Skip to content

Alternatives

"Private" is a claim. Here is what six vendors actually state.

What happens to your voice in six Mac dictation apps — what's sent, what's kept, and whether it can train a model — checked against each vendor's own site.

· 10 min read

On this page (11)
  1. Never leaves the machine, in the vendor's own words
  2. Local for the core job, with a stated exception
  3. Cloud by design, with a stated opt-out
  4. The table
  5. What "verifiable how" is doing in that table
  6. Why any of this is worth checking at all
  7. Who actually needs to care about this
  8. What a privacy policy is a promise about, and what it isn't
  9. The practical version of all of this
  10. One more distinction worth making
  11. Picking one

Every dictation app on the market says some version of "we care about your privacy," and the phrase is close to meaningless on its own — it costs nothing to write and nobody checks it before shipping. What can be checked is narrower and more useful: does the vendor's own site say your audio is sent anywhere, does it say what happens to it once it arrives, and does it say whether any of it can be used to train a model you have no relationship with. This page reads six vendors' own words on those three questions rather than taking anyone's marketing claim at face value, including this app's own.

Three separate questions get run together under "private," and it's worth keeping them apart. Does audio leave the machine at all? If it does, is it stored anywhere after the transcript comes back? Can it be used to improve a model that other people's dictations also feed? An app can answer each of those three differently, and the honest comparison keeps score on all three rather than collapsing them into one word.

Never leaves the machine, in the vendor's own words

Coii VoiceInput

Model weights are fetched once, on first run, from a public model host. A licence activation happens when you enter a key, and there's a clock check at launch. That's the complete list of network activity — none of it happens during a dictation, no audio or transcript is ever sent anywhere, there's no account to attach either to, and the app works identically with Wi-Fi off.

History3 of them, on your Mac
  • 09:024.9sTell the team the migration slipped a day, nothing else changed.Slack
  • 09:447.1sThe retainer clause needs a start date before we can sign.Mail
  • 10:152.3sApproved.Notes
Three dictations, on one Mac, that never became network traffic. Not a setting that was switched on — there's nothing in the app that could send them.

VoiceInk

Checked on tryvoiceink.com today: their own site states VoiceInk "processes all voice transcription locally on your device" and that "your voice data never leaves your Mac," with an optional Cloud Enhancement step that is off by default and, when enabled, sends only the transcribed text — never audio — to be cleaned up. It's also open source, which is a different kind of assurance than a policy: the claim is, in principle, something anyone can go and verify by reading the code rather than trusting the sentence. The comparison covers the rest of a genuinely capable app.

MacWhisper, in local mode

Checked on macwhisper.com today: the site states it uses local models to transcribe and separately promises you can "process sensitive content locally without data ever leaving your Mac." It also integrates with local AI tools like Ollama and LM Studio for anyone who wants the entire pipeline, including any post-processing, kept off the network. Free forever for the local dictation and transcription tier, with Pro at €64 once. The comparison has the rest.

Local for the core job, with a stated exception

BetterDictation

Checked on betterdictation.com today: the core dictation runs on the device with no cloud round-trip, on Apple silicon only. Separately, an optional Pro add-on at $2/month states plainly that it "uses OpenAI" for post-processing and needs internet access — meaning the transcribed text, not raw audio, leaves the Mac if and only if you turn that feature on. That's a precise, stated exception rather than a vague one, which is worth crediting. The comparison sets out the rest.

superwhisper

Checked on their Pro documentation today: local voice models are listed among what a Pro licence includes, and the free tier is described as including limited cloud models — meaning which tier and which model you're running determines whether your audio stays local. Their pricing is $8.49/month, $84.99/year, or $249.99 once, checked on their comparison page. If privacy is the deciding factor, the practical step is confirming which model you're actually using, not assuming from the "local-first" framing alone. The comparison covers the rest of a much larger product.

