Security and data handling

See which providers receive account, audio, transcript or export data, when they receive it and the controls that apply.

Retention
Source audio and transcript text are scheduled for deletion within 30 days.
Speech processing
Deepgram receives raw audio for live and final transcription.
Requested AI functions
OpenAI receives transcript text, not raw audio, when you request an enabled function.
Providers involved in Dicta's data handling
ServiceReceivesWhenControl
CloudflareApplication data, transcript text and private source audioWhile Dicta provides the servicePrivate storage, separate environment bindings and scheduled deletion
WorkOSAccount details needed for authenticationWhen you create an account or sign inAuthentication provider controls and sealed Dicta session cookies
StripeSubscription and payment informationWhen you use paid billingDicta stores customer, subscription and plan references, not full card details
DeepgramRaw audioDuring live and final transcriptionDicta sends mip_opt_out=true; this is not a guarantee of zero operational retention
OpenAITranscript text, not raw audioWhen you request title, review or enabled document functionsRequests use store:false; this is not described as complete zero retention
Google / MicrosoftA produced fileOnly when you connect and request an exportThe exported copy leaves Dicta's deletion controls
PostHogAnonymous product eventsWhile you use product featuresDicta does not intentionally include transcript content in those events

Your controls

Delete a transcript sooner, review every output before use, and choose whether to connect an export provider.

Your responsibilities

Decide whether a matter is appropriate for Dicta, establish recording authority, protect account access and check recipients before export.

Create free account