What it covers
Everything you put through the product:- the audio you record
- the transcripts that come back
- your notes
- prompts and conversations with the AI agent
What our providers are held to
OpenWhispr uses third-party providers to run transcription and language models. They’re bound by the same restriction: they process your content solely to deliver the service, with model training disabled or opted out on our accounts, and they’re not permitted to train on it. The current list is published in Annex 3 of the DPA and kept live on our trust centre.If you use your own cloud account
Bring-your-own-key requests go directly from your machine to the provider whose credentials you entered. Managed Enterprise AI sends text prompts directly to your organization’s Bedrock or Azure OpenAI account; transcription audio follows its separately selected speech-to-text mode. OpenWhispr isn’t in those direct provider paths, so your provider agreement and account configuration govern training there. Most providers disable training on paid API traffic by default, but it’s your account and your agreement with them. If training policy is the reason you chose BYOK, check the terms on the key you’re using. Local and self-hosted modes avoid the question entirely: nothing leaves your machine or your network.FAQ
Does turning on cloud backup change this?
Does turning on cloud backup change this?
No. Cloud backup stores your notes so you can reach them from another device.
It doesn’t make them training data.
Do you read my transcripts?
Do you read my transcripts?
Not as a matter of course. Support can only see what you send us in a ticket.
Access to production systems is restricted, logged, and reviewed — see how
OpenWhispr is secured.
Can I get this in writing for a vendor review?
Can I get this in writing for a vendor review?
Yes — the DPA is the document to send, and Section 3 is the clause. Answering
a security review lists everything else
reviewers usually ask for.