Cloud by design, with a stated opt-out

Wispr Flow

Checked on wisprflow.ai/pricing today: dictation is a cloud service by architecture — speech is sent to their servers to be transcribed, which is also how a learned vocabulary syncs across your devices and how the meeting notetaker works. Their site states you can "opt out of model training at any time" and "choose what's stored and delete it any time." The opt-out existing is real and worth using if you stay on the platform; the default, by the site's own wording, is that training is on unless you turn it off. The comparison covers the rest of a considerably more capable product on almost every other axis.

Apple Dictation

Free and already installed. Apple's own guide states you can check Keyboard settings to see whether voice inputs and transcripts for general text Dictation "are processed on your device and not sent to Siri servers" — so the honest answer here is that it depends on your Mac and your settings, and it's worth checking rather than assuming either way. Turning on Dictation also offers to share audio recordings with Apple, which you can decline. The comparison has the rest.

The table

Audio ever leaves the Mac Stated model training Verifiable how
Coii VoiceInput No, in its only tier No Vendor statement
VoiceInk No (optional text-only add-on) Not stated Vendor statement, open source
MacWhisper (local) No Not stated Vendor statement
BetterDictation No (stated exception for optional Pro) Not stated Vendor statement
superwhisper Depends on tier/model Not stated Vendor statement, tier-dependent
Apple Dictation Depends on setting Not stated Check Keyboard settings
Wispr Flow Yes, by design Yes, opt-out available Vendor statement

What "verifiable how" is doing in that table

A claim you have to take on faith and a claim you can check are not the same strength of assurance, even when both vendors are telling the truth. Most of the apps above ask you to trust a sentence on a marketing page — which is completely normal, and not a reason to distrust any of them specifically, but it is worth naming as a limit. VoiceInk being open source is the one entry on this page where the claim is, at least in principle, independently checkable rather than only assertable. That is a genuinely different category of trust, and it costs VoiceInk nothing to offer and most vendors nothing to withhold — which is exactly why it's worth noticing when a vendor does it anyway.

Why any of this is worth checking at all

Dictation is an unusually intimate category of software, because unlike most apps, what it processes is close to a transcript of your unfiltered thinking — drafts you haven't sent, numbers you haven't decided to share, names you were still deciding whether to mention. A photo app or a to-do list handles things you already chose to write down; a dictation app hears the sentence before you've finished deciding whether you like it. That is a reasonable basis for caring more about where the words go than you would for most other categories of software, and it is also exactly the reasoning a legal, medical or research workflow applies when it rules out cloud tools entirely, regardless of any individual vendor's track record.

None of this is a claim that the cloud vendors above are careless with your data — Wispr Flow's stated opt-out and deletion controls are real commitments that a lot of companies don't bother offering. It's a claim that "sent somewhere, with controls" and "never sent" are architecturally different guarantees, and only one of them survives a change of ownership, a policy update, or a future feature that quietly needs more data than the current one does.

⌥ Space→ Mail4.4s

The retainer needs a start date before either of us can sign it.

A sentence that never became a network request. The privacy property here isn't a setting that was turned on — it's the absence of anywhere for the audio to go.

Who actually needs to care about this

Everyone benefits from a clear answer to "where does my voice go," but some readers arrive at this question with a lower tolerance for ambiguity than others, and it's worth naming who they are. Lawyers dictating anything covered by privilege. Clinicians dictating notes that touch protected health information, where the compliance question isn't optional. Journalists dictating around sources they've promised confidentiality. Anyone under an NDA who dictates client names, deal terms or unreleased product details as a matter of routine. For all four groups, "the vendor has a reasonable privacy policy" is a materially different bar than "the audio never leaves the device," and only the apps in the first two sections of this page clear the second bar.

