openwhispr.com/dpa)