For everyone else — the much larger group dictating grocery lists, Slack replies and blog drafts — a stated, honest cloud policy with real opt-out controls, like Wispr Flow's, is a perfectly reasonable choice, and choosing it isn't careless. The point of this page isn't that cloud dictation is unsafe. It's that "private" means something specific and checkable, and the right amount of caution to apply depends entirely on what you're actually saying into the microphone.

What a privacy policy is a promise about, and what it isn't

It's worth being precise about what even a well-written, sincerely honored privacy policy actually guarantees, because the category of assurance matters as much as the vendor's good faith. A policy is a statement about current intent, backed by current management, under current ownership, under current law. All four of those can change, and when any of them does, the policy is generally the first thing that gets rewritten — not because the company is acting in bad faith, but because a new owner, a new regulatory environment, or a new feature that needs more data than the old one did routinely triggers a policy update as a matter of course, and users are notified, not consulted.

An architecture where the data was simply never transmitted anywhere doesn't have that exposure, because there's no data sitting on a server for a future policy to reinterpret. That's not a claim that any specific vendor above is untrustworthy — it's a claim about the structural difference between a promise and a fact, and it's worth understanding the difference before deciding how much weight to put on any single vendor's current wording.

The practical version of all of this

If you've read this far because a specific situation prompted the question — a new client with a strict NDA, a hospital's compliance requirement, a newsroom policy about source protection — the practical next step is usually narrower than picking a product from this page. It's confirming, in writing if your situation requires it, exactly which of the three questions from the top of this page your specific use case actually cares about. Some compliance requirements only care about the training question and are satisfied by an opt-out. Others require the strict architectural guarantee and rule out anything that ever leaves the device, opt-out or not. Knowing which one you're actually solving for narrows this table considerably before you've spent any money.

One more distinction worth making

It's tempting to treat "local" and "private" as synonyms, and they're close enough that conflating them rarely causes real harm — but there's a narrow case where they come apart. An app can process audio locally and still, in principle, log metadata about your usage for analytics, or phone home with a crash report that happens to include a fragment of recent activity. None of the vendors named on this page are alleged to do that, and most modern analytics and crash-reporting tools are built specifically to exclude content like transcripts. But "the transcription happens on my Mac" and "literally nothing about my usage of this app ever reaches the vendor" are two separate claims, and a vendor's site stating the first doesn't automatically confirm the second. If that distinction matters to your specific situation, it's worth checking a vendor's stated network activity as a whole, not only the sentence about where transcription happens.

Picking one

If you also need to transcribe files, VoiceInk and MacWhisper are both local for that job and MacWhisper's free tier covers it at no cost. If you want the largest local feature set and are comfortable confirming which of superwhisper's models you're running, it's the biggest product here that can stay fully on-device. If your bar is "nothing leaves the Mac, in every tier, with nothing to check," the trial for Coii VoiceInput is thirty days of an app with exactly one tier and exactly one answer to that question.

Questions

Does Wispr Flow train on my voice?
Its site states you can opt out of model training at any time, which means the default is opted in. It also states you can choose what's stored and delete it. Nothing on this page requires you to opt out of anything, because nothing here trains on audio by default.
Is offline the same as private?
No. Offline means the app works with no connection. Private is about what happens to your voice even when a connection exists — whether it's sent anywhere, kept anywhere, or used to train anything.
Which apps state, in their own words, that voice data never leaves the Mac?
Coii VoiceInput, VoiceInk and MacWhisper's local mode. VoiceInk's own site uses the words 'never leaves your Mac'; MacWhisper's says the same about processing sensitive content locally.
Is being open source relevant to privacy?
It's a different kind of assurance. A closed app's privacy claim is a policy you're trusting; VoiceInk being open source means the claim is, in principle, something you or anyone else could verify by reading the code.
Do any private apps still send anything at all?
Coii VoiceInput fetches model weights once on first run, checks a licence and the clock at launch, and sends nothing during a dictation. BetterDictation's optional Pro add-on sends transcribed text to OpenAI if you turn it on. Read what each vendor says a connection is actually used for.